Reusable skills and optional MCP integration for the TestifySec platform: Pushgate, Cilock, Witness policies, jctl, vulnerability scans, provenance and compliance.
Requires current Claude Code or Codex plugin support, plus jctl and cilock on
PATH from your approved TestifySec CLI distribution. Source-development skills
also require a Judge checkout. Authenticate separately for your own tenant using
jctl auth login; inspect jctl auth whoami. Installation carries no credentials.
claude plugin marketplace add testifysec/agent-plugins
claude plugin install testifysec@testifysec-pluginscodex plugin marketplace add testifysec/agent-plugins
codex plugin add testifysec@testifysec-pluginsStart a new session after installation. Ask the agent to use the TestifySec plugin
or the specific platform-vulnerability-inventory, using-pushgate, using-cilock,
using-jctl, or creating-witness-policies skill. Check your installed CLI help if
plugin command names differ; do not invent unsupported commands.
plugins/testifysec is a portable Agent Plugins 1.0
package with Agent Skills and an optional stdio MCP
configuration. Use a compatible client's installation workflow. No universal installation
command is implied. Keep the skill set together to preserve sibling references.
See the plugin guide for the 17 skills,
consolidation sources and development requirements. Optional jctl mcp --stdio exposes both read and write tools. Its current
authentication limitation is documented in the plugin guide. Read-only
inventory does not authorize policy creation, binding or activation. Human signing
ceremonies, scoped credentials and repository gates remain applicable.
The source is maintained in testifysec/judge under subtrees/agent-plugins.
Change it in an isolated worktree and review normally, then split it with:
git subtree split --prefix=subtrees/agent-plugins
# Record the returned commit; inspect and validate its standalone archive.Publish the reviewed split to this repository. Keep Codex and Claude marketplace
entries pointing at ./plugins/testifysec, and keep the three plugin manifests at
the same version. Validate the standalone split and scan it for secrets before
publishing. Never include private scan exports, credentials, tenant IDs or personal
machine paths. Client-specific compatibility files share the same canonical skills.
Imported source-development references retain historical context; verify command support and source citations before acting. Live tests, scans and policy evaluation are required before claiming a real remediation or verified decision.
Follow REVIEW.md for the review process, code consistency checks,
negative scenarios and release evidence. Run python3 scripts/review_package.py
for package consistency checks; these do not replace semantic or runtime tests.
MCP is optional and disabled by default. See the MCP status and configuration examples before enabling it.