Skip to content

[External Plugin]: BackBond Agent Scan #2876

Description

@CorwinFoundation

Plugin name

backbond-agent-scan

Short description

Vet proposed MCP and AI-agent tool manifests before attachment with a pinned local deterministic static gate. The skill returns block, review, or no blocking finding without running tools or uploading scan inputs.

GitHub repository

BackBond/agent-scan

Plugin path inside the repository

plugins/backbond-agent-scan

Ref to review

v0.5.14

Commit SHA to review

6c7e728de5defa434f5e3647f80f7d822daba588

Version

0.5.14

License identifier

MIT

Author name

BackBond

Author URL

https://backbond.ai

Homepage URL

https://backbond.ai/agent-scan/

Keywords

mcp-security
agent-security
tool-vetting
pre-attachment
static-analysis

Additional notes for reviewers

This is deliberately a skill-only Agent Plugin: no hooks, commands, or plugin-level MCP configuration. The dedicated marketplace source root contains only plugin metadata and the agent-scan skill. Installing it cannot start a process or run a scan. The manifest explicitly declares the skill path; the skill pins @backbond/agent-scan@0.5.14, treats incomplete evidence as review, and states that output is not a safety determination, runtime attestation, or insurance decision. The npm package has zero runtime and development dependencies; the release publishes provenance and reproducible standalone/package assets.

Submission checklist

  • The plugin lives in a public GitHub repository.
  • The ref and/or sha I provided is immutable (release tag and/or full 40-character commit SHA), not a branch.
  • This submission follows this repository's contribution, security, and responsible AI policies.
  • This plugin is not already listed in the Awesome Copilot marketplace.

Metadata

Metadata

Assignees

No one assigned

    Labels

    external-pluginPublic external plugin submissionready-for-reviewSubmission passed intake validation and is ready for maintainer review

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions