.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

home/plugins/security
home/plugins/security

Security Plugins

105 security Claude plugins for Claude Code and AI agents, ranked by real installs from npm, PyPI and skills.sh.

#Type
  1. 1mukul975 avataranthropic-cybersecurity-skills817 cybersecurity skills covering web security, pentesting, DFIR, threat intelligence, cloud security, malware analysis, and more.PluginsJun 2026—27k
  2. 2simoneavogadro avatarandroid-reverse-engineering-skillClaude Code skill to support Android app's reverse engineeringPluginsJun 2026—6.6k
  3. 3trailofbits avatarskillsTrail of Bits Claude Code skills for security research, vulnerability detection, and audit workflowsPluginsJul 2026—6.3k
  4. 4microsoft avataragent-governance-toolkitAI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.PluginsJul 2026—5.0k
  5. 5tech-leads-club avataragent-skillsThe secure, validated skill registry for professional AI coding agents. Extend Antigravity, Claude Code, Cursor, Copilot and more with absolute confidence.PluginsJul 2026—5.0k
  6. 6elementalsouls avatarclaude-bughunter82-skill bug-hunting & external red-team bundle for Claude Code — 57 hunt-* web/vuln-class + framework skills, enterprise platform attack chains (M365/Entra, Okta, SharePoint, vCenter, SSL-VPN, APK/iOS), recon/OSINT, reporting & validation gates, and Burp MCP integration.PluginsJul 2026—3.2k
  7. 70xsteph avatarpentest-ai-agents50 specialist subagents for authorized penetration testing and red team engagements — recon, web/API, Active Directory, cloud, mobile, wireless, exploitation, post-exploitation, detection, forensics, and reporting.PluginsJun 2026—2.0k
  8. 8prompt-security avatarclawsecA complete security skill suite for OpenClaw, Hermes, PicoClaw and NanoClaw agents (and variants). Protect your SOUL.md (etc') with drift detection, live security recommendations, automated audits, and skill integrity verification. All from one installable suite.PluginsJul 2026—1.1k
  9. 9cisco-ai-defense avatarmcp-scannerScan MCP servers for potential threats & security findings.PluginsJul 2026—994
  10. 10berabuddies avatarsemiaSemia, security audit for AI agent skills.PluginsJul 2026—587
  11. 11rickytong1 avataraudit-harness审计执行保障框架:为 AI Agent 提供三层审计防线、Context 恢复、审计驱动日报和自我修正闭环。PluginsJun 2026—576
  12. 12trailofbits avatarskills-curatedCurated, community-vetted Claude Code plugin marketplacePluginsJul 2026—469
  13. 13goplussecurity avataragentguardGoPlus AgentGuard — AI agent security guard. Blocks dangerous commands, prevents data leaks, protects secrets. 20 detection rules, runtime action evaluation, trust registry.PluginsJun 2026—448
  14. 14secureagentics avataradrianOpen-source runtime AI agent security tool - monitors and controls AI agents, catching malicious tool use, prompt injection, and policy drift in real time, before the agent acts.PluginsJul 2026—446
  15. 15transilienceai avatarcommunitytoolsClaude Code skills and agents for authorized security testing, bug bounty hunting, and pentesting workflowsPluginsJul 2026—434
  16. 16hashgraph-online avatarhol-guardOpen-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.PluginsJul 2026—419
  17. 17project-codeguard avatarrulesSecurity code review skill based on Project CodeGuard's comprehensive security rules. Helps AI coding agents write secure code and prevent common vulnerabilities.PluginsJan 2026—418
  18. 18pegasi-ai avatarreinsSecurity controls for AI agents — deterministic policy enforcement, OWASP ASI10 scanning, and audit trails.PluginsMay 2026—407
  19. 19aiskillstore avatarmarketplaceSecurity-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.PluginsJul 2026—401
  20. 20ghostsecurity avatarskillsGhost Security's collection of AppSec skills for AI coding agentsPluginsMar 2026—400
  21. 21hypnguyen1209 avataroffensive-claudeSpec-driven offensive-security framework for Claude Code: 31 kill-chain skills, executable safety controls (scope/finding/OPSEC discipline), pattern-learning memory, and a bounded engagement engine — with a SessionStart dispatcher that enforces skill-invocation discipline.PluginsJul 2026—327
  22. 22briiirussell avatarcybersecurity-skillsCybersecurity skills for AI agents — code audit, cloud, recon, IR, AI security, and morePluginsMay 2026—324
  23. 23credittone avatarandroid-reverse-engineering-skill这是一套专为 Codex 适配的 Android 逆向分析 skill,支持在 Codex 会话中反编译 APK、XAPK、JAR、AAR,并结合 jadx、Fernflower/Vineflower 梳理 Manifest、包结构、网络层和调用链。它可辅助提取接口、URL、鉴权头、token 与签名逻辑,并提供 Frida、抓包、JNI/SO 分析前的静态侦察方法,适合接口分 析、安全研究和授权测试。PluginsMay 2026—311
  24. 24cosai-oasis avatarproject-codeguardSecurity code review skill based on Project CodeGuard's comprehensive security rules. Helps AI coding agents write secure code and prevent common vulnerabilities.PluginsJul 2026—278
  25. 25gendigitalinc avatarsageSafety for Agents - Agent Detection & Response (ADR) for AI agentsPluginsJun 2026—256
  26. 26telagod avatarcode-abyss26 domain skills + 5 verification tools for security-first full-stack engineering. Covers security, architecture, DevOps, AI, mobile, office docs, frontend design, and multi-agent coordination.PluginsJul 2026—237
  27. 27evol-ai avatarskillcompassLocal-only skill quality and security evaluator for Claude Code/OpenClaw. Scores six dimensions, runs local validators, and stores reports and snapshots under .skill-compass/.PluginsApr 2026—227
  28. 28hainrixz avatarcyber-neoOpen-source cybersecurity analysis agent. Scans any local project for vulnerabilities: code security (SAST), dependency CVEs (SCA), secret leaks, authentication/authorization flaws, cryptographic weaknesses, misconfigurations, supply chain risks, and CI/CD security.PluginsJul 2026—221
  29. 29fabio-rovai avataropen-ontologiesA Terraforming MCP for Knowledge Graphs: validate, classify, and govern AI-generated ontologies.PluginsJul 2026—214
  30. 30masriyan avatarclaude-code-cybersecurity-skillCybersecurity skills marketplace for Claude Code — offensive, defensive, and operational security domains.PluginsJul 2026—207
  31. 31openzeppelin avataropenzeppelin-skillsSkills for secure smart contract development with OpenZeppelin Contracts librariesPluginsJul 2026—203
  32. 32agricidaniel avatarclaude-cybersecurityAI-powered cybersecurity code review with 8 specialist agents, OWASP Top 10:2021, CWE Top 25:2024, MITRE ATT&CK v15, and framework-aware false-positive suppressionPluginsApr 2026—193
  33. 33alexgreensh avatarrepo-forensicsOffline security scanner for AI-agent repos, skills, plugins, and MCP serversPluginsJul 2026—144
  34. 34jar-analyzer avatarjar-analyzer-claudeClaude Code plugin for Java JAR security audit — 基于 jar-analyzer 的 Claude Code 安全审计插件,构建数据库,AI 深入分析PluginsMar 2026—138
  35. 35pillar-labs avatarsail-skillSAIL V2 (Secure AI Lifecycle) as an agent skill — the full 91-risk catalog for AI/agent gap assessments, security roadmaps, and compliance checklists. Installs on Claude Code, Codex, ChatGPT, Antigravity, and any SKILL.md-compatible agent.PluginsJul 2026—136
  36. 36quillai-network avatarquillshield_skillsStructured skills for smart contract security audits. Infers state invariants, detects semantic guard gaps, models flash loan + oracle attack chains, simulates adversarial exploits, and scores findings.PluginsMar 2026—116
  37. 37khendzel avatarskills-janitorAudit, clean, secure and swipe-triage your Claude Code + Codex skills. Honest token costs, prompt-injection scan, usage tracking — and it actually deletes.PluginsJul 2026—113
  38. 38hacktronai avatarskillsHacktron Claude Code skills for security research, finding triage, and offensive/defensive workflows.PluginsJun 2026—111
  39. 39incogbyte avatarandroid-reverse-engineering-claude-skillClaude Code skill that automates Android application reverse engineeringPluginsJun 2026—92
  40. 40aisa-group avatarskill-injectSkill-Inject: Measuring Agent Vulnerability to Skill File AttacksPluginsJul 2026—88
  41. 41justi avatarclaude-code-project-boundaryBlocks destructive commands outside the project directory. Allows file operations within the project (refactoring, cleanup) but prevents accidental damage outside it.PluginsMay 2026—86
  42. 42stickman230 avatarclaude-pentestAn open source plugin for enabeling claude to gain offensive pentesting capabilitiesPluginsJun 2026—79
  43. 43djadmin avatarfortAudit and fix your Mac's security in one command. No agent, no signup, open source.PluginsJul 2026—73
  44. 44agentrhq avatarauthsomeLocal OAuth2 and API-key credential broker for AI agents.PluginsJul 2026—72
  45. 45mukul975 avatarthreatswarm27 scope-enforced AI agents that run the full pentest kill-chain (recon → exploit → post-ex → DFIR → report) as a one-command Claude Code plugin. Backed by 754 MITRE-mapped skills.PluginsApr 2026—65
  46. 46sysdig avatarskillsSysdig agentic AI skills and pluginsPluginsJul 2026—59
  47. 47yoanbernabeu avatarsupabase-pentest-skillsAI agent skills for security auditing Supabase applications - internal self-assessment toolkitPluginsJan 2026—59
  48. 48purpleailab avatarvigiloAn AI hacker for Web3 Smart Contract. for bug bounties, Audit contest, offensive security research, and real-world exploit thinking.PluginsFeb 2026—57
  49. 49eth0izzle avatarsecurity-skillsA collection of Claude Code skills that help security teams stay securePluginsApr 2026—51
  50. 50solanabr avatarauditor-skillSolana + full-stack security auditor: 20 checklists / 1,346 items / 131 known-vectors, severity 1-10, scope-gated loading.PluginsJul 2026—48
  51. 51assafkip avatarhuntkitInvestigation toolkit for Claude Code. Case management, OSINT, structured analytic techniques (Heuer / CIA tradecraft primer), chain-of-custody evidence capture, and bundled MCP servers for infrastructure recon and threat intel.PluginsJul 2026—47
  52. 52deepbitstechnology avatarclaude-pluginsThis project equips Claude Code with advanced binary analysis capabilities for tasks such as incident response, malware investigation, and vulnerability assessmentPluginsJul 2026—46
  53. 53zscaler avatarzscaler-mcp-serverManage Zscaler cloud security platform including ZPA (private access), ZIA (internet access), ZDX (digital experience), ZCC (client connector), EASM (attack surface), and Z-Insights (analytics).PluginsJul 2026—41
  54. 54auth0 avataragent-skillsAuth0 Agent SkillsPluginsJul 2026—40
  55. 55byamb4 avatarfind-cve-agentCVE hunting harness for open source security research. A 5-agent team that systematically finds, validates, and reports real vulnerabilities in open source packages.PluginsMar 2026—40
  56. 56himself65 avatarauth-specAuth skills for Claude Code — scaffold auth endpoints, review auth code for security issues, and add conformance testsPluginsJul 2026—39
  57. 57railyard-dev avatarrailguardA secure runtime for Claude Code. Intercepts every tool call with policy-based allow/block/ask decisions, evasion detection, path fencing, file snapshots, and audit logging.PluginsMar 2026—39
  58. 58winmin avatarkernel-vuln-analyzerAnalyze Linux kernel vulnerabilities from KASAN/UBSAN/BUG crash logs or CVE descriptions. Full root cause analysis, exploitability assessment, patch development, and QEMU verification.PluginsJul 2026—39
  59. 59prismer-ai avatarsignetProof layer for AI agents. Cryptographically verify every action.PluginsMay 2026—38
  60. 60bridge-mind avatarbridgewardSkeptical-reading and prompt-injection defense for AI coding agents. Trust nothing. Ship safely.PluginsApr 2026—37
  61. 61numen-tech avatarslopornotAgentic AI Humanizer Skill for Codex, Claude and OpenClaw: Bypass AI DetectorsPluginsJul 2026—37
  62. 62killvxk avatarcybersecurity-skills-zh734+ 网络安全技能,涵盖 Web 安全、渗透测试、DFIR、威胁情报、云安全、恶意软件分析等领域。中文版本。PluginsApr 2026—35
  63. 63chronoaiproject avatarnyxidBrokers credentials for downstream services (OpenAI, Anthropic, GitHub, Lark, custom APIs, SSH, MCP) so the agent never sees raw API keys or OAuth tokens. Thin wrapper over the nyxid CLI.PluginsJul 2026—34
  64. 6426zl avatarcybersec-toolkit872 on-demand security skills for CTF, pentest, bug bounty, DFIR, detection engineering, cloud, identity, and red/blue team work. Skills are plain Markdown and activate by task without permanently consuming context.PluginsJul 2026—33
  65. 65christopherkarani avatarorca🚦 Stop AI agents from deleting data, leaking secrets, or taking irreversible actions without approval. One ⭐ takes us a long way :))PluginsJul 2026—33
  66. 66frmoretto avatarhardstopPre-execution safety layer that blocks dangerous shell commands and credential file reads using pattern matching + LLM analysis. Fail-closed design.PluginsApr 2026—30
  67. 67netresearch avatarsecurity-audit-skillSecurity audit patterns (OWASP Top 10, CWE Top 25 2025, CVSS v4.0) and GitHub project security checks for any project. Deep automated PHP/TYPO3 scanning with 80+ checkpoints, 19 reference guides, PreToolUse warnings. By Netresearch.PluginsJul 2026—30
  68. 68wrsmith108 avatarvarlock-claude-skillSecure environment variable management with Varlock for secrets, API keys, credentials, and sensitive configuration.PluginsMar 2026—30
  69. 69ivan-magda avatarswift-security-skillExpert guidance for Apple Keychain Services, biometric authentication, CryptoKit cryptography, credential lifecycle management, certificate trust, and OWASP compliance mapping.PluginsJun 2026—29
  70. 70aks129 avatarhealthclawguardrailsFHIR AI agent guardrails with 14 MCP tools. PHI redaction on every read, step-up authorization for writes, immutable audit trails, tenant isolation, Curatr data quality evaluation and correction, Fasten Connect EHR ingestion, and HealthEx portable health record export.PluginsJul 2026—27
  71. 71rigour-labs avatarrigourThe immune system for AI coding agentsPluginsApr 2026—26
  72. 72fb0sh avatarpentester基于 AI Agent 的渗透测试自动化框架,严格遵循 PTES(Penetration Testing Execution Standard)标准,覆盖渗透测试全生命周期。| An automated penetration testing framework based on AI agents strictly adheres to the PTES (Penetration Testing Execution Standard) standards and covers the entire life cycle of penetration…PluginsJul 2026—20
  73. 73ogrodev avatarfsocietyMarketplace for red team and offensive security plugins developed by ogrodev.PluginsMar 2026—20
  74. 74myr-aya avatargouvernai-claude-code-pluginRuntime guardrails for Claude Code. Auto-approve what's safe, gate what's risky, block what's dangerous. Dual enforcement, full audit trail. MIT.PluginsJul 2026—18
  75. 75fortify avatarskillsOpenText Fortify AppSec skills. Use for SAST/DAST/SCA scanning, vulnerability triage, audit workflows, CI/CD pipeline integration, and FCLI commands. Supports Fortify on Demand (FoD) and Software Security Center (SSC).PluginsJul 2026—16
  76. 76vulhunt-re avatarskillsAgent skills for VulHuntPluginsMar 2026—15
  77. 77jeongjaesoon avataragent-guardReal-time secret-leak guardrails for AI coding agents (Claude Code, Codex), Git hooks, and CI.PluginsJul 2026—14
  78. 78qwerfunch avatarcladdingFor an organization to trust AI with its code, three things must hold — trust, traceability, and stability at scale. cladding wraps your AI coding agent: your intent goes in before it writes, and the result is verified against your spec after, so those three are earned, not…PluginsJul 2026—14
  79. 79raffa-jarrl avatarlictor-aiFree security skills for AI-built apps — run /lictor-security-check in Claude Code before you ship. Plain English, read-only, no telemetry.PluginsJul 2026—14
  80. 80efij avatarsecure-claude-codeRuntime security plugin for Claude Code with balanced default hooks plus the Stallion inline MCP gateway for shell, git, MCP, secret, and exfiltration risks.PluginsMay 2026—13
  81. 81humanbound avatarpluginsHumanbound plugin marketplace for Claude Code and Cursor — adversarial security testing for local AI agents.PluginsJul 2026—13
  82. 82chaingpt-org avatarchaingpt-claude-skillThe Web3 toolkit for Claude Code. AI-powered (ChainGPT chat / NFT / Solidity generator + auditor / crypto news / Solidity LLM) PLUS broad Web3: multi-chain wallet portfolios, token research, risk scanning, on-chain analytics, AI-enriched intel, MAINNET contract deployment with…PluginsJul 2026—12
  83. 83aikidosec avataraikido-claude-pluginAikido Security for Claude Code: scan code (SAST, secrets, IaC) and list all issues from your Aikido feed powered by the Aikido MCP server.PluginsJul 2026—11
  84. 84fullstackcrew-alpha avatarprivacy-maskAuto-mask sensitive info in images before AI upload. 100% local.PluginsMar 2026—11
  85. 85pi-sloane avatarclaude-pluginPi Security workflows for Claude Code and Cowork: investigate findings, review security posture, fetch remediation guidance, start design reviews, submit Markdown reports, and query secure-development playbooks through Pi's hosted MCP server.PluginsJul 2026—11
  86. 86smrafiz avatarclaude-superchargerShell-level guardrails for Claude Code. Command blocking, code security scanner, self-teaching, token economy, agent routing, MCP profiles, and session memory.PluginsJul 2026—11
  87. 87omermaksutii avatarrugproofSmart contract security auditor for Claude Code. Rugproof your code before someone else does.PluginsJul 2026—9
  88. 88chainguard-demo avatarclaude-pluginsOfficial Chainguard plugins and skills for Claude Code - documentation access and secure container image migrationPluginsMay 2026—7
  89. 89vcohere avatarclaude-code-marketplaceA Claude Code marketplace of security and code-quality skills, maintained by Logique.PluginsJun 2026—7
  90. 90attestral-labs avatarattestralOpen-source security scanner for MCP servers and AI agents: finds prompt injection, tool poisoning, and excessive agency, and models the cloud your agents can reach. pip install attestral.PluginsJul 2026—5
  91. 91akirtok avatarpreflight-security-auditFor vibe coders who ship fast and don't want to get hacked. Preflight Security Audit plugin checks your app before its launch. One command finds the security, privacy, and payment vulnerabilities in your code and fixes them. 50+ security checks in 6 categories.PluginsJul 2026—4
  92. 92ap6pack avataroutrider-reconClaude-native authorized external recon and ASM methodology bundle with 90 documented capabilities across 11 skills, deterministic Python controls, an optional loopback-only limited-control web plane, explicit human-reviewed finding promotion, and optional fixed policy-gated MCP…PluginsJul 2026—4
  93. 93casedone avatarclaude-code-security-pluginsAutomated security scanning (Bandit, Semgrep, Trivy, TruffleHog) and comprehensive static security review agent for Claude CodePluginsMar 2026—4
  94. 94froggeric avatarclaude-smart-approvalAuto-approve safe Bash commands in Claude Code using prefix matching and AI evaluation. Requires: shfmt, jq (brew install shfmt jq).PluginsApr 2026—4
  95. 95mcp-fortress avatarmcp-fortressSecurity scanner and install and runtime protection suite for Model Context Protocol (MCP) serversPluginsApr 2026—4
  96. 96jitangupta avatarfile-safety-guardPrevents accidental file deletion, overwrites, and destructive operations. Adds automatic backups, dry-run planning, activity logging, and bulk operation approval to every session.PluginsMar 2026—3
  97. 97shiftleftsecurity avatarclaude-pluginsHarness SAST and SCA plugins for Claude CodePluginsMay 2026—3
  98. 98boranesn avataragentic-baseClaude Code için disiplin katmanı — append-only log, deterministik güvenlik gate'leri, confidence eşikleri ve insan onay kuyruğu (plugin marketplace)PluginsJul 2026—2
  99. 99hijacksecurity avatarclaude-pluginsIntercept security for Claude Code — deep AI security scans that supplement your scanners and write findings back to the Intercept platform. OAuth 2.1, no API key.PluginsJul 2026—2
  100. 100runverdict avatarsf-security-review-toolkitSkills that prepare an ISV partner for the AppExchange/AgentExchange security review end to end — autonomous multi-agent codebase audit, submission-artifact generation, scan orchestration, test-environment runbooks, and an honest readiness verdict.PluginsJul 2026—2

More plugins categories

AI Agents & MCP844Productivity & Workflow295Backend & APIs256DevOps & CI/CD194Agent Meta & Communication189Code Review & Refactor168Product & Project Management154Frontend Development124Documentation & Knowledge110Research92All Plugins →