---
title: "code-safety"
description: "trigger: secrets, eval/exec, unsanitized SQL, hallucinated dependencies. avoid: committing credentials, adding unverified packages, executing dynamic code. Install scan-secrets for the enforced counterpart of the secret "
canonical: https://agentpluginsdirectory.com/plugins/code-safety--open-coder-ai-7
last-updated: 2026-10-03
---

# code-safety
trigger: secrets, eval/exec, unsanitized SQL, hallucinated dependencies. avoid: committing credentials, adding unverified packages, executing dynamic code. Install scan-secrets for the enforced counterpart of the secret slice (a commit-time gate), and verify-dependency-exists for the dependency slice (opt-in: disabled by default, needs a curated allowlist); the eval/exec and unsanitized-SQL guidance stays advisory (a gate can decide only the non-literal slice: agentic-code-security's code pack).
- Slug: code-safety--open-coder-ai-7
- Publisher: chock-core
- Repository: https://github.com/open-coder-ai/chock
- Manifest: .agents/policies/code-safety/plugin.json
- Version: 0.0.3
- License: Apache-2.0
- Category (editorial): other
- Skills: 1 (code-safety)
- MCP servers: 0
- Stars: 8
- Repository created: 2026-08-17
- Repository last pushed: 2026-10-03
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/code-safety--open-coder-ai-7
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## Skills

- code-safety: trigger: secrets, eval/exec, unsanitized SQL, hallucinated dependencies. avoid: committing credentials, adding unverified packages, executing dynamic code. Install scan-secrets for the enforced counterpart of the secret slice (a commit-time gate), and verify-dependency-exists for the dependency sli…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
