About this project

COPS (Copilot Operations Plugins for Security) is an open-source, universal catalog of defensive cybersecurity plugins, agent skills, and offline verification tools. It provides production-grade security capabilities that work across multiple AI coding assistants, including GitHub Copilot, Claude Code, and Codex/ChatGPT, without locking users into a single ecosystem. The project is designed offline-first: all demos, checks, and validations run locally using standard Python, with no cloud credentials or live tenant connections required. ## Quickstart Requires Python 3.11+. Clone the repo and run commands using only the standard library: ```bash git clone https://github.com/sodejm/copilot-operation-plugin-for-security.git cd copilot-operation-plugin-for-security python3 -m cops doctor python3 -m cops list python3 -m cops info sentinel-hunt-workbench python3 -m cops demo sentinel-hunt-workbench python3 -m cops check sentinel-hunt-workbench ``` - `cops doctor`: Checks Python environment readiness and catalog sync. - `cops list`: Lists available security plugins, maturity, and validation status. - `cops demo`: Runs self-contained offline walkthroughs with synthetic data. - `cops check`: Executes deterministic verification suites (syntax, schema, mutation tests). ## Available Plugins Each plugin lives in `plugins/<category>/<plugin-id>/` with a practitioner playbook: - **Security Logging Advisor** (Logging & Telemetry): Audits codebases for security logging gaps, flags sensitive data leaks, prioritizes CVE reachability. - **SOC Investigation Workbench** (Detection & Hunting): Guides incident investigations using competing hypotheses, question ranking, and evidence dependency graphs. - **Sentinel Hunt Workbench** (Detection & Hunting): Authors, adapts, and stress-tests 12 defensive Microsoft Sentinel and Defender KQL threat hunts offline. - **Attack Path Workbench** (Detection & Hunting): Traces multi-hop cloud lateral movement paths from local exports to crown jewels and finds remediation choke points. - **Attack Surface Planner** (Offensive Security): Translates authorized rules of engagement into bounded, passive review plans from local export manifests. ## Universal Portability COPS uses a central catalog (`catalog/plugins.json`) as the single source of truth. Each plugin maintains a core Agent Plugins v1.0.0 manifest (`plugin.json`), host manifests (`.claude-plugin/`, `.codex-plugin/`), and reusable skills. Running `python3 -m cops generate` automatically creates and synchronizes marketplace configuration files for GitHub Copilot, Claude Code, and Codex/ChatGPT. Test gates ensure host indexes never drift out of sync. ## Contributor Setup ```bash python3 -m venv .venv source .venv/bin/activate python3 -m pip install -r requirements.txt make check-prerequisites make check ``` Review `docs/ADDING_A_PLUGIN.md`, `AGENTS.md`, and `CONTRIBUTING.md` before contributing. ## Evidence & Safety Principles - **Offline Safety**: Demos and checks run against local synthetic data; no unreviewed network calls or writes to remote production services. - **Clear Status Separation**: Distinguishes locally validated from unverified live-cloud behavior; passing offline tests prove code correctness, not live SIEM alerts. - **Data Privacy**: Treats all input code and logs as sensitive; no credential storage or third-party telemetry. ## License COPS code and docs are licensed under the PolyForm Noncommercial License 1.0.0. Reusable components from PARK retain Apache-2.0 notices (see THIRD_PARTY_NOTICES.md).