# awesome-claude-security

A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.

- Tier: Indexed (plain plugin)
- Category: Security
- Page: https://www.flowy.sh/listings/jassics-awesome-claude-security
- Source: https://github.com/jassics/awesome-claude-security
- Price: free and open source

## Summary
awesome-claude-security is a Claude Code plugin with 111 hand-picked skills for security work, indexed on Flowy. Install it with the command on its page. It includes a2a-security-review, agent-harness-review, agent-security-review. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.

## Install (Claude Code)
```
npx -y skills add jassics/awesome-claude-security
```

## Skills
- a2a-security-review
- agent-harness-review
- agent-security-review
- autonomy-boundary-test
- mcp-security-review
- tool-permission-audit
- evals-ci-gate
- safety-case
- bias-fairness-assessment
- guardrail-review
- harm-modeling
- responsible-ai-assessment
- safety-evaluation
- safety-red-team
- api-authz-test
- owasp-api-top10
- purple-team-exercise
- board-deck
- cyber-risk-quantification
- security-strategy
- agent-safety-lint
- config-security-scan
- cloud-iam-review
- cloud-misconfig-scan
- cloud-posture-review
- secure-by-design-program
- tech-risk-assessment
- detection-coverage-review
- detection-rule-development
- threat-hunting
- pre-commit-gate
- forensic-triage
- incident-response
- ioc-development
- compliance-assessment
- policy-management
- risk-assessment
- host-hardening-review
- iac-security-review
- secrets-management-review
- k8s-cluster-review
- k8s-rbac-review
- k8s-workload-hardening
- ai-threat-model
- owasp-llm-top10
- prompt-injection-test
- ml-pipeline-security-review
- ml-supply-chain-review
- model-serving-security
- masvs-review
- mobile-pentest
- multimodal-injection-test
- multimodal-security-review
- network-pentest
- network-segmentation-review
- protocol-security-review
- exposure-discovery
- osint-footprinting
- people-osint
- recon
- rag-security-review
- retrieval-poisoning-test
- vector-store-isolation-test
- adversary-emulation
- ai-use-case-intake
- sast-review
- sca-review
- secure-review
- safe-function-lint
- secret-guard
- security-investigation
- prd-security-injection
- secure-architecture-maturity
- security-design-review
- architecture-diagram
- attack-tree
- infographic
- mindmap
- threat-model-dfd
- secure-pipeline
- export-to-drive
- publish-finding-to-jira
- publish-report-to-confluence
- asvs-reference
- attack-lookup
- framework-mapping
- owasp-reference
- secure-coding-kb
- cvss
- executive-summary
- finding
- pentest-report
- alert-triage
- artifact-provenance-verification
- dependency-supply-chain-review
- pipeline-integrity-review
- pipeline-timeout-lint
- cti-analysis
- ioc-enrichment
- threat-actor-profiling
- maestro
- pasta
- risk-rank
- stride
- remediation-tracking
- vulnerability-prioritization
- vulnerability-scan-triage
- access-control-test
- injection-test
- owasp-web-top10
- example-skill

## FAQ

### What is awesome-claude-security?
A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.

### How do I install awesome-claude-security?
Run these in Claude Code: npx -y skills add jassics/awesome-claude-security. Then prompt normally.

### Does awesome-claude-security auto-invoke its skills?
Not yet. It is indexed on Flowy as a plain plugin. Request auto-invocation on its page and Flowy will route its skills for you as you prompt.

### Is awesome-claude-security free?
Yes. Flowy is free and open source, with nothing gated. You can read every skill in full before you install.
