| 42crunch-api-security-testing | 42Crunch integrates with Claude Code to automatically audit OpenAPI specifications, identify OWASP-aligned vulnerabilities like BOLA/BFLA, and apply AI-driven fixes within a continuous security validation cycle. | Security | 42Crunch |
| auth0 | Enterprise-grade authentication tool that adds login, single sign-on, multi-factor authentication, and access control to applications, with framework-specific implementation guidance. | Security | Auth0 |
| claude-security | Performs in-depth code vulnerability scanning within Claude Code sessions at adjustable effort levels, verifying findings via code-based tallying and generating agent-panel-checked patches for optional application. | Security | Anthropic |
| crowdsec | A Claude skill that assists with operating CrowdSec across bare-metal, Docker, Kubernetes, and OPNsense setups—covering bouncers, WAF/AppSec, hub content, and troubleshooting via cscli and LAPI/CAPI, excluding new rule authoring. | Security | CrowdSec |
| crowdstrike-falcon-foundry | CrowdStrike Falcon Foundry provides development skills for creating cybersecurity applications on the Falcon platform, covering UI building, data collections, functions, workflows, API integration, security design patterns, and debugging techniques. | Security | CrowdStrike |
| crowdstrike-falcon-fusion | A toolkit for building and running CrowdStrike Falcon Fusion automation workflows, covering discovery of live actions, schema-validated YAML creation, workflow import/release, execution tracking, and managing Falcon Next-Gen SIEM lookup files. | Security | CrowdStrike |
| duende-skills | A Claude Code extension providing development skills and agents for Duende, addressing OAuth/OIDC, IdentityServer, token handling, ASP.NET Core auth, BFF patterns, and secure identity system design. | Security | Duende Software |
| jfrog | This tool integrates the JFrog Platform with Claude Code, enabling access to Artifactory repositories, security findings, package safety data, SDLC workflows, and platform administration tasks. | Security | JFrog Ltd. |
| security-guidance | This tool checks Claude-generated code for security issues, combining pattern-based edit warnings, LLM diff review, and commit analysis to detect injection, XSS, SSRF, hardcoded secrets, and other vulnerabilities. | Security | Anthropic |
| semgrep | Semgrep detects security vulnerabilities as code is written, helping guide Claude toward producing secure code from the outset. | Security | — |
| sonarqube | Integrates SonarQube into AI coding agents, automatically checking code quality, security, and secrets across 40+ languages using hooks, CLI, MCP server, and slash commands. | Security | SonarSource |
| sonatype-guide | An MCP server from Sonatype Guide that analyzes software dependencies for security vulnerabilities, recommends safer versions, and evaluates component quality metrics for supply chain assessment. | Security | — |
| stackhawk-api | Interacts with the StackHawk platform API to retrieve security posture reports, vulnerability findings, and application management data, assisting agents with authentication, data retrieval, and presenting results. | Security | StackHawk |
| stackhawk-hawkscan | Integrates HawkScan DAST scanning into Claude Code by creating stackhawk.yml configuration files, executing scans through CLI or Docker, and converting security findings into prioritized remediation tasks for coding agents. | Security | StackHawk |
| vanta | Vanta plugin links Claude Code with Vanta's compliance platform via Vanta MCP server, using remediation guidance and local repo context to speed up fixing compliance test failures. | Security | Vanta |
| vanta-mcp-plugin | Vanta plugin links Claude Code to Vanta's compliance platform via Vanta MCP server, combining remediation guidance with local repo context to fix compliance failures. | Security | Vanta |
| workos | Provides WorkOS integration guidance covering AuthKit, single sign-on, Directory Sync, role-based access control, Vault, Audit Logs, migration processes, and API documentation references. | Security | WorkOS |
| zscaler | Administers Zscaler's cloud security suite—ZPA, ZIA, ZDX, ZCC, EASM, and Z-Insights—enabling policy configuration, connectivity troubleshooting, security audits, and incident investigation across these components. | Security | Zscaler |