claude-code
29 resources across 2 kinds
Tools
- Open ↗Skill Security Checkpassive
Claude Code skill and CLI scanner that audits community skill files across 26 detection categories (prompt injection, exfiltration, permission bypass), with runtime hooks that block dangerous commands and inspect MCP responses.
- Open ↗agent-chaperonecloud costhosted
Apache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.
- Open ↗Jev Security Scancloud costhostedopt-inpassive
MIT-licensed Python CLI and Claude Code/Codex skill that reviews Agent Skills, MCP config and source code for suspicious behavior before installation: offline by default, or nine-category Jev triage with a TypeSafe API key.
- Open ↗Jev Sentinelcloud costhosted
MIT-licensed guard for coding agents (a Pi extension and Claude Code/Codex CLI plugins) that scores tool calls, outputs and replies with TypeSafe's Jev for injection and risk, then allows, asks, or blocks; needs a TypeSafe key.
- Open ↗jevkit (Jev Agent Kit)cloud costhosted
MIT-licensed CLI and MCP server giving agents eleven typed-decision tools on TypeSafe's hosted Jev model (route, triage, guard, grep, rank, compact), plus an advisory Claude Code PreToolUse hook; needs a TypeSafe API key.
Frameworks & agents
- Open ↗Agentic Malware Analysiscloud costhigh-risk
Kali-based Docker environment with 50+ RE tools, an MCP-connected Binary Ninja or Ghidra backend, and an orchestrator skill that lets Claude Code or Codex CLI turn a binary into a case directory of ranked evidence and hypotheses.
- Open ↗Anthropic Cybersecurity Skillsdual-use
Apache-2.0 library of 818 agentskills.io-format cybersecurity skills in 34 domains, mapped to MITRE ATT&CK, NIST CSF 2.0, ATLAS, D3FEND, NIST AI RMF and F3, for loading into Claude Code, Codex CLI, Cursor and similar agents.
- Open ↗AppSec (florianbuetow)passive
MIT Claude Code plugin bundling 62 slash-command skills across OWASP, STRIDE, PASTA, LINDDUN, MITRE ATT&CK and CWE Top 25, plus six red-team persona agents, for reviewing a codebase and generating fixes.
- Open ↗Awesome Claude Securitydual-use
Claude Code plugin marketplace of 45 installable plugins (110 skills) covering pentest, threat modeling, detection engineering, DFIR, GRC and LLM/agentic-AI security, with role bundles such as pentester that auto-install their parts.
- Open ↗Claude Coach (archived)licence
Archived Claude Code feature plugin that used hooks to detect friction signals (user corrections, tool failures, tone escalation) and propose CLAUDE.md rule updates; retired in favour of netresearch/retro-skill.
- Open ↗
MIT reference library of Claude Code hooks, 4 skills, 8 agents and 4 slash commands with a setup wizard, for auto-activating skills from prompts and file context in coding sessions; general agent tooling, not security-specific.
- Open ↗Claude Code RE Toolkitactivehigh-risk
Claude Code skill pack wrapping Ghidra, YARA, CAPA, Frida, FakeNet and an 18-service threat-intel client behind Docker and VMware isolation, for static, dynamic and web-forensic malware analysis on Windows.
- Open ↗
MIT-licensed Claude Code plugin whose hooks queue your corrections and 'remember:' notes, then on /reflect review and sync them into CLAUDE.md, AGENTS.md and skill files; it also mines session history for repeatable commands.
- Open ↗
Claude Code skill pack whose /reflect command turns a session's corrections into permanent edits to local skill files, with timestamped backups and git commits, so the assistant stops repeating the same mistakes.
- Open ↗Claude Security (plugin)cloud costlicencepassive
Claude Code plugin that runs a team of agents to scan a repository or diff for vulnerabilities, independently verifies each finding, and writes Markdown, JSONL and SARIF reports plus optional patch files left for review.
- Open ↗
MIT-licensed Claude Code skills and hooks for staying organized when working with AI agents: a date-injection hook, timed nudge reminders, Obsidian daily-journal and vault-management skills, and a CLAUDE.md template.
- Open ↗Feedback Loop Builderlicence
Claude Code plugin that retrofits an existing skill or agent with a @BOOT/@REVIEW/@EVOLVE feedback loop, recording learned patterns to a feedback/ directory and asking for approval before each change.
- Open ↗
Go-based Claude Code UserPromptSubmit hook that ranks installed skills against each prompt with a local embedding index and injects the top matches as context, so long-tail skills that Claude Code would drop still surface.
- Open ↗Pentest AI Agentsactivedual-usehigh-risk
A set of Claude Code subagents, each a domain-specific system prompt for penetration testing, installed as agent files or a plugin, offering an advisory mode and a scope-gated mode that composes and runs tools.
- Open ↗Phoenix Security Skillscloud cost
Six Claude Code plugins (27 skills, MIT) for pre-merge security review, STRIDE threat modelling, opengrep/semgrep rule generation, tiered CTI search across 595 curated domains, and security-first PRD writing.
- Open ↗Security Guidance (Claude Code plugin)cloud costlicence
Claude Code plugin that hooks Edit/Write, end-of-turn, and git commit to flag ~25 dangerous code patterns and run LLM diff reviews for injection, XSS, SSRF, IDOR, and hardcoded secrets in generated code.
- Open ↗Self-Improving Skills (UniM0cha)cloud costhigh-risk
MIT Claude Code plugin (with Codex, Cowork and ChatGPT Work variants) porting Hermes Agent's learning loop: hooks detect complex work, a background session distills it into SKILL.md files, a curator archives stale ones.
- Open ↗
Claude Code plugin of shell hooks and slash commands that logs skill invocations and outcomes, audits skill health, applies backed-up amendments, and checks pre/post metrics to verify the fix.
- Open ↗Skill Conciergelicence
Skill-governance plugin for Claude Code, Codex, Command Code, Oh My Pi, ZCode, DeepSeek Harness and Cline: semantic skill retrieval, a per-turn use-mandate hook and an append-only invocation ledger, so the agent picks and uses the fitting skill.
- Open ↗
MIT-licensed skill pack and development methodology for coding agents (Claude Code, Codex, Cursor and others) covering brainstorming, planning, TDD, code review and subagent-driven implementation; not security-specific.
- Open ↗
Settings template, blocking hooks, path-scoped language rules, slash commands and an MCP template for Claude Code, with notes on sandboxing bypass-permissions runs, local models and context management.
- Open ↗
A Claude Code plugin marketplace of security-analysis, testing and development skills — smart-contract vulnerability scanners, C/C++ and Rust security code review, Semgrep and YARA rule authoring, constant-time and zeroization checks — loadable in Claude Code, Codex or a ChatGPT workspace.