Bash permission management for Claude Code: auto-approve compound commands, sync project permissions to global settings, and analyze permission logs to discover missing allow rules.
Sonatype Guide MCP server for software supply chain intelligence and dependency security analysis. Scan dependencies for vulnerabilities, get version recommendations, and check component quality metrics.
Agentic Application Security Platform (ASPM) for Claude Code. Prevents risk before code exists by rewriting prompts into secure prompts using each repository's Software Graph and organizational security and compliance policies. Run differential SAST, SCA, and Secrets scans and AutoFix risks directly from your IDE…
Use the husk security scanner from Claude Code. Adds the husk MCP server (scan results, findings, packages, remediations, fresh scans) and a skill covering the husk CLI and MCP output.
Artifact-driven, plugin-based multi-agent SAST pipeline for web and mobile app repositories. Web agents cover the OWASP Top 10; mobile agents cover the OWASP Mobile Top 10 (2024, M1-M10). Both share global validation/PoC/reporting agents. Run /vantage:scan-web or /vantage:scan-mobile to scan, then /vantage:fix-issue…
Runs real security scanners over code, full git history, dependencies, IaC and Supabase/Firebase row-level security, then verifies every finding against source before reporting.
Security-testing methodology as portable agent skills, spanning white-box bug hunting, AI-agent and LLM red-teaming, cloud identity and CI/CD trust, client-app trust surfaces across browser and editor extensions and Electron, wire-protocol and token trust across gRPC, WebSocket, and JWT, infrastructure-as-code and…
AI API key & subscription manager. Out-of-band key entry, OS-keychain storage, and a PreToolUse hook that injects real keys into commands so the model only ever sees placeholders.
Stop shipping vulnerabilities. 156 automated security checks for Claude Code. Blocks exposed API keys, disabled Supabase RLS, missing rate limiting, open CORS, and 150+ more before they reach your codebase.
Policy enforcement, PII detection, and audit trails for Claude Code. Govern tool execution, scan outputs for sensitive data, and maintain compliance-grade records of every action.