sha256:6234ccbc863da704d5d4523b546e8c110b2f006b308706925afb9508e03f6579
Last pushed
9 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:6234ccbc863da704d5d4523b546e8c110b2f006b308706925afb9508e03f6579
schemaVersion: "3"
displayName: GitGuardian (ggshield)
description: Installs the GitGuardian CLI (ggshield) with proxy-injected API-key auth for api.gitguardian.com and wires it as a Claude Code AI hook, so the agent's actions are scanned for hardcoded secrets automatically - the real key never enters the sandbox.
version: 1.53.0
kind: mixin
provides:
- [email protected]
requires:
- claude
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
runtime:
allow:
- api.gitguardian.com
- type: com.docker.sandbox/credential@1
config:
apiKey:
inject:
- domain: api.gitguardian.com
format: Token %s
header: Authorization
name: GITGUARDIAN_API_KEY
proxyManaged: true
phase: runtime
service: gitguardian
description: GitGuardian API key (from a Personal or Service Account, "scan" scope). Stored on the host; the sandbox only sees a placeholder and the proxy injects the real value on requests to api.gitguardian.com.
- type: com.docker.sandbox/lifecycle@1
config:
install:
- command: |
set -euo pipefail
export GITGUARDIAN_API_KEY="${GITGUARDIAN_API_KEY:-proxy-managed}"
ggshield machine setup --agent claude-code --no-git-hooks --no-honeytokens
echo "ggshield AI hook installed (~/.claude/settings.json)"
description: Install ggshield as a Claude Code AI hook (agent user)
env:
- GITGUARDIAN_API_KEY
user: "1000"
- type: com.docker.sandbox/agent-context@1
config:
contentFile: /usr/share/sandbox/kit/gitguardian/gitguardian-context.md
args:
version:
default: 1.53.0
description: ggshield release to install
pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
buildArg: GGSHIELD_VERSION