Endor Labs ai-plugins
Sets up endorctl and uses Endor Labs to scan, prioritize, and fix software supply chain security risks.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for Endor Labs ai-plugins, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
A Claude Code plugin that provisions the endorctl CLI and drives Endor Labs to scan a codebase's dependencies for reachable vulnerabilities, secrets, and supply-chain risk. It surfaces prioritized findings and remediation guidance through skills and MCP tools so the agent can fix them in place. Aimed at SCA and supply-chain security within the coding workflow.
Key features and capabilities
- endorctl setup and orchestration
- Reachability-based dependency scanning
- Risk prioritization and fixes
- Supply-chain security coverage
Use cases
- Scanning dependencies for reachable CVEs
- Prioritizing and remediating supply-chain risk