RepoGuard -- Repo Health & Security Scanner
RepoGuard is an Omniscio plugin that scans repositories for security vulnerabilities, dependency issues, configuration problems, and code quality concerns. It produces a composite health score (0-100, letter grade A-F) from 7 scanner categories and generates actionable findings with fix suggestions.
What it is
RepoGuard is an Omniscio plugin that scans repositories for security vulnerabilities, dependency issues, configuration problems, and code quality concerns. It produces a composite health score (0-100, letter grade A-F) from 7 scanner categories and generates actionable findings with fix suggestions.
Where to find it
How to Enable
Marketplace-only plugin (2026-05-28): Install or uninstall via the Marketplace, same as PRD Stack and NightyTidy. There is no separate Settings → Features toggle — the Marketplace is the single control surface. When installed, the plugin adds a virtual project in the sidebar with a dashboard showing all your Omniscio projects and their health scores.
How it behaves
Scanner Categories
RepoGuard runs 7 independent scanner agents. Each produces a score (0-100) and findings:
| Category | Weight | What It Checks | Requires |
|---|---|---|---|
| Security (SAST) | 25% | SQL injection, XSS, command injection, auth issues in security-relevant source files | Claude API |
| Secrets Exposure | 20% | Hardcoded API keys, passwords, tokens, private keys (40+ regex patterns + Claude false-positive filtering) | Claude API |
| Dependencies (SCA) | 15% | npm audit vulnerabilities, wildcard versions, missing lockfile | Network |
| Code Quality | 10% | README quality, linting/formatting config, TypeScript strict, test setup, LICENSE | Claude API |
| CI/CD & Config | 10% | CI pipeline existence, .gitignore completeness, hardcoded secrets in workflows, debug flags | -- |
| Container Security | 10% | Dockerfile root user, latest tags, secrets in build args, docker-compose privileges | Optional Claude |
| Runtime Health | 10% | Sentry unresolved issues, error trends, crash rates | Sentry API |
Scan types:
- Quick Scan: Secrets + Dependencies + Code Quality (fast, minimal API cost)
- Full Audit: All 7 categories (comprehensive, uses Claude API)
Scoring System
Each category produces a score (0-100). The overall score is a weighted average of non-skipped categories (weights redistribute proportionally when categories are skipped).
Letter grades: A (>=90), B (>=80), C (>=70), D (>=60), F (<60)
Remediation priorities (severity x effort):
- Fix Now: Critical/high severity, low effort
- Plan Fix: Critical/high severity, high effort
- Improve: Medium severity
- Nice to Have: Low severity
Dashboard
The RepoGuard dashboard (visible when clicking the RepoGuard virtual project) shows:
- Fleet Health Card: Average score across all scanned projects
- Ad-hoc Scan Bar: Paste any GitHub URL to scan a public repo
- Projects Table: All Omniscio projects with scores, grades, last scan time, trend arrows, and Quick/Full scan buttons
Project Detail View
Click any project row to see:
- Hero section with score, grade, and project metadata
- Category cards grid showing each scanner's score and finding count
- Expandable findings list with severity badges, priority labels, and fix suggestions
- Filter controls (by category and severity)
- Export buttons (Markdown report copied to clipboard)
- Fix Issues button (appears only when there are findings to fix)
Fix Issues button (one-click remediation)
When a project's most recent scan has at least one finding, the project detail view shows a blue Fix Issues button next to the export controls. Clicking it spawns a fresh Claude Code session in that project's folder, pre-loaded with the scan's full markdown report and a category-aware fix prompt — you don't have to copy/paste anything or open a session manually.
What the launched session is told to do:
- Address every finding — no triaging or skipping. Critical and High severity first, then the rest. The prompt explicitly says "nothing is out of scope" so Claude doesn't try to be conservative and quietly drop findings.
- Dependency vulnerabilities — update affected packages to patched versions, run the package manager's audit fix command where applicable.
- Secrets exposure — first run
gh repo view --json isPrivate -q .isPrivateto check repo visibility:- If private: move secrets to env vars (
.env), gitignore.env, update code to read from env, scrub git history viagit filter-repoor BFG. The secrets themselves don't need rotating since the repo was never public. - If public: the secrets are already compromised. Do the same env-var migration AND flag every secret for immediate rotation so you can rotate them at the source.
- If private: move secrets to env vars (
- Code quality & hygiene — add missing CI/CD, tests, linters, formatter configs, LICENSE,
.editorconfig, package.json fields. Flagged as non-optional. - Configuration & best practices — apply security headers, dependency pinning, and any config-hardening suggestions.
The session is launched via the plugin bridge's amc.session.launchWithDraft({ projectId, draftText, autoSend: true }). autoSend: true means the prompt is sent immediately when the session is ready — you don't have to click Send. A "Launching fix session…" toast confirms; on failure (rare — usually a transient scan-export error) a red "Failed to launch fix session" toast appears and nothing is launched.
Implementation: src/plugins/repoguard/ui/plugin.js — fixIssues(projectId, scanId) function at the bottom of the file. The scan-to-markdown render path goes through amc.scan.exportReport(scanId, 'markdown'), which uses src/plugins/repoguard/report-generator.ts. The session-launch bridge is documented in the plugin SDK; the preload exposure is in src/preload/plugin-bridge-preload.ts.
Sentry Integration
For runtime health monitoring, configure your Sentry auth token at Settings -> sentryAuthToken. Then link individual projects to their Sentry project in the project detail view.
Requirements: Sentry free tier is sufficient. Needs an org-level bearer token with project:read scope.
File Layout
src/plugins/repoguard/
manifest.json # Plugin registration
types.ts # Shared types, scoring, weights
scanner.ts # Orchestrator -- runs agents in parallel
scanner-bridge.ts # IPC bridge -- storage + scan execution
scan-storage-schema.ts # Self-heals scan tables from the bundled manifest (app-bundled backend owns its schema)
repo-access.ts # File access abstraction (local + GitHub)
claude-helper.ts # Anthropic SDK wrapper for agents
sentry-client.ts # Sentry REST API client
report-generator.ts # Markdown + JSON export
agents/
sast-agent.ts # Security (SAST)
secrets-agent.ts # Secrets Exposure
sca-agent.ts # Dependencies (SCA)
quality-agent.ts # Code Quality
config-agent.ts # CI/CD & Config
container-agent.ts # Container Security
runtime-agent.ts # Runtime Health (Sentry)
ui/
index.html # Plugin webview shell
plugin.js # View routing + UI logic
styles.css # Dark-theme CSS
API Cost
Claude API calls are used by SAST, Secrets, Quality, and Container agents. A full audit of a medium-sized repo (~500 files) typically costs $0.02-0.10 in API tokens. Quick scans use no Claude API calls.
Costs are tracked via Omniscio's standard API cost ledger (trackApiCost).
For agents
Code Entry Points
- Plugin bridge:
src/main/ipc/plugin-bridge-handler.tsroutesscannamespace tohandleScanBridgeCall - Preload API:
src/preload/plugin-bridge-preload.tsexposesamc.scan.*methods - Settings:
sentryAuthTokenfield onAppSettingsinsrc/shared/types.ts
Related
RepoGuard has no sibling page of its own in the library. INDEX.md is the library index, and it is the fastest way to reach the other Omniscio areas this page leans on — the Marketplace where the plugin is installed and toggled, and the sidebar project list whose repos it scans.
Last verified 2026-09-28