Plugin marketplace repository for Ghost Security's AI-native application security skills for Claude Code.
Auto-invoked ships a router so the right skill fires automatically as you prompt. No remembering which skill to call.
Normal is the plain upstream plugin, installed as-is. You invoke its skills yourself.
The plugin> /plugin marketplace add ghostsecurity/skills> /plugin install ghost@ghost-securityAuto-invocation> /plugin marketplace add flowy-sh/flowy-core> /plugin install flowy-core> /plugin install flowy-ghost
What's inside
Plugin marketplace repository for Ghost Security's AI-native application security skills for Claude Code.
With Claude Code:
claude plugin marketplace add ghostsecurity/skills
claude plugin install ghost@ghost-security
claude
Alternatively, install the skills plugin within Claude Code:
/plugin marketplace add ghostsecurity/skills
/plugin install ghost@ghost-security
Currently, you will need to restart Claude Code for the plugin to load.
Full documentation, tutorials, and video guides at ghostsecurity.ai.
| Skill | Description |
|---|---|
ghost-repo-context | Build shared repository context (business criticality, sensitive data, component map) |
ghost-scan-deps | Exploitability analysis of dependency vulnerabilities (SCA) |
ghost-scan-secrets | Context assessment of detected secrets and credentials |
ghost-scan-code | AI-powered detection of code security issues (SAST) |
ghost-report | Combined security report across all scan results |
ghost-validate | Dynamic validation of findings against a live application (DAST) |
ghost-proxy | HTTP proxy for the ghost-validate skill |
ghost-exo | Build, improve, and debug workflows on the exo agent orchestration platform |
Open an Issue per the Contributing guidelines and Code of Conduct
This repository is licensed under the Apache License 2.0. See LICENSE for details.
FAQ
ghostsecurity-skills is a Claude Code plugin of 8 hand-picked skills with a FLOW.md router. Install it once and the right skill fires as you prompt, with no slash command to remember. It is built for security work. It includes exo, proxy, repo-context. Free and open source.
Is this plugin yours?
Claim it with GitHubSubmit a pluginPromote it