Plugin-Probe

Scan LLM plugins for security risks before you install them.

As of June 2026, Plugin-Probe has users in the Developer Tools category.

Usersno change0%
Ratingno change0%
— reviews
Reviewsno change0%
Version
0.4.6
Manifest V3
90-day change · In the last 90 days this extension 3 version updates, changed permissions.

History

7 snapshots

Tracking since Apr 8, 2026.

Not enough history yet for this metric — the chart fills in as we collect more snapshots.
View as table
DateUsersRatingReviewsVersion
Apr 8, 20260.2.0
Apr 19, 20260.2.0
Apr 25, 20260.3.0
May 9, 20260.3.0
May 13, 20260.4.5
May 25, 20260.4.6
Jun 1, 202610.4.6
Now0.4.6

Changelog

  • May 9, 2026
    host_permissions
    https://api.github.com/*, https://github.com/*, https://api.npmjs.org/*, https://pypi.org/*
    https://api.github.com/*, https://github.com/*, https://api.npmjs.org/*, https://pypi.org/*, https://api.osv.dev/*
  • Apr 19, 2026
    host_permissions
    https://api.github.com/*, https://github.com/*
    https://api.github.com/*, https://github.com/*, https://api.npmjs.org/*, https://pypi.org/*

Permissions & access

Permissions
storageactiveTab
Host access
https://api.github.com/*, https://github.com/*, https://api.npmjs.org/*, https://pypi.org/*, https://api.osv.dev/*

Screenshots

Plugin-Probe screenshot 1Plugin-Probe screenshot 2

About

Plugin-Probe — Scan LLM Plugins for Security Risks

Plugin-Probe automatically scans GitHub repositories for LLM plugin security risks and shows a trust badge directly on the page — no setup, no servers, no data collection.

--- THE PROBLEM ---

We scanned 100 publicly available LLM plugins and found that 54% had at least one security issue. These risks range from subtle prompt injection vulnerabilities to malicious code patterns and outdated dependencies with known exploits. Most developers and users have no visibility into these risks before installing or integrating a plugin.

--- HOW IT WORKS ---

1. Visit any GitHub repository containing an LLM plugin.
2. Plugin-Probe automatically fetches and analyzes the code using the GitHub API.
3. A color-coded badge appears in the top-right corner of the page:
   - Green  = SAFE — no significant issues detected
   - Yellow = SUSPICIOUS — medium-risk patterns worth reviewing
   - Red    = SUSPICIOUS — high-risk patterns found, review before installing

Click the badge to rescan. For detailed findings, run the CLI command shown below the badge.

--- WHAT IT DETECTS ---

Plugin-Probe scans for three categories of security risk:

1. Prompt Injection Risks
   Patterns that could allow malicious instructions to hijack LLM behavior — system prompt leaks, jailbreak vectors, and unsafe instruction handling.

2. Code Malware Patterns
   Suspicious code constructs like obfuscated payloads, unexpected network calls, dangerous eval usage, and exfiltration-style patterns.

3. Dependency Risks
   Outdated or flagged packages in requirements.txt, package.json, and other dependency files that have known vulnerabilities.

--- TRUST SCORE ---

Every scan produces a clear verdict:
- Safe: The plugin passed all checks with no significant findings.
- Suspicious (yellow): Medium-risk patterns detected — worth reviewing before use.
- Suspicious (red): High-risk patterns detected — review carefully before installing.

Smart detection recognizes security tools, developer tools, and test files to reduce false positives. Real-time scan progress shows exactly how many files have been analyzed.

--- PRIVACY FIRST ---

Everything runs locally in your browser. Plugin-Probe does not send your data anywhere, does not track you, and does not require an account. Scan results are stored only in your local browser storage.

Optionally add a GitHub token in settings to avoid API rate limits — your token stays on your device.

--- FREE AND OPEN SOURCE ---

Plugin-Probe is free to use and fully open source. Contributions welcome.
https://github.com/prateekparshwa/llm-plugin-malware-scanner

Technical

Version
0.4.6
Manifest
V3
Size
49.24KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
phmighjmbjmnjmhhnakaeepohheophnm
Developer ID
ue1bc4ace27618721152e855aceec3e14
Developer Email
[email protected]
Created
Apr 8, 2026
Last Updated (Store)
May 13, 2026
Last Scraped
Jun 7, 2026
Website
Support URL

Data sourced from the Chrome Web Store · last verified Jun 7, 2026.