Hacker News new | ask | show | jobs
by mpalmer 41 days ago
They don't have to reliably assess whether a plugin is malicious.

The checks are a filter so they can apply manual review only to those plugins which pass the baseline (and automatable) requirements.