appsec plugins

53 tagged appsec, measured the same way as everything else here.

Browse within: devsecops 13ai-security 11owasp 8cybersecurity 6agentic-appsec 5agentic-workflows 5

airtight

25

Zyoffsec/airtight-secure-coding

Plugin Claude Code

Secure-coding gates for AI-written code. 70 numbered gates mapped to OWASP Top 10 and CWE, plus a pre-write guard that denies the failures it can prove: open routes, IDOR, missing CSRF tokens, interpolated queries and shell commands, raw HTML sinks, unverified webhooks, any-origin CORS with credentials, passwords…

6 28d ago A tokens not measured original MIT

xche

26

xChechi/xche-ai-app-security-pack

Plugin Claude Code

Security guardrails for AI-built apps — drop-in rules, policy, and secret-scanning hooks.

5 2mo ago A tokens not measured original MIT

ai-app-security

27

xChechi/xche-ai-app-security-pack

Plugin Claude Code

Security guardrails for AI-built apps: OWASP/API/LLM/MCP rules applied while building, an /audit skill for full reviews, and a hook that blocks secret commits.

5 2mo ago A tokens not measured original MIT

apiiro/mcp-server

Plugin Claude Code

Agentic Application Security Platform (ASPM) for Claude Code. Prevents risk before code exists by rewriting prompts into secure prompts using each repository's Software Graph and organizational security and compliance policies. Run differential SAST, SCA, and Secrets scans and AutoFix risks directly from your IDE…

4 2mo ago A tokens not measured original Apache-2.0

vantage

30

tinoimammp/vantage-security-agent

Plugin Claude Code

Artifact-driven, plugin-based multi-agent SAST pipeline for web and mobile app repositories. Web agents cover the OWASP Top 10; mobile agents cover the OWASP Mobile Top 10 (2024, M1-M10). Both share global validation/PoC/reporting agents. Run /vantage:scan-web or /vantage:scan-mobile to scan, then /vantage:fix-issue…

4 1mo ago A tokens not measured original MIT

UnboundCompute/security-agent-skills

Plugin Claude Code

Security-testing methodology as portable agent skills, spanning white-box bug hunting, AI-agent and LLM red-teaming, cloud identity and CI/CD trust, client-app trust surfaces across browser and editor extensions and Electron, wire-protocol and token trust across gRPC, WebSocket, and JWT, infrastructure-as-code and…

4 3d ago A tokens not measured original MIT

gauntlet-loop

36

trilwu/gauntlet-loop-skills

Plugin Claude Code

Skills packaging the Gauntlet Loop — build → blind-critic → revise → repeat against a hard bar — for coding, writing, design, data, research, prompt evaluation, detection engineering, and authorized security testing.

3 1mo ago A tokens not measured original MIT

deep-security-audit

38

ravindrakele/claude-skills

Plugin Claude Code

Multi-agent security audit that reads and understands code, adversarially verifies every finding, and scores honest CVSS 3.1. Read-only by default.

3 1mo ago A tokens not measured original MIT

patchman

40

MuhammedZohaib/patchman

Plugin Claude Code

Defensive security audit mode for authorized code review and architecture assessment.

3 4mo ago A tokens not measured original MIT

websec-validator

42

raccioly/websec-validator

Plugin Claude Code

Defensive, local-first security recon that briefs your AI coding agent on your OWN codebase. Read-only by default: facts + tailored probes + a calibrated findings ledger, code-in / artifacts-out, no LLM / no server / no running app. Live probes are opt-in against a TEST instance you own; production is out of scope.

2 yesterday A tokens not measured original MIT

websec

43

emre-guler/websec

Plugin Claude Code

Security review skills for Claude Code.

2 5d ago A tokens not measured original MIT

websec

44

emre-guler/websec

Plugin Claude Code

Web application security review skills: architecture recon, 33 vulnerability-class detectors, and a consolidated severity-ranked report.

2 5d ago A tokens not measured original MIT

redteam-core

46

morodomi/redteam-skills

Plugin Claude Code

Security audit automation. RECON → SCAN → ATTACK → REPORT.

2 6mo ago A tokens not measured original MIT

quant-security

47

Quant-Off/skills

Plugin Claude Code

Security-research toolkit for Claude Code: source-level cryptographic auditing, Ghidra-driven binary verification of constant-time and zeroization guarantees, and zero-trust codebase security auditing. Every skill gates findings on traced evidence before reporting.

1 22d ago A tokens not measured original MIT

Quant-Off/skills

Plugin Claude Code

Verifies in compiled machine code that secret zeroization survived dead-store elimination and that constant-time logic did not regain secret-dependent branches. Ships a Ghidra headless inventory script. Use when auditing a binary, shared object, or firmware image against a source-level guarantee.

1 22d ago A tokens not measured original MIT