security-toolkit
Threat-detection and action-blocking hooks for Claude Code that catch dangerous mistakes like pushes to main, force pushes, and prompt-injection patterns in tool outputs, plus optional skills for PR-merge guarding, Windows/WSL supply-chain compromise triage, and repository-scoped PII/secret blocking via git hooks and CI. Everything fails closed, matches case-insensitively, and is designed as guardrails against accidents—not as a sandbox against determined adversaries.
Install
Source: https://github.com/bogheorghiu/ex-cog-dev/tree/HEAD/security-toolkit
What it's made of
1 command · 3 skills · 5 hooks
- Commands
- 1
- Agents
- 0
- Skills
- 3
- MCP servers
- 0
- Hooks
- 5 · PostToolUse, PreToolUse, SessionStart
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
announce-pr-merge-guard.shblock-dangerous-git.shblock-dc-config.shblock-dc-execute.shdetect-prompt-injection.sh- Talks to
- nothing external detected
Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (bogheorghiu).