No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by github · MCP Server · ★ 344
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is copilot-plugins safe to install? View the security audit →
copilot-plugins The official GitHub Copilot plugins collection ✨ Extend the power of GitHub Copilot with MCP servers, skills, hooks, and other extensibility tools — all in one place. 🔌 What's Inside Skills — Reusable prompts and workflows for common tasks MCP Servers — Model Context Protocol servers that give Copilot new capabilities (coming soon) Hooks — Custom integrations and event-driven automations (coming soon) Extensibility Tools — Building blocks for creating your own plugins (coming soon) 🤝 Contributing We'd love your contributions! Please read our Contributing Guide for details on how to submit pull requests. 📄 License This project is licensed under the MIT License.
| Stars | 344 |
| Forks | 109 |
| Language | PowerShell |
| Category | MCP Server |
| License | MIT |
| Quality Score | 46.9713586979322/100 |
| Open Issues | 35 |
| Last Updated | 2026-08-31 |
| Created | 2026-01-21 |
| Platforms | mcp |
| Est. Tokens | ~15k |
Explore other popular mcp server tools:
copilot-plugins is The official GitHub Copilot plugins collection — MCP servers, skills, hooks, and other extensibility tools for GitHub Copilot.. It is categorized as a MCP Server with 344 GitHub stars.
copilot-plugins is primarily written in PowerShell.
You can find installation instructions and usage details in the copilot-plugins GitHub repository at github.com/github/copilot-plugins. The project has 344 stars and 109 forks, indicating an active community.
copilot-plugins is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: