C

Cordon

Deterministic trust boundary between untrusted content and agent actions for Claude Code, Gemini CLI, MCP hosts and LangChain that strips the hidden layer, keeps provenance of every piece of data, issues an intent certificate and gates calls against it with no model call anywhere on the hot path, covered by 998 tests over 18 pinned attack vectors

ilyautov/cordon · v0.12.1 · Tools & Integrations

ilyautovcaution

Trust Score

72

Security

64

Surfaces

1

What is Cordon?

Cordon is a published tools & integrations plugin for AI coding agents in the gemini-cli ecosystem, developed by ilyautov and distributed through the HOL AI plugin registry. Deterministic trust boundary between untrusted content and agent actions for Claude Code, Gemini CLI, MCP hosts and LangChain that strips the hidden layer, keeps provenance of every piece of data, issues an intent certificate and gates calls against it with no model call anywhere on the hot path, covered by 998 tests over 18 pinned attack vectors

Canonical slug
ilyautov/cordon
Version
v0.12.1 · updated Oct 7, 2026

Trust & Reputation

HOL Trust Score
72

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
64pts
Maintenance
100pts
MCP Posture
100pts
Plugin Security
64pts
Provenance
70pts
Publisher Quality
75pts

Registry Snapshot

Publisher verification
No
Marketplace source
Unknown
Scanner
Broker fallback
Safety label
caution
Digest verified
Yes
1 bundled skill — copy or download SKILL.mdOpen skills

Trust & reputation

Trust & Reputation

HOL Trust Score
72

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
64pts
Maintenance
100pts
MCP Posture
100pts
Plugin Security
64pts
Provenance
70pts
Publisher Quality
75pts

Provenance

Plugin root
.
Source repo
https://github.com/ilyautov/cordon
Source commit
1181ed7e1103…
Publisher verified
No
Owner verified
Not owner verified

Continuous scanner CI detected

No action is required. This plugin receives the full trust score.

Verified badge not detected

Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.

Security Posture

caution
Safety label
64
Security score
0
High findings
Provider
registry-broker-fallback
Grade
D · caution
Version
Unknown
cisco-skill-scanner: unknown

Findings

mediumpublishabilitypublishability.link.missing.websiteURL

websiteURL should be present for marketplace readiness.

mediumpublishabilitypublishability.link.missing.privacyPolicyURL

privacyPolicyURL should be present for marketplace readiness.

mediumpublishabilitypublishability.link.missing.termsOfServiceURL

termsOfServiceURL should be present for marketplace readiness.

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

Cordon — Frequently asked questions

What is Cordon?
Cordon is an AI plugin in the HOL registry. Deterministic trust boundary between untrusted content and agent actions for Claude Code, Gemini CLI, MCP hosts and LangChain that strips the hidden layer, keeps provenance of every piece of data, issues an intent certificate and gates calls against it with no model call…
How do I install Cordon?
Install Cordon in your harness: Claude Code — /plugin marketplace add ilyautov/cordon; Antigravity CLI — npx skills add ilyautov/cordon; MCP — git clone https://github.com/ilyautov/cordon. Full step-by-step guidance is on the HOL plugin page.
How do I install Cordon in Claude Code?
To install Cordon in Claude Code, start with /plugin marketplace add ilyautov/cordon. The complete step-by-step install guide for Claude Code is on the HOL plugin page.
How do I install Cordon in Antigravity CLI?
To install Cordon in Antigravity CLI, start with npx skills add ilyautov/cordon. The complete step-by-step install guide for Antigravity CLI is on the HOL plugin page.
How do I install Cordon in MCP?
To install Cordon in MCP, start with git clone https://github.com/ilyautov/cordon. The complete step-by-step install guide for MCP is on the HOL plugin page.
Is Cordon free?
Pricing for Cordon is published on its HOL plugin page when the maker schedules a launch.
Who publishes Cordon?
Cordon is published by ilyautov and listed on HOL.
Is Cordon available now?
Cordon availability is listed on its HOL plugin page.

Install Guidance

Install in Claude Code

Install through the Claude Code plugin marketplace.

Claude Code plugin docs
  1. 1

    Add the marketplace

    Run this inside a Claude Code session.

    claude code
  2. 2

    Install the plugin

    Use the plugin name and the marketplace name shown by the previous command.

    claude code
  3. 3

    Scripted alternative

    Non-interactive equivalent for scripts and CI pipelines. Add --scope project to pin the install to one repository.

    shell

Plugin Manifest

{
  "name": "cordon",
  "version": "0.12.1",
  "description": "A prompt-injection firewall for AI agents, with no AI inside: your agent reads anything and takes orders only from you. For Claude Code, Codex CLI, Kimi Code, DeepSeek Harness, Gemini CLI, MCP hosts and LangChain.",
  "repository": "https://github.com/ilyautov/cordon",
  "interface": {
    "displayName": "cordon",
    "developerName": "ilyautov"
  },
  "skills": "./",
  "holManifestOrigin": "repository",
  "registryIndexVersion": 5
}

Marketplace Source

Repo URL
https://github.com/ilyautov/cordon
Marketplace path
Unknown
Source path
.
Install policy
Unspecified

Skills

1 SKILL.md file ship with this plugin. Preview, copy, or download each one, then install them with the Skills CLI.

Share
skills-cli
  • cordon-install

    skills/cordon-install/SKILL.md

    Install Cordon, a deterministic layer between untrusted content and agent actions, and verify that the harness actually calls it. Cordon strips the hidden layer from what the agent reads, remembers where data came from, and refuses calls outside the effect classes the user's own instruction allows. No model call on the hot path. Use when someone asks to protect an agent from prompt injection, to check whether a hook is really firing, or to install Cordon. Triggers: «install cordon», «поставь cordon», «защити агента от prompt injection», «prompt injection protection», «скрытые инструкции в тексте», «agent reads untrusted content», «cordon doctor», «проверь что хук срабатывает».

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

File Inventory

.codex-plugin/plugin.json

plugin-manifest

452 bytes

bfa30a15bc763dbf…

AGENTS.md

file

6,398 bytes

46c3b7685e7d2377…

gemini-extension.json

file

280 bytes

84ba2ac26cddb154…

hooks/hooks.json

file

1,583 bytes

e5c1705a5268ad57…

package-lock.json

file

78,980 bytes

b600bafa1b64a49d…

package.json

file

2,279 bytes

2b01bea13d8cf192…

README.md

file

15,797 bytes

62106f443e27883d…

SECURITY.md

file

3,256 bytes

9ddbf5293d0536bc…

skills/cordon-install/SKILL.md

skill

3,827 bytes

a493232d9627f538…

tsconfig.json

file

334 bytes

528912a32ede2e47…