Plugins · Security & identity
50 listings on this page, in order of arrival. Each one has its own page with README, repository facts and source links.
- aikido ★ 13
Aikido Security scanning for Claude Code — SAST, secrets, and IaC vulnerability detection powered by the Aikido MCP server. - Auth0 ★ 49
Essential Auth0 skills including quickstarts, migration from other providers, and Multi-Factor Authentication (MFA). - claude-security ★ 36,087
Deep vulnerability scanning of your own code, run entirely inside your Claude Code session at a chosen effort tier, with every finding chall - duende-skills ★ 9
Duende development skills and agents for Claude Code — covering OAuth/OIDC protocols, IdentityServer, token management, ASP.NET Core authent - firebase ★ 36,087
Google Firebase MCP integration. Manage Firestore databases, authentication, cloud functions, hosting, and storage. Build and manage your Fi - semgrep ★ 12
Semgrep catches security vulnerabilities in real-time and guides Claude to write secure code from the start. - StackHawk API ★ 16
Query the StackHawk platform API for security posture reporting, findings analysis, and app management. Guides agents through authentication - vanta ★ 4
The Vanta plugin connects Claude Code to Vanta's security and compliance platform through the Vanta MCP server. It combines Vanta's test-spe - Vanta ★ 4
The Vanta plugin connects Claude to Vanta's security and compliance platform through the Vanta MCP server. List failing compliance tests, ge - workos ★ 46
WorkOS integration skills for AuthKit, SSO, Directory Sync, RBAC, Vault, Audit Logs, migrations, and API references. - accessibility-audit ★ 3
Generate WCAG compliance audit reports - akf ★ 15
The AI native file format. EXIF for AI — stamps every file with trust scores, source provenance, and compliance metadata. 20+ formats. - apiiro ★ 4
The Apiiro plugin for Claude Code connects developers directly to Apiiro’s Software and Risk Graph along with organizational context, bringi - appstore-prep
A 5-skill bundle that captures the gnarly pre-submission failure modes — Apple Distribution + 3rd Party Mac Developer Installer signing, Swi - bci
The first BCI toolkit for researchers, developers, and security engineers. Threat modeling, vulnerability scoring, pattern detection, and ne - carryall-policy-enforcement
Deterministic IAM control plane for AI agents. Translates natural language intent into minimal-scope Ed25519-signed envelopes. You bring you - claude-code-vulnerability-check ★ 1
Detect CVE (Common Vulnerability Exposure) in PHP / JS project. Auto apply minor fixes and patch Alert on necessity of major update (prevent - claude-md-optimizer ★ 23
Optimize oversized CLAUDE.md files using progressive disclosure, content tiers, encryption constraints, and sub-documents. - claude-project-context-manager ★ 3
A skill and agent plugin that reads your project's architecture documentation — README.md, architecture.md, and related files — and enforces - claude-universe ★ 72
Five intelligence systems for Claude Code. Analyze instruction quality, generate deeper tests, scan for security vulnerabilities, understand - claude-vault
Session analytics MCP plugin for Claude Code. Ingests JSONL conversation logs into SQLite JSONB, tags sessions by namespace, and produces st - clawkeeper ★ 2
Frictionless security, compliance, and threat detection for Claude Code and Co-Work. Advanced Behavioral detection patterns catch credential - clawlock
Identity, credential vault, and audit security for AI agents. ClawLock gives every AI agent its own Ed25519 cryptographic identity, stores A - compliance-checks
EU regulatory compliance checks for businesses. Assess whether your organisation is affected by NIS-2, classify AI systems under the EU AI A - context-vault
Persistent structured memory for Claude Code. SQLite JSONB vault with 7 MCP tools for entity CRUD, todos with dependencies, and context inje - cyber-punk
Automated security vulnerability scanner for Claude Code. Fetches CVE/CWE data from NIST NVD, scans code for vulnerable patterns across 9 la - dotsecenv ★ 5
Manage GPG-encrypted environment secrets from Claude Code - a secure alternative to plaintext .env files. Store, retrieve, share, and revoke - duende-agent-skills ★ 9
Duende development skills and agents for Claude Code — covering OAuth/OIDC protocols, IdentityServer, token management, ASP.NET Core authent - easysend
Upload, share and transfer files instantly from Claude Code. Drag-drop file sharing with end-to-end encryption. No signup or API key require - eu-ai-act-compliance ★ 1
EU AI Act compliance toolkit. Article 6 risk classifier (prohibited / high-risk / limited / minimal), Article 26(9) FRIA generator for deplo - findem-studio
Findem Studio plugin for talent intelligence — 3 remote MCP connectors with OAuth, comprehensive reviewer runbook. - fresh-eyes-review ★ 93
Mandatory final sanity check before commits/PRs - catches security vulnerabilities, logic errors, and bugs that slip through tests - gia-eu-ai-act-compliance ★ 1
Classify any AI system under the EU AI Act (Regulation 2024/1689). Screens all 8 prohibited practices (Article 5), classifies high-risk syst - harness-architect ★ 2
harness-architect is a meta-tool that scans any target project and builds an end-to-end Claude Code harness — CLAUDE.md, settings, rules, ag - hig-compliance-auditor
Audits codebases and design systems against Apple's Human Interface Guidelines. Scans SwiftUI, UIKit, CSS, HTML, and JavaScript for HIG viol - latio-secure-supply-chain-skills ★ 15
Audit and take action to secure your repository against supply chain misconfigurations and malware. - malchela ★ 118
MalChela is a Rust-based malware analysis toolkit for DFIR analysts and malware researchers. It exposes file triage, string extraction with - maxim ★ 2
Behavioral intelligence layer for Claude Code. Every output cites a peer-reviewed framework (64 total: Fogg, COM-B, Cialdini, Hook Model, an - mcp-amplenote
Connect Claude Code to your Amplenote account and manage notes without leaving your workflow. Supports creating notes with tags, reading ful - messages-for-ai
AI proposes, you approve. A safety-gate alternative for AI iMessage automation — every message Claude drafts via this MCP is staged in a com - nah ★ 480
nah is a local safety guard for Claude Code. It runs before tool use and classifies actions by what they actually do, so safe operations can - opsera-devsecops ★ 3
Opsera DevSecOps Agent — AI-powered architecture analysis, security scanning, compliance auditing, and SQL security for your codebase. Free - product-review-expert
product-review-expert is a Claude Code plugin for structured product and UX review. It is intended to help users analyze product requirement - project-manager-vibes
PM Vibe is a free skill for Claude Code that adds project management and bug prevention for vibe coders. It builds structured specs before w - railscto ★ 14
A complete Ruby on Rails toolkit for Claude Code: planning, idiomatic code, tests, linting, security scans, and git workflows — all enforced - rootcx
Official plugin for RootCX, the open-source platform for building internal software and AI agents on a unified, secure foundation. Connect t - scalekit-mcp-auth
Secure MCP servers with OAuth 2.1, token introspection, dynamic client registration, and CIMD so AI agents can call your MCP tools with veri - scalekit-modular-sso
Add SAML or OIDC SSO to your app without replacing your auth system. Let enterprise customers log in via Okta, Azure AD, Google Workspace, a - second-brain ★ 1
A personal knowledge vault that compounds over time. Drop sources into raw/ and Claude writes a structured, interlinked wiki — extracting co - secure-sdlc-agents ★ 13
A team of 8 AI security specialists embedded in your coding workflow — covering every phase of the Software Development Lifecycle. Includes