Agent plugins are being marketed as convenience. That undersells them and, more importantly, under-threat-models them. A plugin for a coding agent is not a theme, a snippet pack, or a harmless preference bundle. It can carry instructions, skills, hooks, app integrations, MCP servers, and policy-shaped defaults. In other words: it