Endor Labs AgentHQ Plugin
AppAbout
By endorlabs
41 installs
Tags
(2)Pricing
Select a tab navigation
The Endor Labs GitHub AgentHQ brings dependency risk and vulnerability intelligence directly into GitHub Copilot. Ask about any open-source package and get instant answers on known vulnerabilities, security risks, and CVE details — powered by Endor Labs. Make safer application security decisions and fixes without leaving your coding workflow.
Capabilities
- Check any open-source dependency for known vulnerabilities
- Check a dependency for supply chain and security risks
- Look up detailed information on a specific vulnerability or CVE
Benefits
- Shift security left: Catch vulnerable and risky dependencies while you code, not at release.
- Faster decisions: Get instant, evidence-backed answers without leaving Copilot.
- Informed choices: Understand a package's risk before you depend on it.
- Zero setup friction: No API key or Endor Labs account required.
- Agentic remediation: Fix vulnerabilities with Endor Labs' extensive vulnerability context and data.
Getting Started
Requirements:
- Plan: Free — runs on the Endor Labs Developer Edition.
- User Permissions: Standard repository access; no Endor Labs credentials needed.
- Availability: Generally available.
Setup Process:
- Install the Endor Labs plugin from the marketplace.
- Mention the agent and ask a dependency or vulnerability question.
Example Prompts
Try these prompts:
- "Does lodash 4.17.20 have any known vulnerabilities?"
- "Are there supply chain risks with requests 2.28.0?"
- "Explain CVE-2021-44228 and how serious it is."
- "Check express 4.18.2 for vulnerabilities and risks."




Plans and pricing
Developer Edition is a free tier that gives individual developers access to the AURI MCP Server and CLI. It includes SAST, SCA, secrets detection, and malicious package detection.
$0Endor Labs AgentHQ Plugin is provided by a third-party and is governed by separate terms of service, privacy policy, and support documentation