Description
Integrate the SIN-Code-Security-Bundle (v1.3.0, production ready) as sin security subcommand.
Current State
- SIN-Code-Security-Bundle exists at
OpenSIN-Code/SIN-Code-Security-Bundle
- Has Go CLI (
sin-security) + Python MCP server (8 tools)
- Orchestrates 8 security tools: Secrets, SAST, SCA, SBOM, Container, IaC, License, DAST
- 8 compliance frameworks: CIS, NIST, SOC2, ISO27001, GDPR, HIPAA, PCI, OWASP
- 44 tests, CI/CD, v1.3.0 tag, 6 commits
- NOT integrated into
sin CLI at all
Required Integration
- Add
sin security top-level command wrapping sin-security binary
- Add
sin code security to sin code hub
- Register MCP server in
sin serve / opencode.json
- Add to
sin status detection
Commands to Expose
sin security scan . --compliance cis,nist --fail-on high
sin security sca .
sin security container .
sin security iac .
sin security license .
sin security dast --target-url https://app.example.com
sin security sast .
sin security secrets .
sin security sbom .
sin security openafd . --url https://openafd.example.com
sin security list-tools
sin security list-frameworks
MCP Tools (8) to Register
sin_security_full_scan
sin_security_blast_radius
sin_security_remediation_plan
sin_security_compliance_report
sin_security_executive_summary
sin_security_technical_report
sin_security_html_dashboard
sin_security_list_tools
sin_security_list_compliance_frameworks
Acceptance Criteria
Priority
HIGH — Production-ready security orchestration sitting unused; biggest missing feature
Description
Integrate the SIN-Code-Security-Bundle (v1.3.0, production ready) as
sin securitysubcommand.Current State
OpenSIN-Code/SIN-Code-Security-Bundlesin-security) + Python MCP server (8 tools)sinCLI at allRequired Integration
sin securitytop-level command wrappingsin-securitybinarysin code securitytosin codehubsin serve/ opencode.jsonsin statusdetectionCommands to Expose
MCP Tools (8) to Register
sin_security_full_scansin_security_blast_radiussin_security_remediation_plansin_security_compliance_reportsin_security_executive_summarysin_security_technical_reportsin_security_html_dashboardsin_security_list_toolssin_security_list_compliance_frameworksAcceptance Criteria
sin security --helpshows all subcommandssin security scan .runs full orchestrationsin code securityworks in hubsin servesin statusshows "Security Bundle: v1.3.0 ✅"Priority
HIGH — Production-ready security orchestration sitting unused; biggest missing feature