-
Notifications
You must be signed in to change notification settings - Fork 5k
[External Plugin]: sechelix-lite #3147
Copy link
Copy link
Open
Labels
external-pluginPublic external plugin submissionPublic external plugin submissionneeds-review:MEDIUMContributor reputation check flagged MEDIUM riskContributor reputation check flagged MEDIUM riskready-for-reviewSubmission passed intake validation and is ready for maintainer reviewSubmission passed intake validation and is ready for maintainer review
Description
Activity
Metadata
Metadata
Assignees
Labels
external-pluginPublic external plugin submissionPublic external plugin submissionneeds-review:MEDIUMContributor reputation check flagged MEDIUM riskContributor reputation check flagged MEDIUM riskready-for-reviewSubmission passed intake validation and is ready for maintainer reviewSubmission passed intake validation and is ready for maintainer review
Plugin name
sechelix-lite
Short description
Application-security review skill for codebases and pull requests you are authorized to assess. Maps trust boundaries, keeps issues as hypotheses until evidenced, runs a separate pass that tries to refute material findings, and ends with a release verdict.
GitHub repository
omarmohelal/SecHelix
Plugin path inside the repository
distributions/awesome-copilot
Ref to review
v4.0.0-alpha.6
Commit SHA to review
a73be865fccf5cefcf98d4dcce2c2bf2b6afce2f
Version
4.0.0-alpha.6
License identifier
Apache-2.0
Author name
Omar
Author URL
https://github.com/omarmohelal
Homepage URL
No response
Keywords
security
appsec
security-review
code-review
authorization
business-logic
supply-chain
ai-security
Additional notes for reviewers
This is a fresh submission after addressing the feedback on #2899. The public-directory package has been reduced to a focused AppSec skill:
SKILL.mdis now 197 lines with 5 supporting files (all Markdown references, no scripts). Product, runtime, SEO and cleanup material is intentionally excluded from this package, and the plugin path points at that package rather than the repository root.It needs no runtime or network access. A CI check in the source repository keeps the package within 220 lines and 6 supporting files.
Submission checklist