18 plugins, each analyzed from its own files.
anthropics
Hookify creates custom hooks to prevent unwanted behaviors by analyzing conversation patterns or explicit instructions, using simple markdown configuration files with regex pattern matching. It supports four hook events (PreToolUse, PostToolUse, UserPromptSubmit, Stop) and provides commands to generate rules, list configurations, and interactively manage hook behavior without requiring restarts.
4 commands · 1 agent · 1 skill · 4 hooks
#hook-management#pattern-matching#behavior-prevention#markdown-config
netresearch
This skill audits any project for security vulnerabilities (OWASP Top 10, CWE Top 25, CVSS scoring) and GitHub repositories, with deep PHP/TYPO3 scanning across 80+ checkpoints and 19 reference guides. It hooks into PreToolUse events to warn about risky commands before execution.
1 skill · 1 hook
#security-audit#owasp-top10#vulnerability-scanning#php-security
spences10
This plugin automatically loads credentials from a CLAUDE_ENV_FILE environment variable on session start and redacts secrets from CLI output in real-time using the nopeek CLI tool. It intercepts both session initialization and tool execution to prevent sensitive data from being exposed in logs or terminal output.
1 skill · 2 hooks
#secret-redaction#credential-loading#env-security#cli-safety
netresearch
This skill prevents dangerous GitHub release commands (like unsigned tags and bypassed CI) by intercepting them via hooks, then orchestrates safe releases with version bumps, signed tags, and CI-driven workflows across multiple ecosystems (TYPO3, PHP, Node.js, Go, Python, Rust). It auto-detects project type, manages versioning from conventional commits, and ensures supply chain security through signed tags and attestations.
3 commands · 1 skill · 2 hooks
#github-releases#supply-chain-security#signed-tags#version-management
composio-community
This plugin acts as a security reminder hook that warns developers about potential security vulnerabilities—including command injection, XSS, and unsafe code patterns—when they edit files. It uses a Python-based analysis triggered by PreToolUse events to flag risky code patterns before they're executed.
1 hook
#security-scanning#code-analysis#injection-prevention#xss-detection
pegasi-ai
Reins intercepts tool calls via pre/post hooks to block destructive actions, route high-risk operations to human approval, and maintain an immutable audit trail of all decisions. It protects against vulnerabilities covered in OWASP MCP, ASI, and Agentic Skills Top 10 threat models by analyzing commands before execution and logging outcomes to a local decision log.
1 skill · 10 hooks
Security 💲 Pegasi Watchtower free runs shell hooks #runtime-security#ai-agent-safety#pre-hook-interception#audit-trail
hyhmrright
brooks-lint performs AI-powered code reviews grounded in twelve classic engineering books, diagnosing code against six decay risk dimensions with book citations and severity labels. It offers six analysis modes (PR review, architecture audit, tech debt, test quality, health dashboard, and auto-fix) that produce structured findings with symptoms, sources, consequences, and remedies.
6 commands · 6 skills · 1 hook
#code-review#decay-risk-diagnostics#engineering-classics#book-citations
kenryu42
Safety Net intercepts and blocks destructive git and filesystem commands before AI agents execute them by analyzing command semantics, making it immune to flag reordering and shell wrappers. It runs as a PreToolUse hook across seven coding agent CLIs (Claude Code, Codex, Gemini CLI, GitHub Copilot CLI, Kimi Code, OpenCode, and Pi) and works on Windows, macOS, and Linux.
1 skill · 1 hook
#safety-hook#git-protection#destructive-command-blocking#semantic-analysis
alexei-led
This plugin provides Git workflow automation including worktree management, branch cleanup, secret scanning, and configuration validation through hooks and guardrails. It uses a PreToolUse hook to inspect and control tool execution decisions, with built-in shell integration for Git operations.
3 skills · 1 hook
#git-workflow#secret-scanning#branch-management#hooks
phuryn
This plugin documents AI-generated codebases and audits them for security/performance gaps by comparing documented intent against actual implementation, producing a reviewer-ready shipping packet. It provides five commands to reverse-engineer architecture, map test coverage, and identify risks that generic scanners miss.
5 commands · 2 skills
#security-audit#code-review#documentation#vibe-code
ccplugins
This plugin performs security audits on codebases through a single command that analyzes code for potential vulnerabilities and security issues. It operates without requiring external dependencies or third-party services.
1 command
#security-audit#codebase-scanning#vulnerability-detection#code-security
ccplugins
This agent implements AI ethics frameworks, governance policies, and responsible AI practices for B2B applications, focusing on bias detection and algorithmic transparency. It helps enterprises establish AI governance structures and compliance requirements that build trust in AI systems.
1 agent
#ai-ethics#governance#bias-detection#compliance
ccplugins
This agent implements data privacy engineering and GDPR compliance frameworks for B2B applications, covering data minimization, consent management, and privacy-by-design principles. It specializes in helping enterprises meet global privacy regulation requirements across their platforms.
1 agent
#gdpr-compliance#data-privacy#privacy-engineering#consent-management
ccplugins
This agent automates compliance processes for major regulatory frameworks including SOC 2, ISO 27001, GDPR, and HIPAA, helping B2B platforms with audit preparation and continuous monitoring. It provides a specialized interface for implementing and managing enterprise regulatory requirements without external dependencies.
1 agent
#compliance-automation#soc2#iso27001#gdpr
netresearch
This Agent Skill assesses software projects against enterprise-grade security and quality standards including OpenSSF Scorecard, Best Practices Badge, SLSA, and supply chain security frameworks. It provides dynamic scoring across different platforms and languages, with automation scripts and templates to help projects progress toward compliance certifications.
2 commands · 1 skill
#openssf-compliance#supply-chain-security#security-hardening#quality-gates
ccplugins
This plugin provides an AI agent that conducts comprehensive security assessments and compliance validation for B2B SaaS platforms, covering SOC 2, GDPR, and ISO 27001 standards. It specializes in multi-tenant security reviews, enterprise compliance checks, and audit preparation without requiring external API keys or tools.
1 agent
#security-audit#compliance-review#b2b-saas#soc2
netresearch
Provides best-practice guidance for Dockerfile development, Docker Compose orchestration, and multi-platform builds with Docker Bake, including CI testing patterns and security hardening. Includes a companion skill for Windows hosts running Docker Desktop via WSL2 to prevent bind-mount path corruption.
2 skills
#dockerfile-patterns#docker-compose#multi-platform-builds#ci-testing
netresearch
This skill validates deployable TYPO3 v14 site/project repositories against a gold-standard ruleset covering layout, Docker/Compose topology, Concourse CI pipelines, supply-chain gating, secrets, and Valkey/ofelia runtime. It includes a self-contained Python checker and machine-readable rule catalogue requiring only pyyaml, no external services.
1 skill
#typo3-conformance#docker-compose#ci-cd-gating#concourse-ci