molecule-core/plugins
Hongming Wang 720e92e426 feat(plugin): split compliance-posture into 3 plugins (#256)
Closes #256. Per CEO direction, shipping three separate opt-in plugins
instead of one bundled "compliance-posture" — keeps installs granular
so a workspace that only wants CVE scanning doesn't carry OWASP policy
or append-only audit retention.

- plugins/molecule-compliance/        — wraps compliance.py (OWASP OA-01
  prompt injection + OA-03 excessive agency). Skill: owasp-agentic.
- plugins/molecule-audit/              — wraps audit.py (EU AI Act Art.
  12/13/17 append-only JSONL log, SIEM-friendly). Skill: ai-act-audit-log.
- plugins/molecule-security-scan/      — wraps security_scan.py (Snyk or
  pip-audit CVE gate on skill requirements.txt). Skill: skill-cve-gate.

Each plugin ships a manifest + one SKILL.md with:
- When to install / when to skip
- Configuration shape (config.yaml blocks)
- Anti-patterns to avoid
- Cross-references to the other two plugins so an operator can reason
  about the full compliance surface

All three wrap code that already exists in workspace-template/builtin_tools/
— no Python changes. Install per workspace via
POST /workspaces/:id/plugins {"source":"builtin://molecule-<name>"}.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-15 14:15:25 -07:00
..
browser-automation initial commit — Molecule AI platform 2026-04-13 11:55:37 -07:00
ecc initial commit — Molecule AI platform 2026-04-13 11:55:37 -07:00
molecule-audit feat(plugin): split compliance-posture into 3 plugins (#256) 2026-04-15 14:15:25 -07:00
molecule-audit-trail feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-careful-bash feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-compliance feat(plugin): split compliance-posture into 3 plugins (#256) 2026-04-15 14:15:25 -07:00
molecule-dev initial commit — Molecule AI platform 2026-04-13 11:55:37 -07:00
molecule-freeze-scope feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-hitl feat(plugin): molecule-hitl — opt-in HITL gates (#257) 2026-04-15 14:03:19 -07:00
molecule-prompt-watchdog feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-security-scan feat(plugin): split compliance-posture into 3 plugins (#256) 2026-04-15 14:15:25 -07:00
molecule-session-context feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-skill-code-review feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-skill-cron-learnings feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-skill-cross-vendor-review feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-skill-llm-judge feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-skill-update-docs feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-workflow-retro feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
molecule-workflow-triage feat(plugins): split guardrails into 12 modular plugins 2026-04-14 12:20:04 -07:00
superpowers chore: structural cleanup — dead dirs, moves, gitignore 2026-04-13 14:06:52 -07:00