Plugin architecture
Plugin architecture documentation.
Fuzit provides a restricted plugin SDK and host.
Commands
bash
fuzit plugin list
fuzit plugin inspect <plugin-id>
fuzit plugin validate plugins/example/fuzit-plugin.json
fuzit plugin enable <plugin-id>
fuzit plugin disable <plugin-id>
fuzit plugin doctorCapabilities
Plugin manifests can declare:
text
provider
parser
collector
renderer
policy
profile
secret-detector
ranker
graph-enricherPermissions
Permissions are deny-by-default.
Supported permission areas include:
- filesystem read paths;
- filesystem write paths;
- network allowed hosts;
- shell execution;
- environment variables;
- credentials;
- persistence.
Filesystem paths must be safe relative paths.
They cannot contain:
- absolute paths;
- Windows drive-letter paths;
- `..`;
- null bytes.
Network permissions require explicit hostnames.
Shell and persistence default to denied.
Plugin lifecycle
text
discover
↓
parse manifest
↓
validate compatibility
↓
inspect permissions
↓
enable/disable decision
↓
restricted hostThe plugin model exists so extension authority is explicit and auditable.
------------------------------------------------------------------------
