NebuSec CLI plugin
Use NebuSec Platform security scanning and findings workflows from Codex or Claude Code. The package contains native executables for macOS and Linux on x64 and arm64.
The plugin authenticates with NEBUSEC_PLATFORM_API_KEY or the credential
stored by nebu auth login. It connects to https://platform.nebusec.ai by
default; NEBUSEC_PLATFORM_API_URL overrides the API base URL.
Installation does not sign the user in. When no valid credential exists, the
agent runs nebu auth login --headless, presents a NebuSec Platform URL and a
one-time code, and waits while the user completes sign-in in their own browser.
The saved credential is reused on later runs for the same operating-system
user; unattended CI should use NEBUSEC_PLATFORM_API_KEY instead.
Paid scans are never started with unconditional consent. Ask the agent to estimate first, then provide an explicit maximum price if you want it to run a scan.
macOS Gatekeeper
The first public version is checksum-verified but not Apple-notarized. If macOS blocks the executable, approve the blocked NebuSec executable in System Settings → Privacy & Security, then retry. The launcher never changes Gatekeeper or quarantine settings automatically.
Support
- Product: https://nebusec.ai/
- Privacy: https://nebusec.ai/privacy/
- Terms: https://nebusec.ai/terms/
- Issues: https://github.com/NebuSec/nebu-plugin/issues
License
Use of the NebuSec plugin and service is governed by the NebuSec Terms of Service.