Security plugins

1,303 tagged Security, measured the same way as everything else here.

Browse within: compliance 68ai-security 49claude-ai 47fedramp 44gdpr 35claude-plugin 34appsec 33data-privacy 30cybersecurity 29devsecops 28claude-code-skill 25claude-code-skills 23claude-code-hooks 22agent-security 19

hono-guide

265

vcode-sh/vibe-tools

Plugin Claude Code

Build ultrafast web APIs and apps with Hono across any JavaScript runtime. Covers routing, Context API, 25+ built-in middleware (auth, CORS, caching, security), type-safe RPC client, Zod/Standard Schema validation, JSX rendering, streaming/SSE, WebSocket, cookie/JWT helpers, testing patterns, and deployment to…

19 6mo ago A tokens not measured

tm-skills

266

izar/tm_skills

Plugin Claude Code

Auxiliary skills for threat modeling - with and without OWASP pytm.

19 +1 1mo ago A tokens not measured original MIT

vibe-ship

267

sudais-khalid/vibe-ship

Plugin Claude Code

Generates a complete production-ready deployment setup for any app in one pass: Dockerfile, docker-compose, CI/CD pipeline, security hardening, and scalability config. Also audits existing Dockerfiles and CI setups with a static scoring script.

18 1mo ago A tokens not measured original MIT

lictor-security-suite

268

Raffa-jarrl/Lictor-AI

Plugin Claude Code

Four free security skills for AI-built apps. Run lictor-security-check before you ship to scan for leaked API keys, exposed databases, broken access control (IDOR), injection (SQL/XSS/command), SSRF, exposed admin/debug surfaces, missing rate limits, and prompt-injection in AI features. Then lictor-explain, lictor-fix.

18 1mo ago A tokens not measured original Apache-2.0

ai-iq

269

kobie3717/ai-iq

Plugin Claude Code

Memory → Evaluation → Credential → Access Control for AI agents. Persistent memory with W3C Verifiable Credentials, capability-based access control, drift detection, and FSRS-6 spaced repetition.

18 1mo ago A tokens not measured original MIT

ironlint

270

ironlint/ironlint

Plugin Claude Code

Local CI for AI coding agents: a checks pipeline (files + run/steps) where any nonzero exit blocks the write, guarded by a trust allow-list. Claude Code adapter.

18 5d ago A tokens not measured original Apache-2.0

enterprise-team

271

Chipagosfinest/enterprise-team

Plugin Claude Code

Complete virtual company with 76 specialized AI agents across Engineering, Product, Infrastructure, Data, Security, Marketing, Sales, Finance, Legal, and People. Pipeline modes (Full/Sprint/Micro), Dev↔QA loops, quality gates, and handoff protocols.

18 4mo ago A tokens not measured

vastlint

272

aleksUIX/vastlint

Plugin Claude Code

Validate VAST, VMAP, and DAAST ad tags against IAB Tech Lab specs. Hosted MCP at https://vastlint.org/mcp. Auth none for public tools.

18 3d ago A tokens not measured

dungnotnull/hybrid-harness-chaos-process-prm

Plugin Claude Code

A 36-skill agentic workflow for platform engineering — spanning CI/CD, security, chaos engineering, observability, governance, compliance, deep research, system optimization, documentation, and adversarial critique. Purpose-built for AI-assisted development.

18 2mo ago A tokens not measured original MIT

shipproof

274

kingggg5/shipproof

Plugin Claude Code

Evidence-first engineering and production audits for secure, efficient, scalable systems.

18 6d ago A tokens not measured original MIT

fedramp-docs

275

hackIDLE/fedramp-docs-mcp

Plugin Claude Code

FedRAMP compliance toolkit - search docs, analyze controls, track changes.

18 4mo ago A tokens not measured original MIT archived

supabase-plugin

276

supabase-community/supabase-plugin

Plugin Claude Code

Official Supabase plugin for Claude Code with bundled Supabase skills and MCP access for project management, database work, auth, storage, and Postgres best practices.

17 14d ago A tokens not measured

api

278

stackhawk/agent-skills

Plugin Claude Code

Query the StackHawk platform API for security posture reporting, findings analysis, and app management. Uses the combined hawk CLI (hawk op …) for all platform queries.

16 +1 12d ago A tokens not measured original MIT

hawkscan-ci

279

stackhawk/agent-skills

Plugin Claude Code

Configure HawkScan in your CI/CD pipeline. Provider-agnostic: detects GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure Pipelines, Bitbucket, Buildkite, and other CI systems from repo files, edits the pipeline file in place to add a HawkScan job, and prompts for HAWKAPIKEY storage (CI-native secrets store or extern.

16 +1 12d ago A tokens not measured original MIT

java-quality

281

ducpm2303/claude-java-plugins

Plugin Claude Code

Java quality toolkit — security (OWASP), performance (N+1, memory, threading), and testing (JUnit 5, Mockito, Testcontainers) for Java 8+ projects.

16 4mo ago A tokens not measured

hackingtool

284

MAXZL1/hackingtool-plugin

Plugin Claude Code

183+ pentesting and OSINT tools (nmap, nuclei, amass, subfinder, httpx, sherlock, maigret, trufflehog, sqlmap, impacket, and more) wired into Claude Code as a single skill. Runs locally on any OS via native Bash, WSL, or purpose-built Docker images (instrumentisto/nmap, projectdiscovery/nuclei, caffix/amass, etc.).…

16 4d ago A tokens not measured

appsec-advisor

286

appsec-foundry/appsec-advisor

Plugin Claude Code

Code-derived threat modeling plugin: the architecture model is derived from the repository, not maintained by hand. Provides AppSec-focused agents and skills for threat modeling, STRIDE analysis, dependency scanning, QA review, and security context resolution.

16 yesterday A tokens not measured

compliance-trestle

287

oscal-compass-lab/compliance-trestle-skills

Plugin Claude Code

Manage OSCAL compliance packages using Compliance Trestle - a CNCF sandbox project for machine-readable compliance documentation (NIST OSCAL standard).

15 28d ago A tokens not measured original Apache-2.0

toru-claude-agents

288

ToruAI/toru-claude-agents

Plugin Claude Code

A dev pipeline for Claude Code that will not call work done until tests, lint and a security audit all exit zero. Seven specialists run it, for 1.1k tokens of always-on context.

15 1mo ago A tokens not measured original MIT