Secure extension installer for AI coding agents with vulnerability scanning
Project description
extension-agent-installer
Secure extension installer for AI coding agents with vulnerability scanning and credential guidance
Current Version: 1.5.0 | Changelog | Repository
Why This Skill Exists
The AI era brings new security risks.
AI agents like Claude Code, OpenCode, and Cursor have unprecedented access to your digital life:
- Your files and documents
- Your terminal and commands
- Your API keys and credentials
- Your browsing and communication
A single malicious extension can steal your banking credentials, exfiltrate sensitive data, or execute unauthorized transactions.
This skill protects users who cannot verify extension safety themselves.
Many people use AI agents but don't have the technical expertise to:
- Review extension source code
- Identify hidden malicious payloads
- Detect prompt injection attacks
- Understand what permissions an extension requires
Our mission is to promote digital hygiene in the AI era by:
- Never install blindly - Always scan before installation
- Alert to risks - Show vulnerabilities and explain what they mean
- Guide setup - Help users understand what access they're granting
- Empower users - Give everyone the tools to make informed decisions
Don't let your AI agent become a backdoor for attackers. Verify before you install.
Features
- Multi-Client Support - Works with OpenCode, Claude Code, Cursor, Windsurf, Gemini CLI, Codex, GitHub Copilot
- Security Scanning - Dual vulnerability detection using mcp-scan (Snyk) and Agent Trust Hub (Gen Digital)
- Credential Guidance - Step-by-step setup help for non-technical users
- Vulnerability Notifications - Always alerts user before installing risky extensions
- Auto-Detection - Automatically determines extension type and target client
- Dependency Checking - Verifies required tools before installation
- Self-Update - Can update itself from GitHub
Updating
To update this skill to the latest version, send this to your agent:
Update extension-agent-installer from https://github.com/lmt-expert-company/extension-agent-installer
Steps:
1. Fetch SKILL.md from the repository
2. Compare version numbers
3. If newer version available, download and replace current SKILL.md
4. Also update scripts/ and references/ folders
5. Report what changed
Or simply say:
- "update extension-agent-installer"
- "check for updates"
- "обнови скилл инсталлер"
Installation
Quick Install (Recommended)
Using uv (fastest):
# Auto-detect client, install to current project
uvx extension-agent-installer install
# Install globally for all projects
uvx extension-agent-installer install --global
# Specify client
uvx extension-agent-installer install --client opencode --global
Using npm:
# Auto-detect client, install to current project
npx extension-agent-installer install
# Install globally for all projects
npx extension-agent-installer install --global
# Specify client
npx extension-agent-installer install --client opencode --global
Supported Clients
| Client | --client value |
Project Path | Global Path |
|---|---|---|---|
| OpenCode | opencode |
.opencode/skills/ |
~/.config/opencode/skills/ |
| Claude Code | claude |
.claude/skills/ |
~/.claude/skills/ |
| Cursor | cursor |
.cursor/skills/ |
~/.cursor/skills/ |
| Windsurf | windsurf |
.windsurf/skills/ |
~/.codeium/windsurf/skills/ |
| Gemini CLI | gemini |
.gemini/skills/ |
~/.gemini/skills/ |
| Codex | codex |
.agents/skills/ |
~/.agents/skills/ |
| GitHub Copilot | copilot |
.github/skills/ |
~/.copilot/skills/ |
Detect Installed Clients
uvx extension-agent-installer detect
# or
npx extension-agent-installer detect
Manual Installation (Alternative)
Choose your AI client below and copy the instruction to send to your agent.
For OpenCode
Copy and send this to your agent:
Install the skill from repository: https://github.com/lmt-expert-company/extension-agent-installer
Steps:
1. Create directory: .opencode/skills/extension-agent-installer/ (project) or ~/.config/opencode/skills/extension-agent-installer/ (global)
2. Download SKILL.md from the repository and save it to the path above
3. Optionally download scripts/ and references/ folders for full functionality
4. Verify the file was created correctly
For Claude Code
Copy and send this to your agent:
Install the skill from repository: https://github.com/lmt-expert-company/extension-agent-installer
Steps:
1. Create directory: .claude/skills/extension-agent-installer/ (project) or ~/.claude/skills/extension-agent-installer/ (global)
2. Download SKILL.md from the repository and save it to the path above
3. Optionally download scripts/ and references/ folders for full functionality
4. Verify the file was created correctly
For Cursor
Copy and send this to your agent:
Install the skill from repository: https://github.com/lmt-expert-company/extension-agent-installer
Steps:
1. Create directory: .cursor/skills/extension-agent-installer/ (project) or ~/.cursor/skills/extension-agent-installer/ (global)
2. Download SKILL.md from the repository and save it to the path above
3. Optionally download scripts/ and references/ folders for full functionality
4. Verify the file was created correctly
For Windsurf
Copy and send this to your agent:
Install the skill from repository: https://github.com/lmt-expert-company/extension-agent-installer
Steps:
1. Create directory: .windsurf/skills/extension-agent-installer/ (project) or ~/.codeium/windsurf/skills/extension-agent-installer/ (global)
2. Download SKILL.md from the repository and save it to the path above
3. Optionally download scripts/ and references/ folders for full functionality
4. Verify the file was created correctly
For Gemini CLI
Copy and send this to your agent:
Install the skill from repository: https://github.com/lmt-expert-company/extension-agent-installer
Steps:
1. Create directory: .gemini/skills/extension-agent-installer/ (project) or ~/.gemini/skills/extension-agent-installer/ (global)
2. Download SKILL.md from the repository and save it to the path above
3. Optionally download scripts/ and references/ folders for full functionality
4. Verify the file was created correctly
For Codex
Copy and send this to your agent:
Install the skill from repository: https://github.com/lmt-expert-company/extension-agent-installer
Steps:
1. Create directory: .agents/skills/extension-agent-installer/ (project) or ~/.agents/skills/extension-agent-installer/ (global)
2. Download SKILL.md from the repository and save it to the path above
3. Optionally download scripts/ and references/ folders for full functionality
4. Verify the file was created correctly
For GitHub Copilot
Copy and send this to your agent:
Install the skill from repository: https://github.com/lmt-expert-company/extension-agent-installer
Steps:
1. Create directory: .github/skills/extension-agent-installer/ (project) or ~/.copilot/skills/extension-agent-installer/ (global)
2. Download SKILL.md from the repository and save it to the path above
3. Optionally download scripts/ and references/ folders for full functionality
4. Verify the file was created correctly
Usage
Once installed, just give your AI agent a link to any extension:
Install this skill: https://github.com/user/awesome-skill
The agent will:
- Fetch and analyze the extension
- Scan for security vulnerabilities
- Alert you to any risks found
- Ask for your confirmation
- Install to the correct location
- Guide you through credential setup if needed
Example Prompts
Install this MCP server: https://github.com/modelcontextprotocol/servers/tree/main/src/github
Add this plugin to opencode: https://github.com/user/opencode-wakatime
I want a notification plugin for my AI agent
Security
This skill uses two complementary security scanners:
1. mcp-scan (Snyk)
Local static analysis that detects:
- Prompt injection attacks
- Tool poisoning attacks
- Toxic flows
- Malware payloads
- Hard-coded secrets
2. Agent Trust Hub (Gen Digital)
Cloud-based verification backed by Gen Threat Labs:
- Real-time threat intelligence
- Community-reported vulnerabilities
- Trusted developer verification
Vulnerability Handling
| Severity | Action |
|---|---|
| SAFE | Install freely |
| LOW | Warn, install |
| MEDIUM | Ask user |
| HIGH | Warn strongly, require explicit OK |
| CRITICAL | Strongly discourage, require explicit OK |
Supported Clients
| Client | Project Path | Global Path | Docs |
|---|---|---|---|
| OpenCode | .opencode/skills/ |
~/.config/opencode/skills/ |
Docs |
| Claude Code | .claude/skills/ |
~/.claude/skills/ |
Docs |
| Cursor | .cursor/skills/ |
~/.cursor/skills/ |
Docs |
| Windsurf | .windsurf/skills/ |
~/.codeium/windsurf/skills/ |
Docs |
| Gemini CLI | .gemini/skills/ |
~/.gemini/skills/ |
Docs |
| Codex | .agents/skills/ |
~/.agents/skills/ |
Docs |
| GitHub Copilot | .github/skills/ |
~/.copilot/skills/ |
Docs |
Credential Setup
This skill automatically detects when extensions need credentials and guides you through setup:
- Detects required credentials - API keys, tokens, OAuth
- Provides direct links - URLs to get credentials
- Step-by-step instructions - Plain language, no jargon
- Offers to help - Can assist with configuration
Supported Services
| Service | Credential Type |
|---|---|
| OpenAI | API Key |
| Anthropic | API Key |
| GitHub | Personal Access Token |
| Vercel | API Token |
| Sentry | Auth Token |
| Stripe | Secret Key |
| Cloudflare | API Token |
Project Structure
extension-agent-installer/
├── SKILL.md # Main skill file
├── README.md # This file
├── LICENSE # MIT License
├── scripts/
│ ├── scan_extension.py # mcp-scan wrapper
│ └── scan_agent_trust.py # Agent Trust Hub API client
└── references/
├── mcp-scan.md # mcp-scan documentation
└── agent-trust-hub.md # Agent Trust Hub documentation
Inspiration & Resources
This project was inspired by and builds upon:
- Snyk agent-scan - Security scanner for AI agents, MCP servers and agent skills
- Gen Digital Agent Trust Hub - AI agent security scanner
- VoltAgent awesome-agent-skills - Curated collection of 380+ agent skills
- OpenCode Documentation - Official OpenCode docs
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
License
MIT License - see LICENSE for details.
Disclaimer
IMPORTANT: Third-Party Security Tools Disclaimer
This skill relies on third-party security scanning tools and APIs developed and maintained by independent organizations:
- mcp-scan is developed by Snyk - a third-party security company
- Agent Trust Hub is operated by Gen Digital - a third-party security company
The author of this skill:
- Does NOT guarantee the accuracy, completeness, or reliability of security scans
- Is NOT responsible for any security issues that may not be detected by these third-party tools
- Is NOT affiliated with Snyk, Gen Digital, or any other third-party security providers
- Cannot be held liable for any damages resulting from the use of this skill or the third-party security tools it integrates
Users acknowledge that:
- Security scanning is provided by independent third parties
- Third-party tools may have limitations, bugs, or false positives/negatives
- Extensions may be modified after scanning
- Users should always review extension source code before installation
- Security tools may share data with their respective providers (see their privacy policies)
Third-Party Terms:
- Using mcp-scan means you agree to Snyk's Terms of Use and Privacy Policy
- Using Agent Trust Hub means you agree to Gen Digital's Terms and Privacy Policy
Use this skill at your own risk. Always verify extensions manually before installation.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file extension_agent_installer-1.5.0.tar.gz.
File metadata
- Download URL: extension_agent_installer-1.5.0.tar.gz
- Upload date:
- Size: 21.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e0a74138bdf7beb5737691eecabd4e81f6f768c5359ec4b4aa985dac29164385
|
|
| MD5 |
aa82269ba88d1799af0e515c312432d2
|
|
| BLAKE2b-256 |
ceb82465d27fb0cb3958106b020bf7abe0b4958252df7a31bcebb5df319d7d36
|
File details
Details for the file extension_agent_installer-1.5.0-py3-none-any.whl.
File metadata
- Download URL: extension_agent_installer-1.5.0-py3-none-any.whl
- Upload date:
- Size: 8.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
d3a64d4edafe4b1fcf6b3ad6ac024695f7ec1d49d4d3a54e50dd1617191a204b
|
|
| MD5 |
b8b9e363a76aa924ac813707c4a78e1e
|
|
| BLAKE2b-256 |
ae62f32c76462e1070f0e94192fadcfca722169f4a27f12d9805fe3dc740bf61
|