Security Codex plugins
Codex Plugin Stats: discover plugins, explore their skills and track catalog growth and observed changes.
Explore 5,319 plugins across 14 categories.
Security plugins 13
1–13 of 13All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.
| Plugin / developer | Category | Follow |
|---|---|---|
Authorised OSINT ToolkitRobert LaneNine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting. Plugin name Authorised OSINT Toolkit Show in context →3 more matching sourcesPublisher description Nine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting. Show in context →Publisher full description A nine-skill toolkit for authorised organisational OSINT, attack-surface analysis, email and cloud exposure review, identity-security assurance, monitoring design, risk quantification and evidence-led reporting. The replaceme… Show in context → |
SecurityVersion 1.1.0 | View details → |
Authorized Security ReviewIssam ChaabanEvidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools. Plugin name Authorized Security Review Show in context →4 more matching sourcesPublisher description Evidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools. Show in context →Publisher full description An independent skills-only workflow for authorized security research. Uses tools already connected to the active chat. Supports source review, scoped web/API investigation, validation, and HackerOne report drafting. Does not bundle testing… Show in context → |
SecurityVersion 1.0.1 | View details → |
DecionisBinariesDecionis is an execution-authority layer for AI agents. Before an agent takes a consequential action, Decionis evaluates the proposed act... Publisher subtitle Execution Authority Show in context →1 more matching sourcesPublisher description Decionis is an execution-authority layer for AI agents. Before an agent takes a consequential action, Decionis evaluates the proposed action against organization policy and determines whether it may proceed, must be held, or… Show in context → |
SecurityVersion 1.0.1 | View details → |
Aivana Security InvestigatorAivanaGuided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API. Publisher capabilities · listing Direct OAuth/OBO Defender XDR KQL API Read-only cross-domain investigations Evidence packages and analyst review Show in context →2 more matching sourcesPublisher description Guided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API. Show in context →Publisher full description …equests into transparent KQL and executes bounded, read-only Defender XDR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response execution. Show in context → |
SecurityVersion 1.1.1 | View details → |
Above SecurityAbove Security Publisher description …e Security account and is scoped to your role and company; read and write are governed by explicit OAuth consent. Show in context → |
SecurityVersion 1.0.0 | View details → |
BastionBastion Technologies Publisher description …ntation. Monitor code security findings and GitHub configuration status. All data is scoped to your authenticated account - you only ever see your own tenant. Show in context → |
SecurityVersion 1.0.0 | View details → |
BreezeBreeze Security Publisher description Breeze helps authenticated users explore their organization's security posture, connected integrations, scan status, tenants, and entity risk data through ChatGPT and Codex. Show in context → |
SecurityVersion 1.0.0 | View details → |
Cloudflare SecurityThe Doers Firm Publisher full description …ation, Workers, Pages, D1, storage, APIs, DNS, TLS, origins, WAF, and deployment workflows. It uses authorized read-only account data and supplied code to produce evidence-backed findings, prioritized fixes, side-effect warnings, and verification steps. Customer support: https://thedoersfirm.com/sup… Show in context → |
SecurityVersion 0.1.0 | View details → |
Keybookailuntz Publisher description …keys, or SSH key paths in a user-maintained local YAML file; inject only the selected value into an authorized trusted process without printing secrets. Show in context → |
SecurityVersion 0.6.1 | View details → |
MCP PrecheckPolicyLayer Publisher full description Check configured or proposed MCP servers against PolicyLayer registry records for identity, authentication posture, tool capabilities, risk grade and recent changes. Show in context → |
SecurityVersion 1.0.0 | View details → |
Radar LiteRed Sift Publisher description Analyze any domain’s email authentication, DNS, and web security configuration. Radar Lite scans your domain, visualizes security scores on a radar chart, and generates a summary with prioritized findings and remediation guidan… Show in context → |
SecurityVersion 2.0.0 | View details → |
Tahr SecurityTahr Security Inc Publisher full description Review applications with an evidence-first security workflow that maps attack surfaces, tests authentication and access controls, traces dangerous inputs, models threats, and verifies fixes. Show in context → |
SecurityVersion 0.3.3 | View details → |
Vibe Code Security ReviewerThe Doers Firm Publisher full description …ence-based security reviews of AI-generated and rapidly built applications. It checks Supabase RLS, authentication, authorization, tenant isolation, API leaks and misuse, inputs, secrets, uploads, dependencies, data exposure, AI tools, deployment configuration, and abuse paths, then prioritizes find… Show in context → |
SecurityVersion 0.1.0 | View details → |