MARKET RESEARCH

Security Codex plugins

Codex Plugin Stats: discover plugins, explore their skills and track catalog growth and observed changes.

Explore 5,334 plugins across 14 categories.

Security plugins 14

1–14 of 14

All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.

Discover Codex plugins by task and category
Plugin / developerCategoryFollow
MinimusMinimusMinimus hardened-image skills (Dockerfile & Kubernetes)

Publisher subtitle

Dockerfiles on hardened images

Show in context →
2 more matching sources

Publisher description

Minimus hardened-image skills (Dockerfile & Kubernetes)

Show in context →

Publisher full description

Minimus plugin that teaches AI coding tools to build Dockerfiles and Kubernetes manifests with hardened near-zero-CVE images

Show in context →
SecurityVersion 1.0.4
View details →
SmartphoneKeySmartphoneKeySmartphoneKey lets you manage residents on your smart locks through natural conversation. You can: ...

Publisher subtitle

Manage lock residents

Show in context →
1 more matching sources

Publisher description

SmartphoneKey lets you manage residents on your smart locks through natural conversation. You can: • View the current resident list for any of your locks • Add new residents by name and email — they'll receive intercom calls and notifications • Remove res…

Show in context →
SecurityVersion 1.0.0
View details →
Atbash SafetyAtbash AIAutomatically guards supported Codex tool calls with Atbash safety judgments and provides secure local setup guidance.

Publisher capabilities · listing

Safety policy enforcement Local credential setup

Show in context →
2 more matching sources

Publisher description

Automatically guards supported Codex tool calls with Atbash safety judgments and provides secure local setup guidance.

Show in context →

Publisher full description

…odex tool calls against your Atbash agent's safety policy before execution. The package includes a local PreToolUse hook, the bundled production Atbash SDK, and a setup and troubleshooting skill; it does not use an MCP server. Requires a supported local Codex environment, Node.js 22.13 or newer, an…

Show in context →
SecurityVersion 0.3.3
View details →
Authorised OSINT ToolkitRobert LaneNine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting.

Publisher capabilities · listing

…Review email and cloud exposure Analyse identity security architecture Design exposure monitoring processes Quantify and prioritise security risk Produce evidence-led security reports

Show in context →
SecurityVersion 1.1.0
View details →
KeybookailuntzFind configured website logins, macOS passwords, publishing and cloud service tokens, model API keys, or SSH key paths in a user-maintain...

Publisher capabilities · listing

首次配置时询问现有凭据 YAML 的绝对路径,仅在本地校验并登记路径 按名称查找网站用户名、邮箱、密码变体和 PIN,供已授权的网站任务使用 为 npm、Hugging Face、Docker、GitHub/GitLab、Cloudflare 等操作提供已配置的服务令牌 为 OpenRouter、ModelScope 等模型 API 调用提供已配置的密钥 区分 macOS 登录与钥匙串密码,并为 SSH 操作提供私钥文件路径 向可信本地程序注入选定凭据,不在对话中输出明文

Show in context →
2 more matching sources

Publisher description

…swords, publishing and cloud service tokens, model API keys, or SSH key paths in a user-maintained local YAML file; inject only the selected value into an authorized trusted process without printing secrets.

Show in context →

Publisher full description

…中的用户名、邮箱、指定密码变体和 PIN;需要本机授权时,可分别查找 system 中的 macOS 登录密码或登录钥匙串密码。发布 npm 包、上传 Hugging Face 模型或数据集、推送 Docker 镜像、操作 GitHub/GitLab、部署 Cloudflare 时,可按名称查找 services 中对应的令牌。调用 OpenRouter、ModelScope 等模型 API 时,查找 llm 中的密钥;连接已授权的 SSH 主机时,查找 ssh 中的私钥文件路径。实际可用条目取决于你自己的 YAML,Keybook 不会假定某个服务已配置。 Keybook 先搜索条目名称,再…

Show in context →
SecurityVersion 0.6.1
View details →
Skill Risk CheckOrbralScan agent skills and plugins locally for reviewable risk patterns before installation.

Publisher capabilities · listing

Scan local skills and plugins before install Find risky instructions, permissions, and downloads Show file-and-line evidence and remediation Export JSON, Markdown, and SARIF Never run or upload the target

Show in context →
2 more matching sources

Publisher description

Scan agent skills and plugins locally for reviewable risk patterns before installation.

Show in context →

Publisher full description

Use this before installing an agent skill or plugin. Skill Risk Check scans local files for hidden instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure, then returns ranked findings with file-and-line evidence and remed…

Show in context →
SecurityVersion 0.1.5
View details →
Aivana Security InvestigatorAivanaGuided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.

Publisher keywords · listing

defender-xdr soc security-investigation kql microsoft-graph sentinel

Show in context →
1 more matching sources

Publisher description

Guided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.

Show in context →
SecurityVersion 1.1.1
View details →
BastionBastion Technologies

Publisher description

…ity and compliance posture through natural conversation. Review framework compliance status across SOC 2, ISO 27001, HIPAA, and GDPR. Drill into failing tests, upload evidence, and submit controls for review. Ask your knowledge base security and compliance questions grounded in your own policies and…

Show in context →
SecurityVersion 1.0.0
View details →
DecionisBinaries

Publisher description

…Decionis evaluates the proposed action against organization policy and determines whether it may proceed, must be held, or requires additional authority. When human approval is required, Decionis can request verified approval through Presence and re-evaluate the action using the resulting signed ev…

Show in context →
SecurityVersion 1.0.1
View details →
GuardioGuardio

Publisher full description

…he check. It is not a guarantee that a site or an entire message is safe. The plugin does not scan local executable files or provide continuous browser protection merely by being connected.

Show in context →
SecurityVersion 0.2.2
View details →
NightVisionNightVision Security, Inc.

Publisher description

NightVision application security workflows for local development and CI/CD.

Show in context →
1 more matching sources

Publisher full description

…n API discovery, DAST scan configuration, CI/CD integration, and security-finding triage using the local NightVision CLI.

Show in context →
SecurityVersion 0.2.0
View details →
PrivacyHawkPrivacyHawk, Inc

Publisher description

…ough privacy laws now require them to stop when requested, opting out is difficult due to complex processes and the sheer number of companies. PrivacyHawk simplifies this process by handling it for you.

Show in context →
SecurityVersion 1.0.0
View details →
Prompt Injection SecurityThe Doers Firm

Publisher full description

Review prompts, AI application designs, retrieved documents, web content, and tool workflows for prompt-injection risks. Get evidence-linked attack-path analysis, calibrated severity and confidence, layered mitigations, and safe regression tests. Resu…

Show in context →
SecurityVersion 0.1.0
View details →
SkarnSkarn Software OÜ

Publisher description

Audit AI coding sessions and assistant configs with the locally installed skarn CLI: leaked credentials and risky hooks or MCP servers, reported on this machine with every secret masked.

Show in context →
1 more matching sources

Publisher full description

…entry recording a finding the user has explicitly confirmed as a false positive. The skill runs a local shell command, so it is offered in Codex. It does not carry the skarn binary, which is installed separately: brew install skarn-security/tap/skarn npm install -g @skarn-security/skarn Release bin…

Show in context →
SecurityVersion 0.27.0
View details →