53c57871d6
Snyk lands as a standalone Agent Plugins v1 package (NousResearch/hermes-plugin-snyk, pinned 2a41a07f) instead of an optional-mcps entry: the package carries the pinned `npx -y snyk@1.1306.0 mcp` stdio launch with CLI analytics disabled AND the workflow skill that tells the agent when to use which scanner, so a single `hermes plugins install snyk` gives both the tools and the playbook. Third-party product integrations ship outside the core tree per the contribution rubric. Supersedes the optional-mcps manifest from #73860 (same pin, same telemetry posture, tool-pruning rationale moved into the skill).
17 lines
721 B
YAML
17 lines
721 B
YAML
name: snyk
|
|
repo: https://github.com/NousResearch/hermes-plugin-snyk
|
|
sha: 2a41a07f81e45125bf82a19af1b13396ace4b81f
|
|
description: 'Scan code (SAST), dependencies, container images, IaC and SBOMs with Snyk through its
|
|
first-party MCP server (pinned snyk@1.1306.0 over npx stdio, CLI analytics disabled), with the
|
|
snyk-security-scan workflow skill bundled. Portable Agent Plugins v1 package (mcp.json + skills/);
|
|
needs Node.js/npm on PATH and a free Snyk account (browser login via the snyk_auth tool).'
|
|
maintainer: NousResearch
|
|
tier: official
|
|
docs_url: https://github.com/NousResearch/hermes-plugin-snyk
|
|
platforms: []
|
|
capabilities:
|
|
provides_tools: []
|
|
provides_hooks: []
|
|
provides_middleware: []
|
|
requires_env: []
|