Language:JapaneseEnglish

Topic: Security, Auth & Compliance

32 items in the "Security, Auth & Compliance" topic.

Plugins (Claude Code)

NameDescriptionCategoryAuthor
42crunch-api-security-testing42Crunch integrates with Claude Code to automatically audit OpenAPI specifications, identify OWASP-aligned vulnerabilities like BOLA/BFLA, and apply AI-driven fixes within a continuous security validation cycle.Security42Crunch
agentforce-adlcA workflow tool supporting the full lifecycle of Agentforce agents, covering authoring, discovery, scaffolding, deployment, testing, and optimization of .agent files.Development
ai-pluginsEndor Labs is a security tool that installs via endorctl to analyze software supply chains, identifying, ranking, and remediating vulnerabilities and related risks.
aikidoAikido Security integrates with Claude Code via its MCP server to perform static application security testing, secrets detection, and infrastructure-as-code vulnerability scanning.
auth0Enterprise-grade authentication tool that adds login, single sign-on, multi-factor authentication, and access control to applications, with framework-specific implementation guidance.SecurityAuth0
aws-agents-for-devsecopsAWS DevOps Agent and AWS Security Agent assist software teams by investigating incidents, reviewing code, conducting user acceptance testing before releases, scanning for vulnerabilities, and performing penetration tests.DevelopmentAmazon Web Services
aws-startup-advisorThis tool offers tailored AWS guidance for startups on architecture, cost, security, and migration, from initial setup to production infrastructure, including credits, exclusive offers, and multi-account support.DevelopmentAmazon Web Services
claude-securityPerforms in-depth code vulnerability scanning within Claude Code sessions at adjustable effort levels, verifying findings via code-based tallying and generating agent-panel-checked patches for optional application.SecurityAnthropic
coderabbitCodeRabbit is an AI-powered code review tool combining specialized architecture with 40+ static analyzers to detect bugs, vulnerabilities, and logic errors, using AST-based context analysis and project guidelines, offering actionable fixes at no cost.Productivity
crowdsecA Claude skill that assists with operating CrowdSec across bare-metal, Docker, Kubernetes, and OPNsense setups—covering bouncers, WAF/AppSec, hub content, and troubleshooting via cscli and LAPI/CAPI, excluding new rule authoring.SecurityCrowdSec
crowdstrike-falcon-foundryCrowdStrike Falcon Foundry provides development skills for creating cybersecurity applications on the Falcon platform, covering UI building, data collections, functions, workflows, API integration, security design patterns, and debugging techniques.SecurityCrowdStrike
crowdstrike-falcon-fusionA toolkit for building and running CrowdStrike Falcon Fusion automation workflows, covering discovery of live actions, schema-validated YAML creation, workflow import/release, execution tracking, and managing Falcon Next-Gen SIEM lookup files.SecurityCrowdStrike
discordDiscord messaging bridge featuring built-in access control, allowing management of pairing, allowlists, and policies through /discord:access.Productivity
duende-skillsA Claude Code extension providing development skills and agents for Duende, addressing OAuth/OIDC, IdentityServer, token handling, ASP.NET Core auth, BFF patterns, and secure identity system design.SecurityDuende Software
firebaseAn MCP-based plugin linking Claude Code to Google Firebase, enabling direct management of backend resources during coding sessions. Specific commands, auth scopes, and configuration details are undocumented.Database
google-cloud-storageEnables a coding agent to perform Google Cloud Storage tasks via natural-language commands, including bucket/object management, FUSE mounting, error diagnosis, security audits (SAIF), and Terraform/client code generation; requires a GCP project and gcloud ADC authentication.DeploymentGoogle LLC
jfrogThis tool integrates the JFrog Platform with Claude Code, enabling access to Artifactory repositories, security findings, package safety data, SDLC workflows, and platform administration tasks.SecurityJFrog Ltd.
netsuite-suitecloudA guidance tool for building NetSuite SuiteCloud solutions, covering SuiteScript record handling and upgrades, SDF object and role/permission management, UIF single-page app development, OWASP-based secure coding, documentation practices, and SAFE Guide standards.DevelopmentOracle NetSuite
nightvisionProvides skills for configuring scan targets/authentication/scope, triaging scan results, extracting OpenAPI specs from source code, and integrating scanning into CI/CD pipelines; portable across agent tools like Claude Code, Codex, and Cursor.
qodoQodo Skills offers a library of reusable AI agent capabilities enhancing Claude for software development, enabling code quality checks, testing, security scanning, and compliance validation throughout the SDLC.DevelopmentQodo
security-guidanceThis tool checks Claude-generated code for security issues, combining pattern-based edit warnings, LLM diff review, and commit analysis to detect injection, XSS, SSRF, hardcoded secrets, and other vulnerabilities.SecurityAnthropic
semgrepSemgrep detects security vulnerabilities as code is written, helping guide Claude toward producing secure code from the outset.Security
sonarqubeIntegrates SonarQube into AI coding agents, automatically checking code quality, security, and secrets across 40+ languages using hooks, CLI, MCP server, and slash commands.SecuritySonarSource
sonatype-guideAn MCP server from Sonatype Guide that analyzes software dependencies for security vulnerabilities, recommends safer versions, and evaluates component quality metrics for supply chain assessment.Security
spotify-ads-apiEnables managing Spotify ad campaigns via natural language conversation, covering campaign, ad set, and ad creation, reporting, and OAuth authentication handling.Productivity
stackhawk-apiInteracts with the StackHawk platform API to retrieve security posture reports, vulnerability findings, and application management data, assisting agents with authentication, data retrieval, and presenting results.SecurityStackHawk
stackhawk-hawkscanIntegrates HawkScan DAST scanning into Claude Code by creating stackhawk.yml configuration files, executing scans through CLI or Docker, and converting security findings into prioritized remediation tasks for coding agents.SecurityStackHawk
supabaseEnables database management, authentication, storage handling, and real-time subscriptions for Supabase projects, allowing SQL query execution and direct backend interaction via MCP integration.Database
vantaVanta plugin links Claude Code with Vanta's compliance platform via Vanta MCP server, using remediation guidance and local repo context to speed up fixing compliance test failures.SecurityVanta
vanta-mcp-pluginVanta plugin links Claude Code to Vanta's compliance platform via Vanta MCP server, combining remediation guidance with local repo context to fix compliance failures.SecurityVanta
workosProvides WorkOS integration guidance covering AuthKit, single sign-on, Directory Sync, role-based access control, Vault, Audit Logs, migration processes, and API documentation references.SecurityWorkOS
zscalerAdministers Zscaler's cloud security suite—ZPA, ZIA, ZDX, ZCC, EASM, and Z-Insights—enabling policy configuration, connectivity troubleshooting, security audits, and incident investigation across these components.SecurityZscaler

Claude Code Topics