secawa-com/plugin-auditor

Static security audit for Claude Code plugins, skills, agents, hooks, and MCP servers. Detects backdoors, prompt injection, persistence hooks, and supply-chain risks via parallel sub-agents.

2Stars on the repository
15Mods indexed here, across every type
1mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

plugin-auditor

02

secawa-com/plugin-auditor

Plugin Claude Code

Static security audit for projects extending Claude (skills, agents, hooks, plugins, MCP servers, slash commands, etc.) before installing them in Claude Code. Detects backdoors, prompt injection, persistence hooks, and supply-chain risks via parallel sub-agents.

2 1mo ago A tokens not measured original MIT

safe-fixture

04

secawa-com/plugin-auditor

Plugin Claude Code

A minimal known-good fixture used by plugin-auditor tests. Should produce a NO FINDINGS (static) verdict.

2 1mo ago A tokens not measured original MIT