tech-debt-mcp
337Plugin Claude Code
Static technical-debt analysis across 14 languages, exposed as MCP tools and resources (SQALE ratings, debt summaries, custom rules, dependency vulnerabilities).
1,172 tagged Security, measured the same way as everything else here.
Browse within: compliance 70fedramp 49claude-ai 47ai-security 43gdpr 34appsec 32claude-plugin 31data-privacy 30cybersecurity 26devsecops 25claude-code-skills 23claude-code-hooks 22claude-code-skill 22ai-governance 19
Plugin Claude Code
Static technical-debt analysis across 14 languages, exposed as MCP tools and resources (SQALE ratings, debt summaries, custom rules, dependency vulnerabilities).
bzsasson/pre-launch-audit-skill
Plugin Claude Code
Run a comprehensive pre-launch website audit covering technical SEO, AI accessibility, security, performance, and on-page SEO.
Plugin Claude Code
Commits with unsourced constants get BLOCKED. Three mechanical gates, zero agents: a zetetic checker (absolute claims and 3+ decimal constants need a source: annotation), a craftsmanship checker (coding-standards size limits, tunable via .craftsmanship.conf), and a secret-shield that stops credential-file reads.…
Plugin Claude Code
Supply chain gate for Claude Code. Intercepts npm, pip, cargo, and go installs — blocks CRITICAL packages before they run. Powered by getcommit.dev.
Plugin Claude Code
Plugin marketplace listing 16 plugins: ctx, pentest, context-handoff, statusline, gh-issues.
Plugin Claude Code
Codebase health tools: deep audits via orchestrated specialists (security, performance, libraries, quality, dead code) plus dead-code cleanup and documentation maintenance.
Plugin Claude Code
Vibe coding is how you start; engineering is what keeps it alive. Auto-activating Claude Code plugin that silently installs production engineering guardrails — architecture awareness, TDD, quality gates, security-first development, and 25+ skills so vibe coders build real systems without thinking about process.
antgroup/adversarial-ai-coding-plugin
Plugin Claude Code
A coding plugin built around adversarial review, where opposing checks look for security problems in generated code.
Plugin Claude Code
A dependency security plugin for Claude Code. DepGuard intercepts package installs, checks reputation with Socket.dev, runs installs in a Modal sandbox, and blocks suspicious behavior before it reaches your machine.
Plugin Claude Code
Install/configure helper for @brainwebuk/payload-plugin-mcp-oauth — OAuth 2.1 + PKCE for a Payload @payloadcms/plugin-mcp server.
Plugin Claude Code
Security scanner for AI-agent configuration files — detects prompt injection, dangerous permissions, and credential exposure in settings.json, CLAUDE.md, MCP configs, and more.
chainguard-demo/claude-plugins
Plugin Claude Code
Generate secure Dockerfiles and apko configurations, and migrate existing Dockerfiles to use Chainguard Containers.
chainguard-demo/claude-plugins
Plugin Claude Code
Access Chainguard documentation including container images, security guides, Wolfi, apko, melange, and SBOMs through an MCP server. Search docs, get image information, and learn about supply chain security.
zaryab2000/decipher-gas-optimizoor
Plugin Claude Code
Analyzes Solidity smart contracts for gas inefficiencies. Detects storage packing gaps, loop anti-patterns, custom error opportunities, visibility mismatches, unchecked arithmetic, calldata vs memory decisions, and deployment cost issues. Enforces gas regression detection on every file save via forge integration.
Plugin Claude Code
Security enforcement layer for Claude Code. Blocks dangerous commands, audits every tool call, detects prompt injection.
Plugin Claude Code
Supply-chain security guard that intercepts package install commands across npm, pnpm, pip, go, and cargo ecosystems and enforces package risk policies before execution.
camilooscargbaptista/cto-toolkit
Plugin Claude Code
The ultimate CTO & Staff Engineer toolkit — 54 skills, 5 autonomous agents, 9 automation scripts, 5 intelligent hooks, and workflow orchestrators covering code review, architecture, security, DevOps, data engineering, AI/ML, compliance, DDD, multi-tenancy, feature flags, vendor evaluation, engineering budget, on-call…
godlovepenn/attack-simulation-claude
Plugin Claude Code
Claude Code plugins for adversary simulation and red teaming tools.
godlovepenn/attack-simulation-claude
Plugin Claude Code
Automate TTPForge TTP creation, validation, and management for adversary simulation.
Plugin Claude Code
AI data-flow governance for coding agents: run borderlint before adding any AI SDK, endpoint, or model id — residency, sovereignty, and provenance checked in the conversation, before commit.
Plugin Claude Code
Official JFrog plugin. Connect Claude Code to JFrog to manage, secure, and govern your software supply chain. Give agents the context to build secure, compliant software.
Plugin Claude Code
A collection of Claude Code plugins developed by PagerDuty for pre-commit risk assessment and PagerDuty skill creation for AI agents (Early Access).
Plugin Claude Code
Find and fix security issues in vibecoded apps. Scan a live URL, a local repo, or your macOS machine for TLS, headers, auth, secrets, IDOR/OAuth, and injection issues, then apply framework-aware fixes and re-scan to verify. Mapped to OWASP with SARIF output. Runs as a skill or CLI. Authorized testing only.
Zyoffsec/airtight-secure-coding
Plugin Claude Code
Secure-coding gates for AI-written code. 70 numbered gates mapped to OWASP Top 10 and CWE, plus a pre-write guard that denies the failures it can prove: open routes, IDOR, missing CSRF tokens, interpolated queries and shell commands, raw HTML sinks, unverified webhooks, any-origin CORS with credentials, passwords…