sekar3s/secure-code
v1.0.0MIT
Security guardian: blocks secrets and dangerous commands before they land, scans for OWASP Top 10 patterns, and guides fast, minimal fixes so code ships safely.
MCP servers
Declared configuration, as published in mcp.json. The directory shows indexed content; it never connects to or executes these servers.
vuln-scoutstdio
{
"type": "stdio",
"command": "node",
"args": [
"${PLUGIN_ROOT}/servers/vuln-scout.mjs"
],
"cwd": "${PLUGIN_ROOT}"
}What this package declares
The files a client reads when it loads this plugin, exactly as this revision carries them.
{
"$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
"name": "secure-code",
"version": "1.0.0",
"description": "Security guardian: blocks secrets and dangerous commands before they land, scans for OWASP Top 10 patterns, and guides fast, minimal fixes so code ships safely.",
"author": {
"name": "OctoCAT Platform Team",
"url": "https://github.com/sekar3s"
},
"homepage": "https://github.com/sekar3s/octocat-agent-plugins-demo/tree/main/plugins/secure-code#readme",
"repository": "https://github.com/sekar3s/octocat-agent-plugins-demo",
"license": "MIT",
"keywords": ["security", "appsec", "owasp", "secrets", "cwe", "devsecops"]
}
What else this package ships
These files come with the package and this site does not publish them. They are listed so you know what is there before you install it.
- scan.mjs
- hooks.json
Client extensions
Data this package carries for particular clients. The directory lists the clients named and never reads what is addressed to them.
- com.github.copilotships a directory of files