sha256:6234ccbc863da704d5d4523b546e8c110b2f006b308706925afb9508e03f6579
Last pushed
9 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:6234ccbc863da704d5d4523b546e8c110b2f006b308706925afb9508e03f6579
Installs the GitGuardian CLI (ggshield) with proxy-injected API-key auth for api.gitguardian.com and wires it as a Claude Code AI hook, so the agent's actions are scanned for hardcoded secrets automatically - the real key never enters the sandbox.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 1.53.0 | ggshield release to install |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Required | GitGuardian API key (from a Personal or Service Account, "scan" scope). Stored on the host; the sandbox only sees a placeholder and the proxy injects the real value on requests to api.gitguardian.com. | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
claudesbx run <agent> --kit docker/sbx-kit-gitguardian:1.53.0Run the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbx