Local-first secret, PII, and dependency-CVE scanning for Claude Code, built on Spidercob's open-source scanning engines. No account or API key required for the core scans — everything runs on your machine.
| Component | Type | What it does |
|---|---|---|
dlp-scan |
skill (/dlp-scan) |
Scan a file, directory (recursive, skips lockfiles/binaries/vendor dirs), or staged diff for secrets/PII locally via dlp-patterns >= 0.2.0. |
dep-scan |
skill (/dep-scan) |
Scan dependency manifests (requirements.txt, pyproject.toml >= 0.2.0, package.json/package-lock.json, go.mod, Cargo.toml, pom.xml) for known CVEs via dep-scanner + OSV.dev. No API key. |
dlp-deep-scan |
skill (/dlp-deep-scan, manual only) |
ML-scored scan (Presidio + intent classifier) via the hosted Spidercob API. Requires SPIDERCOB_API_KEY. |
dlp-triage |
skill (auto-loaded) | Teaches Claude how to read context_score and severity to separate real leaks from false positives. |
| pre-commit hook | PreToolUse hook |
Blocks git commit when staged files contain secrets, using dlp-scan --secrets-only. |
Requires the dlp-patterns and osv-scan PyPI packages for local scans (the skills will offer to pip install them if missing). dlp-deep-scan additionally requires pip install spidercob and a Spidercob API key from https://spidercob.com/settings.
This repo doubles as its own marketplace (.claude-plugin/marketplace.json alongside .claude-plugin/plugin.json). There is no Anthropic-curated app-store review step — a "Claude Code marketplace" is just a git repo with a marketplace.json, and anyone can add it directly:
/plugin marketplace add SpiderCob/spidercob-plugin
/plugin install spidercob@spidercob
The pre-commit hook and dlp-scan never leave your machine and make no network call. dep-scan doesn't need an account or API key, but it does query the free public OSV.dev database over the network to look up CVEs — no code or file content is sent, only package name/version pairs. dlp-deep-scan is opt-in for when you want Spidercob's ML classifiers (fewer false positives, CISO-grade remediation text, compliance tagging) and are willing to send the content to the hosted API.
Dual-licensed under MIT or Apache-2.0, at your option.