Security plugins

1,172 tagged Security, measured the same way as everything else here.

Browse within: compliance 70fedramp 49claude-ai 47ai-security 43gdpr 34appsec 32claude-plugin 31data-privacy 30cybersecurity 26devsecops 25claude-code-skills 23claude-code-hooks 22claude-code-skill 22ai-governance 19

security-sweep

361

Onome-AJ/security-sweep-plugin

Plugin Claude Code

Comprehensive security scanner for codebases — finds hardcoded secrets, injection flaws, auth issues, misconfigurations, AI-specific vulnerabilities, and more. Covers OWASP Top 10, Mobile Top 10, and LLM Top 10.

6 4mo ago A tokens not measured original MIT

flow-dev

362

onflow/flow-ai-tools

Plugin Claude Code

Skills for developing on the Flow blockchain — covering Cadence language fundamentals, token standards, DeFi actions, security auditing, and project setup.

6 27d ago A tokens not measured

caushell-claude

363

fatmo666/Caushell

Plugin Claude Code

Session-aware shell guardrails for Claude Code backed by the Caushell runtime.

6 3d ago A tokens not measured original Apache-2.0

agentic-ai-security

365

jassics/awesome-claude-security

Plugin Claude Code

Security for autonomous, tool-using AI agents: review, tool-permission audit, autonomy-boundary testing for excessive agency, MCP server trust review, agent harness/runtime testing, and agent-to-agent (A2A) protocol trust.

6 26d ago A tokens not measured GPL-3.0

ai-safety-engineer

366

jassics/awesome-claude-security

Plugin Claude Code

AI safety engineer role bundle: build and operationalize safeguards (evals-in-CI, guardrails, monitoring, safety cases, RAI governance). Auto-installs the ai-safety stack.

6 26d ago A tokens not measured GPL-3.0

pyobfus

367

zhurong2020/pyobfus

Plugin Claude Code

Protect Python source before shipping it — obfuscate AND verify the output still runs. Wraps the pyobfus obfuscator (AST-based, framework-aware, AI-debuggable) and its MCP server.

6 3d ago A tokens not measured original Apache-2.0

redact

368

r3352/redact-mcp

Plugin Claude Code

Auto-obfuscates sensitive client data during pentesting so Claude never sees real PII, hostnames, or credentials.

6 5mo ago A tokens not measured

Threat-Model Agent

369

suyogpawar88/Threat-Model

Plugin Claude Code

Pulls context from Jira, Jenkins, ServiceNow, and a code repository, then runs an end-to-end threat model covering both conventional application/API systems and AI/ML/LLM infrastructure: data flow diagram, trust boundaries, threat actors, STRIDE threat register (optionally full 7-stage PASTA), AI/ML-specific threats…

6 28d ago A tokens not measured original MIT

skanna

370

proluct/skanna

Plugin Claude Code

Security-scan a Claude Code skill, plugin, or MCP server before installing it. SAFE / CAUTION / DANGEROUS verdict with file:line findings. Read-only, never executes the target.

6 1mo ago A tokens not measured original MIT

code-coherence

371

reggiechan74/cc-plugins

Plugin Claude Code

Multi-agent verification system implementing organizational intelligence for production-grade code reliability. Achieves 92%+ accuracy through team-of-rivals architecture with specialized critic agents.

6 3mo ago A tokens not measured original MIT

safecmd

372

AnswerDotAI/claude-plugins

Plugin Claude Code

Auto-approve safe bash commands validated against safecmd's allowlist.

6 1mo ago A tokens not measured

shiiman-common

375

shiiman/claude-code-plugins

Plugin Claude Code

A set of shared development tools for reviewing local code changes and updating several AI command-line tools at once.

6 2mo ago A tokens not measured

malskills-zh

376

killvxk/malskills-zh

Plugin Claude Code

Offensive security skills collection for authorized penetration testing, CTF challenges, and security research. Includes tools for reconnaissance, exploitation, C2 frameworks, evasion, reverse engineering, and programming patterns.

6 5mo ago A tokens not measured

blindfold

378

thesaadmirza/blindfold

Plugin Claude Code

Blindfolds the LLM from your secrets. Stores API keys, tokens, and passwords in your OS keychain. The LLM works with placeholders, never sees actual values. Kernel-level sandbox enforcement on macOS.

6 3mo ago A tokens not measured original MIT

audit-protocol

379

sturec5/code-audit-protocol

Plugin Claude Code

Audits a code change against a 54-phase failure taxonomy and reports what it did not check, not just what it found. Domain overlays run first and force critical-path treatment.

6 +1 19d ago A tokens not measured original MIT

tailscale

380

dinglebear-ai/rtailscale

Plugin Claude Code

MCP server and CLI for Tailscale: inspect and manage tailnet devices, routes, users, keys, DNS, and ACL policy over stdio or streamable HTTP.

5 8d ago A tokens not measured AGPL-3.0

diffgate

381

srbsa/diffgate

Plugin Claude Code

A deterministic guardrail your coding agent runs on itself — structured findings on just the changed lines, before the code reaches disk. Zero LLM tokens, 0 false blocks.

5 1mo ago A tokens not measured original Apache-2.0

rad-code-review

382

RadOrigin-LLC/RAD-Claude-Skills

Plugin Claude Code

The specialist lanes and memory that the built-in /code-review doesn't have. Invokes the built-in engine for general bug-finding (quick/standard/deep map to its effort levels), then adds what it lacks: a mechanical hallucinated-imports validator (lockfile-verified across Python/JS/TS/Rust/Go, with a vendored denylist…

5 16d ago A tokens not measured original Apache-2.0

peephole

383

akashsebastian333/peephole

Plugin Claude Code

A plugin for coding agents. They ship secure code. Steers the write and can ask or deny before a file is saved.

5 3d ago A tokens not measured original MIT

pitimon/claude-cybersecurity-skill

Plugin Claude Code

Cybersecurity professional skills: 22 domains covering IR, DFIR, DevSecOps, SOC+SOAR, GitOps, Code Security, Container/Supply Chain, Threat Modeling, Compliance Frameworks, Cloud Security & CSPM, Zero Trust Architecture, AI/ML Security, API Security, Vulnerability Management, Threat Intelligence, Cross-Domain…

5 3mo ago A tokens not measured