Security Codex plugins
Codex Plugin Stats: discover plugins, explore their skills and track catalog growth and observed changes.
Explore 5,319 plugins across 14 categories.
Security plugins 8
1–8 of 8All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.
| Plugin / developer | Category | Follow |
|---|---|---|
Codex SecurityOpenAICodex Security workflows for security scans, analysis, and investigation. Plugin name Codex Security Show in context →5 more matching sourcesPublisher keywords · listing security code-review diff-review appsec threat-modeling Show in context →Publisher description Codex Security workflows for security scans, analysis, and investigation. Show in context →Publisher full description Codex Security packages reusable workflows for security scans, analysis, validation, and investigation across code, diffs, and related artifacts. Show in context → |
SecurityVersion 0.1.31 | View details → |
Tahr SecurityTahr Security IncEvidence-backed application security workflows for finding, validating, and fixing vulnerabilities. Package name tahr-codex-plugin Show in context →1 more matching sourcesPublisher full description Review applications with an evidence-first security workflow that maps attack surfaces, tests authentication and access controls, traces dangerous inputs, models threats, and verifies fixes. Show in context → |
SecurityVersion 0.3.3 | View details → |
Authorized Security ReviewIssam Chaaban Publisher full description …for authorized security research. Uses tools already connected to the active chat. Supports source review, scoped web/API investigation, validation, and HackerOne report drafting. Does not bundle testing tools or the Codex Security backend. Show in context →3 more matching sourcesPublisher description Evidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools. Show in context → |
SecurityVersion 1.0.1 | View details → |
Atbash SafetyAtbash AI Publisher full description Atbash Safety checks supported Codex tool calls against your Atbash agent's safety policy before execution. The package includes a local PreToolUse hook, the bundled production Atbash SDK, and a setup and troubleshooting skill; it… …ent private key and exact organization name in the local Atbash configuration file, then explicitly review and trust the hook in Codex. Never paste private keys into chat. Once configured, enabled, and trusted, the hook sends tool-call details through the SDK to Atbash for a judgment. ALLOW permits… Show in context →2 more matching sourcesPublisher description Automatically guards supported Codex tool calls with Atbash safety judgments and provides secure local setup guidance. Show in context → |
SecurityVersion 0.3.3 | View details → |
Endor Labs Agent KitEndor LabsEndor Labs security workflows and setup for Codex. Publisher keywords · listing endor-labs security sca sast codex Show in context →2 more matching sourcesPublisher full description …ged AppSec workflows for SCA remediation, AI SAST triage, CI/CD posture, malware response, findings review, Endor Labs setup, and more. Show in context → |
SecurityVersion 2.2.2 | View details → |
SkarnSkarn Software OÜ Publisher full description …ine and reports risky declarations: hooks, MCP servers, and permission grants that could run remote code or send data off the machine. Both passes run entirely on this machine and make no network call. Neither modifies a session transcript or a configuration file, and every credential value in the output is masked, so a finding names a rule and a masked preview and never the credential itself. Skarn surfaces findings and does not rotate a credential or edit a configuration on its own: the skill proposes, and the user decides. The one thing the skill c… …explicitly confirmed as a false positive. The skill runs a local shell command, so it is offered in Codex. It does not carry the skarn binary, which is installed separately: brew install skarn-security/tap/skarn npm install -g @skarn-security/skarn Release binaries: https://github.com/skarn-security… Show in context →1 more matching sourcesPublisher keywords · listing security secrets credential-leak ai-coding-sessions audit codex Show in context → |
SecurityVersion 0.27.0 | View details → |
Skill Risk CheckOrbralScan agent skills and plugins locally for reviewable risk patterns before installation. Publisher keywords · listing plugin-security agent-skills pre-install-scan prompt-injection supply-chain sarif codex claude-code Show in context →1 more matching sourcesPublisher description Scan agent skills and plugins locally for reviewable risk patterns before installation. Show in context → |
SecurityVersion 0.1.5 | View details → |
GuardioGuardio Publisher full description Guardio helps you check suspicious links and understand your online protection from ChatGPT and Codex. Check a website before opening it, or check links extracted from a suspicious message without sending the message body to Guardio. Connect your Guardio account to review protection setup, scan activity, recent data leaks, linked-service counts, and security recommendations. You can also check whether an email address or phone number appears in known data breach… Show in context →2 more matching sourcesPublisher capabilities · listing Check suspicious links Check links in messages Look up known email and phone breaches Review account protection and scan activity Review security recommendations Set up browser protection Send requested product feedback Show in context →Publisher description Check suspicious links, review known data leaks, and understand your Guardio protection. Show in context → |
SecurityVersion 0.2.2 | View details → |