Endor Labs
Official@endorlabs · United States of America
Offers comprehensive supply chain security, dependency risk assessment, and vulnerability reachability analysis for enterprise software development environments.
Agent Skills by Endor Labs
Showing 63 vetted skills indexed across 3 GitHub repositories.
findings-browser
Browse and filter Endor Labs findings with severity summaries via the Endor API.
upgrade-impact-analysis
Query the VersionUpgrade workflow to assess Endor Labs upgrade impact and risks.
probe-droid
Compare GitHub repository inventory with Endor project details to identify monitored-branch coverage gaps.
sca-remediation
Automate dependency vulnerability remediation using Endor SCA findings and UIA evidence.
package-risk-summary
Summarize a package version's risk profile via Endor's MCP and Endorctl API.
repository-dependency-reviewer
Review repository dependencies for risks using local manifests and Endor MCP tools.
cicd-posture
Generate deterministic CI/CD and supply chain posture assessments from Endor and GitHub evidence.
endor-troubleshooter
Diagnose Endor Labs errors and configuration issues from read-only evidence.
malware-response
Correlate malware intelligence with Endor Labs package inventory and classify exposure.
vulnerability-explainer
Explain CVE vulnerabilities and assess severity using Endor MCP data.
ai-sast-triage
Analyze and triage Endor AI SAST findings into context-aware change requests.
remediation-planner
Assess dependency remediation options using Endor findings and version upgrades.
dependency-decision-helper
Analyze package version safety using Endor risk evidence and MCP tools.
endor-agent-kit-setup
Automate Endor Labs Agent Kit prerequisite setup and verification for Gemini CLI.
create-endor-labs-agent
Automates creation and maintenance of Endor Labs Agent Kit agents with structured files and evaluations.
endor-fetch-and-search-call-graph
Fetch and search decoded call graph artifacts for symbol reachability.
endor-duplicate-projects
Identify duplicate Project registrations across tenant namespaces and output CSV reports.
endor-dependency-finding-provenance
Trace vulnerability and dependency lineage to verify fixed, present, or inconclusive status at a commit.
endor-implement-sdk-resource
Align Endor Labs Python SDK models and resource facades with OpenAPI changes.
endor-model-sync-drift
Diagnose and repair OpenAPI and model-sync drift in the Endor Labs SDK.
endor-troubleshooting-scans
Diagnose Endor Labs scan regressions by comparing scan pairs and searching logs.
endor-custom-sast-rules
Validate and import custom OpenGrep and Semgrep rule YAML into Endor Labs SemgrepRule resources.
endor-author-agent-skill
Author and update agent skills with portable SKILL.md frontmatter and sync validation.
endor-route-estate-queries
Route estate-scale Endor Labs queries between graph joins and facade patterns.
Frequently Asked Questions About Endor Labs
FAQPage SchemaWhat specific security tasks can I perform using these capabilities?▼
You can perform dependency vulnerability scanning, reachability analysis, secret detection, license compliance auditing, and generate SBOMs in CycloneDX or SPDX formats. These capabilities enable automated remediation planning and security policy enforcement across your entire project namespace.
Which personas benefit most from these security integrations?▼
Security engineers, DevSecOps practitioners, and software developers benefit by integrating these checks directly into their development lifecycle. These capabilities assist teams in triaging SAST findings, validating security policies, and diagnosing scan regressions without manual intervention.
What are the prerequisites for running these security checks?▼
You require an active Endor Labs tenant, valid authentication credentials, and the configured environment for your specific project namespace. Setup involves verifying SSO tokens, configuring local manifests, and ensuring the necessary scan permissions are granted for your repository infrastructure.