Plugins
L1 — Drop-in capabilities. Tools, guardrails, compliance hooks.
OWASP Agentic Top 10
Real-time scanning against the OWASP Agentic Top 10 attack vectors. Blocks prompt injection, tool poisoning, and lateral A2A escalation before execution.
Secret Redactor
Redacts API keys, tokens, and PII from agent prompts and outputs. Pattern library updated nightly.
Bash Destructive Guard
Refuses rm -rf, chmod 777, fork bombs, and 60+ destructive shell patterns. Hard block, no override.
Path Freeze
Lock workspace filesystem access to declared paths. Anything outside throws EACCES at the runtime layer.
16-Dimension Code Review
Multi-dimensional review — security, performance, readability, test coverage, dependency hygiene, license compatibility, and 10 more.
PR Seven-Gate Validator
Lint, type, test, coverage, security, license, signoff. Seven mandatory gates before any agent-authored PR can merge.
HITL Approval Router
Tiered human approval — single reviewer, dual sign-off, or executive override. Routes by risk score and org topology.
Doc Sync on Diff
Watches code diffs, regenerates the corresponding docs section, opens a PR. Keeps docs.* and src/* in lockstep.
EU AI Act · Art. 12/13/17
Auto-generates audit trails, transparency disclosures, and human oversight records mapped to specific EU AI Act articles. Export-ready PDF & JSON.
CVE Supply-Chain Gate
Blocks any agent from importing dependencies with known CVEs above your configured CVSS threshold. NIST + GHSA feeds.
Episodic Memory Layer
Long-term memory with TTL, scoping, and decay. Drops in any agent; backed by pgvector.
Browser Automation Kit
Headless Chromium under HITL gating. Form fill, scrape, screenshot, PDF export — with a kill switch on every action.
License Compatibility Gate
Blocks GPL/AGPL contamination of proprietary code. Per-package allowlist. SPDX-compliant.
Cross-Model Adversarial Review
Routes the same diff to Claude, GPT-5, and Gemini. Surfaces disagreements as review comments — consensus or escalation.
Datadog Trace Bridge
Streams every tool call as a Datadog span. Latency, error rate, and cost all flow into your existing dashboards.
Cron-Tick Learner
Hourly memory consolidation. Promotes repeated successful patterns into Hermes skills. Set-and-forget.
Dual Sign-off Enforcer
Two-key HITL — production diffs require two distinct human approvers. Enforces separation of duties.