owasp plugins

23 tagged owasp, measured the same way as everything else here.

Browse within: appsec 8ai-security 7sast 5

claude-code-plugin

01

asamassekou10/ship-safe

Plugin Claude Code

Security audit your project with Ship Safe — 29 agents, 80+ attack classes, real-time Claude Code hooks, deep LLM analysis, and CI mode.

828 3d ago A tokens not measured original MIT

praxen

03

open-agent-ai-security/praxen

Plugin Claude Code

Praxen — agent behavior verifier. Compares an AI agent's declared policy (Worker Remit) against the available evidence — source code, live deployment state, or behavioral artifacts — and reports where observed behavior diverges from declared intent. Make sure your agent does its job — and only its job.

59 2d ago A tokens not measured original Apache-2.0

appsec-advisor

05

appsec-foundry/appsec-advisor

Plugin Claude Code

Code-derived threat modeling plugin: the architecture model is derived from the repository, not maintained by hand. Provides AppSec-focused agents and skills for threat modeling, STRIDE analysis, dependency scanning, QA review, and security context resolution.

16 today A tokens not measured

oc-security-audit

07

miclivne/oc-security-audit

Plugin Claude Code

Pre-launch security audit for web apps. Runs OWASP checks via shell scripts, then AI analyzes findings. Covers rate limiting, hosting bypass, data exposure, headers, session security, AI risks.

8 3mo ago A tokens not measured

penthera

08

danoszz/penthera

Plugin Claude Code

Plugin marketplace listing 1 plugin: penthera.

6 16d ago A tokens not measured original MIT

penthera

09

danoszz/penthera

Plugin Claude Code

Find and fix security issues in vibecoded apps. Scan a live URL, a local repo, or your macOS machine for TLS, headers, auth, secrets, IDOR/OAuth, and injection issues, then apply framework-aware fixes and re-scan to verify. Mapped to OWASP with SARIF output. Runs as a skill or CLI. Authorized testing only.

6 16d ago A tokens not measured original MIT

airtight

11

Zyoffsec/airtight-secure-coding

Plugin Claude Code

Secure-coding gates for AI-written code. 70 numbered gates mapped to OWASP Top 10 and CWE, plus a pre-write guard that denies the failures it can prove: open routes, IDOR, missing CSRF tokens, interpolated queries and shell commands, raw HTML sinks, unverified webhooks, any-origin CORS with credentials, passwords…

6 27d ago A tokens not measured original MIT

security-sweep

13

Onome-AJ/security-sweep-plugin

Plugin Claude Code

Comprehensive security scanner for codebases — finds hardcoded secrets, injection flaws, auth issues, misconfigurations, AI-specific vulnerabilities, and more. Covers OWASP Top 10, Mobile Top 10, and LLM Top 10.

6 4mo ago A tokens not measured original MIT

vantage

15

tinoimammp/vantage-security-agent

Plugin Claude Code

Artifact-driven, plugin-based multi-agent SAST pipeline for web and mobile app repositories. Web agents cover the OWASP Top 10; mobile agents cover the OWASP Mobile Top 10 (2024, M1-M10). Both share global validation/PoC/reporting agents. Run /vantage:scan-web or /vantage:scan-mobile to scan, then /vantage:fix-issue…

4 1mo ago A tokens not measured original MIT

vibecheck

16

Wishmakingfairy/vibecheck

Plugin Claude Code

Stop shipping vulnerabilities. 156 automated security checks for Claude Code. Blocks exposed API keys, disabled Supabase RLS, missing rate limiting, open CORS, and 150+ more before they reach your codebase.

4 5mo ago A tokens not measured original MIT

redteam-core

18

morodomi/redteam-skills

Plugin Claude Code

Security audit automation. RECON → SCAN → ATTACK → REPORT.

2 6mo ago A tokens not measured original MIT

claude-owasp-10

19

joaovicdev/claude-owasp-10

Plugin Claude Code

OWASP Top 10:2025 secure-coding material for Claude Code, written to be read by an agent while it writes backend code.

2 6d ago A tokens not measured original MIT

secure-coding

20

joaovicdev/claude-owasp-10

Plugin Claude Code

OWASP Top 10:2025 rules for writing and reviewing backend/API code in any language, plus /api-secure-report — a full security inventory of every HTTP route in a project.

2 6d ago A tokens not measured original MIT

security-audit

21

ReeperReepx/Security-Audit-Claude-Skill

Plugin Claude Code

Enterprise-grade security audit skill for Claude Code. Performs comprehensive SAST, secrets detection, dependency auditing, IaC review, API security, and auto-remediation across any codebase with PDF report generation.

2 5mo ago A tokens not measured original MIT

sentinel

22

robcsaszar/sentinel

Plugin Claude Code

Plugin marketplace listing 1 plugin: robcsaszar-sentinel.

0 2d ago A tokens not measured original MIT

robcsaszar-sentinel

23

robcsaszar/sentinel

Plugin Claude Code

Static security audit skill for web application codebases: stack triage, checklist-driven scan, and a PASS/FAIL/MANUAL-REVIEW report with file:line evidence and remediation code.

0 2d ago A tokens not measured original MIT