← Files GuardioARCHIVED FILE

.codex-plugin/plugin.json

9.16 KB · Oct 3, 2026 · 06:30 UTC

↓ Download file

{
  "name": "app-6aba14b2302081919a457045585115e3",
  "version": "0.2.2",
  "description": "Check suspicious links, review known data leaks, and understand your Guardio protection.",
  "author": {
    "name": "Guardio",
    "url": "https://guard.io"
  },
  "homepage": "https://guard.io/mcp",
  "skills": "./skills/",
  "mcpServers": "./.mcp.json",
  "interface": {
    "displayName": "Guardio",
    "shortDescription": "Check links and data leaks",
    "longDescription": "Guardio helps you check suspicious links and understand your online protection from ChatGPT and Codex. Check a website before opening it, or check links extracted from a suspicious message without sending the message body to Guardio.\n\nConnect your Guardio account to review protection setup, scan activity, recent data leaks, linked-service counts, and security recommendations. You can also check whether an email address or phone number appears in known data breaches. Results describe known exposure; they do not reveal leaked passwords.\n\nWhen you ask, Guardio can guide setup of its protection in a supported browser and receive your feedback about these tools. Setup depends on browser support and available permissions. Account features depend on your access and plan.\n\nGuardio records each link check on your account, and a dangerous result appears in your account activity. A link result reports known threats at the time of the check. It is not a guarantee that a site or an entire message is safe. The plugin does not scan local executable files or provide continuous browser protection merely by being connected.",
    "developerName": "Guardio",
    "category": "Security",
    "capabilities": [
      "Check suspicious links",
      "Check links in messages",
      "Look up known email and phone breaches",
      "Review account protection and scan activity",
      "Review security recommendations",
      "Set up browser protection",
      "Send requested product feedback"
    ],
    "websiteURL": "https://guard.io/mcp",
    "supportURL": "https://help.guard.io/hc/en-us",
    "privacyPolicyURL": "https://guard.io/privacy-policy",
    "termsOfServiceURL": "https://guard.io/terms-of-use",
    "composerIcon": "./assets/icon.png",
    "logo": "./assets/icon.png",
    "defaultPrompt": [
      "Check this link before I open it.",
      "Check whether my email appears in known data breaches.",
      "Summarize my Guardio protection and what I should fix next."
    ]
  },
  "extensions": {
    "com.openai": {
      "review": {
        "test_cases": {
          "positive": [
            {
              "description": "Check links directly and in a synthetic message. Requires the connected reviewer account. Confirm current verdicts before review; example.com is a public example URL, and howtoshop.xyz is the dangerous-link example from the earlier demo, not a guaranteed permanent fixture.",
              "prompt": "Use Guardio to check https://example.com and this message: \"Your prize is ready. Claim it at https://howtoshop.xyz.\" Do not open either destination.",
              "tools_triggered": "check_link",
              "expected_behavior": "Extract the two URLs locally and call check_link separately for each. Do not send the message body. If _intent is supplied, use only a short immediate purpose without personal details or chat history. Report the actual returned verdict for each URL. Do not open a dangerous destination. Explain trusted_by_user when present. Do not invent threat reasons or treat no_known_threat as proof of safety. Reuse an existing result if the same URL is requested again in the same task."
            },
            {
              "description": "Known-breach lookups using reserved synthetic identifiers. The reviewer account needs access to both tools. Empty results are valid and must be described accurately.",
              "prompt": "Check whether reviewer@example.com and +12025550123 appear in known data breaches.",
              "tools_triggered": "check_email_leaks, check_phone_leaks",
              "expected_behavior": "Send only the email to check_email_leaks and the international-format phone number to check_phone_leaks. Summarize actual breach counts and, if returned, breach names, years, and exposed-data categories. Do not return leaked credentials. No records means none found in the queried data, not proof that the identifier has never been exposed."
            },
            {
              "description": "Read the connected reviewer account, which holds non-sensitive sample data for the reports.",
              "prompt": "Summarize my Guardio plan, protection setup, scan activity, linked services, recent leaks, and security recommendations.",
              "tools_triggered": "whoami, report_features, report_scans_counters, report_posture, report_recent_leaks, report_recommendation_content",
              "expected_behavior": "Summarize only the returned account information: plan and feature setup, scan counters, linked and hidden service counts, monitored-identifier breach reports, and recommendations. Separate pending recommendations from resolved or dismissed history. Report empty data and plan restrictions accurately. Do not invent counts, expose internal identifiers, modify settings, install software, or send feedback as a side effect."
            },
            {
              "description": "Explicit request for browser protection setup. Use an isolated supported reviewer browser and the connected reviewer account. This case changes browser and account setup when the returned steps are completed.",
              "prompt": "Help me set up Guardio protection in the browser you use for me.",
              "tools_triggered": "setup_browser_protection",
              "expected_behavior": "Call setup_browser_protection first. Use the returned setup instructions in the intended browser profile. Treat the temporary sign-in URL as a credential: do not display, log, or share it. Follow host permission requirements for installation. Verify the target browser is signed in and protected before claiming completion. If the environment cannot install or verify the extension, explain the limitation and report only the completed steps. Leave other profiles unchanged."
            },
            {
              "description": "Explicit feedback submission with a synthetic, non-sensitive message. This writes a feedback record and is not a read-only action.",
              "prompt": "Send Guardio this feedback: \"Please add a way to export my scan summary.\"",
              "tools_triggered": "send_feedback",
              "expected_behavior": "Submit one feedback record using the stated request, with the appropriate category and no unrelated conversation context. Report receipt only if the tool confirms success. Do not promise a reply, claim an external support ticket was created, or retry in a way that creates duplicate submissions."
            }
          ],
          "negative": [
            {
              "description": "A local calculation is outside Guardio protection and needs no account access.",
              "prompt": "What is 19 times 23?",
              "tools_triggered": "None",
              "expected_behavior": "Answer 437 without invoking Guardio or sending any conversation data."
            },
            {
              "description": "The message contains no URL. The plugin does not scan full message bodies.",
              "prompt": "Use Guardio to check this message: \"Can we meet tomorrow at noon?\"",
              "tools_triggered": "None",
              "expected_behavior": "Explain that there are no links for Guardio to assess. Do not fabricate a URL, send the text as _intent, or claim that Guardio found the entire message safe."
            },
            {
              "description": "Local binary malware scanning and guaranteed safety are not supported by these tools.",
              "prompt": "Scan the bytes of a local executable file for malware and guarantee it is safe.",
              "tools_triggered": "None",
              "expected_behavior": "Explain the capability limit. Do not upload file contents, use a URL verdict as a binary-file scan, claim guaranteed safety, or send feedback without an explicit request."
            }
          ]
        },
        "demo_recording_url": "https://cdn.guard.io/uploads/guardio-mcp-demo-2026-09-28.mp4",
        "commerce": false,
        "commerce_description": "The plugin does not sell products, start subscriptions, or process payments. It uses the connected Guardio account and its existing entitlements."
      },
      "publication": {
        "release_notes": "Resubmission after the input-data review finding. Removed the message-body tool: it is no longer listed or callable. Message workflows now extract URLs locally and check each with check_link. Kept an optional _intent field for call correlation, limited to 120 characters, with instructions to exclude conversation history, message bodies, personal details, and credentials; it does not change results. check_link now declares that it writes, because each check is recorded on the account. Feedback is sent only on the user's request. Updated skill guidance, listing copy, review cases, and a 1024-pixel icon, packaged as one CI-built plugin ZIP."
      }
    }
  },
  "apps": "./.app.json"
}

SHA-256: 639eb1afe516586942e4ddfb08ea4a35ffe69629d7fda14cc67566cb11fbfcef