---
title: "squirex"
description: "Agent-security scanner for Salesforce Agentforce, ServiceNow Now Assist, MuleSoft Agent Fabric, and MCP servers."
canonical: https://agentpluginsdirectory.com/plugins/squirex
last-updated: 2026-10-06
---

# squirex
Agent-security scanner for Salesforce Agentforce, ServiceNow Now Assist, MuleSoft Agent Fabric, and MCP servers.
- Slug: squirex
- Publisher: SquireX
- Repository: https://github.com/SquireX-dev/squirex-plugins
- Manifest: plugin.json
- Version: 0.0.0-dev
- License: MIT
- Category (editorial): other
- Skills: 5 (squirex-agent-config-review, squirex-agentforce-review, squirex-fix-violation, squirex-scan-agents, squirex-triage-findings)
- MCP servers: 1 (squirex)
- Stars: 0
- Repository created: 2026-10-05
- Repository last pushed: 2026-10-05
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/squirex
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What squirex does, in the publisher's words

This folder is the MIT-licensed plugin wrapper for SquireX. It packages:

- a local stdio MCP server launched via a pinned npx @squirex.dev/mcp-server@
- five agent skills for scan → triage → fix workflows
- manifests for Cursor (feeds Grok Bot), Claude plugin directory, and Agent Plugins / Codex

The scan engine itself (squirex CLI + Go interpreter) and @squirex.dev/mcp-server remain proprietary. This matches how Semgrep/Sonar ship marketplace plugins that invoke a separate engine.

> Status: packaging only. Marketplace submit clicks, npm publish, and the hosted HTTPS MCP (mcp.squirex.dev) are not done in this PR. See PUBLISH.md.

- SQUIREX_PROJECT_DIR: absolute path of the workspace to scan
- SQUIREX_LICENSE_KEY: Pro key for private-repo CI (sensitive). Not required for local scans of public repos.
- Email: hello@squirex.dev

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/SquireX-dev/squirex-plugins/HEAD/README.md

## MCP servers

- squirex: transport: stdio; command: npx @squirex.dev/mcp-server@0.0.0-dev; env: SQUIREX_PROJECT_DIR, SQUIREX_LICENSE_KEY

Read from the plugin's own mcp.json. Environment variable names only, never values.
