Supercov icon

Supercov

Coverage, security and code quality for coding agents.

supercorp/supercov · v4.0.0 · Development & Workflow

SupercorpOwner verifiedsafe

Trust Score

78

Security

95

Surfaces

2

What is Supercov?

Supercov is a published development & workflow plugin for AI coding agents in the codex ecosystem, developed by Supercorp and distributed through the HOL AI plugin registry. Coverage, security and code quality for coding agents.

Canonical slug
supercorp/supercov
Version
v4.0.0 · updated Oct 8, 2026

Trust & Reputation

HOL Trust Score
78

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
100pts
Maintenance
55pts
MCP Posture
100pts
Plugin Security
95pts
Provenance
70pts
Publisher Quality
75pts

Registry Snapshot

Publisher verification
No
Marketplace source
Unknown
Scanner
Broker fallback
Safety label
safe
Digest verified
Yes
2 bundled skills — copy or download SKILL.mdOpen skills

Trust & reputation

Trust & Reputation

HOL Trust Score
78

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
100pts
Maintenance
55pts
MCP Posture
100pts
Plugin Security
95pts
Provenance
70pts
Publisher Quality
75pts

Provenance

Plugin root
plugins/supercov
Source repo
https://github.com/supercorp-ai/supercov
Source commit
1e9732832971…
Publisher verified
No
Owner verified
@Nedomas

Continuous scanner CI not detected

This plugin remains listed. Its overall trust score is reduced by 10% because security checks are not maintained in the source repository's CI.

Optional: maintain the scanner in the source repository's CI to receive the full trust score. Listing does not require that change.

Verified badge not detected

Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.

Security Posture

safe
Safety label
95
Security score
0
High findings
Provider
registry-broker-fallback
Grade
A · safe
Version
Unknown
cisco-skill-scanner: unknown

Findings

lowoperational-securitysupply-chain.lockfile-missing

Repository snapshot does not include a lockfile.

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

Supercov — Frequently asked questions

What is Supercov?
Supercov is an AI plugin in the HOL registry. Coverage, security and code quality for coding agents.
How do I install Supercov?
Install Supercov in your harness: Codex — codex plugin marketplace add supercorp-ai/supercov; Claude Code — /plugin marketplace add supercorp-ai/supercov; Any agent — npx skills add supercorp-ai/supercov. Full step-by-step guidance is on the HOL plugin page.
How do I install Supercov in Codex?
To install Supercov in Codex, start with codex plugin marketplace add supercorp-ai/supercov. The complete step-by-step install guide for Codex is on the HOL plugin page.
How do I install Supercov in Claude Code?
To install Supercov in Claude Code, start with /plugin marketplace add supercorp-ai/supercov. The complete step-by-step install guide for Claude Code is on the HOL plugin page.
Is Supercov free?
Pricing for Supercov is published on its HOL plugin page when the maker schedules a launch.
Who publishes Supercov?
Supercov is published by Supercorp and listed on HOL.
Is Supercov available now?
Supercov availability is listed on its HOL plugin page.

Install Guidance

Install in Claude Code

Install through the Claude Code plugin marketplace.

Claude Code plugin docs
  1. 1

    Add the marketplace

    Run this inside a Claude Code session.

    claude code
  2. 2

    Install the plugin

    Use the plugin name and the marketplace name shown by the previous command.

    claude code
  3. 3

    Scripted alternative

    Non-interactive equivalent for scripts and CI pipelines. Add --scope project to pin the install to one repository.

    shell

Plugin Manifest

{
  "name": "supercov",
  "version": "4.0.0",
  "description": "Coverage, security and code quality for coding agents.",
  "author": {
    "name": "Supercorp",
    "url": "https://supercorp.ai"
  },
  "homepage": "https://supercov.com",
  "repository": "https://github.com/supercorp-ai/supercov",
  "license": "MIT",
  "keywords": [
    "coverage",
    "testing",
    "code-quality",
    "security"
  ],
  "skills": "./",
  "interface": {
    "displayName": "Supercov",
    "developerName": "Supercorp",
    "shortDescription": "Coverage, security and code quality for coding agents",
    "longDescription": "Runs your project's existing tests, measures line, branch and MC/DC coverage, and hands the agent the untested code to test next. Finds risky lines and code smells file by file, on the whole repository or only on the change. JavaScript, TypeScript, Python, Ruby, Rust, Go, Java and Kotlin.",
    "category": "Developer Tools",
    "capabilities": [
      "Interactive",
      "Read",
      "Write"
    ],
    "websiteURL": "https://supercov.com",
    "privacyPolicyURL": "https://supercov.com/privacy",
    "termsOfServiceURL": "https://supercov.com/terms",
    "defaultPrompt": [
      "Find the untested code in this repository and add tests for it.",
      "Check this branch for security issues.",
      "What should I refactor first?"
    ],
    "brandColor": "#000000",
    "composerIcon": "./assets/logo.png",
    "logo": "./assets/logo.png",
    "screenshots": [
      "./assets/screenshot.png"
    ]
  },
  "holManifestOrigin": "repository",
  "registryIndexVersion": 5
}

Marketplace Source

Repo URL
https://github.com/supercorp-ai/supercov
Marketplace path
Unknown
Source path
plugins/supercorp-ai/supercov
Install policy
AVAILABLE

Skills

2 SKILL.md files ship with this plugin. Preview, copy, or download each one, then install them with the Skills CLI.

Share
skills-cli
  • supercov-security

    skills/supercov-security/SKILL.md

    Scans a repository's source for security vulnerabilities with the supercov CLI, pointing to the line of each finding and mapping it to CWE classes. Use when the user asks for a security scan or audit, whether code is secure, or to find vulnerabilities, injection, hardcoded secrets or other insecure code.

    Raw SKILL.md
  • supercov

    skills/supercov/SKILL.md

    Measures test coverage and code quality in a repository with the supercov CLI, and turns what it finds into small, focused tests or fixes. Use when the user asks to add or improve tests, find untested code or raise coverage, or find what to refactor. Works with JavaScript, TypeScript, Python, Ruby, Rust, Go, Java and Kotlin projects.

    Raw SKILL.md

File Inventory

.claude-plugin/plugin.json

file

405 bytes

75d497561c0011ed…

.codex-plugin/plugin.json

plugin-manifest

1,351 bytes

260e8379878ace08…

assets/logo.png

asset

30,712 bytes

0ff2739aa0bb8b6f…

assets/screenshot.png

asset

231,580 bytes

cfaa67a54182e0d9…

commands/coverage.md

file

683 bytes

887670e7e77e702e…

commands/quality.md

file

790 bytes

e36aed62862365b9…

commands/review.md

file

902 bytes

7dd199ad34504df7…

commands/security.md

file

775 bytes

0e48d8d9afb3ac25…

plugin.json

file

480 bytes

899a1b82cae8a4bb…

README.md

file

1,504 bytes

a40e1c7fd2c6e9a2…

SECURITY.md

file

183 bytes

25e62c9be53f1cd9…

skills/supercov-security/SKILL.md

skill

942 bytes

34ba656f0899697a…

skills/supercov/SKILL.md

skill

1,660 bytes

6a9ee8e81c76f146…