PlugMyPlugin
← Browse

security-toolkit

bogheorghiu ★ 0

Threat-detection and action-blocking hooks for Claude Code that catch dangerous mistakes like pushes to main, force pushes, and prompt-injection patterns in tool outputs, plus optional skills for PR-merge guarding, Windows/WSL supply-chain compromise triage, and repository-scoped PII/secret blocking via git hooks and CI. Everything fails closed, matches case-insensitively, and is designed as guardrails against accidents—not as a sandbox against determined adversaries.

Security DevOps free runs shell

Install

> /plugin marketplace add bogheorghiu/ex-cog-dev/tree/HEAD/security-toolkit
> /plugin install security-toolkit

Source: https://github.com/bogheorghiu/ex-cog-dev/tree/HEAD/security-toolkit

What it's made of

1 command · 3 skills · 5 hooks

Commands
1
Agents
0
Skills
3
MCP servers
0
Hooks
5 · PostToolUse, PreToolUse, SessionStart

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
announce-pr-merge-guard.sh block-dangerous-git.sh block-dc-config.sh block-dc-execute.sh detect-prompt-injection.sh
Talks to
nothing external detected

Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (bogheorghiu).