ClaudeSuperPower

Best of / Plugins

Best Security Plugins

20 Plugins in the security category, ranked by GitHub stars — updated automatically as our nightly sync refreshes stats.

  1. 1

    claude-security

    Deep vulnerability scanning of your own code, run entirely inside your Claude Code session at a chosen effort tier, with every finding challenged before it is reported and the verification tally computed in code. Turns surviving findings into targeted patches, each verified by a panel of agents, tha

    32.9K
  2. 2

    math-olympiad

    Solve competition math (IMO, Putnam, USAMO) with adversarial verification that catches what self-verification misses. Fresh-context verifiers attack proofs with specific failure patterns. Calibrated abstention over bluffing.

    32.9K
  3. 3

    jfrog

    Use the JFrog Platform from Claude Code: Artifactory repos and artifacts, security findings and exposures, Catalog package safety and downloads, workflows across the SDLC, and platform administration.

    32.9K
  4. 4

    project-artifact

    Generate and publish a living project status page — overview & success criteria, the workstream sequence, and next steps — as a shareable claude.ai artifact backed by a per-project config, so refreshes re-gather live state, redeploy the same URL, and report only the delta.

    32.9K
  5. 5

    ralph-loop

    Interactive self-referential AI loops for iterative development, implementing the Ralph Wiggum technique. Claude works on the same task repeatedly, seeing its previous work, until completion.

    32.8K
  6. 6

    code-simplifier

    Agent that simplifies and refines code for clarity, consistency, and maintainability while preserving functionality. Focuses on recently modified code.

    32.8K
  7. 7

    receipts

    A personal Claude Code impact report for justifying your usage to a manager or a self-review: what you shipped, which projects it went to, and each project's share of your usage. Reads your ~/.claude/projects transcripts and runs read-only git locally; only counts and project names are sent to write

    32.8K
  8. 8

    aws-agents-for-devsecops

    Investigate incidents, review code and execute UAT for release readiness, scan code for vulnerabilities, and run penetration tests with AWS DevOps Agent and AWS Security Agent.

    2.2K
  9. 9

    claude-forge

    Supercharge Claude Code with 11 AI agents, 36 commands & 15 skills — the claude-code plugin framework inspired by oh-my-zsh. 6-layer security hooks included. 5-min install.

    792
  10. 10

    miro

    Secure access to Miro boards. Enables AI to read board context, create diagrams, and generate code with enterprise-grade security.

    142
  11. 11

    postman

    Full API lifecycle management for Claude Code. Sync collections, generate client code, discover APIs, run tests, create mocks, publish docs, and audit security. Powered by the Postman MCP Server.

    34
  12. 12

    stackhawk-api

    Query the StackHawk platform API for security posture reporting, findings analysis, and app management. Guides agents through authentication, data retrieval, and result presentation.

    12
  13. 13

    aikido

    Aikido Security scanning for Claude Code — SAST, secrets, and IaC vulnerability detection powered by the Aikido MCP server.

    11
  14. 14

    semgrep

    Semgrep catches security vulnerabilities in real-time and guides Claude to write secure code from the start.

    10
  15. 15

    duende-skills

    Duende development skills and agents for Claude Code — covering OAuth/OIDC protocols, IdentityServer, token management, ASP.NET Core authentication/authorization, BFF patterns, and secure identity architecture

    9
  16. 16

    ai-plugins

    Set up endorctl and use Endor Labs to scan, prioritize, and fix security risks across your software supply chain

    9
  17. 17

    vanta-mcp-plugin

    The Vanta plugin connects Claude Code to Vanta's security and compliance platform through the Vanta MCP server. It combines Vanta's test-specific remediation intelligence with your local repository context to help you fix compliance failures faster.

    5
  18. 18

    sonatype-guide

    Sonatype Guide MCP server for software supply chain intelligence and dependency security. Analyze dependencies for vulnerabilities, get secure version recommendations, and check component quality metrics.

    3
  19. 19

    42crunch-api-security-testing

    Automate API security directly in Claude Code with 42Crunch - automatically audit OpenAPI specs, detect vulnerabilities aligned with OWASP API Security risks (including BOLA/BFLA), and apply AI-powered fixes. Designed for AI-assisted development workflows, it provides continuous guardrails through a

    1
  20. 20

    vanta

    The Vanta plugin connects Claude Code to Vanta's security and compliance platform through the Vanta MCP server. It combines Vanta's test-specific remediation intelligence with your local repository context to help you fix compliance failures faster.

    0

FAQ

How is this ranked?

By GitHub stars by default. Once a plugin has community reviews, its rating is shown alongside the star count on its detail page.

How often is this updated?

Star counts and READMEs refresh automatically every night via our GitHub sync.