Skip to content

Claude Code Security plugins and skills

Flowy lists 103 plugins in the Security category for Claude Code. auth, secrets, vulnerability scanning, threat modelling, compliance, audits Every listing shows what is inside before you install, who built it, and whether it is Auto-invoked, meaning a FLOW.md router fires the right skill as you prompt instead of leaving them dormant.

cybersecurity-skills
Plugin

cybersecurity-skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

200 skills
@mukul975@mukul975View Plugin
prowler
Plugin

prowler

Prowler is the world’s most widely used Open-Source Cloud Security Platform that automates security and compliance across any cloud environment.

39 skills
@prowler-cloud@prowler-cloudView Plugin
laravel-permission
Plugin

laravel-permission

Associate users with roles and permissions

1 skill
@spatie@spatieView Plugin
ida-pro-mcp
Plugin

ida-pro-mcp

Simple MCP Server to allow vibe reversing in IDA Pro. The binaries and prompt for the video are available in the mcp-reversing-dataset repository.

1 skill
@mrexodia@mrexodiaView Plugin
trailofbits-skills
Plugin

trailofbits-skills

A Claude Code plugin marketplace from Trail of Bits providing skills to enhance AI-assisted security analysis, testing, and development workflows. Codex can load this marketplace through its Claude marketplace compatibility.

83 skills
@trailofbits@trailofbitsView Plugin
agentic-bug-hunter
Plugin

agentic-bug-hunter

AI-powered bug bounty hunting toolkit that works with or without subscription.

15 skills
@shuvonsec@shuvonsecView Plugin
claude-bughunter
Plugin

claude-bughunter

A self-contained Claude skill bundle for bug hunting and external red-team work · 83 skills · 15 slash commands · 681 disclosed-report patterns (433 now individually cited & auditable) across 24 core vulnerability classes · enterprise identity +

83 skills
@elementalsouls@elementalsoulsView Plugin
claude-osint
Plugin

claude-osint

8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft.

10 skills
@elementalsouls@elementalsoulsView Plugin
shiro-attack2
Plugin

shiro-attack2

shiro反序列化漏洞综合利用(仅限授权测试使用)

1 skill
@summersec@summersecView Plugin
skill-scanner
Plugin

skill-scanner

A best-effort security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns.

24 skills
@cisco-ai-defense@cisco-ai-defenseView Plugin
hack-skills
Plugin

hack-skills

Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 102 deep topic skills across 14 security domains.

103 skills
@yaklang@yaklangView Plugin
pentest-ai-agents
Plugin

pentest-ai-agents

50 Claude Code subagents for penetration testing.

@0xsteph@0xstephView Plugin
kenryu42-cc-safety-net
Plugin

kenryu42-cc-safety-net

A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.

2 skills
@kenryu42@kenryu42View Plugin
kenryu42-claude-code-safety-net
Plugin

kenryu42-claude-code-s…

A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.

2 skills
@kenryu42@kenryu42View Plugin
sast-skills
Plugin

sast-skills

A collection of agent skills that turn your LLM coding assistant into a fully functional SAST scanner to find vulnerabilities in your codebase. Works natively with Claude Code, Codex, Opencode, Cursor and any other assistant that supports agent skills.

16 skills
@utkusen@utkusenView Plugin
vibesec-skill
Plugin

vibesec-skill

Stop vibe coding vulnerabilities into production. An AI skill that brings 5+ years of bug bounty hunting experience directly into your AI coding workflow - so LLM models write secure code from the start.

1 skill
@behisecc@behiseccView Plugin
agentshield
Plugin

agentshield

Security auditor for AI agent configurations Scans Claude Code setups for hardcoded secrets, permission misconfigs, hook injection, MCP server risks, and agent prompt injection vectors. Available as CLI, GitHub Action, and GitHub App integration.

1 skill
@affaan-m@affaan-mView Plugin
pashov-skills
Plugin

pashov-skills

AI-powered Solidity security skills — built by Pashov Audit Group. Supported AI Platforms:

2 skills
@pashov@pashovView Plugin
clawsec
Plugin

clawsec

A complete security skill suite for OpenClaw, Hermes, PicoClaw and NanoClaw agents (and variants). Protect your SOUL.md (etc') with drift detection, live security recommendations, automated audits, and skill integrity verification. All from one installable suite.

16 skills
@prompt-security@prompt-securityView Plugin
pentest-agents
Plugin

pentest-agents

Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

39 skills
@h-mmer@h-mmerView Plugin
coderunner
Plugin

coderunner

CodeRunner helps you sandbox your AI agents and its actions inside a sandbox. Key use case: You can run multiple Claude Code or AI agents in our sandbox without any fear of data loss and exfilteration.

2 skills
@instavm@instavmView Plugin
code-audit
Plugin

code-audit

Professional white-box code security audit skill with 55+ vulnerability types, dual-track audit model, and multi-agent deep analysis.

1 skill
@3stonebrother@3stonebrotherView Plugin
api-relay-audit
Plugin

api-relay-audit

Local security audit for AI API relays and LLM proxies. DSH Plugin

1 skill
@toby-bridges@toby-bridgesView Plugin
iothackbot
Plugin

iothackbot

Open-source IoT security testing toolkit with integrated Claude Code skills for automated vulnerability discovery.

13 skills
@brownfinesecurity@brownfinesecurityView Plugin
reverse-engineering-assistant
Auto-invokedPlugin

reverse-engineering-as…

A Ghidra extension that provides a Model Context Protocol (MCP) server for AI-assisted reverse engineering ReVa (Reverse Engineering Assistant) is a Ghidra MCP server that enables AI language models to interact with Ghidra's powerful reverse engineering

6 skills
@cyberkaida@cyberkaidaView Plugin
verified-agent-identity
Plugin

verified-agent-identit…

A decentralized identity management toolkit for AI agents using iden3 protocol on Billions Network.

1 skill
@billionsnetwork@billionsnetworkView Plugin
keycloak-authservices
Plugin

keycloak-authservices

🔐 Easy Authentication and Authorization with Keycloak in .NET.

3 skills
@nikiforovall@nikiforovallView Plugin
semia
Plugin

semia

Security audit for AI agent skills. Know what a skill can do before you trust it. Agent skills are markdown files with embedded shell commands, network calls, and tool invocations. They run with **your credentials, on your machine, with your data**.

1 skill
@berabuddies@berabuddiesView Plugin
cti-expert
Plugin

cti-expert

CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code / Codex. 120+ commands, 57 techniques, 79 typed MCP tools, deterministic case pipeline + ICD-203 reports. No API keys required for core.

1 skill
@7onez@7onezView Plugin
bug-hunter
Plugin

bug-hunter

Adversarial AI bug hunter with auto-fix skill for Claude Code, Cursor, Codex CLI, GitHub Copilot CLI, Kiro CLI, Opencode, Pi Coding Agent, and more. Multi-agent pipeline finds security vulnerabilities, logic errors, and runtime bugs — then fixes them autonomously on a safe branch.

10 skills
@codexstar69@codexstar69View Plugin
android-reverse-engineering-skill
Plugin

android-reverse-engine…

Android 逆向分析全家桶 — 从 APK 反编译到 Frida 动态插桩、从 HTTP 接口提取到 JNI/SO 原生层逆向,覆盖静态分析→动态分析→流量解密→签名追踪的完整链路。支持 Claude Code / Codex 双平台,兼容 macOS、Linux、Windows(PowerShell),一套技能打通 Android 安全研究与授权渗透测试的绝大部分需求。

1 skill
@credittone@credittoneView Plugin
claude-code-cybersecurity-skill
Plugin

claude-code-cybersecur…

22 production-quality Claude Code Skills for cybersecurity professionals — covering offensive security, defensive operations, reverse engineering, threat hunting, threat intelligence, purple team / adversary emulation, CSOC automation, AI/LLM security,

22 skills
@masriyan@masriyanView Plugin
project-codeguard-codeguard-security
Plugin

project-codeguard-code…

Project CodeGuard is an AI model-agnostic security framework and ruleset that embeds secure-by-default practices into AI coding workflows (generation and review). It ships core security rules, translators for popular coding agents, and validators to test rule compliance.

1 skill
@project-codeguard@project-codeguardView Plugin
sandvault
Plugin

sandvault

SandVault (sv) manages a limited user account to sandbox shell commands and AI agents, providing a lightweight alternative to application isolation using virtual machines.

1 skill
@webcoyote@webcoyoteView Plugin
ghostsecurity-skills
Auto-invokedPlugin

ghostsecurity-skills

Plugin marketplace repository for Ghost Security's AI-native application security skills for Claude Code.

8 skills
@ghostsecurity@ghostsecurityView Plugin
trust-center
Plugin

trust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

101 skills
@grcengclub@grcengclubView Plugin
dogwood
Plugin

dogwood

Dogwood is a governance language designed for AI agents and their tools. It supports Cedar policies and adds temporal conditions (since, formerly, once, aggregations) to look back over an agent's recent events.

4 skills
@dogwood-policy@dogwood-policyView Plugin
windiff
Plugin

windiff

Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI and/or LLMs.

1 skill
@ergrelet@ergreletView Plugin
eyadkelleh-awesome-skills-security
Plugin

eyadkelleh-awesome-ski…

A curated collection of security testing resources packaged as agent skills, available on skills.sh Repository: Eyadkelleh/awesome-skills-security · skills.sh: Eyadkelleh/awesome-skills-security

7 skills
@eyadkelleh@eyadkellehView Plugin
eyadkelleh-awesome-skills-security-2
Plugin

eyadkelleh-awesome-ski…

A curated collection of security testing resources packaged as agent skills, available on skills.sh Repository: Eyadkelleh/awesome-skills-security · skills.sh: Eyadkelleh/awesome-skills-security

7 skills
@eyadkelleh@eyadkellehView Plugin
offensive-claude
Plugin

offensive-claude

A spec-driven offensive security framework for Claude Code — structured engagement workflows based on the Cyber Kill Chain, 32 kill-chain skills (multi-file progressive-disclosure) plus a discipline layer (a SessionStart dispatcher + 6 process/discipline

38 skills
@hypnguyen1209@hypnguyen1209View Plugin
prismor
Plugin

prismor

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt injection, supply chain etc in a local dashboard. Agent agnostic (Claude, codex, langchain etc.)

1 skill
@prismorsec@prismorsecView Plugin
claude-code-owasp
Plugin

claude-code-owasp

A Claude Code skill providing the latest OWASP security best practices (2025-2026) for developers building secure applications.

1 skill
@agamm@agammView Plugin
threat-modeling
Plugin

threat-modeling

AI-native automated software risk analysis skill. LLM-driven, Code-First approach for comprehensive security risk assessment, threat modeling, security analysis, security audit, and penetration testing.

1 skill
@fr33d3m0n@fr33d3m0nView Plugin
cosai-oasis-codeguard-security
Plugin

cosai-oasis-codeguard-…

This repository is for the work of the Coalition for Secure AI (CoSAI). CoSAI is an OASIS Open Project and an open ecosystem of AI and security experts from industry-leading organizations.

3 skills
@cosai-oasis@cosai-oasisView Plugin
ksafe
Plugin

ksafe

Encrypted by default. Plain (unencrypted) when needed. Persist variables, Compose State, StateFlow, and serializable objects across Android, iOS, macOS, Desktop, and Web Easy to use by design — plus key rotation, cross-platform biometrics, and an encryption

1 skill
@ioannisa@ioannisaView Plugin
sage
Plugin

sage

Safety for Agents — Agent Detection & Response for AI coding assistants Sage is a lightweight security layer that protects AI agents from executing dangerous actions.

1 skill
@gendigitalinc@gendigitalincView Plugin
dashclaw
Plugin

dashclaw

Remote approvals, policy checks, and execution evidence for unattended AI agents.

20 skills
@ucsandman@ucsandmanView Plugin

FAQ

What are the best Claude Code Security plugins?
Flowy lists 103 plugins for Security, ranked by fit and signal rather than raw install count. Open any listing to read every skill in full before you install it.
Do these Security skills run automatically?
The Auto-invoked ones do. They ship a FLOW.md router and a hook, so Claude Code loads the matching skill as you prompt. Indexed listings install normally and you invoke them yourself.
How does Flowy decide a plugin is a Security plugin?
The tag is derived from the plugin's own content, its skill names, descriptions, README and file types, not from a tag someone typed. A plugin appears here only when its real content matches.
Are these Security plugins free?
Yes. Flowy is free and open source with nothing gated. You can read every skill before installing, and each listing links to its upstream repository and its creator.

Browse every plugin