Security plugins

1,172 tagged Security, measured the same way as everything else here.

Browse within: compliance 70fedramp 49claude-ai 47ai-security 43gdpr 34appsec 32claude-plugin 31data-privacy 30cybersecurity 26devsecops 25claude-code-skills 23claude-code-hooks 22claude-code-skill 22ai-governance 19

agent-inspector

314

cylestio/agent-inspector

Plugin Claude Code

AI Agent Security Analysis - scan, fix, analyze, and report on AI agent vulnerabilities using OWASP LLM Top 10.

9 7mo ago A tokens not measured

security-guidance

315

pablo-albaladejo/kaiord

Plugin Claude Code

Security reminder hook that warns about potential security issues when editing files, including command injection, XSS, and unsafe code patterns.

9 6d ago A tokens not measured copy · 100% MIT

shor

316

tr4m0ryp/shor

Plugin Claude Code

Shor — autonomous AI web pentester. Provides the /shor-setup slash-command: an interactive wizard that guides you from zero to a running scan (black-box or white-box, GCP deployment included).

9 1mo ago A tokens not measured

kvkk-uyum-tr

318

kapital-legal/claude-for-tr-legal

Plugin Claude Code

KVKK m.10 aydınlatma metni üretir, ilgili kişi başvurularını (KVKK m.13/2 30 günlük süre içinde) yanıtlar, VERBİS uyumunu kontrol eder, veri ihlali triajı yapar (72 saatlik bildirim — KVKK m.12/5 + Kurul'un 24.01.2019 tarih ve 2019/10 sayılı kararı), KVKK iyi uygulama düzeyinde risk değerlendirmesi üretir ve…

9 3mo ago A tokens not measured original Apache-2.0

code-quality-atlas

319

brandondees/code-quality-atlas

Plugin Claude Code

A research-derived suite of 41 code-review and maintenance lenses covering correctness, readability, structure, security, performance, tests, migrations, accessibility, observability, LLM and agentic/tool-use safety, install/upgrade experience, authored-artifact conventions (e.g. SKILL.md), and repo-wide audits…

9 3d ago A tokens not measured

protect-mcp

320

ScopeBlind/scopeblind-gateway

Plugin Claude Code

Fail-closed Cedar policy gate plus Ed25519 signed receipts for AI agent tool calls. Blocks what breaks the rules before it runs, denies on any policy error, and proves the gate is live with a startup self-test.

9 1mo ago A tokens not measured fork MIT

verify-mcp

321

ScopeBlind/scopeblind-gateway

Plugin Claude Code

Offline verifier for signed receipts, audit bundles, and trust artifacts. Ed25519 + JCS, no accounts, no network calls. Verify what an agent's gate decided without trusting the operator.

9 1mo ago A tokens not measured fork MIT

servicenow-mcp-ai

323

IvanBBaev/servicenow-mcp-ai

Plugin Claude Code

Drive ServiceNow from your AI assistant — 67 tools over the full REST surface, with plan-and-apply write safety, capability preflight and an ACL security scan.

8 4d ago A tokens not measured original MIT

oc-security-audit

324

miclivne/oc-security-audit

Plugin Claude Code

Pre-launch security audit for web apps. Runs OWASP checks via shell scripts, then AI analyzes findings. Covers rate limiting, hosting bypass, data exposure, headers, session security, AI risks.

8 3mo ago A tokens not measured

complisec

325

eyesecurity/skills

Plugin Claude Code

EU compliance enforcement for AI agents — NIS2, GDPR, ISO 27001.

8 4mo ago A tokens not measured GPL-3.0

clouddrove

326

anmolnagpal/devops-skills

Plugin Claude Code

Team DevOps review and scaffolding skills: Terraform (source and plan), Kubernetes/Helm, Docker, GitHub Actions, GitLab CI, Argo CD/Flux, AWS FinOps, OWASP and application security, observability, incident runbooks, deployment gating, and ADRs. Findings carry shared auditkit rule IDs.

8 3d ago A tokens not measured original MIT

dotforge

327

luiseiman/dotforge

Plugin Claude Code

Behavior governance for Claude Code — declarative runtime policies on tool calls (search-first, no-destructive-git, verify-before-done, …) compiled to PreToolUse hooks, plus configuration governance: 18 skills, 7 agents, 16 stacks, audit scoring, practices pipeline.

8 2mo ago A tokens not measured original MIT

ponytail-sec

328

andypitcher/ponytail-sec

Plugin Claude Code

Ponytail security companion and audit: diff-scoped hardening for active development, plus full-project security scans.

8 4d ago A tokens not measured original MIT

polygraph

329

polygraphso/litmus

Plugin Claude Code

Grade and verify MCP servers A–F with the open polygraph litmus — tool-output injection, egress, sensitive-data, and adversarial-input checks. Bundles the polygraph skill, the polygraph-litmus MCP server, and /polygraph:grade · /polygraph:check.

8 1mo ago A tokens not measured original Apache-2.0

sparda-gate

330

zyx77550/sparda

Plugin Claude Code

The behavior gate for AI edits — proves each edit lost no auth guard, dropped no route, and grew no blast radius. Deterministic, <2s, offline, zero API key.

8 7d ago A tokens not measured

geniro

331

geniro-io/geniro-claude-harness

Plugin Claude Code

Production-grade Claude Code harness with AI-driven setup, multi-agent skills, and safety hooks. Includes /setup for project-tailored configuration.

8 3d ago A tokens not measured original Apache-2.0

Peaky8linders/specter-oss

Plugin Claude Code

Specter — EU AI Act compliance toolkit. Validate citations against the canonical 113-article + 13-annex catalog, query the four-axis agentic compound-risk taxonomy, look up role obligations, and run the LLM-as-Judge reward-hack detector on proposed remediation tasks.

8 1mo ago A tokens not measured

ctx

333

tabnine/skills

Plugin Claude Code

Context Engine CLI (ctx-cli) as focused skills — guided tenant onboarding, code & knowledge-graph search, service investigation, CVE & SAST triage with ready-to-apply fixes, and coding-guideline checks.

8 1mo ago A tokens not measured

sanctuary-framework

334

eriknewton/sanctuary-framework

Plugin Claude Code

The open source standard for secure, private AI: operating-system enforcement is live on macOS today; Linux and Windows are not live enforcement yet, and your data stays under your own keys with current portability bounds called out in the Assurance Matrix. Wraps any MCP-compatible agent with encrypted state, approval.

8 2d ago A tokens not measured original Apache-2.0

claude-crap

335

ahernandez-developer/claude-crap

Plugin Claude Code

Deterministic Quality Assurance plugin for Claude Code. Wraps every Write / Edit / Bash tool call with a PreToolUse gatekeeper, a PostToolUse verifier, and a Stop quality gate backed by CRAP index, Technical Debt Ratio, tree-sitter AST metrics, and SARIF 2.1.0 reports. Forbids the agent from writing functional code…

8 +1 4mo ago A tokens not measured original MIT

outrider-recon

336

Ap6pack/outrider-recon

Plugin Claude Code

Claude-native authorized external recon and ASM methodology bundle with 90 documented capabilities across 11 skills, deterministic Python controls, an optional loopback-only limited-control web plane, explicit human-reviewed finding promotion, and optional fixed policy-gated MCP enrichment. It does not provide…

8 +4 25d ago A tokens not measured