Skip to content

awesome-claude-security — a Claude Code plugin marketplace

Teach Claude Code to do security work

A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. Add the marketplace once, then install only the plugins you need.

/plugin marketplace add jassics/awesome-claude-security
/plugin install llm-security@awesome-claude-security

A pentester knows which OWASP test bends a broken-access-control endpoint. An analyst knows which Sigma rule catches Kerberoasting. Claude Code doesn't — until you install the plugin that teaches it.

There's nothing to run. Each plugin adds skills — namespaced slash commands like /llm-security:owasp-llm-top10 — and agents to your Claude Code session. Everything installs à la carte, or grab a bundle (a role like pentester, a suite like genai-suite) and it auto-pulls its parts.

  • New here? Start with Getting started


    From "never heard of it" to installed-and-using in five steps, plus the bucket mental model.

    Getting started

  • Browse the plugin catalog


    All 45 plugins, grouped by bucket and searchable. Generated straight from the marketplace, so it's never stale.

    Plugin catalog

  • Follow an end-to-end recipe


    Web pentest, incident response, vuln triage, design review, securing a GenAI feature — each chains the right skills.

    Recipes

  • Understand the taxonomy


    How plugins are bucketed — core, domain, GenAI security, AI safety, role, executive — and why AI security ≠ AI safety.

    Taxonomy

  • Install & use


    Adding the marketplace, install scopes, bundles, MCP-dependent plugins, and updating or removing.

    Install & use

  • Build a plugin


    Scaffold from a template and follow the authoring conventions to contribute a new skill, agent, or domain.

    Authoring guide

Scope & ethics

Everything here targets authorized security testing, defensive security, detection, GRC, research, education, and CTF use. Role agents confirm scope and rules of engagement before acting. This is a community project — it is not affiliated with or endorsed by Anthropic.