ai-plugins-endorlabs
Endor Labs plugin: set up endorctl to scan, prioritize, and fix software supply chain security risks.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for ai-plugins-endorlabs, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
Endor Labs' plugin for Claude Code. It sets up the endorctl CLI and uses Endor Labs to scan, prioritize, and fix security risks across the software supply chain (dependencies, SCA, reachability). Surface is commands/skills that install endorctl and run supply-chain scans, returning prioritized findings.
Key features and capabilities
- Sets up endorctl CLI
- Software supply chain scanning
- Risk prioritization by reachability
- Guided remediation
Use cases
- Find and prioritize vulnerable dependencies
- Reduce SCA noise using reachability analysis