← Endor Labs Agent KitCONTENT HISTORY

Update to Endor Labs Agent Kit

Snapshot Sep 30, 2026 · 23:13 UTC · version 2.2.2

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "description": "Use when checking Endor Agent Kit readiness in Codex, verifying the local Endor CLI, authentication, namespace, GitHub, or toolchain prerequisites.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 280
    }
  ],
  "name": "endor-agent-kit-setup",
  "skill_md_contents": "---\nname: endor-agent-kit-setup\ndescription: \"Use when checking Endor Agent Kit readiness in Codex, verifying the local Endor CLI, authentication, namespace, GitHub, or toolchain prerequisites.\"\n---\n\n<!-- Generated by Endor Labs Agent Kit. Do not hand-edit installed copies. -->\n<!-- endor_agent_kit_managed=true agent_id=endor-agent-kit-setup host=codex-directory package=endor-labs-agent-kit version=2.2.2 -->\n\n# Endor Agent Kit Setup For Codex\n\nThis public Codex package contains eleven workflow skills plus `endor-agent-kit-setup`. Plugin installation is already complete; this package does not bundle a custom-agent installer.\n\nBundled workflows: `ai-sast-remediation`, `cicd-posture`, `configuration-automation`, `dependency-reviewer`, `findings-browser`, `malware-responder`, `oss-upgrade-investigator`, `remediation-planning`, `sca-remediation`, `troubleshooting`, `vulnerability-explainer`.\n\n## Authentication Boundary\n\n- The plugin itself has no hosted MCP server, connector, app, OAuth flow, or bundled credentials.\n- Endor workflows use the customer's local `endorctl` process and its existing authentication configuration.\n- Let `endorctl` consume authentication internally. Never print, copy, parse, or ask the user to paste secret values.\n- Treat missing or expired Endor authentication as a local readiness issue, not a plugin installation failure.\n- Normal setup does not require MCP. Discuss or configure MCP only when the user explicitly asks for that separate capability.\n\n# Endor Agent Kit Setup\n\nUse this setup workflow when the user asks to install, check, update, or remove\nEndor Labs Agent Kit plugin support files, or when an Endor Agent Kit workflow\nis blocked by missing `endorctl`, GitHub CLI, authentication, namespace, or\nlocal toolchain readiness.\n\n## Setup Contract\n\nBe proactive about checking the environment, but do not make persistent changes\nwithout explicit user approval. Report evidence for each check. Never print\nsecret values.\n\nSetup may:\n\n- Inspect command availability and versions for `endorctl`, `gh`, `git`, and\n  workflow-relevant language tooling.\n- Read `ENDOR_NAMESPACE` from the current process environment and report it as\n  namespace provenance when present.\n- Safely parse `~/.endorctl/config.yaml` for non-secret fields such as\n  `ENDOR_API` and `ENDOR_NAMESPACE`.\n- Report the presence of credential fields by key name only.\n- Report the presence of `ENDOR_API_CREDENTIALS_*` authentication variables by\n  key name only.\n- Run lightweight read-only Endor auth verification when config or credentials\n  are present.\n- Offer re-authentication when verification fails.\n- Check `gh` authentication and point to official installation guidance.\n- Inspect Endor MCP support when a selected workflow needs MCP or the user asks\n  for MCP setup.\n- Offer host-specific Endor MCP configuration only after explaining the exact\n  file, command, and validation step.\n- Install, update, or uninstall host-specific Agent Kit support files only after\n  explicit approval.\n\nSetup must not:\n\n- Run `endorctl scan`.\n- Run `endorctl host-check`.\n- Print `~/.endorctl/config.yaml` or secret values.\n- Read, cat, source, recurse through, or point `ENDORCTL_CONFIG` or\n  `--config-path` at tenant-specific, customer-specific, production, backup,\n  or other non-default Endor config directories.\n- Ask the user to paste API keys, API secrets, tokens, or passwords into chat.\n- Write `ENDOR_API_CREDENTIALS_KEY` or `ENDOR_API_CREDENTIALS_SECRET`.\n- Edit shell profile files such as `.zshrc`, `.bashrc`, or PowerShell profile.\n- Install `gh`, package managers, language runtimes, Docker, JDKs, or build\n  tooling.\n- Configure MCP globally without explicit user approval. MCP remains opt-in per\n  recipe/workflow.\n\n## Readiness Report\n\nStart with a concise readiness report. Separate configured state from verified\nstate.\n\nInclude these sections when relevant:\n\n- Ready\n- Needs action\n- Optional checks\n- Available fixes\n\nFor Endor auth, report sanitized fields only:\n\n```text\nEndor config: found\nAPI endpoint: https://api.endorlabs.com\nNamespace candidates:\n- ENDOR_NAMESPACE: not set\n- ~/.endorctl/config.yaml ENDOR_NAMESPACE: example-namespace\nSelected namespace: example-namespace from ~/.endorctl/config.yaml\nAuth: API credential fields present\nEndor auth: verified for namespace example-namespace\nSecret values: hidden\n```\n\nIf a namespace is missing, say that a namespace is required before live Endor\nlookups. If a namespace is detected, let the user use it or override it for the\ncurrent workflow.\n\nIf `ENDOR_NAMESPACE` from the current process environment and\n`~/.endorctl/config.yaml` disagree, surface both values and stop before live\nEndor lookups. Ask the user which namespace to use for this workflow. Do not\nsilently trust either value, and do not unset environment variables or edit\nconfig files unless the user explicitly asks for that separate operational\ncleanup.\n\nWhen the user selects or supplies a namespace, later workflow agents must pass\nit explicitly with `-n <namespace>` or `--namespace <namespace>` for scoped\nEndor lookups rather than relying on bare `endorctl` namespace resolution.\n\n## Endor Tooling\n\nIf `endorctl` is missing, offer documented install options in this order:\n\n1. Package manager route when available, such as Homebrew or npm.\n2. Direct binary download with checksum verification.\n\nOnly install `endorctl` after explicit approval. If installing to `~/bin`, tell\nthe user how to update `PATH` for the current shell. Do not edit shell profiles.\n\nIf API credential fields are present, do not run browser auth unless the user\nexplicitly asks to switch or re-authenticate. If API credential setup is needed,\ntell the user to set `ENDOR_API_CREDENTIALS_KEY` and\n`ENDOR_API_CREDENTIALS_SECRET` through their preferred secure environment\nmechanism.\n\nWhen browser or SSO authentication is requested, confirm the namespace first.\nUse non-interactive flags where supported. If multi-tenant selection appears,\nsummarize the available tenant choices and ask the user before retrying.\n\n## Endor MCP\n\nRequire `endorctl agent api --help` to succeed for workflows that use Endor CLI\nAPI calls. Each selected workflow must pass its canonical recipe id through\n`--agent-id`; never fall back to the unattributed legacy API command. Configure\nEndor MCP only when a selected MCP-capable workflow needs it or the user\nexplicitly asks for it.\n\nThe distribution may include ready-to-use Endor MCP config snippets such as\nroot `.mcp.json` or Gemini `mcpServers` metadata. Treat those files as setup\ninputs, not permission to start or register MCP without approval.\n\nWhen MCP setup is requested:\n\n1. Check whether `npx` is available.\n2. Check whether `endorctl` is available.\n3. Verify the proposed server command is:\n   `npx -y endorctl ai-tools mcp-server`.\n4. Inspect the host-specific MCP config location or installed plugin metadata.\n5. If `endor-cli-tools` is already registered, report it and ask before\n   changing anything.\n6. If it is missing, show the exact config that would be added and ask for\n   approval before writing host config files.\n7. After approval and configuration, validate in a fresh host session when the\n   host supports tool visibility checks.\n\nDo not claim Endor MCP tools are available to a workflow until the host exposes\nthem in the current session. If MCP tools are unavailable, continue with\nCLI-first workflows when they support `endorctl agent api --agent-id\n<canonical-recipe-id>`; otherwise record the missing MCP capability in\n`data_gaps`.\n\n## GitHub CLI\n\nCheck `gh auth status` when workflows need GitHub evidence, repository\ninventory, pull requests, or comments. If `gh` is missing, provide current\nofficial installation guidance instead of installing it automatically.\n\nDo not manage GitHub token scopes or create personal access tokens. Verify\nonly the specific read or write capability needed for the selected workflow.\n\n## Language Tooling\n\nDetect and report workflow-relevant package managers, language runtimes, and\nbuild tools. Do not install them.\n\nWhen tooling is missing, report the affected validation step and ask the user to\ninstall it through their team-standard toolchain.\n\n## Workflow Safety\n\nSetup never performs remediation, creates branches, opens PRs/MRs, posts\ncomments, writes Endor policies, or runs scans. Mutating workflows such as SCA\nRemediation and AI SAST Remediation keep those actions behind their generated agent\napproval gates.\n\n## Codex Directory Rules\n\n- Do not search for or install repository-marketplace custom agents from this public-directory package.\n- Start a new Codex task after installing or updating the plugin so all bundled skills are discoverable.\n- Setup never runs scans, remediates findings, edits repositories, or changes Endor state.\n"
}

SHA-256 of public snapshot: 630551829a649d82284a74f8a452d677a51ef412f672d63713db9789629b0278