How to add a scanner, lockfile parser, or rule to HoneyBadger, plus the test-fixture and self-check requirements. Use when extending scanners or contributing to honeybadger.
Scanned 10/6/2026
npx -y skills add famclaw/honeybadger --skill honeybadger-dev --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Honeybadger Dev?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/famclaw-honeybadger-dev)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: honeybadger-dev
description: How to add a scanner, lockfile parser, or rule to HoneyBadger, plus the test-fixture and self-check requirements. Use when extending scanners or contributing to honeybadger.
---
# HoneyBadger — extending scanners
## Adding a scanner
- New scanner = its own package under `internal/scanner/<name>/`.
- Register it in `internal/engine/engine.go` (scanner list + verdict weighting).
- Ship a matching fixture in `internal/testfixture/` — fixtures build secrets **at runtime** (never hardcoded) so GitHub push protection doesn't reject the push.
## Common extensions
- New lockfile parser (Cargo.lock, pnpm-lock.yaml, poetry.lock): add in `internal/scanner/cve/deps.go`.
- New supply-chain rule / secret pattern: add YAML under `rules/` (embedded via `rules/embed.go`).
- Typosquat dictionary entries: `internal/scanner/supplychain`.
- New test fixture: add to `internal/testfixture/` with secrets built at runtime.
## Before submitting
`make build` · `make test` · `make self-check` (scans itself) · `go test -tags integration ./...`. Open the PR against `main`.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!