Fuzit

Plugin architecture

Plugin architecture documentation.

Fuzit provides a restricted plugin SDK and host.

Commands

bash
fuzit plugin list
fuzit plugin inspect <plugin-id>
fuzit plugin validate plugins/example/fuzit-plugin.json
fuzit plugin enable <plugin-id>
fuzit plugin disable <plugin-id>
fuzit plugin doctor

Capabilities

Plugin manifests can declare:

text
provider
parser
collector
renderer
policy
profile
secret-detector
ranker
graph-enricher

Permissions

Permissions are deny-by-default.

Supported permission areas include:

  • filesystem read paths;
  • filesystem write paths;
  • network allowed hosts;
  • shell execution;
  • environment variables;
  • credentials;
  • persistence.

Filesystem paths must be safe relative paths.

They cannot contain:

  • absolute paths;
  • Windows drive-letter paths;
  • `..`;
  • null bytes.

Network permissions require explicit hostnames.

Shell and persistence default to denied.

Plugin lifecycle

text
discover
   ↓
parse manifest
   ↓
validate compatibility
   ↓
inspect permissions
   ↓
enable/disable decision
   ↓
restricted host

The plugin model exists so extension authority is explicit and auditable.

------------------------------------------------------------------------