Skip to content

About

Autonomous security auditing, exploit PoC validation, and patch remediation skill for Google Antigravity

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

CodeMender Security Plugin (codemender-security)

Important

CodeMender Public Preview Access: Access to the Google Cloud CodeMender (cm) API and artifacts is currently in Public Preview (contact your Google Cloud representative for project allowlisting). Ensure your Google Cloud account is authenticated and associated with an authorized project where the Vertex AI API is enabled before running scans.

The codemender-security plugin equips AI coding agents with autonomous security auditing, zero-false-positive exploit verification, and context-aware patch remediation powered by Google Cloud CodeMender (cm) on the Gemini Enterprise Agent Platform.

Built on the open Agent Plugins specification, this plugin bundles curated Agent Skills, safety guardrails, and operational runbooks for Google Antigravity, Anthropic Claude Code, and OpenAI Codex.


🚀 Installation

Google Antigravity (agy)

Install directly via the Antigravity CLI:

agy plugin install https://github.com/edwardc-gcp/codemender-security.git

Tip

You can also install via the Antigravity IDE UI under Settings (Cmd+, / Ctrl+,) → Plugins → Install from URL.

Anthropic Claude Code (claude)

Install directly via the Claude Code CLI:

claude plugin install https://github.com/edwardc-gcp/codemender-security.git

OpenAI Codex (codex)

Install directly via the OpenAI Codex CLI:

codex plugin install https://github.com/edwardc-gcp/codemender-security.git

🔑 Prerequisites

Before using the plugin, ensure your environment meets the following requirements:

  1. Google Cloud Project, APIs & IAM Role: Enable the required Google Cloud APIs and ensure your account has the Vertex AI User (roles/aiplatform.user) IAM role on an allowlisted Public Preview project:

    gcloud services enable aiplatform.googleapis.com cloudresourcemanager.googleapis.com

    (Note: On your very first run in a newly provisioned project, the backend may return Resource setup has just started. Please try again shortly. Wait 1–2 minutes and retry.)

  2. Google Cloud Application Default Credentials (ADC): Authenticate your local development machine with Google Cloud:

    gcloud auth application-default login

    Ensure your active Google Cloud project has access to CodeMender on Gemini Enterprise Agent Platform.

  3. CodeMender CLI (cm) Installation & Updates: Review and run the bundled cross-platform installer script (requires curl and unzip), which checks the latest official release manifest, downloads the binary, and verifies its uncompressed SHA-256 checksum:

    bash ~/.gemini/config/plugins/codemender-security/scripts/install_cm.sh

    Re-running install_cm.sh automatically checks for newer remote releases and upgrades cm when available (or run cm update manually).

  4. Privacy & Telemetry Opt-Out (Optional): CodeMender follows a local-first architecture (only targeted code snippets are transmitted via the Interactions API). CLI telemetry (which excludes source code, findings, and identity) is enabled by default; to disable it, export:

    export CM_TELEMETRY_OPT_OUT=1

📦 What's Included

Bundled Skills

  • codemender-audit: Full-codebase AST and taint scanning, differential git scanning, external SAST report ingestion (cm report import -f findings.sarif), and 2-Tier verification (cm verify --skip-exploit-verification for fast semantic verification or sandboxed dynamic PoC execution).
  • codemender-remediate: Domain-guided patch synthesis (cm fix), automated regression testing, exploit re-attack validation, and an atomic multi-vulnerability remediation loop with enforced outer-shell build gates and automatic git stash restoration.

Safety Rules, Hooks & Execution Wrappers

  • codemender-safety.md (Always-On Routing Stub): Lightweight (~75-token) always-on rule that enforces wrapper execution and requires explicit operator confirmation before running install_cm.sh or cm verify --unrestricted.
  • hooks.json & pre_tool_guard.sh (Deterministic PreToolUse Interceptor): Pure-Bash runtime hook (<2ms fast-path) that intercepts shell commands before execution—blocking unwrapped stateful cm subcommands and cm init -y while enforcing interactive confirmation (force_ask) for install_cm.sh and --unrestricted verification.
  • cm_exec.sh (Stateless Workspace Wrapper): Isolates .codemender/ and HOME="${PROJECT_ROOT}/.cache" per repository, forwards GIT_CONFIG_GLOBAL and CLOUDSDK_CONFIG (ADC), prevents .codemender/config.yaml overwrites, and registers .codemender/ and .cache/ in .git/info/exclude.
  • cm_remediate_loop.sh (Atomic Multi-Vulnerability Remediation Loop): Automates non-destructive git stash push -u tracking, declarative Strategy Pipeline polyglot build gates (OUTER_BUILD_CMD), per-finding cm fix synthesis, post-commit AST line reconciliation, and automatic git stash pop restoration.
  • check_env.sh (Diagnostic Environment Health Checker): Instantly verifies CLI version, Google Cloud ADC authentication status, active project, and workspace data protection in a structured ASCII summary.

💡 How It Works

Once installed, simply prompt your coding agent using natural language. The agent autonomously determines the best workflow and executes it safely under CodeMender guardrails.

Scenario 1: Post-Vibe-Coding Hardening Pass

You just generated a new MVP or feature with AI and want to secure it before deployment:

"I just finished building this full-stack project with AI. Do a comprehensive security audit and hardening pass, verify real vulnerabilities, and remediate them before I deploy."

  1. Discovery & Scoping: The agent initializes .codemender/ and scans the codebase for high-risk vulnerabilities (hardcoded credentials, open CORS, SQL injection, unsanitized inputs).
  2. 2-Tier Verification: Uses cm verify --skip-exploit-verification for fast 15–25s semantic taint verification (or isolated sandbox PoC execution) to eliminate false positives.
  3. Adaptive Remediation & Hard Gate: Synthesizes context-aware patches (cm fix), validates the build/syntax in the outer shell, and reverts any patch that breaks compilation.
  4. Automatic Stash Restoration: Commits validated security fixes (git add -A && git commit) and restores any pre-existing uncommitted user files (git stash pop).

📄 License & Disclaimer

Licensed under the Apache License, Version 2.0. Disclaimer: This is not an official Google product.

About

Autonomous security auditing, exploit PoC validation, and patch remediation skill for Google Antigravity

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages