[External Plugin]: sechelix-lite
Plugin name
sechelix-lite
Short description
Application-security review skill for codebases and pull requests you are authorized to assess. Maps trust boundaries, keeps issues as hypotheses until evidenced, runs a separate pass that tries to refute material findings, and ends with a release verdict.
GitHub repository
omarmohelal/SecHelix
Plugin path inside the repository
distributions/awesome-copilot
Ref to review
v4.0.0-alpha.6
Commit SHA to review
a73be865fccf5cefcf98d4dcce2c2bf2b6afce2f
Version
4.0.0-alpha.6
License identifier
Apache-2.0
Author name
Omar
Author URL
https://github.com/omarmohelal
Homepage URL
No response
Keywords
security appsec security-review code-review authorization business-logic supply-chain ai-security
Additional notes for reviewers
This is a fresh submission after addressing the feedback on #2899. The public-directory package has been reduced to a focused AppSec skill: SKILL.md is now 197 lines with 5 supporting files (all Markdown references, no scripts). Product, runtime, SEO and cleanup material is intentionally excluded from this package, and the plugin path points at that package rather than the repository root.
It needs no runtime or network access. A CI check in the source repository keeps the package within 220 lines and 6 supporting files.
Submission checklist
- The plugin lives in a public GitHub repository.
- The ref and/or sha I provided is immutable (release tag and/or full 40-character commit SHA), not a branch.
- This submission follows this repository's contribution, security, and responsible AI policies.
- This plugin is not already listed in the Awesome Copilot marketplace.
Source: github/awesome-copilot