verify-dependency-exists
v0.0.4Block hallucinated or unknown dependencies before they enter the repo. Watches requirements.txt, pyproject.toml, package.json, and go.mod, and blocks any newly added dependency not present in the allowlist file. Opt-in: disabled by default because it requires a curated allowlist. Enable with `chock enable verify-dependency-exists` after populating .chock/dependency-allowlist.txt. Runs at commit and at agent tool-use (a manifest edit is judged against the file on disk, and at the turn's end against HEAD). [Session-enforced at the turn's end by a Stop hook; needs git and a Python 3.11+. This client records no file-writing tool vocabulary, so the write itself is not judged: what the turn actually left on disk is re-read, and a construct a rule denies is refused then, however it was written. With no working Python the hook exits 2; without git, fail-open clients allow silently. A gate that cannot reach a decision refuses rather than allowing one it never judged. Enforcement at every commit and in CI still needs chock installed in the repo. Enforces only in a client that reads the com.github.copilot namespace and tells the hook where the package lives; a client that exports no plugin-root variable runs the hook, which then allows, so treat this package as advisory unless a deny has been witnessed in your own client.]
By chock-coreLicense: Apache-2.02 GitHub starsUpdated 6 days ago
Directory evidence
- Runtimes
- Agent Plugins
- Parsed components
- 1 skill or MCP entry
- Source updated
- Sep 30, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Get the plugin
git clone https://github.com/open-coder-ai/chock-copilot-pluginsClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is copilot/verify-dependency-exists/.
This listing currently publishes only the generic Agent Plugins format. Automatic install commands for other clients are not generated yet.
Plugin files
├── plugin.json└── skills/verify-dependency-exists/SKILL.md
Included Skills1
Block hallucinated or unknown dependencies before they enter the repo. Watches requirements.txt, pyproject.toml, package.json, and go.mod, and blocks any newly added dependency not present in the allowlist file. Opt-in: disabled by default because it requires a curated allowlist. Enable with `chock enable verify-dependency-exists` after populating .chock/dependency-allowlist.txt. Runs at commit and at agent tool-use (a manifest edit is judged against the file on disk, and at the turn's end against HEAD).
Plugin manifests1
{
"$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
"name": "verify-dependency-exists",
"version": "0.0.4",
"description": "Block hallucinated or unknown dependencies before they enter the repo. Watches requirements.txt, pyproject.toml, package.json, and go.mod, and blocks any newly added dependency not present in the allowlist file. Opt-in: disabled by default because it requires a curated allowlist. Enable with `chock enable verify-dependency-exists` after populating .chock/dependency-allowlist.txt. Runs at commit and at agent tool-use (a manifest edit is judged against the file on disk, and at the turn's end against HEAD). [Session-enforced at the turn's end by a Stop hook; needs git and a Python 3.11+. This client records no file-writing tool vocabulary, so the write itself is not judged: what the turn actually left on disk is re-read, and a construct a rule denies is refused then, however it was written. With no working Python the hook exits 2; without git, fail-open clients allow silently. A gate that cannot reach a decision refuses rather than allowing one it never judged. Enforcement at every commit and in CI still needs chock installed in the repo. Enforces only in a client that reads the com.github.copilot namespace and tells the hook where the package lives; a client that exports no plugin-root variable runs the hook, which then allows, so treat this package as advisory unless a deny has been witnessed in your own client.]",
"author": {
"name": "chock-core"
},
"repository": "https://github.com/open-coder-ai/chock",
"license": "Apache-2.0",
"keywords": [
"chock",
"policy-as-code",
"hook",
"block",
"{'control': 'asi04', 'coverage': 'partial', 'note': 'allowlist gate over newly-added dependencies in requirements.txt, pyproject.toml, package.json, go.mod at commit entry; it checks membership in a curated allowlist, not existence in the upstream registry'}"
],
"extensions": {
"io.github.open-coder-ai": {
"artifact": "hook",
"enforcement": "block",
"hooks": "com.github.copilot/hooks/hooks.json"
}
}
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[verify-dependency-exists on Agent Plugins Marketplace](https://pluginsmp.com/plugins/verify-dependency-exists-7)