security

security is a plugin for Claude Code from KhaledSaeed18/dotclaude. Its manifest loads nothing; the 3 skills, 1 command, 1 agent it bundles cost 420 tokens per session together, scanned A, original, MIT.

A security review toolkit for checking application code, third-party dependencies, and stored secrets against common web-security risks.

In plain words
What is it for?
Use it for OWASP-aligned reviews, dependency audits, secret audits, security-focused code review, and full-project security audits.
Why use it?
It gives you a structured way to find vulnerabilities, unsafe dependencies, and exposed credentials across a codebase.

Plugin for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Claude Code
/plugin marketplace add KhaledSaeed18/dotclaude
agentmods
npx agentmods add plugins/khaledsaeed18/dotclaude/security
Clone the repo
git clone --depth 1 https://github.com/KhaledSaeed18/dotclaude

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security

README.md
[![agentmods](https://agentmods.dev/badge/plugins/khaledsaeed18/dotclaude/security.svg)](https://agentmods.dev/plugins/khaledsaeed18/dotclaude/security)
Your own site
<a href="https://agentmods.dev/plugins/khaledsaeed18/dotclaude/security"><img src="https://agentmods.dev/badge/plugins/khaledsaeed18/dotclaude/security.svg" alt="Measured on agentmods" height="20"></a>
Per session not measured What this adds to a session before it is invoked.
When invoked not measured The manifest loads nothing itself; its 3 skills, 1 command, 1 agent cost 420 tokens a session between them.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Security

Grade A, and why

security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

The scan reads marketplace.json#security. This mod also ships 6 executable files (plugins/format-on-edit/scripts/format-on-edit.mjs, plugins/notify/scripts/notify.mjs, plugins/precompact-saver/scripts/precompact-saver.mjs, …), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude-plugin/marketplace.json#security · 18 lines

What it actually says

{
  "name": "security",
  "source": "./.claude-plugin/plugins/security",
  "description": "Security review toolkit: OWASP-aligned code review, dependency and secret auditing skills, a security-auditor agent, and a full-codebase /security-audit command.",
  "author": {
    "name": "Khaled Saeed"
  },
  "homepage": "https://github.com/KhaledSaeed18/dotclaude",
  "repository": "https://github.com/KhaledSaeed18/dotclaude",
  "license": "MIT",
  "category": "security",
  "keywords": [
    "owasp",
    "audit",
    "secrets",
    "dependencies"
  ]
}
Contents

What it installs

The manifest is a name and a version. 3 skills, 1 command, 1 agent travel with it, and installing the plugin installs all of them — 420 tokens a session between them. Each is measured on its own page, and each can be installed alone.

Files

What ships with it

60 files beside marketplace.json#security in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 18 lines scan A a2c1225589cd

Subscribe to this mod's changes

security is a plugin published in the GitHub repository KhaledSaeed18/dotclaude (5 stars, last pushed 3d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other plugins, from other repositories

instruction-placement

Routes agent-instruction content to the surface that loads it at the right moment. The audit skill sweeps a repository's instruction layer and its ordinary markdown for content whose scope is narrower than the surface carrying it — conventions keyed to one file type or one subtree sitting in an always-loaded CLAUDE.md.

melodic-software/claude-code-plugins · not measured

context-guard

Per-session context-window observability plus the first shipped consumer: a statusline wrapper tees each session's contextwindow fields to a per-session snapshot file, a zone resolver classifies usage into smart/acceptable/dumb bands (percentage bands plus window-class token bands, conservative-min combination, zones.

melodic-software/claude-code-plugins · not measured

ai-briefing

Build source-backed AI-industry briefings from official vendor publications, configured RSS/Atom feeds, GitHub releases, reputable secondary reporting, and user-supplied URLs. Deduplicate, rank, and present results as markdown or optional HTML/PPTX decks, with repository-owned profile, audience, and brand…

melodic-software/claude-code-plugins · not measured

docs-hygiene

Documentation-hygiene toolkit: compress (flavor-trim markdown with a semantic-diff safety net), audit-noise (classify markdown noise), extract-ssot (deduplicate repeated content into a single source of truth), audit-encapsulation (detect citations into skill-private surfaces), rename-references (sweep stale references.

melodic-software/claude-code-plugins · not measured

codebase-health

Repo-wide drift audit between docs, config, code, and architecture: verifies every factual claim against reality via parallel subagent fan-out, severity-rates findings, and reports read-only, delegating remediation to the implementation/verification lanes. Audit dimensions are configurable through a tracked…

melodic-software/claude-code-plugins · not measured

firecrawl

Web scraping, search, crawling, and file parsing through the firecrawl-cli binary with a write-to-disk-then-Read pattern that keeps large results out of context — a user-facing wrapper skill, a lazy-install setup skill, and a separate gated maintainer update skill tracking the upstream CLI and skill source.

melodic-software/claude-code-plugins · not measured