PlugMyPlugin
← Browse all plugins

Best Security plugins for Claude Code

18 plugins, each analyzed from its own files.

hookify

★ 896
anthropics

Hookify creates custom hooks to prevent unwanted behaviors by analyzing conversation patterns or explicit instructions, using simple markdown configuration files with regex pattern matching. It supports four hook events (PreToolUse, PostToolUse, UserPromptSubmit, Stop) and provides commands to generate rules, list configurations, and interactively manage hook behavior without requiring restarts.

4 commands · 1 agent · 1 skill · 4 hooks
Productivity free runs shell hooks
#hook-management#pattern-matching#behavior-prevention#markdown-config

security-audit

★ 859
netresearch

This Agent Skill performs automated security audits using OWASP Top 10, CWE Top 25 2025, and CVSS v4.0 standards for any project, with deep PHP/TYPO3 scanning across 80+ checkpoints and 19 reference guides. It integrates via a PreToolUse hook to flag risky commands and provides vulnerability assessment, risk scoring, secure coding guidance, and DevSecOps pipeline security.

1 skill · 1 hook
Security free runs shell hooks
#security-audit#owasp-top-10#vulnerability-scanning#cvss-scoring

nopeek

★ 829
spences10

This plugin automatically loads credentials from a CLAUDE_ENV_FILE environment variable on session start and redacts secrets from CLI output in real-time using the nopeek CLI tool. It intercepts both session initialization and tool execution to prevent sensitive data from being exposed in logs or terminal output.

1 skill · 2 hooks
Security free runs shell hooks
#secret-redaction#credential-loading#env-security#cli-safety

github-release

★ 710
netresearch

This Claude Code plugin prevents unsafe GitHub release practices by intercepting dangerous `gh release` commands via hooks and provides orchestrated version bumping, signed tagging, and CI-driven release workflows across multiple ecosystems (TYPO3, PHP, Node.js, Go, Python, Rust). It detects project type, manages semantic versioning from conventional commits, and ensures releases flow through proper code review and CI pipelines with supply chain security features like SBOMs and attestations.

3 commands · 1 skill · 2 hooks
DevOps free runs shell hooks
#github-releases#supply-chain-security#semantic-versioning#signed-tags
composio-community

This plugin acts as a security reminder hook that warns developers about potential security vulnerabilities—including command injection, XSS, and unsafe code patterns—when they edit files. It uses a Python-based analysis triggered by PreToolUse events to flag risky code patterns before they're executed.

1 hook
Security free runs shell hooks
#security-scanning#code-analysis#injection-prevention#xss-detection

reins

★ 525
pegasi-ai

Reins intercepts tool calls via pre/post hooks to block destructive actions, route high-risk operations to human approval, and maintain an immutable audit trail of all decisions. It protects against vulnerabilities covered in OWASP MCP, ASI, and Agentic Skills Top 10 threat models by analyzing commands before execution and logging outcomes to a local decision log.

1 skill · 10 hooks
Security free runs shell hooks
#runtime-security#ai-agent-safety#pre-hook-interception#audit-trail

safety-net

★ 301
kenryu42

Safety Net intercepts and blocks destructive git and filesystem commands before AI agents execute them by analyzing command semantics, making it immune to flag reordering and shell wrappers. It runs as a PreToolUse hook across seven coding agent CLIs (Claude Code, Codex, Gemini CLI, GitHub Copilot CLI, Kimi Code, OpenCode, and Pi) and works on Windows, macOS, and Linux.

1 skill · 1 hook
Security free runs shell hooks
#safety-hook#git-protection#destructive-command-blocking#semantic-analysis

git-flow

★ 153
alexei-led

This plugin provides Git workflow automation including worktree management, branch cleanup, secret scanning, and configuration validation through hooks and guardrails. It uses a PreToolUse hook to inspect and control tool execution decisions, with built-in shell integration for Git operations.

3 skills · 1 hook
DevOps free runs shell hooks
#git-workflow#secret-scanning#branch-management#hooks

pm-ai-shipping

★ 817
phuryn

This plugin documents AI-generated codebases and audits them for security/performance gaps by comparing documented intent against actual implementation, producing a reviewer-ready shipping packet. It provides five commands to reverse-engineer architecture, map test coverage, and identify risks that generic scanners miss.

5 commands · 2 skills
Code Review free prompt pack
#security-audit#code-review#documentation#vibe-code

audit

★ 815
ccplugins

This plugin performs security audits on codebases through a single command that analyzes code for potential vulnerabilities and security issues. It operates without requiring external dependencies or third-party services.

1 command
Security free prompt pack
#security-audit#codebase-scanning#vulnerability-detection#code-security
ccplugins

This agent implements AI ethics frameworks, governance policies, and responsible AI practices for B2B applications, focusing on bias detection and algorithmic transparency. It helps enterprises establish AI governance structures and compliance requirements that build trust in AI systems.

1 agent
Security free prompt pack
#ai-ethics#governance#bias-detection#compliance
ccplugins

This agent implements data privacy engineering and GDPR compliance frameworks for B2B applications, covering data minimization, consent management, and privacy-by-design principles. It specializes in helping enterprises meet global privacy regulation requirements across their platforms.

1 agent
Security free prompt pack
#gdpr-compliance#data-privacy#privacy-engineering#consent-management

security

★ 555
cbrock84

This Claude Code plugin provides eight skills for threat modeling, security architecture review, incident response, vulnerability management, and access/identity governance. It enforces blocking findings that cannot be overruled by reviewed departments, establishing a strict security governance framework.

8 skills
Security free prompt pack
#threat-modeling#security-review#incident-response#vulnerability-management
ccplugins

This agent automates compliance processes for major regulatory frameworks including SOC 2, ISO 27001, GDPR, and HIPAA, helping B2B platforms with audit preparation and continuous monitoring. It provides a specialized interface for implementing and managing enterprise regulatory requirements without external dependencies.

1 agent
Security free prompt pack
#compliance-automation#soc2#iso27001#gdpr
netresearch

This Agent Skill assesses software projects against enterprise-grade standards including OpenSSF Scorecard, Best Practices Badges (Passing/Silver/Gold), SLSA, and supply chain security frameworks. It provides dynamic cross-platform scoring, quality gates, automated security hardening scripts, and guided certification pathways with no external API dependencies.

2 commands · 1 skill
Security free prompt pack
#openssf-compliance#supply-chain-security#slsa-framework#enterprise-audit
ccplugins

This plugin provides an AI agent that conducts comprehensive security assessments and compliance validation for B2B SaaS platforms, covering SOC 2, GDPR, and ISO 27001 standards. It specializes in multi-tenant security reviews, enterprise compliance checks, and audit preparation without requiring external API keys or tools.

1 agent
Security free prompt pack
#security-audit#compliance-review#b2b-saas#soc2

legal-risk

★ 57
cbrock84

This plugin provides eight specialized skills for contract review, privacy protection, enterprise risk assessment, corporate governance, compliance verification, and audit readiness. Its reviewer-class findings are authoritative and cannot be overridden by the department under review.

8 skills
Security free prompt pack
#contract-review#compliance#data-protection#enterprise-risk
netresearch

This skill provides a conformance ruleset and self-contained checker for TYPO3 v14 site/project repositories, validating repository layout, Docker/Compose topology, Concourse CI pipelines, supply-chain security, secret handling, and runtime configuration against the Netresearch gold standard. The bundled checker (check.py) requires only Python 3 and PyYAML to audit a target repo and generate a prioritized remediation list across seven rule families (STRUCT, CONTAINER, CI, DEPLOY, DEP, SEC, DOC).

1 skill
DevOps free prompt pack
#typo3-site-config#docker-compose-validation#concourse-ci-audit#supply-chain-gating