How to tell a plugin will fight your agent, before you install it
Is this plugin safe to install on my agent? Too many tools, two names that overlap, a disclosure you cannot check, a version that is not the one described, a delete that reads like a read: all of it is readable before you install, in about ten minutes, with nothing run.
TL;DR
If you are asking whether a plugin is safe to install on your agent, the registry's green scan is not the answer: of the 23 rogue plugins Manifold Security found under official-looking names in September 2026, the scanner passed 17 as clean. The answer is five things you can read yourself, with nothing installed, in about ten minutes: who published it, how many things it adds and whether their names overlap, what it asks for from your machine and what it says it does not do, whether the version described is the version you get, and whether anything that deletes or runs on its own says so where the agent reads it. Too many tools, or two that overlap, is the first of those and the one most people skip.
The question behind the question
People type it three or four ways. Is this plugin safe to install on my agent. How many plugins can my agent handle. Why does my agent pick the wrong tool since last week. Underneath there are two fears, and it is worth naming them, because the check is different for each.
The first fear is that the plugin will make your agent worse. You install it, and by the third turn the agent is picking the wrong tool or has run out of room to think. That is a plugin fighting your agent's judgment.
The second fear is that the plugin will do things you did not ask for: talk to servers you have never heard of, keep a login on your disk, run in the background, delete something without checking. That is a plugin fighting your control.
Here is the position, and you are welcome to argue with it: a plugin that is going to fight you tells you so before you install it, in the plain-language parts of its listing and its disclosure. The only reason people get surprised is that they trust the summary instead of reading the claims.
Why the green scan is not your answer
On 2026-09-02 Manifold Security reported 23 code-executing plugins published under the two official-looking name prefixes of the OpenClaw host and its ClawHub registry, by accounts unaffiliated with either project. Some could make payments on their own. Some could run commands on the host machine. Some could export the agent's configuration. Six were flagged as suspicious. Seventeen passed.
The registry is honest about what a listing is. Its own documentation says the listing page "is the canonical place for users to inspect what a skill or plugin claims to do before installing it". The word doing the work in that sentence is claims. The protocol these tools are modelled on says the same thing in stronger language: the MCP specification states that "clients MUST consider tool annotations to be untrusted unless they come from trusted servers".
So the reading is not whether the summary looks fine. It is whether the claims hold up against each other. Five signals follow, and none of them needs a terminal.
Signal 1: who published it, and does the name match
Scope squatting is the plain trick behind the 23: give a plugin a name that looks like it belongs to the host project, and publish it from an account that does not. Manifold's example names were ordinary and reassuring, "security-gate", "prediction-market", and the post's warning is that a name under an official-looking prefix "can lead developers to install them believing they are ClawHub-built or ClawHub-endorsed".
The check takes a minute. The listing shows a publisher and a source link. Does the publisher own the source it points at, and does the name claim membership in a project that publisher is not part of? If the name looks official and the publisher does not, stop there. Nothing further down this list rescues a plugin that fails this one.
Signal 2: how many things it adds, and whether their names overlap
This is the question behind "how many plugins can my agent handle", and the honest answer is that the number is the wrong thing to count. Every plugin declares, up front, the list of tools it will add to your agent, and the host reads that declaration before it runs any of the plugin's code; OpenClaw's documentation says the declaration is read "to validate configuration without executing plugin code". So the list is there for you to read too, with zero exposure.
Read it the way your agent will read it: a flat list of names, each with a one-line description. Two names that differ by a single word are a coin flip for the agent unless their descriptions clearly separate them, because your agent chooses between descriptions, not tools. One plugin with two overlapping tools will do more damage than three plugins with none. 4GPTs ships two plugins for this host and reads its own lists this way before every release, because overlap is easy to create and invisible from the inside.
The other half of this signal is weight. Some plugins introduce themselves to your agent in a sentence and keep the manual out of the way until asked. Others put the whole manual in front of the agent on every turn. You cannot measure that before install, but you can read its shape: a listing whose self-description reads like a manual will read like a manual to your agent too, and that is what charging your context window looks like from the outside.
Signal 3: what it wants from your machine, and what it says it does not do
Any plugin that talks to the internet, keeps a login on your disk, runs on a timer, or launches other programs should say so in a disclosure you can read on the listing or at the source. Three questions, in order.
Does it list them at all? A plugin with no disclosure has told you nothing, and nothing is not the same as none.
Are they listed as items you can check, or as a paragraph you have to take on faith? "Contacts one service, for this purpose" is checkable. A wall of prose that explains everything at once is a claim you cannot verify line by line, even when every word of it is true.
Does it say what it does not do? "No other servers are contacted, no analytics, no telemetry" is the most useful sentence a disclosure can contain, because a single counter-example disproves it. A disclosure that never says what the plugin does not do has given you nothing to test.
One more habit: read a warning with its reason. A plugin that admits it launches another program, and says which one and why, is being straight with you. A plugin with a clean record and no explanation has told you less.
What the listing claims
What you can check
Publisher
An official-looking name
Publisher
The account that owns the source it links to
Tools
A count
Tools
The list, read flat, for two names that answer the same question
Weight
A summary
Weight
Whether the self-description is a sentence or a manual
Access
A green scan
Access
A disclosure with checkable items, including what it does not do
Version
A changelog
Version
The version and date the registry actually serves
Deletes
A capability
Deletes
The tool's own description saying it is destructive
Publisher
What the listing claims
An official-looking name
What you can check
The account that owns the source it links to
Tools
What the listing claims
A count
What you can check
The list, read flat, for two names that answer the same question
Weight
What the listing claims
A summary
What you can check
Whether the self-description is a sentence or a manual
Access
What the listing claims
A green scan
What you can check
A disclosure with checkable items, including what it does not do
Version
What the listing claims
A changelog
What you can check
The version and date the registry actually serves
Deletes
What the listing claims
A capability
What you can check
The tool's own description saying it is destructive
Signal 4: whether the version described is the version you get
A listing, a changelog, or a blog post can describe a version you cannot install yet. The registry serves one specific version, with a date. If the description promises that something was added or removed, and the served version predates that change, you get the older behaviour, and the disclosure you just read does not describe what lands on your machine.
Two more things to read on the same page. Does the install run anything of its own? A well-built plugin runs nothing at install time and says so. And how much does it bring with it? A plugin that lists a handful of other packages, each held to a specific version, is a small thing to trust. One that pulls in dozens, or leaves their versions open, is a larger thing to trust every time you update.
Signal 5: whether a delete says it deletes
The disclosure tells you a plugin can delete. It does not stop a deletion. The only thing that stops one is a sentence in the text the agent reads at the moment it chooses.
For trust & safety and security, there SHOULD always be a human in the loop with the ability to deny tool invocations.
That ability is only real if the tool's own description says the word. Before install, read the description of every tool whose name suggests removing, replacing, or waiting. Does it say it is destructive and that it should confirm with you first? Does the one that polls in the background say that it does? If a delete reads like a read, the plugin has taken the human out of the loop before you noticed. 4GPTs writes the word destructive into the description of every tool of its own that is, and would rather a stranger find that sentence than trust a disclosure elsewhere to carry it.
The check, in about ten minutes
No terminal, nothing installed.
- Read the listing for the publisher, not the summary. Publisher, name, source link. If the name looks official and the publisher is not, stop.
- Read the tool list flat. Two names one word apart need descriptions that clearly separate them. Note whether the self-description is a sentence or a manual.
- Read the disclosure as a checklist. Internet, logins, timers, other programs, anything run at install. Items you can check beat prose you must trust. Look for the sentence that says what it does not do.
- Match the served version to the description. The version and date on the listing against whatever the changelog promises. Few dependencies, held to specific versions, nothing run at install.
- Read every destructive or background tool's own description. If it does not say so there, it does not say so anywhere that matters.
Walk away on any mismatch
A tool list that disagrees with the description, a served version that predates the changelog, a negative claim you can disprove: any one of them means the disclosure is decoration, and you cannot trust the parts you could not check.
What a well-behaved plugin looks like, read this way: the publisher and the name agree; the tools are few enough to read and none of them overlap; it introduces itself in a sentence and keeps the manual for later; its disclosure is a checklist that includes what it does not do; the served version is the described one, with nothing run at install; and every tool that deletes or waits says so in its own description. That answers how many plugins your agent can handle better than any number does: as many as pass this reading.
You should not have to hold any of this
If you are earlier in your setup, the install order for a personal AI setup is the read that comes first: host, model, plugins, skills, memory. This piece is the gate between the second step and the third.
The point of running the check once is that you never think about it again. A well-built plugin declares what it does, ships what it declares, and says so in the sentences the agent reads. Once you have seen that it does, it disappears into your agent and you get on with your day. Nobody should have to hold a tool list and a disclosure in their head. That is the plugin's job, and ten minutes is how you find out whether it is doing it.
Sources
- Manifold Security, Scope Squatting: Those @openclaw and @clawhub Plugins Aren't Officially Theirs, published 2026-09-02: 23 plugins, six flagged, 17 passed.
- ClawHub, How it works, for the listing's own description of itself, and the OpenClaw plugin manifest reference, for what the host reads before it loads plugin code.
- The MCP specification, Tools, 2025-06-18, for untrusted annotations and the human in the loop.
- 4GPTs did not run the registry scanner itself and makes no claim about any third-party plugin.
Run the reading on a plugin 4GPTs publishes
The tool list, the disclosure and every tool description are public and Apache-2.0. Read them the way this piece says to, and hold 4GPTs to it.
FAQ
Do not rely on the registry scan: of 23 rogue plugins Manifold Security found under official-looking names in September 2026, 17 passed as clean. Read five things yourself before installing: that the publisher owns the source the listing points at, that the tool list has no two names answering the same question, that the disclosure lists what the plugin contacts, stores and runs as checkable items and says what it does not do, that the version served matches the version described with nothing run at install, and that every tool that deletes or waits says so in its own description.