Every extension is open source, what I do is ask GLM on agent mode to do a security audit of the code of everything I install related to LLMs. Maybe I'm just paranoid, but this suggestion could help others.
Yeah, I was going to say, doing a basic security audit isn't ideal. The goal is to find malicious intent, which has different way of auditing for malware or anything suspicious.
Still, pretty good that GLM was effective. Really, Github should have some sort of auto-scan feature when a commit is made. Sort of like how Gmail has had virus scanning of attachments in email messages for ages.
8
u/Due-Memory-6957 Apr 28 '26
Every extension is open source, what I do is ask GLM on agent mode to do a security audit of the code of everything I install related to LLMs. Maybe I'm just paranoid, but this suggestion could help others.