Security Codex plugins
Codex Plugin Stats: discover plugins, explore their skills and track catalog growth and observed changes.
Explore 5,817 plugins across 14 categories.
Security plugins 12
1–12 of 12All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.
| Plugin / developer | Category | Follow |
|---|---|---|
Awesome Maintainer DefenseDUC THANG LUURead-only repository governance and GitHub Actions risk audits with reviewable patches. Publisher subtitle Audit repository trust safely Show in context →3 more matching sourcesPublisher keywords · listing github-actions repository-security governance maintainers audit Show in context →Publisher description Read-only repository governance and GitHub Actions risk audits with reviewable patches. Show in context →Publisher full description Inspect repository policy, GitHub Actions trust boundaries, and moderation automation without network access or repository mutation; generate reviewable remediation patches on request. Show in context → |
SecurityVersion 1.1.1 | View details → |
Codex Security CloudOpenAICloud security scans, findings, and continuous repository monitoring. Publisher subtitle Find and fix vulnerabilities across your repositories Show in context →3 more matching sourcesPublisher description Cloud security scans, findings, and continuous repository monitoring. Show in context →Publisher full description Codex Security Cloud brings cloud security scans, findings, and continuous repository monitoring into your workspace. Show in context → |
SecurityVersion 0.1.1 | View details → |
Authorised OSINT ToolkitRobert LaneNine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting. Publisher capabilities · listing …n exposure monitoring processes Quantify and prioritise security risk Produce evidence-led security reports Show in context →2 more matching sourcesPublisher description Nine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting. Show in context →Publisher full description …posure review, identity-security assurance, monitoring design, risk quantification and evidence-led reporting. The replacement planning, identity and exposure-analysis skills exclude credentials, account enumeration, authentication testing, exploitation, access-control bypass and surveillance. Show in context → |
SecurityVersion 1.1.0 | View details → |
VIDOC Security ReviewVidoc Security LabVIDOC Security Review by Vidoc Security Lab: review source code for security issues, validate suspected findings, and prepare reports wit... Publisher capabilities · listing Security code review Finding validation Review reporting Show in context →2 more matching sourcesPublisher description …idoc Security Lab: review source code for security issues, validate suspected findings, and prepare reports with supporting evidence using three defined skills. Show in context →Publisher full description …three defined skills review supplied code or diffs, validate suspected vulnerabilities, and prepare reports with evidence, impact, and proposed fixes. Findings distinguish supported issues from concerns that need more context. Reviews use supplied code and the host's existing read-only access. This… Show in context → |
SecurityVersion 0.1.1 | View details → |
Authorized Security ReviewIssam Chaaban Publisher description Evidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools. Show in context →1 more matching sourcesPublisher full description …to the active chat. Supports source review, scoped web/API investigation, validation, and HackerOne report drafting. Does not bundle testing tools or the Codex Security backend. Show in context → |
SecurityVersion 1.0.1 | View details → |
CalmidoCalmido Publisher description Look up who is behind a phone number in the Netherlands, Belgium or Luxembourg: community reports, spam and scam categories, a trust verdict and the registered business, from Calmido's phone directory. Use it when someone asks who called them, whether a number is safe, spam or a scam, or w… Show in context → |
SecurityVersion 1.0.0 | View details → |
GuardioGuardio Publisher full description …link check on your account, and a dangerous result appears in your account activity. A link result reports known threats at the time of the check. It is not a guarantee that a site or an entire message is safe. The plugin does not scan local executable files or provide continuous browser protection… Show in context → |
SecurityVersion 0.2.2 | View details → |
LeakDataLeakdata.io Publisher description …he verified email address on your connected LeakData account appears in known data breaches. Review reported breach sources, dates and affected data types to understand your email exposure. You can also look up aggregate statistics for a five-character SHA-1 password hash prefix computed on your dev… Show in context → |
SecurityVersion 1.0.2 | View details → |
Orca SecurityOrca Security Publisher description …the reasoning without writing the prompts, Orca maintains the AI Skills Hub, an open-source GitHub repo of agent skills. Type "triage alert orca-9012345" and the orca-alert-triage skill handles retrieval, analysis, and formatting. Teams can fork it, modify it, and extend it to their own use cases.… Show in context → |
SecurityVersion 1.0.0 | View details → |
RelayShield Scam ChecksRelayShield Publisher description …known data breaches. Free, no signup, no API key. Verdicts are FLAGGED or unknown — the tools never report anything as safe, because absence of evidence is not evidence of absence. Show in context → |
SecurityVersion 1.0.0 | View details → |
SafeguardSafeguard Publisher description …including vulnerabilities, SBOMs, findings, projects, components, policies, guardrails, compliance reports, remediation plans, SCM integrations, notifications, and organization workflows. Show in context → |
SecurityVersion 1.0.0 | View details → |
SkarnSkarn Software OÜ Publisher description …nt configs with the locally installed skarn CLI: leaked credentials and risky hooks or MCP servers, reported on this machine with every secret masked. Show in context →1 more matching sourcesPublisher full description …audit skill, skarn-audit, teaches the model to run the skarn CLI on this machine and act on what it reports. The skill runs two passes. skarn assess reads the session transcripts that AI coding assistants have already written to disk and reports leaked credentials, prompt injection, exfiltration att… Show in context → |
SecurityVersion 0.27.0 | View details → |