Security Codex plugins
Codex Plugin Stats: discover plugins, explore their skills and track catalog growth and observed changes.
Explore 5,324 plugins across 14 categories.
Security plugins 16
1–16 of 16All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.
| Plugin / developer | Category | Follow |
|---|---|---|
Codex SecurityOpenAICodex Security workflows for security scans, analysis, and investigation. Plugin name Codex Security Show in context →6 more matching sourcesPublisher keywords · listing security code-review diff-review appsec threat-modeling Show in context →Publisher description Codex Security workflows for security scans, analysis, and investigation. Show in context →Publisher full description Codex Security packages reusable workflows for security scans, analysis, validation, and investigation across code, diffs, and related artifacts. Show in context → |
SecurityVersion 0.1.31 | View details → |
Codex Security CloudOpenAICloud security scans, findings, and continuous repository monitoring. Plugin name Codex Security Cloud Show in context →6 more matching sourcesPublisher full description Codex Security Cloud brings cloud security scans, findings, and continuous repository monitoring into your workspace. Show in context →Publisher description Cloud security scans, findings, and continuous repository monitoring. Show in context → |
SecurityVersion 0.1.1 | View details → |
Vibe Code Security ReviewerThe Doers FirmAdvanced security review for AI-generated applications, Supabase RLS, APIs, secrets, databases, and production deployments. Plugin name Vibe Code Security Reviewer Show in context →6 more matching sourcesPublisher full description Vibe Code Security Reviewer performs advanced evidence-based security reviews of AI-generated and rapidly built applications. It checks Supabase RLS, authentication, authorization, tenant isolation, API leaks and m… Show in context →Publisher description Advanced security review for AI-generated applications, Supabase RLS, APIs, secrets, databases, and production deployments. Show in context → |
SecurityVersion 0.1.0 | View details → |
Tahr SecurityTahr Security IncEvidence-backed application security workflows for finding, validating, and fixing vulnerabilities. Package name tahr-codex-plugin Show in context →7 more matching sourcesPublisher description Evidence-backed application security workflows for finding, validating, and fixing vulnerabilities. Show in context →Publisher full description Review applications with an evidence-first security workflow that maps attack surfaces, tests authentication and access controls, traces dangerous inputs, models threats, and verifies fixes. Show in context → |
SecurityVersion 0.3.3 | View details → |
Orca SecurityOrca SecurityExtend Orca Security's reasoning into ChatGPT. That means every asset, alert, identity, and dependency is already stitched together in Or... Publisher subtitle Fix code, cloud & AI risks. Show in context →2 more matching sourcesPublisher description Extend Orca Security's reasoning into ChatGPT. That means every asset, alert, identity, and dependency is already stitched together in Orca’s Unified Data Model before users ask a question. Every answer facto… …and extend it to their own use cases. The result: security and engineering teams work across cloud, code, and AI from a single workspace, with Orca's reasoning behind every answer. Show in context → |
SecurityVersion 1.0.0 | View details → |
Endor Labs Agent KitEndor LabsEndor Labs security workflows and setup for Codex. Publisher keywords · listing endor-labs security sca sast codex Show in context →7 more matching sourcesPublisher capabilities · listing Security Remediation Investigation Application Security Agentic Workflows Agentic Remediation Agentic AppSec Show in context →Publisher full description Packaged AppSec workflows for SCA remediation, AI SAST triage, CI/CD posture, malware response, findings review, Endor Labs setup, and more. Show in context → |
SecurityVersion 2.2.2 | View details → |
SkarnSkarn Software OÜAudit AI coding sessions and assistant configs with the locally installed skarn CLI: leaked credentials and risky hooks or MCP servers, r... Publisher keywords · listing security secrets credential-leak ai-coding-sessions audit codex Show in context →7 more matching sourcesPublisher full description Skarn is a command-line security scanner for AI coding sessions. The audit skill, skarn-audit, teaches the model to run the skarn CLI on this machine and act on what it reports. The skill runs two passes… …ine and reports risky declarations: hooks, MCP servers, and permission grants that could run remote code or send data off the machine. Both passes run entirely on this machine and make no network call. Neither modifies a session transcript or a configuration file, and every credential value in the o… Show in context →Publisher capabilities · listing Scan AI coding sessions for leaked credentials Vet assistant hooks, MCP servers and permission grants Show in context →Publisher description Audit AI coding sessions and assistant configs with the locally installed skarn CLI: leaked credentials and risky hooks or MCP servers, reported on this machine with every secret masked. Show in context → |
SecurityVersion 0.27.0 | View details → |
Skill Risk CheckOrbralScan agent skills and plugins locally for reviewable risk patterns before installation. Publisher keywords · listing plugin-security agent-skills pre-install-scan prompt-injection supply-chain sarif codex claude-code Show in context →7 more matching sourcesPublisher capabilities · listing Scan local skills and plugins before install Find risky instructions, permissions, and downloads Show file-and-line evidence and remediation Export JSON, Markdown, and SARIF Never run or upload the target Show in context →Publisher description Scan agent skills and plugins locally for reviewable risk patterns before installation. Show in context →Publisher full description Use this before installing an agent skill or plugin. Skill Risk Check scans local files for hidden instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure, th… Show in context → |
SecurityVersion 0.1.5 | View details → |
Authorized Security ReviewIssam Chaaban Publisher full description An independent skills-only workflow for authorized security research. Uses tools already connected to the active chat. Supports source review, scoped web/API investigation, validation, and HackerOne report drafting. Does not bundle testing tools or the Codex Security backend. Show in context →6 more matching sourcesPublisher description Evidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools. Show in context → |
SecurityVersion 1.0.1 | View details → |
BreezeBreeze Security Publisher description Breeze helps authenticated users explore their organization's security posture, connected integrations, scan status, tenants, and entity risk data through ChatGPT and Codex. Show in context →3 more matching sources |
SecurityVersion 1.0.0 | View details → |
Cloudflare SecurityThe Doers Firm Publisher full description Cloudflare Security reviews Cloudflare account configuration, Workers, Pages, D1, storage, APIs, DNS, TLS, origins, WAF, and deployment workflows. It uses authorized read-only account data and supplied code to produce evidence-backed findings, prioritized fixes, side-effect warnings, and verification steps. Customer support: https://thedoersfirm.com/support. It cannot guarantee complete security. Show in context →6 more matching sourcesPublisher description Audit and harden Cloudflare-hosted applications, data, accounts, and infrastructure with evidence-based security guidance. Show in context → |
SecurityVersion 0.1.0 | View details → |
GuardioGuardio Publisher full description Guardio helps you check suspicious links and understand your online protection from ChatGPT and Codex. Check a website before opening it, or check links extracted from a suspicious message without sending the message body to Guardio. Connect your Guardio account to review protection setup, scan… Show in context →3 more matching sourcesPublisher capabilities · listing Check suspicious links Check links in messages Look up known email and phone breaches Review account protection and scan activity Review security recommendations Set up browser protection Send requested product feedback Show in context →Publisher description Check suspicious links, review known data leaks, and understand your Guardio protection. Show in context → |
SecurityVersion 0.2.2 | View details → |
ProofXCyberSec AI Ltd Publisher description ProofX protects your digital content with cryptographic signatures. What you can do: - Protect your articles, poems, scripts, code, and text with tamper-proof cryptographic proof - Verify if content is registered with ProofX using a content ID or hash - Look up creator profiles and their protection history - Get digital fing… Show in context →3 more matching sources |
SecurityVersion 1.0.0 | View details → |
Atbash SafetyAtbash AIAutomatically guards supported Codex tool calls with Atbash safety judgments and provides secure local setup guidance. Publisher keywords · listing atbash codex safety policy guardrails Show in context →4 more matching sourcesPublisher description Automatically guards supported Codex tool calls with Atbash safety judgments and provides secure local setup guidance. Show in context →Publisher full description Atbash Safety checks supported Codex tool calls against your Atbash agent's safety policy before execution. The package includes a local PreToolUse hook, the bundled production Atbash SDK, and a setup and troubleshooting skill; it… Show in context → |
SecurityVersion 0.3.3 | View details → |
BastionBastion Technologies Publisher description Connect Bastion to ChatGPT to manage your security and compliance posture through natural conversation. Review framework compliance status across SOC 2, ISO 27001, HIPAA, and GDPR. Drill into failing tests, upload evidence, and submit contr… …dge base security and compliance questions grounded in your own policies and documentation. Monitor code security findings and GitHub configuration status. All data is scoped to your authenticated account - you only ever see your own tenant. Show in context →1 more matching sources |
SecurityVersion 1.0.0 | View details → |
ToolCheck by M8venM8ven Inc. Publisher description ToolCheck is M8ven's trust layer for the MCP ecosystem. Give it a GitHub URL or npm package name and it returns an independent trust score (0–100) and a clear verdict (Trusted / Caution / Concern), backed by static code analysis, runtime behavioral observation in a sandbox, CVE scanning, and a semantic check comparing the tool's declared behavior against what its code actually does — catching the gap between "re… Show in context → |
SecurityVersion 1.0.0 | View details → |