C1 Identity & least privilege
Minimal 0.05 / 1.00
The plugin itself holds no identity of its own: it points the host at one NotFair OAuth connection that, once authorized, can read and write across Google, Meta, X, LinkedIn, Reddit and TikTok Ads, GA4, Search Console, WordPress and GoHighLevel. Which scopes that connection carries is decided by NotFair's private server, not by anything in this repository. The bundled Search Console scripts mint the user's ambient gcloud credentials with the broad cloud-platform scope and fall back to an unscoped token. Authorization beyond that is described only in skill prose (a saved account ID is not proof of access).
C2 Approval gates
Minimal 0.05 / 1.00
Every consequential action this plugin enables (budget, bid and campaign changes, CRM edits, WordPress changes, sitemap submissions) flows through NotFair's remote MCP, and the plugin's only safeguard on that path is instruction text telling the model to get explicit approval. The one write path implemented in this repo, the Strapi SEO push script, shows a real diff and asks y/N, but it refuses to prompt when not on a terminal and tells the caller to pass --yes, which the model can simply add. Two skills also pre-approve unrestricted Bash in their frontmatter, removing the host's per-command prompt while they run. Whatever the host's own approval UI does is not credited to this plugin.
C3 Tool & action scoping
Minimal 0.35 / 1.00
The CMS scripts validate their configured base URL (http/https only, private and loopback addresses rejected, DNS-resolved addresses checked), and the Strapi push refuses stale writes. That validation is not a complete boundary, and the broken-link crawler fetches any URL with no internal-address block. The real tool surface, the remote MCP, is shipped fully enabled with no read-only option in the plugin.
C4 Code-execution isolation
Minimal 0.00 / 1.00
The plugin ships Python and shell scripts that the host agent runs directly on the user's machine, as the user, with access to the home directory and gcloud credentials. Nothing in the plugin isolates them, and two skills pre-approve unrestricted Bash so commands they drive run without a host prompt. The upgrade skill pulls the latest main branch and copies it into the plugin cache, so newly fetched code later runs the same way.
C5 Untrusted input blast radius
Minimal 0.07 / 1.00
The skills routinely have the agent read content the user did not write: competitor pages, crawled sites, CMS content, search data and MCP results. Nothing in the plugin marks that content as untrusted or separates it from instructions, and the same session holds write access to ad budgets, CRM conversations and CMS content plus open web egress. If injected text hijacks the agent, nothing in the plugin stops it leaking data or making changes; any protection comes from the host's approval prompts, which this plugin does not control.
C6 Memory, context & configuration integrity
Minimal 0.10 / 1.00
Skills save business context, personas, change logs and content calendars to a local data directory and read them back in later sessions, with no validation or provenance: whatever the model writes becomes trusted context next time. A project-level .notfair.json switches which account and data directory are used. The CMS scripts also auto-load .env and .env.local from the working directory and up to five parent directories, and send the stored API key as a Bearer token to whatever STRAPI_URL those files name, so a cloned project can redirect credentials.
C7 Third-party extensions
Minimal 0.13 / 1.00
The plugin wires a remote MCP server whose tools and descriptions are whatever NotFair's server returns at each connection, with nothing pinned. The upgrade skill fetches main, hard-resets the marketplace checkout and copies it into the plugin cache with no signature or hash check, and its inline flow is labelled auto-upgrade. Upgraded code and the MCP tools run with the user's full authority and OAuth grants.
C8 Secrets & sensitive-data protection
Minimal 0.05 / 1.00
The setup-cms skill asks the user to paste WordPress application passwords and Strapi full-access tokens into the chat, which puts them in the model's context and the host transcript, then writes them in plaintext to .env.local without restricting permissions. There is no redaction anywhere in the scripts. The plugin ships no telemetry.
C9 Audit & traceability
Minimal 0.00 / 1.00
Plugin code keeps no record of what it did: scripts print progress to stderr and nothing is persisted. The skills ask the model to write change logs and intervention records, but those are model-authored files in a user-writable directory, not an audit trail. Any transcript or server-side history belongs to the host or NotFair's private service.
C10 Limits & kill switch
Minimal 0.35 / 1.00
All 20 HTTP calls in the bundled scripts carry timeouts, retries are capped at three, and the crawler stops at 50 pages by default, though the caller can raise that. Nothing in the plugin bounds the consequential path: there is no spend ceiling, rate limit or count limit on MCP mutations. Pausing or stopping is left entirely to the host.