Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add xChechi/xche-ai-app-security-packnpx agentmods add plugins/xchechi/xche-ai-app-security-pack/ai-app-securitygit clone --depth 1 https://github.com/xChechi/xche-ai-app-security-packWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/xchechi/xche-ai-app-security-pack/ai-app-security)<a href="https://agentmods.dev/plugins/xchechi/xche-ai-app-security-pack/ai-app-security"><img src="https://agentmods.dev/badge/plugins/xchechi/xche-ai-app-security-pack/ai-app-security.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
ai-app-security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"$schema": "https://json.schemastore.org/claude-code-plugin.json",
"name": "ai-app-security",
"description": "Security guardrails for AI-built apps: OWASP/API/LLM/MCP rules applied while building, an /audit skill for full reviews, and a hook that blocks secret commits.",
"version": "1.0.7",
"author": { "name": "xChe" },
"homepage": "https://github.com/xChechi/xche-ai-app-security-pack",
"repository": "https://github.com/xChechi/xche-ai-app-security-pack",
"license": "MIT",
"keywords": ["security", "appsec", "owasp", "llm-security", "mcp", "vibe-coding", "devsecops", "secrets-detection"]
}
What it installs
The manifest is a name and a version. 2 skills, 1 hook travel with it, and installing the plugin installs all of them — 85 tokens a session between them. Each is measured on its own page, and each can be installed alone.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 12 lines scan A 41cc54fb7f45
ai-app-security is a plugin published in the GitHub repository xChechi/xche-ai-app-security-pack (5 stars, last pushed 2mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
oswe
Deep white-box OSWE-style web app security audit via /oswe:audit (PHP, Node.js, Python, Java, .NET) — Markdown + visual HTML reports. By Laucked Security.
web-app-security-skill
Audit and harden authorized Web projects with explainable, reproducible evidence.
claude-cybersecurity
AI-powered cybersecurity code review with 8 specialist agents, OWASP Top 10:2021, CWE Top 25:2024, MITRE ATT&CK v15, and framework-aware false-positive suppression.
Claude-BugHunter
82-skill bug-hunting & external red-team bundle for Claude Code — 57 hunt- web/vuln-class + framework skills, enterprise platform attack chains (M365/Entra, Okta, SharePoint, vCenter, SSL-VPN, APK/iOS), recon/OSINT, reporting & validation gates, and Burp MCP integration. Skills auto-load by topic; 15 slash commands in.
appsec-advisor
Code-derived threat modeling plugin: the architecture model is derived from the repository, not maintained by hand. Provides AppSec-focused agents and skills for threat modeling, STRIDE analysis, dependency scanning, QA review, and security context resolution.
evil-plugin
A malicious plugin for scanner testing.