Installable Claude Code plugins from community marketplaces — bundles of commands, agents, hooks and MCP servers. 119 curated, ranked by GitHub signal.
119 plugins in Security
tanweai
WooYun business logic vulnerability methodology — a security testing knowledge plugin distilled from 22,132 public cases, adding evidence-based references, quantitative statistics, and data-driven prioritization.
project-codeguard
Comprehensive security rules for AI coding agents
hypnguyen1209
Spec-driven offensive-security framework: 31 kill-chain skills, executable safety controls, pattern-learning memory, bounded engagement engine, and a SessionStart skill-invocation dispatcher.
ioannisa
KSafe — Kotlin Multiplatform encrypted persistence: patterns, anti-patterns, and gotchas for AI agents
cosai-oasis
Comprehensive security rules for AI coding agents
OpenZeppelin
team-telnyx
Telnyx Verify — phone verification via SMS, call, or flash call (2FA OTP)
mlunato47
GRC domain knowledge — 15 frameworks, 24 commands, cross-framework mapping, document review, and operational workflows. Cloud-agnostic.
artwist-polyakov
SSH подключение к удалённым серверам с agent forwarding
zhou210712
对AI应用场景按登记册分类,开展算法安全评估和科技伦理审查,审查AI供应商合同条款(训练数据、责任、模型变更等),保持AI政策与最新实践同步。适配生成式人工智能服务管理办法、科技伦理审查办法。
zhou210712
发现、评估和安装社区法律技能——带有安全审查关卡、来源白名单和许可证合规检查,防止未审查的代码落地到工作环境。
zhou210712
分类个人信息处理场景是否需要保护影响评估(个保法第55条),生成评估报告,审查个人信息处理协议,起草个人信息主体权利响应,并监控隐私政策与实践之间的偏差。适配个人信息保护法、数据安全法、网络安全法。
rfxlamia
Comprehensive red teaming methodology for both cybersecurity (MITRE ATT&CK, pentesting) and AI/LLM systems (prompt injection, jailbreaking, OWASP Top 10 LLM). Includes threat modeling, attack simulation, compliance validation (NIST, EU AI Act), and progressive attack technique references.
djadmin
Audit your Mac's security posture, understand what each finding means and why it matters, then fix what's safe, all from Claude Code. Wraps the fort CLI over your shell. Read-only by default; never applies a fix without your explicit go-ahead. Findings also map to SOC 2 / ISO 27001 / NIST / CIS if you need audit evidence.
tonone-ai
Legal Compliance Auditor — internal controls, legal risk register, audit trail
tonone-ai
Compliance Framework Engineer — SOC2, GDPR, HIPAA, ISO 27001 gap analysis
tonone-ai
Compliance gap analysis — SOC2, GDPR, HIPAA, ISO 27001
tonone-ai
Survey existing compliance artifacts and certifications
tonone-ai
Deep clause-by-clause analysis with risk scores
tonone-ai
Scan existing contracts for risk patterns
tonone-ai
Audit existing infrastructure for security issues, waste, and misconfigurations. Use when asked to "audit my infra", "check cloud setup", "infra review", "are we wasting money", "security check on infra", or "review my terraform".
tonone-ai
Infrastructure reconnaissance — inventory all cloud resources, map connections, flag risks. Use when asked to "inventory our infra", "what infrastructure do we have", "map our cloud resources", "infra discovery", or "what's running in our cloud".
tonone-ai
AI Operations Team — Guard: Input/output safety filters, PII detection, content moderation, and AI policy enforcement at runtime.
tonone-ai
Audit guardrail coverage — bypass vectors, false positive rates, policy gap analysis, red-team scenarios.
tonone-ai
Design guardrail layers — input classifiers, output validators, PII scrubbers, policy rule engines.
tonone-ai
Map current AI safety controls — filter inventory, coverage gaps, latency impact, incident history.
tonone-ai
Infrastructure Specialist Team — Kube: Kubernetes cluster design — RBAC, networking, operators, workload configuration
tonone-ai
Kube skill: kube-rbac
tonone-ai
Infrastructure Specialist Team — Mesh: Service mesh design — Istio/Linkerd/Envoy, mTLS, traffic management, observability integration
tonone-ai
Multi skill: multi-recon
tonone-ai
Audit an existing CI/CD pipeline for slowness, security issues, and reliability gaps. Use when asked to "audit pipeline", "why is CI slow", "pipeline review", or "deployment review".
tonone-ai
IP & Trademark Advisor — trademark clearance, patent landscape, OSS license compliance
tonone-ai
Open source license compliance audit — GPL, LGPL, AGPL risks
tonone-ai
Survey IP assets, license obligations, and assignment gaps
tonone-ai
Serv skill: serv-recon
tonone-ai
Regulatory Risk Advisor — GDPR, CCPA, FTC, financial regulation, export controls
tonone-ai
Map product data flows and identify regulatory triggers
tonone-ai
Privacy & ToS Drafter — GDPR-compliant privacy policies, ToS, cookie policies, DPAs
tonone-ai
Check privacy policy and ToS for completeness and compliance
tonone-ai
Mobile reconnaissance — understand the app's tech stack, architecture, dependencies, and health for takeover. Use when asked to "understand this app", "mobile assessment", or "app health".
tonone-ai
Security engineer — IAM, secrets, compliance, threat modeling
tonone-ai
Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. Use when asked for "security audit", "check for vulnerabilities", "security review", or "are we secure".