Hello,
By default, the private plugins can be shown be everyone, with the --private attribute, except if listPrivatePlugins is set to False.
I think that, even if listPrivatePlugins is True, users who haven't the 'trusted' shouldn't list private plugin.
Best regards,
ProgVal