Vault-agnostic secret handling for Claude Code: store, list, and inject secrets without the model ever seeing plaintext. Multi-backend (file/Keychain/1Password) with PreToolUse blocking and output redaction.
★not rated 2 4mo agoA
tokens not measured
originalMIT
Source-grounded EU AI Act governance for European legal, compliance, privacy, security, and AI governance teams: classification, DPIA and FRIA workflows, vendor review, policy review, and evidence packs.
★not rated 2 1mo agoA
tokens not measured
originalApache-2.0
Security auditor and guard-builder for vibecoded apps. Finds vulnerabilities and missing guards across web, AI/LLM, Supabase/Firebase, Android, iOS, Electron, backend/IaC and CI/CD, then generates paste-ready hardening code. Community project, not an official Anthropic product.
★not rated 2 1mo agoA
tokens not measured
originalMIT
Static security audit for projects extending Claude (skills, agents, hooks, plugins, MCP servers, slash commands, etc.) before installing them in Claude Code. Detects backdoors, prompt injection, persistence hooks, and supply-chain risks via parallel sub-agents.
★not rated 2 1mo agoA
tokens not measured
originalMIT
Enterprise-grade security audit skill for Claude Code. Performs comprehensive SAST, secrets detection, dependency auditing, IaC review, API security, and auto-remediation across any codebase with PDF report generation.
★not rated 2 5mo agoA
tokens not measured
originalMIT
Local privacy enforcement for Claude Code. Checks prompts before model processing and blocks or requires review when SecuRedact detects protected information.
★not rated 2▲
+1 yesterdayA
tokens not measured
originalApache-2.0
The integration layer a product needs once it has users: Stripe subscription billing reconciled into your own database, crypto payments that survive over-payment and duplicate webhooks, ad and conversion tracking under Consent Mode v2, Google sign-in with the account-linking guards, the wider Google auth surface, and…
★not rated 2
changed 2d agoA
tokens not measured
originalMIT
Comprehensive SpiceDB development toolkit for designing permission models, generating schemas, implementing authorization, testing, and migrating from other authorization systems (OpenFGA, Okta FGA, etc.) to SpiceDB.
★not rated 2 9d agoA
tokens not measured
originalApache-2.0
Grounds your AI coding agent in a cited security baseline (OWASP/CWE/EU AI Act) and warns before risky actions. Advisory, free, read-only. Real-time blocking is Kernora Axiora.
★not rated 1 1mo agoA
tokens not measured
originalApache-2.0
Pre-execution governance for AI agents. Intercepts MCP tool calls with deterministic blocking, human-in-the-loop holds, and behavioral drift detection.
★not rated 1 2mo agoA
tokens not measured
originalMIT