Endor Labs

Set up endorctl and use Endor Labs to scan, prioritize, and fix security risks across your software supply chain

Play video

Endor Labs AI Plugins brings application security scanning directly into your development workflow. It automates the installation, authentication, and configuration of endorctl, the Endor Labs CLI, so you can scan, prioritize, and fix security risks across your software supply chain without leaving your coding environment. The plugin supports macOS (Intel/ARM), Linux, and Windows, and handles authentication via browser-based OAuth or API key credentials.

The plugin's setup skill walks through the full onboarding flow — checking for an existing endorctl installation, downloading it automatically if missing, collecting your Endor Labs namespace, authenticating, and running security scans. It fetches current scan options from Endor Labs documentation to ensure you always have the latest flags and capabilities available. Special handling is included for multi-tenant environments and non-interactive sessions.

How to use: After installing the plugin, try prompts like "set up endorctl" to install and configure the CLI, "install and authenticate with Endor Labs" to get started with your credentials, "switch to namespace my-company.my-project" to change your active namespace, or "scan this project for vulnerabilities" to run a security scan on your codebase.