{"id":4277,"external_id":"plugins_6a6ceacd1df481918fc5f6abe65e439c","name":"endor-labs-agent-kit","display_name":"Endor Labs Agent Kit","developer":"Endor Labs","category":"Security","listing_language":"en","listing_language_details":{"method":"cld-0.13.0/listing-v1","reliable":true,"detected_at":"2026-10-01T13:22:04Z","input_sha256":"322c5bd33959e5b3254b12e6c3116b1ce1aa458a62fa8bf25997722020fb4f46","source_fields":["release.description","release.interface.short_description","release.interface.long_description"]},"version":"2.2.2","skill_count":12,"first_seen_at":"2026-09-30T22:02:35.000Z","last_seen_at":"2026-10-02T18:00:00.211Z","last_changed_at":"2026-09-30T22:02:35.000Z","install_count":null,"research_summary":null,"research_reviewed_at":null,"metadata":{"id":"plugins_6a6ceacd1df481918fc5f6abe65e439c","name":"endor-labs-agent-kit","scope":"GLOBAL","status":"ENABLED","release":{"id":"pluginrel_4ac3014ca56c8191b286e5a0a154e6a9","skills":[{"name":"ai-sast-remediation","interface":{"brand_color":null,"iconography":"bolt","display_name":"AI SAST Remediation","default_prompt":"Use $ai-sast-remediation for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Triages and remediates Endor AI SAST findings with exploit evidence and approval-gated fixes."},"description":"Triages Endor AI SAST findings using exploit-reproduction evidence, data-flow context, and remediation guidance to distinguish actionable vulnerabilities from noise. It can prepare targeted code fixes and, after explicit approval, edit files and open change requests. For exception workflows, it can create or update scoped Endor exception policies only after verified AppSec approval and explicit user confirmation.","plugin_release_skill_id":"pluginrsk_6a90712d604881919646813d22e30c93"},{"name":"cicd-posture","interface":{"brand_color":null,"iconography":"radar","display_name":"CI/CD And Supply Chain Posture","default_prompt":"Use $cicd-posture for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Scores CI/CD and supply-chain posture from read-only Endor and repository evidence."},"description":"Assesses CI/CD and software supply-chain security across an Endor namespace, GitHub organization, selected repositories, or the current repository. It combines existing Endor SCPM, CI/CD, GitHub Actions, and supply-chain findings with read-only repository configuration evidence and optional local CI inspection to produce deterministic scores, critical overrides, prioritized improvements, and explicit data gaps. It does not modify Endor, GitHub, or repository state.","plugin_release_skill_id":"pluginrsk_6a906fd3ca2881918efbb508fe6bf250"},{"name":"configuration-automation","interface":{"brand_color":null,"iconography":"chart","display_name":"Configuration Automation","default_prompt":"Use $configuration-automation for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Finds GitHub-to-Endor onboarding and monitored-branch coverage gaps without making changes."},"description":"Compares GitHub repository inventory with Endor projects, GitHub App coverage, monitored branches, scan profiles, package-manager integrations, dependency resolution, and reachability evidence. It identifies onboarding and configuration gaps and provides targeted setup instructions without changing GitHub, Endor, or source repositories.","plugin_release_skill_id":"pluginrsk_6a9071352bc081919be81e76c3c0fb84"},{"name":"dependency-reviewer","interface":{"brand_color":null,"iconography":"radar","display_name":"Dependency Reviewer","default_prompt":"Use $dependency-reviewer for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Reviews package versions, package risk, or repository dependencies using bounded evidence."},"description":"Evaluates an exact package version, summarizes package risk, or reviews dependencies declared by a repository through one focused workflow. It uses available vulnerability, malware, package-health, license, policy, and Endor evidence to provide a read-only recommendation and clearly identify missing information.","plugin_release_skill_id":"pluginrsk_6a906fd28b84819187d6d0531be87a08"},{"name":"endor-agent-kit-setup","interface":{"brand_color":null,"iconography":"radar","display_name":"Endor Agent Kit Setup","default_prompt":"Use $endor-agent-kit-setup to check Endor Agent Kit readiness.","icon_large_url":null,"icon_small_url":null,"short_description":"Check local Endor Agent Kit readiness"},"description":"Use when checking Endor Agent Kit readiness in Codex, verifying the local Endor CLI, authentication, namespace, GitHub, or toolchain prerequisites.","plugin_release_skill_id":"pluginrsk_6a906fd539a081919a5579409ff787e5"},{"name":"findings-browser","interface":{"brand_color":null,"iconography":"search","display_name":"Findings Browser","default_prompt":"Use $findings-browser for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Browses and filters existing Endor findings with clear scope, pagination, and evidence gaps."},"description":"Browses, filters, and summarizes existing Endor findings without starting new scans or performing remediation. It shows the applied scope and filters, relevant severity and reachability context, pagination or truncation limits, and any evidence gaps affecting the results.","plugin_release_skill_id":"pluginrsk_6a906fd4babc81919bdf82e54142ee91"},{"name":"malware-responder","interface":{"brand_color":null,"iconography":"radar","display_name":"Malware Responder","default_prompt":"Use $malware-responder for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Correlates current malware intelligence with Endor inventory to assess tenant exposure."},"description":"Correlates current software supply-chain malware intelligence for affected packages and versions with Endor inventory across a namespace and its child namespaces. It distinguishes confirmed exposure, possible exposure, not-observed exposure, and insufficient data using exact package, version, and inventory evidence. It reports affected projects, indicators of compromise, containment guidance, and recommended follow-up actions without modifying Endor or source systems.","plugin_release_skill_id":"pluginrsk_6a906fd2b64881918dc8e4efb9732ae4"},{"name":"oss-upgrade-investigator","interface":{"brand_color":null,"iconography":"hierarchy","display_name":"OSS Upgrade Investigator","default_prompt":"Use $oss-upgrade-investigator for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Compares Endor upgrade candidates, risk, breaking changes, and code impact."},"description":"Evaluates candidate dependency upgrades using Endor VersionUpgrade data, Code Impact Analysis, findings, breaking-change information, and Endor-provided manifest targets. It compares findings fixed or introduced and explains the safest available upgrade path, including whether to upgrade now, proceed cautiously, defer, or gather more evidence.","plugin_release_skill_id":"pluginrsk_6a906fd3a390819192f4141114ba9254"},{"name":"remediation-planning","interface":{"brand_color":null,"iconography":"radar","display_name":"Remediation Planning","default_prompt":"Use $remediation-planning for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Compares read-only remediation options and recommends the safest evidence-backed next step."},"description":"Previews safe remediation options for existing Endor findings without changing code or opening a pull request. It compares VersionUpgrade and Upgrade Impact Analysis candidates using findings fixed, upgrade risk, compatibility evidence, and available data, then recommends the safest evidence-backed next step.","plugin_release_skill_id":"pluginrsk_6a906fd3ba7481919b12762df56f8f74"},{"name":"sca-remediation","interface":{"brand_color":null,"iconography":"hierarchy","display_name":"SCA Remediation","default_prompt":"Use $sca-remediation for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Plans and applies approval-gated SCA fixes with upgrade-risk evidence and local validation."},"description":"Plans and applies dependency-vulnerability fixes using Endor SCA findings, VersionUpgrade and Upgrade Impact Analysis evidence, deterministic risk decisions, and local validation. It separates low-risk changes from upgrades requiring deeper compatibility review and requires explicit approval before editing files, pushing branches, opening change requests, or creating tickets.","plugin_release_skill_id":"pluginrsk_6a906fd4d93481918f87f23f1e7e07a8"},{"name":"troubleshooting","interface":{"brand_color":null,"iconography":"radar","display_name":"Troubleshooting","default_prompt":"Use $troubleshooting for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Diagnoses Endor setup and workflow problems using focused read-only evidence."},"description":"Diagnoses Endor setup, authentication, integration, scanning, dependency-resolution, container, reachability, policy, and workflow problems. It gathers the smallest useful set of read-only evidence needed to identify the likely root cause and recommend the lowest-friction repair without modifying Endor, source-provider, or repository state.","plugin_release_skill_id":"pluginrsk_6a906fd2b0548191bb66d5e6982aeb7f"},{"name":"vulnerability-explainer","interface":{"brand_color":null,"iconography":"search","display_name":"Vulnerability Explainer","default_prompt":"Use $vulnerability-explainer for this Endor Labs workflow.","icon_large_url":null,"icon_small_url":null,"short_description":"Explains vulnerability severity, exploitability, affected versions, and recommended remediation."},"description":"Explains a CVE, GHSA, or Endor vulnerability, optionally in the context of a supplied package and version. It summarizes severity, exploitability signals, affected and fixed versions, recommended remediation, and relevant reachability or repository context when supported by exact Endor evidence. It clearly identifies missing information rather than inferring package or project applicability.","plugin_release_skill_id":"pluginrsk_6a906fd3cbe4819193b7520d1064cdec"}],"app_ids":[],"version":"2.2.2","keywords":["endor-labs","security","sca","sast","codex"],"interface":{"category":"Security","logo_url":"https://files.openai.com/content?id=file_00000000d3bc81fd89006d3d0b73b716","brand_color":"#26D07C","website_url":"https://www.endorlabs.com/","capabilities":["Security","Remediation","Investigation","Application Security","Agentic Workflows","Agentic Remediation","Agentic AppSec"],"logo_url_dark":null,"default_prompt":"Use the SCA remediation agent to fix the P0 findings in this repo for my tenant.","developer_name":"Endor Labs","default_prompts":["Use the SCA remediation agent to fix the P0 findings in this repo for my tenant.","Triage the top AI SAST findings for my repo and propose a PR to fix them.","Plan a safe dependency remediation using Endor Labs evidence."],"screenshot_urls":[],"long_description":"Packaged AppSec workflows for SCA remediation, AI SAST triage, CI/CD posture, malware response, findings review, Endor Labs setup, and more.","composer_icon_url":"https://files.openai.com/content?id=file_0000000073ec81fd903d64b560118531","short_description":"Endor Labs Agentic AppSec","plugin_category_id":"security","privacy_policy_url":"https://www.endorlabs.com/legal/privacy-policy","terms_of_service_url":"https://www.endorlabs.com/legal/terms-of-use","composer_icon_dark_url":null},"description":"Endor Labs security workflows and setup for Codex.","app_manifest":null,"display_name":"Endor Labs Agent Kit","app_templates":[],"onboarding_skill_name":null,"requires_local_executor":false},"created_at":"2026-07-31T19:01:13.413501Z","is_template":false,"connector_id":null,"discoverability":"UNLISTED","canonical_app_id":null},"research":null,"package_metadata":{"name":"endor-labs-agent-kit","author":{"url":"https://www.endorlabs.com/","name":"Endor Labs"},"license":"MIT","sources":[{"path":".codex-plugin/plugin.json","sha256":"9cd90e68ff5d79181eb822e476917cc527e700f2f7e36e3e2910c3c006d3231a"}],"version":"2.2.2","homepage":"https://github.com/endorlabs/ai-plugins","keywords":["endor-labs","security","sca","sast","codex"],"repository":"https://github.com/endorlabs/ai-plugins","artifact_id":11114,"observed_at":"2026-10-02T00:29:45Z","support_url":"https://www.endorlabs.com/lp/contact-us","capabilities":["Security","Remediation","Investigation","Application Security","Agentic Workflows","Agentic Remediation","Agentic AppSec"],"field_sources":{"name":0,"author":0,"license":0,"version":0,"homepage":0,"keywords":0,"repository":0,"support_url":0,"capabilities":0},"extraction_version":1,"conflicts_or_errors":[]}}