Verune

Plugin

magician

Comprehensive software development lifecycle plugin that takes task from the idea to merged PR autonomously. Core capabilities: 1. Dynamic Project Inspector On every session start, it scans your project files (package.json, go.mod, Cargo.toml, pom.xml, etc.) and auto-assembles targeted knowledge ("lore") for every detected technology — no manual stack selection needed. Polyglot stacks get full coverage automatically. 2. Full Autonomous SDLC (/manifest) One command drives the entire flow with only 4 human approval gates: * /conjure — design dialogue (with an ability to strictly use design) → approved spec * /blueprint — implementation plan with parallelism map * /portal — git worktree isolation * /orchestrate + /ward — parallel agents with TDD * /certify — tests + types + linter + browser verification * /scrutinize → /absorb — multi-agent code review + integration * /seal — PR creation, loops until merged 3. Self-Learning A Stop hook (chronicle-stop.sh) captures git diffs at session end, writes entries to a chronicle, and detects repeated patterns. After 3 occurrences, it offers to codify the pattern as a reusable skill via /inscribe. 4. Team Memory Workspace .workspace/shared/ (git-committed, team-visible) holds context, roadmap, specs, and post-mortems. .workspace/local/ (gitignored) holds personal prefs and session state. 5. Security Infrastructure * Hard deny rules in settings.json blocking pipe-to-shell, eval, credential access * sentinel-guard.sh PreToolUse hook scanning every Bash command for injection patterns * magician-scan standalone CLI for CI pipelines * /sentinel skill for full OWASP Top 10 + credential + injection audits Skill Set (20 skills) Covers: debugging (/unravel), performance (/accelerate), incident analysis (/autopsy), CI/CD (/deploy), security (/sentinel), and meta-tooling (/inscribe).

Analysed
Last observed

What the code does

  • Sends data to outside servers Code that posts data to network addresses.
  • Refers to credential files Code that names files such as SSH keys or cloud credentials.
  • Runs hooks automatically Hooks that execute without being called explicitly.

Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.

This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.

Risk

Sign in to see this tool's overall risk level and what drives it. Free.

Sign in to see the risk level

Coverage

Complete static analysis

How coverage is measured

Detailed report

3 findings from automated static analysis of the latest version, with severities and explanations.

Sign in to view detailed report

Using this tool across your team? We can assess your whole inventory.

Request an inventory assessment