ai-security plugins

60 tagged ai-security, measured the same way as everything else here.

Browse within: llm-security 10AI Safety 9cybersecurity 9cli-agents 8devsecops 8appsec 7bug-bounty 5owasp 5

Mikaru0Mystic/sectinel

Plugin Claude Code

753 cybersecurity skills covering web security, pentesting, DFIR, threat intelligence, cloud security, malware analysis, and more.

11 2mo ago A tokens not measured copy · 89% Apache-2.0

claude-tools

26

akasecurity/claude-tools

Plugin Claude Code

AKA Claude Tools guard hooks (command-guard, leak-guard) for your active profile. Requires bun; guards fail OPEN (never block) and announce themselves inactive at session start if bun is missing. For the full hardened ISOLATED profile (credential-read denies, rtk-safe permission allowlist, status line, alias), install.

10 1mo ago A tokens not measured original MIT

assay

27

Rul1an/assay

Plugin Claude Code

Connect Claude Code to Assay's MCP policy and evidence tools and golden-path skill.

9 2d ago A tokens not measured copy · 86% MIT

protect-mcp

28

ScopeBlind/scopeblind-gateway

Plugin Claude Code

Fail-closed Cedar policy gate plus Ed25519 signed receipts for AI agent tool calls. Blocks what breaks the rules before it runs, denies on any policy error, and proves the gate is live with a startup self-test.

9 1mo ago A tokens not measured fork MIT

verify-mcp

29

ScopeBlind/scopeblind-gateway

Plugin Claude Code

Offline verifier for signed receipts, audit bundles, and trust artifacts. Ed25519 + JCS, no accounts, no network calls. Verify what an agent's gate decided without trusting the operator.

9 1mo ago A tokens not measured fork MIT

security-sweep

30

Onome-AJ/security-sweep-plugin

Plugin Claude Code

Comprehensive security scanner for codebases — finds hardcoded secrets, injection flaws, auth issues, misconfigurations, AI-specific vulnerabilities, and more. Covers OWASP Top 10, Mobile Top 10, and LLM Top 10.

6 4mo ago A tokens not measured original MIT

peephole

31

akashsebastian333/peephole

Plugin Claude Code

A plugin for coding agents. They ship secure code. Steers the write and can ask or deny before a file is saved.

5 3d ago A tokens not measured original MIT

pitimon/claude-cybersecurity-skill

Plugin Claude Code

Cybersecurity professional skills: 22 domains covering IR, DFIR, DevSecOps, SOC+SOAR, GitOps, Code Security, Container/Supply Chain, Threat Modeling, Compliance Frameworks, Cloud Security & CSPM, Zero Trust Architecture, AI/ML Security, API Security, Vulnerability Management, Threat Intelligence, Cross-Domain…

5 3mo ago A tokens not measured

cybersecurity-pro

33

pitimon/claude-cybersecurity-skill

Plugin Claude Code

Professional cybersecurity skill: 22 domains covering IR, DFIR, DevSecOps, SOC+SOAR, GitOps, Code Security, Container/Supply Chain, Threat Modeling, Compliance Frameworks, Cloud Security & CSPM, Zero Trust Architecture, AI/ML Security, API Security, Vulnerability Management, Threat Intelligence, Cross-Domain…

5 3mo ago A tokens not measured

ai-app-security

34

xChechi/xche-ai-app-security-pack

Plugin Claude Code

Security guardrails for AI-built apps: OWASP/API/LLM/MCP rules applied while building, an /audit skill for full reviews, and a hook that blocks secret commits.

5 2mo ago A tokens not measured original MIT

trust-issues

35

howshannon/trust-issues

Plugin Claude Code

Adversarial, attacker-minded security review of untrusted code before you install it. A read-only scanner plus a five-persona reasoning pass, ending in a GO / GO-WITH-MITIGATIONS / NO-GO verdict.

5 1mo ago A tokens not measured original MIT

claude-hunterkit

36

vigilantshield/Claude-HunterKit

Plugin Claude Code

148 offensive security skills — web, API, AI, network, cloud, recon, auth. Bug bounty, red team, pentest. Recon-first conditional agent launch pipeline.

5 1mo ago A tokens not measured

evil-plugin

37

AgentSafety/ClawCare

Plugin Claude Code

A malicious plugin for scanner testing.

5 4mo ago A tokens not measured original Apache-2.0

UnboundCompute/security-agent-skills

Plugin Claude Code

Security-testing methodology as portable agent skills, spanning white-box bug hunting, AI-agent and LLM red-teaming, cloud identity and CI/CD trust, client-app trust surfaces across browser and editor extensions and Electron, wire-protocol and token trust across gRPC, WebSocket, and JWT, infrastructure-as-code and…

4 4d ago A tokens not measured original MIT

stm

40

matterhornso/subscribetome

Plugin Claude Code

AI API key & subscription manager. Out-of-band key entry, OS-keychain storage, and a PreToolUse hook that injects real keys into commands so the model only ever sees placeholders.

4 11d ago A tokens not measured original MIT

vibecheck

41

Wishmakingfairy/vibecheck

Plugin Claude Code

Stop shipping vulnerabilities. 156 automated security checks for Claude Code. Blocks exposed API keys, disabled Supabase RLS, missing rate limiting, open CORS, and 150+ more before they reach your codebase.

4 5mo ago A tokens not measured original MIT

usap-skills

42

jaskaranhundal/usap-skills

Plugin Claude Code

Unified Security Agent Platform — 79 cybersecurity skills + 12 cs- orchestrator agents that emit a typed 11-field JSON output contract, mapped to MITRE ATT&CK and NIST CSF 2.0. Runs in any LLM. Bundles 7 slash commands (usap:run, usap:fortigate, usap:orchestrate, usap:challenge, usap:compare, usap:test, usap:README) a.

4 19d ago A tokens not measured original Apache-2.0

calllint

43

calllint/calllint

Plugin Claude Code

Preflight risk linting for MCP & agent tools. Before you add or edit an agent-tool config, CallLint recommends scanning the blast radius — SAFE / REVIEW / BLOCK / UNKNOWN with evidence. Advisory and non-blocking; never executes the server it judges.

2 2d ago A tokens not measured original Apache-2.0

mcp-redteam

45

m0rvayne/mcp-redteam

Plugin Claude Code

Full audit and penetration testing of MCP servers — health, architecture, completeness, security.

2 2mo ago A tokens not measured original MIT

security-audit-pro

46

xsourabhsharma/ai-security-audit-pro

Plugin Claude Code

Universal security-audit plugin and CLI engine for AI agents, built for defensive website, API, and codebase audits with professional Markdown, HTML, and PDF reports.

2 2mo ago A tokens not measured original MIT

kernora-ai/agent-sec

Plugin Claude Code

Grounds your AI coding agent in a cited security baseline (OWASP/CWE/EU AI Act) and warns before risky actions. Advisory, free, read-only. Real-time blocking is Kernora Axiora.

1 1mo ago A tokens not measured original Apache-2.0

securedact-enforced

48

GigantesHJI/securedact-mcp

Plugin Claude Code

Local privacy enforcement for Claude Code. Checks prompts before model processing and blocks or requires review when SecuRedact detects protected information.

1 2d ago A tokens not measured original Apache-2.0