Security and trust primitives for AgentPlugins: integrity hashing, SSRF-safe fetch, lifecycle script policy, and wrappers for osv-scanner, OpenSSF Scorecard, and npm provenance.