Contribute a check
What the repository asks for, how it is proved, and the route from an idea to a merged template.
cxg ships with no checks in it. The engine is one thing and the checks are another, and the second is cert-x-gen-templates: a public repository under the Apache-2.0 licence, with its own release schedule, its own CI, and an open contribution process.
That split is the reason a check can land without an engine release, and the reason a template you write for yourself is the same kind of artifact as one that ships. There is no privileged internal format.
A file, in one of twelve languages, that cxg runs against a target and reads a JSON findings array back from. Its metadata is a comment header in the first fifty lines, in the file’s own comment syntax, which is what the engine reads to list, filter, and select it.
The repository states the bar in its own first paragraph: a template is a program that decides, not a pattern that matches. It runs against a target, observes something specific, and returns a verdict it can defend.
| To learn | Read |
|---|---|
| The contract, end to end, by building one | Write your first template |
| Every field the three parsers accept | Template schemas |
| Why a template is a process and not a plugin | How cxg executes templates |
| What that grants the template on your machine | Template trust model |
| Conventions language by language | docs/TEMPLATE_GUIDE.md |
Checks live at templates/<category>/<subject>/, one file per check. The
category set is fixed, and adding to it is a change to the repository’s own CI
configuration rather than a matter of taste:
ai cli-baseline databases devops messagingmonitoring network recon tooling webThree other directories carry the parts of a check that are not the check:
fixtures/<template-id>/ holds a synthetic target built for that template,
in a flawed and a fixed variant from one source, with a prove.sh that asserts
both directions.docs/playbooks/ holds one human-facing document per differentiated
template: the case for the check, a mermaid diagram of the probe flow ending at
its verdict, and why observing the behaviour beats reading the configuration.
Every one is published here under
Playbooks, and
Execution authority
is the worked example: the best single thing to read to understand what the
corpus is aiming at.tests/ holds the behavioural harnesses too large to sit beside a fixture.The template catalog publishes every one of those checks. Browse it by category, language, severity or target kind, or by the weakness class a check looks for. Each check has a page of its own setting out what it looks for, with a link to the file it is written in and to its playbook where it has one.
cxg fetches the published set the first time you run any command, into the user
template directory. cxg template update refreshes it, cxg template pwd prints
the directories being searched and their priority order, and cxg template add
installs a file of your own alongside them. A scan can also ignore all of that
and take --template-dir, which replaces the normal discovery locations
entirely.
Apache-2.0, the same licence as the engine. Free to use commercially, free to fork, free to extend privately.
The repository carries the governance that goes with that: a
contribution guide
that is the contract for what a merged template has to satisfy, a
Contributor Covenant code of conduct,
a security policy
routing vulnerability reports to security@bugb.io rather than the issue
tracker, and
CONTRIBUTORS.md,
where people who land a check are named.
A check you needed and could not find is the most useful thing you can send.
Contribute a check
What the repository asks for, how it is proved, and the route from an idea to a merged template.
See why the bar is where it is
A check whose evidence exists only across a sample of responses, run against a target that has the defect and one that does not.