Security plugins

1,355 tagged Security, measured the same way as everything else here.

Browse within: compliance 68ai-security 49claude-ai 48fedramp 44claude-plugin 35gdpr 35appsec 33data-privacy 30cybersecurity 29devsecops 28claude-code-skill 25claude-code-skills 25claude-code-hooks 23claude-code-plugins 23

src-hunter

241

fb0sh/pentester

Plugin Claude CodeCodex

A collection of tools and instructions for finding security weaknesses through SRC programs, public bug-bounty programs run by companies or platforms.

23 1mo ago A tokens not measured original MIT

pentest

242

humaidhahm/opencode-pentester

Plugin Claude Code

Full penetration testing framework - 69 attack categories across 16 domains covering OWASP, injection, authentication, cloud, and more.

23 +2 7d ago A tokens not measured

krait

245

ZealynxSecurity/krait

Plugin Claude Code

Smart contract security analysis powered by 4,500+ real audit findings from Solodit. Quick scans, full framework assessments, and integration with audit-readiness.zealynx.io.

22 22d ago A tokens not measured original MIT

gouvernai

246

Myr-Aya/GouvernAI-claude-code-plugin

Plugin Claude Code

Achieve flow state safely with Claude Code. Auto-approves routine work, gates risky actions, hard-blocks dangerous patterns. Dual enforcement (skill + hooks), token cap for cost governance, full audit trail. Zero dependencies.

22 1mo ago A tokens not measured original MIT

air-blackbox

247

airblackbox/airblackbox

Plugin Claude Code

EU AI Act compliance scanner and trust infrastructure for Python AI projects.

22 3d ago A tokens not measured original Apache-2.0

maven-mcp

249

kirich1409/krozov-ai-tools

Plugin Claude Code

Maven dependency intelligence — dependency updates, vulnerability and license scanning, transitive dependency graphs, version compatibility checks, artifact search, and version-catalog management, exposed as skills and an MCP server. Works in Claude Code and Grok Build without any NPM setup.

22 22d ago A tokens not measured original MIT

akira

250

kalpmodi/akira

Plugin Claude Code

The AI pentest co-pilot that actually finds bugs. Phase-chained, evidence-gated offensive security skills for bug bounty and authorized pentesting.

21 1mo ago A tokens not measured original MIT

sentinel-ai

251

MaxwellCalkin/sentinel-ai

Plugin Claude Code

Real-time safety scanning for LLM interactions. Detects prompt injection, PII leaks, harmful content, toxicity, obfuscation, secrets, and dangerous tool calls — 600-case benchmark at 100% accuracy with sub-millisecond latency.

21 5mo ago A tokens not measured original Apache-2.0

security

254

roboco-io/plugins

Plugin Claude Code

A security review and vulnerability analysis skill based on the OWASP Top 10 2025, a list of common and serious web application security risks.

21 1mo ago A tokens not measured original MIT

shipspec

255

jsegov/shipspec-claude-code-plugin

Plugin Claude Code

Spec-driven development for big features. When features get too big, plan mode gets too vague—leading to hallucinations during implementation. ShipSpec replaces vague plans with structured PRDs, technical designs, and ordered tasks that keep Claude grounded.

20 7mo ago A tokens not measured original MIT

dev-safety-net

257

pstuart/pstuart

Plugin Claude Code

Universal developer safety guardrails — blocks dangerous commands, verifies builds, provides session context, and scans repo health.

20 14d ago A tokens not measured original MIT

soundcheck

261

thejefflarson/soundcheck

Plugin Claude Code

Automated OWASP security checks — Web Top 10:2025, LLM Top 10:2025, API Security Top 10:2023.

20 1mo ago A tokens not measured original MIT

claude-code-hooks

262

yurukusa/claude-code-hooks

Plugin Claude Code

Production safety hooks for autonomous Claude Code operation. Context monitoring, syntax checking, branch protection, activity logging, and more.

19 4d ago A tokens not measured original MIT

luffy-arm

263

Ares960826/luffy-arm

Plugin Claude Code

Give a local AI agent a remote hand over SSH: read, run, diagnose and pull data from a remote Linux server behind a tiered, unprivileged, ACL-read-only safety model.

19 6d ago A tokens not measured original MIT

dos-kernel

264

anthony-chaudhary/dos-kernel

Plugin Claude Code

The kernel is the part that doesn't believe the agents. Bundles the DOS hooks (verify-on-stop, deny-a-refused-call, re-surface-a-stalled-stream), the DOS MCP server (verify / arbitrate / refuse-with-a-reason as tools), and the generic skill pack — one install. Requires the dos-kernel Python package: pip install 'dos.

19 8d ago A tokens not measured original MIT