agent security plugins

33 tagged agent security, measured the same way as everything else here.

Browse within: ai-security 8ai-agent-security 5audit-trail 5

claude-code-plugin

02

emiliaprotocol/emilia-protocol

Plugin Claude Code

Require a named human's signed approval before Claude does anything irreversible — money movement, destructive shell, external sends. High-risk tool calls are held until a person approves on their own device (Face ID / passkey), producing an offline-verifiable Trust Receipt. Fail-closed.

653 yesterday A tokens not measured original Apache-2.0

adrian

03

secureagentics/Adrian

Plugin Claude Code

Runtime AI-security tooling for Claude Code and agentic AI, from the Adrian OSS project.

553 12d ago A tokens not measured original Apache-2.0

claude-code

04

secureagentics/Adrian

Plugin Claude Code

Adrian runtime security: observability and blocking for Claude Code sessions.

553 12d ago A tokens not measured original Apache-2.0

claude-code-plugin

05

hashgraph-online/hol-guard

Plugin Claude Code

Install and manage the local-first HOL Guard package for Claude Code. This plugin guides setup and status checks; HOL Guard itself installs and owns runtime security hooks for risky commands, secrets, packages, MCP, and supply-chain activity.

504 2d ago A tokens not measured original Apache-2.0

sponsio-claude-code

07

SponsioLabs/Sponsio

Plugin Claude Code

Runtime contract guardrails for every tool call in your Claude Code session — backed by per-plugin contract libraries under /.sponsio/plugins/.

438 3d ago A tokens not measured original Apache-2.0

pegasi

08

pegasi-ai/reins

Plugin Claude Code

Plugin marketplace listing 1 plugin: reins.

408 3mo ago A tokens not measured original Apache-2.0

reins

09

pegasi-ai/reins

Plugin Claude Code

Security controls for AI agents — deterministic policy enforcement, OWASP ASI10 scanning, and audit trails.

408 3mo ago A tokens not measured original Apache-2.0

reins

10

pegasi-ai/reins

Plugin Claude Code

Runtime security for AI agents. Blocks destructive actions before execution, routes high-risk operations through human approval, and maintains an immutable audit trail. Covers OWASP MCP Top 10, ASI Top 10, and Agentic Skills Top 10.

408 3mo ago A tokens not measured original Apache-2.0

praxen

12

open-agent-ai-security/praxen

Plugin Claude Code

Praxen — agent behavior verifier. Compares an AI agent's declared policy (Worker Remit) against the available evidence — source code, live deployment state, or behavioral artifacts — and reports where observed behavior diverges from declared intent. Make sure your agent does its job — and only its job.

59 2d ago A tokens not measured original Apache-2.0

trustabl

13

trustabl/trustabl

Plugin Claude Code

Plugin marketplace listing 1 plugin: trustabl.

42 5d ago A tokens not measured original Apache-2.0

trustabl

14

trustabl/trustabl

Plugin Claude Code

Self-audit AI agent, tool, and MCP-server code for security and reliability misconfigurations with Trustabl, the agent reliability scanner for the OpenAI Agents SDK, Claude Agent SDK, Google ADK, and MCP. Ships two skills (trustabl-scan and trustabl-enrich) and a subagent (trustabl) that together form a scan → enrich…

42 5d ago A tokens not measured original Apache-2.0

ryk

15

christopherkarani/ryk

Plugin Claude Code

ryk safety hooks and skills for Claude Code.

39 12d ago A tokens not measured original Apache-2.0

signet

17

Prismer-AI/signet

Plugin Claude Code

Cryptographic signing and audit tools for AI agent tool calls.

38 3mo ago A tokens not measured original Apache-2.0

signet

18

Prismer-AI/signet

Plugin Claude Code

Cryptographic signing for every AI agent tool call — Ed25519 receipts + hash-chained audit log.

38 3mo ago A tokens not measured original Apache-2.0

vaara

19

vaaraio/vaara

Plugin Claude Code

Vaara runtime tool-call governance plugins for Claude Code.

12 2d ago A tokens not measured AGPL-3.0

vaara-governance

20

vaaraio/vaara

Plugin Claude Code

Accountable autonomy for Claude Code. PreToolUse runs a two-layer check on Bash, WebFetch, WebSearch, Write, Edit, NotebookEdit, Task, SendMessage and MCP calls (regex deny patterns on shell, web and file mutation; conformal risk scorer on MCP). PostToolUse writes a hash-chained SQLite audit record across the same set.

12 2d ago A tokens not measured AGPL-3.0

agent-inspector

22

cylestio/agent-inspector

Plugin Claude Code

AI Agent Security Analysis - scan, fix, analyze, and report on AI agent vulnerabilities using OWASP LLM Top 10.

9 7mo ago A tokens not measured

geckovision

23

GeckoVision/gecko-surf

Plugin Claude Code

GeckoVision's plugins for making any API agent-usable — comprehension, x402 payments, and anti-poisoning defense.

6 yesterday A tokens not measured original Apache-2.0

gecko-surf

24

GeckoVision/gecko-surf

Plugin Claude Code

Make any API agent-usable — even one with broken docs, no OpenAPI, a WAF, or an auth wall. Comprehend a spec (or JS-rendered docs) into first-call-correct MCP tools your agent calls right the first time, with auth injected and no integration code. On a painful real API, first-call-correctness goes from 10% to 65%…

6 yesterday A tokens not measured original Apache-2.0