Add tools to 0sec. Share the tools you build.
An extension gives the 0sec agent a tool it can call during a scan. Use one to run a scanner, test a custom framework, or work with your own hardware. This repository holds the extension source and the registry the CLI reads.
Install 0sec and check the commands available in your version:
0sec --version
0sec plugin --help
0sec plugin browse
0sec plugin install foxguard.scanner
0sec plugin info foxguard.scanner
0sec plugin enable foxguard.scannerUse 0sec 0.17.0 or newer for these commands and direct plugin run calls.
The 0.16.3 binary has a tool-registry bug in plugin run. The live community
registry includes foxguard.scanner 0.13.2; its adapter version is independent
of the installed Foxguard scanner version.
Review the source before enabling an extension. Installation only writes files. Enabled extensions execute code under your user account when loaded. Capability declarations inform approval prompts; they do not sandbox the code.
The Foxguard extension requires the foxguard executable
on PATH. Run it on an absolute path you have permission to scan:
0sec plugin run foxguard.scanner foxguard_scan --yes path=/absolute/path/to/projectYou can also browse the registry with /hackstore in the 0sec console.
To disable an extension for the current project:
0sec plugin disable foxguard.scannerStart with the author guide for the runtime protocol and local testing. The authoring commands below are available in 0sec 0.17.0 and newer.
0sec hackstore init my-extension
0sec hackstore validate ./my-extensionAn installable extension needs a manifest and a self-contained plugin.js.
Manifest validation does not execute the plugin or establish that its code is safe.
See CONTRIBUTING.md to package, test, and submit an extension.
extensions/: extension source and instructions.index.json: generated registry consumed by 0sec.hackstore-manifest.schema.json: editor and build-time manifest checks. The harness validator is authoritative at install time.
To rebuild and check the registry, use Node.js 22 or newer:
npm ci
npm run build
npm run check
npm testThese are local checks. This repository has no CI workflow enforcing them yet.