appsec-foundry/appsec-advisor

Claude Code plugin for code-anchored threat modeling and security architecture review.

16Stars on the repository
65Mods indexed here, across every type
todayLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

appsec-foundry/appsec-advisor

Agent

INTERNAL — controller-dispatched actor discovery after config/IaC scanning and before architecture modeling; writes .actors-discovered.json and is skipped in quick mode.

16 today A 40 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — Stage 4 of the create-threat-model skill. Rewrites the prose of an assembled threat model for clarity and consistency, and changes nothing else. Reads the bounded projection at .dispatch-context/editorial/blocks.json and writes one plan to .dispatch-context/editorial/plan.json; applyeditorialplan.py…

16 changed today A 90 tokens

appsec-foundry/appsec-advisor

Agent

Standalone AuthN/AuthZ analyzer. Consumes deterministic scanner output (sourceauthscanner, authzconfirm, routeinventory) and optional requirements violations to produce a cross-component authentication and authorization threat report. Runs as part of the authnz-review skill or as a post-Phase-9 deepener.

16 today B 67 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — controller-dispatched configuration and IaC analysis after recon and before STRIDE fan-out; emits contracted findings from supported deployment and package surfaces.

16 today B 36 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — controller-dispatched context resolver for approved external context, business context, and bounded repository documents; writes .threat-modeling-context.md.

16 today B 36 tokens

appsec-eval-judge

09

appsec-foundry/appsec-advisor

Agent

Semantic-quality judge for a threat-model run, used by the eval-threat-model dev/test skill (NOT in the create-threat-model phase map). Two modes: JUDGE surfaces candidate quality defects for one rubric dimension from a pre-digested brief; VERIFY adversarially refutes another judge's candidates (refute-by-default)…

16 today A 104 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — lightweight repair executor for the create-threat-model re-render loop; rewrites only planned fragments and reruns deterministic composition without analysis stages.

16 today A 36 tokens

appsec-ms-renderer

12

appsec-foundry/appsec-advisor

Agent

INTERNAL specialist for Stage-2 Management Summary fragments. Authors only management-summary inputs; the controller owns composition and shared stage state.

16 today A 32 tokens

appsec-qa-reviewer

14

appsec-foundry/appsec-advisor

Agent

INTERNAL — exceptional Stage-3 semantic triage after the deterministic QA gate. Consumes a compact repair plan; never repeats the full mechanical detector battery.

16 today A 38 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — controller-dispatched repository reconnaissance for structure, technology, and security-relevant code signals; writes $OUTPUTDIR/.recon-summary.md.

16 today D 37 tokens

appsec-reviewer

16

appsec-foundry/appsec-advisor

Agent

Security reviewer for a single code change. Reads the diff, works out which security expectations it implicates, and grades the post-change code PASS/PARTIAL/FAIL/UNVERIFIABLE/NOTAPPLICABLE with file:line evidence and a code-aware fix → .requirements-verification.json. Grades against the active standard: the company…

16 today A 137 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — dispatched on request when APPSECPLUGINDEV=1, either from the offer after a create-threat-model run's completion summary or from /appsec-advisor:diagnose-run. Reads the deterministic .run-issues.json, decides per issue whether the symptom is a defect in this plugin or an environment/expected condition, and…

16 today A 110 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL specialist for the Stage-2 Security Architecture fragment. Authors only evidence-grounded prose in security-architecture.md; the controller owns composition and shared stage state.

16 today A 40 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — controller-dispatched STRIDE fan-in reviewer for bounded merge candidates; emits merge, keep, or consolidate decisions without performing STRIDE analysis.

16 changed today A 36 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — controller-dispatched cross-component threat triage; validates rating consistency and prioritization, writes .triage-flags.json, and annotates .threats-merged.json.

16 changed today A 45 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — dedicated Stage-1b analyst. Assesses deterministic crossing signals in a fresh context and writes only untrusted trust-boundary candidates and explicit signal dispositions.

16 today A 43 tokens