MARKET RESEARCH

Security Codex plugins

Codex Plugin Stats: discover plugins, explore their skills and track catalog growth and observed changes.

Explore 5,331 plugins across 14 categories.

Security plugins 34

1–34 of 34

All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.

Discover Codex plugins by task and category
Plugin / developerCategoryFollow
Aivana Security InvestigatorAivanaGuided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.

Plugin name

Aivana Security Investigator

Show in context →
3 more matching sources

Package name

aivana-xdr-investigator

Show in context →

Publisher capabilities · listing

Direct OAuth/OBO Defender XDR KQL API Read-only cross-domain investigations Evidence packages and analyst review

Show in context →

Publisher

Aivana

Show in context →
SecurityVersion 1.1.1
View details →
Awesome Maintainer DefenseDUC THANG LUURead-only repository governance and GitHub Actions risk audits with reviewable patches.

Plugin name

Awesome Maintainer Defense

Show in context →
2 more matching sources

Package name

awesome-maintainer-defense

Show in context →

Publisher keywords · listing

github-actions repository-security governance maintainers audit

Show in context →
SecurityVersion 1.1.1
View details →
CertScore.ai Privacy ScannerCertScore.ai, LLCScan public websites for fast preliminary cookie/tracker evidence, then continue to persisted privacy findings, typed GPC response compar...

Plugin name

CertScore.ai Privacy Scanner

Show in context →
1 more matching sources

Publisher

CertScore.ai, LLC

Show in context →
SecurityVersion 2.0.0
View details →
MalwarebytesMalwarebytes Inc.Protect yourself from phishing and scams by verifying links, domains, emails, and phone numbers before you click, call, or reply. Get ins...

Publisher subtitle

Verify links, domains, phones.

Show in context →
1 more matching sources

Publisher description

Protect yourself from phishing and scams by verifying links, domains, emails, and phone numbers before you click, call, or reply. Get instant reputation insights, ownership details, and risk levels for unknown numbers, suspicious emails, shortened URLs, and unfami…

Show in context →
SecurityVersion 1.0.0
View details →
Orca SecurityOrca SecurityExtend Orca Security's reasoning into ChatGPT. That means every asset, alert, identity, and dependency is already stitched together in Or...

Publisher subtitle

Fix code, cloud & AI risks.

Show in context →
1 more matching sources

Publisher description

…mpact from the first response. For teams that want the reasoning without writing the prompts, Orca maintains the AI Skills Hub, an open-source GitHub repo of agent skills. Type "triage alert orca-9012345" and the orca-alert-triage skill handles retrieval, analysis, and formatting. Teams can fork it,…

Show in context →
SecurityVersion 1.0.0
View details →
PalisadeSamuel ChenardPalisade helps email teams investigate SPF, DKIM, DMARC, and MTA-STS issues. Review monitored domains, DMARC pass rates and sending sourc...

Publisher subtitle

Monitor email deliverability

Show in context →
1 more matching sources

Publisher description

Palisade helps email teams investigate SPF, DKIM, DMARC, and MTA-STS issues. Review monitored domains, DMARC pass rates and sending sources, inspect DNS and SPF records, and retrieve remediation tasks with supporting…

Show in context →
SecurityVersion 1.0.0
View details →
Radar LiteRed SiftAnalyze any domain’s email authentication, DNS, and web security configuration. Radar Lite scans your domain, visualizes security scores ...

Publisher subtitle

Domain security with Red Sift

Show in context →
1 more matching sources

Publisher description

Analyze any domain’s email authentication, DNS, and web security configuration. Radar Lite scans your domain, visualizes security scores on a radar chart, and generates a summary with prioritized findings and remedi…

Show in context →
SecurityVersion 2.0.0
View details →
SafeguardSafeguardSafeguard helps users inspect software supply chain risk from ChatGPT, including vulnerabilities, SBOMs, findings, projects, components, ...

Publisher subtitle

Secure software supply chain

Show in context →
1 more matching sources

Publisher description

Safeguard helps users inspect software supply chain risk from ChatGPT, including vulnerabilities, SBOMs, findings, projects, components, policies, guardrails, compliance reports, remediation plans, SCM integrations, notifications, and organization…

Show in context →
SecurityVersion 1.0.0
View details →
SkarnSkarn Software OÜAudit AI coding sessions and assistant configs with the locally installed skarn CLI: leaked credentials and risky hooks or MCP servers, r...

Publisher subtitle

AI session security scanner

Show in context →
4 more matching sources

Publisher capabilities · listing

Scan AI coding sessions for leaked credentials Vet assistant hooks, MCP servers and permission grants

Show in context →

Publisher keywords · listing

security secrets credential-leak ai-coding-sessions audit codex

Show in context →

Publisher description

Audit AI coding sessions and assistant configs with the locally installed skarn CLI: leaked credentials and risky hooks or MCP servers, reported on this machine with every secret masked.

Show in context →

Publisher full description

Skarn is a command-line security scanner for AI coding sessions. The audit skill, skarn-audit, teaches the model to run the skarn CLI on this machine and act on what it reports. The skill runs two passes. skarn assess reads the session transcrip…

Show in context →
SecurityVersion 0.27.0
View details →
Authorised OSINT ToolkitRobert LaneNine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting.

Publisher capabilities · listing

Plan lawful defensive OSINT reviews Assess organisational attack surfaces Review email and cloud exposure Analyse identity security architecture Design exposure monitoring processes Quantify and prioritise security risk Produce evidence-led security reports

Show in context →
1 more matching sources

Publisher full description

A nine-skill toolkit for authorised organisational OSINT, attack-surface analysis, email and cloud exposure review, identity-security assurance, monitoring design, risk quantification and evidence-led reporting. The replacement planning, identity and exposure-analysis skills exclude c…

Show in context →
SecurityVersion 1.1.0
View details →
GuardioGuardioCheck suspicious links, review known data leaks, and understand your Guardio protection.

Publisher capabilities · listing

Check suspicious links Check links in messages Look up known email and phone breaches Review account protection and scan activity Review security recommendations Set up browser protection Send requested product feedback

Show in context →
1 more matching sources

Publisher full description

…nt data leaks, linked-service counts, and security recommendations. You can also check whether an email address or phone number appears in known data breaches. Results describe known exposure; they do not reveal leaked passwords. When you ask, Guardio can guide setup of its protection in a supported…

Show in context →
SecurityVersion 0.2.2
View details →
Atbash SafetyAtbash AIAutomatically guards supported Codex tool calls with Atbash safety judgments and provides secure local setup guidance.

Publisher keywords · listing

atbash codex safety policy guardrails

Show in context →
2 more matching sources

Publisher

Atbash AI

Show in context →

Publisher full description

Atbash Safety checks supported Codex tool calls against your Atbash agent's safety policy before execution. The package includes a local PreToolUse hook, the bundled production Atbash SDK, and a setup and troubleshooting skill; it does not use an MCP…

Show in context →
SecurityVersion 0.3.3
View details →
Skill Risk CheckOrbralScan agent skills and plugins locally for reviewable risk patterns before installation.

Publisher keywords · listing

plugin-security agent-skills pre-install-scan prompt-injection supply-chain sarif codex claude-code

Show in context →
SecurityVersion 0.1.5
View details →
Ansvar GatewayAnsvar AIAnsvar Systems AB is a Swedish cybersecurity company that gives AI agents verifiable access to law, regulation and security standards. C...

Publisher

Ansvar AI

Show in context →
1 more matching sources

Publisher description

Ansvar Systems AB is a Swedish cybersecurity company that gives AI agents verifiable access to law, regulation and security standards. Customers connect the AI assistant they already use (Claude, Microsoft Copilot, ChatGPT or any MCP-compatible client) to the Ansv…

Show in context →
SecurityVersion 1.0.0
View details →
Codex SecurityOpenAICodex Security workflows for security scans, analysis, and investigation.

Publisher

OpenAI

Show in context →
SecurityVersion 0.1.31
View details →
Codex Security CloudOpenAICloud security scans, findings, and continuous repository monitoring.

Publisher

OpenAI

Show in context →
SecurityVersion 0.1.1
View details →
KeybookailuntzFind configured website logins, macOS passwords, publishing and cloud service tokens, model API keys, or SSH key paths in a user-maintain...

Publisher

ailuntz

Show in context →
2 more matching sources

Publisher description

…, macOS passwords, publishing and cloud service tokens, model API keys, or SSH key paths in a user-maintained local YAML file; inject only the selected value into an authorized trusted process without printing secrets.

Show in context →

Publisher full description

Keybook 是供本机已授权任务使用的凭据目录。首次使用时,告诉它你现有凭据 YAML 文件的绝对路径;它会在本地检查格式,只保存路径。以后无需反复粘贴密码或 API Key,直接让 AI 继续原任务即可。 需要登录网站时,可查找 web 分类中的用户名、邮箱、指定密码变体和 PIN;需要本机授权时,可分别查找 system 中的 macOS 登录密码或登录钥匙串密码。发布 npm 包、上传 Hugging Face 模型或数据集、推送 Docker 镜像、操作 GitHub/GitLab、部署 Cloudflare 时,可按名称查找 services 中对应的令牌。调用 Op…

Show in context →
SecurityVersion 0.6.1
View details →
ProofXCyberSec AI LtdProofX protects your digital content with cryptographic signatures. What you can do: - Protect your articles, poems, scripts, code, and ...

Publisher

CyberSec AI Ltd

Show in context →
SecurityVersion 1.0.0
View details →
Above SecurityAbove Security

Publisher description

Above brings your identity-security data into ChatGPT. Ask in plain language to list open incidents and high-risk identities; inspect incident timelines, evidence, and insights; look up devices, monitored applications, and audit logs; and run investigative searche…

Show in context →
SecurityVersion 1.0.0
View details →
AccessOwlOmni Owl GmbH

Publisher description

AccessOwl lets organizations manage access to SaaS apps. Users can browse available apps and request access as needed.

Show in context →
SecurityVersion 1.0.0
View details →
AJAXX Data ScrubberFORTRESS APPS LLC

Publisher description

…ChatGPT provides read-only information about digital privacy risks and data broker exposure. It explains how personal data appears online, how removal services work, and answers common questions about scans, monitoring, and protection options. This ChatGPT app does not run scans, show personal scan…

Show in context →
SecurityVersion 1.0.0
View details →
BastionBastion Technologies

Publisher description

…versation. Review framework compliance status across SOC 2, ISO 27001, HIPAA, and GDPR. Drill into failing tests, upload evidence, and submit controls for review. Ask your knowledge base security and compliance questions grounded in your own policies and documentation. Monitor code security findings…

Show in context →
SecurityVersion 1.0.0
View details →
CookieYesCookieYes Limited

Publisher description

…g cookie banners. The connector covers consent management, cookie scans, and compliance checks in plain conversation.

Show in context →
SecurityVersion 1.0.0
View details →
DecionisBinaries

Publisher description

Decionis is an execution-authority layer for AI agents. Before an agent takes a consequential action, Decionis evaluates the proposed action against organization policy and determines whether it may proceed, must be held, or requires additional…

Show in context →
SecurityVersion 1.0.1
View details →
Endor Labs Agent KitEndor Labs

Publisher full description

Packaged AppSec workflows for SCA remediation, AI SAST triage, CI/CD posture, malware response, findings review, Endor Labs setup, and more.

Show in context →
SecurityVersion 2.2.2
View details →
IsThisSpamUltron Developments Pty. Ltd.

Publisher description

IsThisSpam checks suspicious phone numbers, messages, links, websites, and email addresses using structured scam signals and cautious safety guidance. Results distinguish likely scams from unverified findings; no result is a guarantee of safety.

Show in context →
SecurityVersion 0.1.0
View details →
MCP PrecheckPolicyLayer

Publisher description

Check MCP servers against the PolicyLayer registry before connecting to them.

Show in context →
1 more matching sources

Publisher full description

Check configured or proposed MCP servers against PolicyLayer registry records for identity, authentication posture, tool capabilities, risk grade and recent changes.

Show in context →
SecurityVersion 1.0.0
View details →
MinimusMinimus

Publisher full description

Minimus plugin that teaches AI coding tools to build Dockerfiles and Kubernetes manifests with hardened near-zero-CVE images

Show in context →
SecurityVersion 1.0.4
View details →
PrivacyHawkPrivacyHawk, Inc

Publisher description

…data by easily sending "Do Not Sell" requests to thousands of businesses. - Unsubscribe from spam emails and clean up your inbox. Now supporting Gmail, Yahoo, and Microsoft accounts—including Hotmail, MSN, Live, and Outlook. - Use advanced data broker tools to opt out of data brokers and protect you…

Show in context →
SecurityVersion 1.0.0
View details →
Prompt Injection SecurityThe Doers Firm

Publisher description

Assess prompt injection exposure in prompts, AI workflows, retrieved content, and tool designs with evidence-based findings and mitigations.

Show in context →
1 more matching sources

Publisher full description

Review prompts, AI application designs, retrieved documents, web content, and tool workflows for prompt-injection risks. Get evidence-linked attack-path analysis, calibrated severity and confidence, layered mitigatio…

Show in context →
SecurityVersion 0.1.0
View details →
RelayShield Scam ChecksRelayShield

Publisher description

RelayShield Free Scam Checks screens links, crypto wallets, suspicious emails, and email addresses against RelayShield's threat-intelligence corpus — 115 monitored Telegram marketplaces, 494K+ indicators, 7.8M+ citations — before you click, pay, or reply. Four read-only to…

Show in context →
SecurityVersion 1.0.0
View details →
SmartphoneKeySmartphoneKey

Publisher description

…. You can: • View the current resident list for any of your locks • Add new residents by name and email — they'll receive intercom calls and notifications • Remove residents by name or email All actions are secured through your SmartphoneKey account, so you can only manage locks you own. More featur…

Show in context →
SecurityVersion 1.0.0
View details →
ToolCheck by M8venM8ven Inc.

Publisher description

…servation in a sandbox, CVE scanning, and a semantic check comparing the tool's declared behavior against what its code actually does — catching the gap between "read-only market data" and code that can move your funds.

Show in context →
SecurityVersion 1.0.0
View details →
Vibe Code Security ReviewerThe Doers Firm

Publisher description

Advanced security review for AI-generated applications, Supabase RLS, APIs, secrets, databases, and production deployments.

Show in context →
1 more matching sources

Publisher full description

Vibe Code Security Reviewer performs advanced evidence-based security reviews of AI-generated and rapidly built applications. It checks Supabase RLS, authentication, authorization, tenant isolation, API leaks and misuse, inputs, secrets, uploads, dependencies, data exposure, AI to…

Show in context →
SecurityVersion 0.1.0
View details →