Plugin Claude Code
Plugin marketplace listing 1 plugin: secure-sdlc-agents.
Plugin Claude Code
Plugin marketplace listing 1 plugin: secure-sdlc-agents.
Plugin Claude Code
A team of AI security specialists embedded in your coding workflow. 8 agents covering every phase of the Secure SDLC: requirements, threat modelling, code review, IaC security, compliance, and release gating. Works with Claude Code, Cursor, Windsurf, and any MCP-compatible tool.
Agent Claude Code
AI/LLM Security Engineer. Specialist in the security risks unique to AI and LLM-powered features: prompt injection, indirect prompt injection, model poisoning, agentic trust boundaries, AI supply chain, output validation, and PII leakage to external model APIs. References OWASP Top 10 for LLMs 2025 and emerging 2026…
Agent Claude Code
Application Security Engineer. Performs threat modelling, reviews code for security vulnerabilities, triages SAST/DAST findings, coordinates penetration testing, and provides remediation guidance. This is the primary security SME throughout the SDLC. Use this agent when: A new architecture or significant feature…
Agent Claude Code
Cloud and Platform Security Engineer. Reviews infrastructure-as-code for misconfigurations, enforces secrets management practices, performs CSPM-style checks, validates runtime hardening, and ensures the deployment pipeline is secure. Use this agent when: Reviewing Terraform, Pulumi, CloudFormation, Helm, or…
Agent Claude Code
Secure Development Lead. Enforces secure coding standards, reviews pull requests for security issues, manages software composition analysis (SCA / dependency review), and implements fixes for vulnerabilities identified by AppSec. The bridge between security findings and developer-ready solutions. Use this agent when…
Agent Claude Code
Governance, Risk and Compliance Analyst. Maintains the risk register, maps security controls to compliance frameworks, collects audit evidence, and produces compliance attestations. Participates at the Plan, Design, Test and Release phases. Use this agent when: A new project requires a compliance framework mapping A…
Agent Claude Code
Secure Product Manager. Elicits and documents security requirements by mapping user stories and acceptance criteria to OWASP ASVS controls. Engages stakeholders to surface implicit security expectations. Should be invoked at the start of every feature or sprint to produce a security requirements document before design…
Agent Claude Code
Security-focused Release Manager. Executes the pre-release security checklist, aggregates sign-offs from all other agents, and issues a formal go/no-go decision. The final gate before any code reaches production. Use this agent when: A release candidate is ready and requires a security sign-off Running a pre-release…
Agent Claude Code
Security Champion — a developer-level security advocate embedded in the squad. Provides first-line security guidance, answers quick security questions, reviews small changes informally, and coaches developers on secure patterns. Lower friction than a full appsec review; higher throughput for day-to-day questions. Use…
Cursor rule Cursor
Secure SDLC — automatically apply security practices at every phase of development.
Instructions file
Instructions for Kaademos/secure-sdlc-agents, covering secure sdlc — multi-agent orchestration, agent roster, lifecycle phases & handoffs, 1. plan and 2. design.
Skill Claude CodeCodex
Use when building any feature that calls an LLM API, processes user input sent to a model, uses RAG or embeddings, deploys an AI agent with tool access, or makes AI-generated output visible to users or downstream systems.
Skill Claude CodeCodex
Use when a project requires a compliance framework mapping, when risks need formal documentation, when audit evidence must be collected, or when producing a compliance attestation before release. Applies to SOC 2, ISO 27001, GDPR, PCI DSS, NIST CSF, and DORA.
Skill Claude CodeCodex
Use when writing or reviewing code that handles user input, authentication, access control, cryptography, error handling, file uploads, or dependency management. Also activates when a pull request touches any security-sensitive component.
Skill Claude CodeCodex
Use when a new feature, architecture, or significant design decision is being made. Run before any code is written. Produces a structured STRIDE threat model and architecture review that feeds directly into security requirements and PR review.