COPS
Copilot Operations Plugins for Security: an open-source, universal catalog of defensive cybersecurity plugins, 18 specialist agent profiles, and offline verification tools for AI coding assistants.
Why COPS?
Whether your engineering and security teams operate in GitHub Copilot, Claude Code, or Codex / ChatGPT, COPS provides production-grade cybersecurity capabilities without vendor lock-in.
- 100% Offline-First by Default: Explore tools, run demos, and validate detection logic straight from your local terminal with standard Python. No cloud credentials, assistant installations, or live tenant connections required.
- Deterministic Script-First Tooling: Offloads calculations, graph traversals, and schema validations to standard-library Python scripts. Fast, deterministic, and preserves model tokens.
- Universal Multi-Assistant Portability: A single catalog in
catalog/plugins.jsonpowers GitHub Copilot, Claude Code, and Codex with zero configuration drift. - 18 Specialist Agent Profiles: Pre-tuned security personas spanning detection engineering, threat hunting, DFIR, cloud IAM, and AppSec, with dynamic zero-token routing and Triad orchestration.
- Truth-in-Advertising & Evidence Standard: Every capability is categorized into four explicit operational readiness modes (
planned,import,laboratory,live-validated), preventing over-claiming. - MITRE ATT&CK & Attack Flow Coverage: Formally mapped against the pinned ATT&CK Enterprise Matrix (v18.0) and MITRE Attack Flow standards.
5-Minute Quickstart
Run these standard Python commands in your terminal to explore the catalog:
# 1. Clone the repository
git clone https://github.com/sodejm/copilot-operation-plugin-for-security.git
cd copilot-operation-plugin-for-security
# 2. Check local environment health and catalog synchronization
python3 -m cops doctor
# 3. List all 13 plugins and their validation status
python3 -m cops list
# 4. Route a natural language security task to the optimal specialist
python3 -m cops route "Optimize Sentinel KQL query for high-volume sign-in events"
# 5. Run a safe, offline demonstration with synthetic data
python3 -m cops demo sentinel-hunt-workbench
# 6. Run the plugin's deterministic verification suite
python3 -m cops check sentinel-hunt-workbench
Read the full Getting Started Guide for detailed step-by-step instructions.
Cybersecurity Capability Domains
COPS organizes 13 dedicated security plugins across six cybersecurity disciplines:
📡 Logging & Telemetry
Audit codebases for security logging gaps, flag sensitive data leaks, and verify end-to-end pipeline routes from Cribl to Splunk and Sentinel.
Plugins: Security Logging Advisor Stable, Telemetry Proof Pack Beta
🔍 Detection & Hunting
Guide SOC alert triage with rival hypotheses, stress-test 12 Microsoft Sentinel KQL hunts, trace cloud lateral movement paths, and enrich indicators.
Plugins: SOC Investigation, Sentinel Hunt, Attack Path, Detection Quality, Threat Intel
🔑 Identity & Access
Audit Microsoft Entra ID role assignments, app registrations, service principal credentials, and consent grants from offline JSON exports.
Plugins: Entra Identity Workbench Beta
🛡️ Vulnerability Management
Correlate advisory CVEs with software bills of materials (SBOM) and call graph reachability, and inspect pull request diffs for dangerous patterns.
Plugins: Exposure Triage Beta, Patch Security Review Beta
⚔️ Offensive Security
Translate authorized rules of engagement into bounded, passive review plans and evaluate AI agent prompt injection resistance in a sandbox.
Plugins: Attack Surface Planner Experimental, Foundry Agent Harness Beta
🚨 Incident Response
Rehearse containment playbooks, calculate cloud resource blast radius, and generate cryptographic execution receipts under interactive operator approval.
Plugins: Incident Response Sandbox Beta
For a side-by-side comparison of problem statements and operational playbooks, see When to Use Each Plugin.
18 Specialist Agent Profiles & Dynamic Routing
COPS centralizes 18 callable specialist profiles housed in agents/ across offensive, defensive, forensics, identity, and governance domains:
flowchart LR
TASK["Incoming Security Task"] --> ROUTER["Zero-Token Router<br/>cops route"]
ROUTER --> SPEC["18 Specialist Profiles"]
SPEC --> OFF["Offensive Security<br/>Pentest, Red Team, AI Red Team"]
SPEC --> DEF["Defensive & Detection<br/>Sentinel KQL, Threat Hunter, SOC"]
SPEC --> DFIR["Incident Response & Forensics<br/>Blast Radius, Collector, Malware"]
SPEC --> IAM["Identity & AppSec<br/>Entra ID, Exposure, Code Review"]
SPEC --> GOV["Governance & Efficacy<br/>Purple Team, Logging Architect"]
When high-risk operations are requested (e.g. penetration testing, red team emulation, active containment rehearsal), COPS dynamically activates Triad Orchestration (Primary Specialist + Domain Skeptic + Evidence Auditor) requiring interactive human operator confirmation.
Learn more in the Specialist Agents Guide.
Documentation Quick Links
- 5-Minute Quickstart Guide: Installation, diagnostics, and running your first demo.
- Plugin Selection Guide: Clear criteria on when to reach for each plugin.
- 18 Specialist Agents: Agent catalog, zero-token routing, and Triad safety.
- ATT&CK Matrix (v18.0): Mappings and validation state across all capabilities.
- Universal Portability: Multi-assistant sync architecture.
- Contributor Guide: Development environment setup, adding plugins, and test gates.
- Troubleshooting: Step-by-step solutions for common setup issues.
- Security Model: Threat modeling, prompt injection resistance, and readiness modes.
- Engagement Contracts Specification: Schema contracts for engagements, scenarios, action plans, and findings.
- Execution Authorization Specification: Cryptographically bound approval envelopes and legacy receipt rejection.
- Isolated Worker and Approval Store Specification: Process boundaries, SQLite approval store, and anti-replay execution.
- Execution Scope & Egress Specification: Execution-time destination verification, cloud metadata defense, and DNS pinning.
- Tool Adapter Registry Specification: Declarative typed parameters, command assembly, and parameter injection prevention.
- Credential and Evidence Handling Specification: Real-time stream redaction, secret masking, and cryptographic run-result evidence binding.
- Execution Recovery and Cleanup Specification: Ownership-aware side-effect ledgers, cancellation resilience, non-idempotent handling, and verifiable cleanup receipts.
- Pinned Scenario Registry: Pinned research sources and canonical scenario registry.
- Capability Reconciliation: Operational readiness taxonomy and truth-in-advertising invariants.