Skip to content

About

Local-first secret, PII, and dependency-CVE scanning plugin for Claude Code

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

8 Commits

Folders and files

Repository files navigation

spidercob (Claude Code plugin)

Local-first secret, PII, and dependency-CVE scanning for Claude Code, built on Spidercob's open-source scanning engines. No account or API key required for the core scans — everything runs on your machine.

What's included

Component Type What it does
dlp-scan skill (/dlp-scan) Scan a file, directory (recursive, skips lockfiles/binaries/vendor dirs), or staged diff for secrets/PII locally via dlp-patterns >= 0.2.0.
dep-scan skill (/dep-scan) Scan dependency manifests (requirements.txt, pyproject.toml >= 0.2.0, package.json/package-lock.json, go.mod, Cargo.toml, pom.xml) for known CVEs via dep-scanner + OSV.dev. No API key.
dlp-deep-scan skill (/dlp-deep-scan, manual only) ML-scored scan (Presidio + intent classifier) via the hosted Spidercob API. Requires SPIDERCOB_API_KEY.
dlp-triage skill (auto-loaded) Teaches Claude how to read context_score and severity to separate real leaks from false positives.
pre-commit hook PreToolUse hook Blocks git commit when staged files contain secrets, using dlp-scan --secrets-only.

Install

Requires the dlp-patterns and osv-scan PyPI packages for local scans (the skills will offer to pip install them if missing). dlp-deep-scan additionally requires pip install spidercob and a Spidercob API key from https://spidercob.com/settings.

This repo doubles as its own marketplace (.claude-plugin/marketplace.json alongside .claude-plugin/plugin.json). There is no Anthropic-curated app-store review step — a "Claude Code marketplace" is just a git repo with a marketplace.json, and anyone can add it directly:

/plugin marketplace add SpiderCob/spidercob-plugin
/plugin install spidercob@spidercob

Why local-first

The pre-commit hook and dlp-scan never leave your machine and make no network call. dep-scan doesn't need an account or API key, but it does query the free public OSV.dev database over the network to look up CVEs — no code or file content is sent, only package name/version pairs. dlp-deep-scan is opt-in for when you want Spidercob's ML classifiers (fewer false positives, CISO-grade remediation text, compliance tagging) and are willing to send the content to the hosted API.

License

Dual-licensed under MIT or Apache-2.0, at your option.

About

Local-first secret, PII, and dependency-CVE scanning plugin for Claude Code

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages