MARKET RESEARCH

Security Codex plugins

Find plugins for your work. Follow them to see what changes.

Explore 5,283 plugins across 14 categories.

Security plugins 19

1–19 of 19
Plugin growth →
Sources & collection details
Collection coverage →

Last completed check: Oct 3, 2026 · 00:02 UTC.

Monetization research dated Oct 1, 2026. Unreviewed pricing is marked explicitly. The time range applies to the activity filter; Recently changed includes listing, instruction and pricing-reference changes, excluding technical-only metadata.

Export this page ↓

All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.

Discover Codex plugins by task and category
Plugin / developerCategoryFollow
Authorized Security ReviewIssam ChaabanEvidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools.

Plugin name

Authorized Security Review

Show in context →
3 more matching sources

Package name

authorized-security-review

Show in context →

Publisher description

Evidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools.

Show in context →

Publisher full description

…for authorized security research. Uses tools already connected to the active chat. Supports source review, scoped web/API investigation, validation, and HackerOne report drafting. Does not bundle testing tools or the Codex Security backend.

Show in context →
SecurityVersion 1.0.1
View details →
Vibe Code Security ReviewerThe Doers FirmAdvanced security review for AI-generated applications, Supabase RLS, APIs, secrets, databases, and production deployments.

Plugin name

Vibe Code Security Reviewer

Show in context →
3 more matching sources

Package name

vibe-code-security-reviewer

Show in context →

Publisher description

Advanced security review for AI-generated applications, Supabase RLS, APIs, secrets, databases, and production deployments.

Show in context →

Publisher full description

Vibe Code Security Reviewer performs advanced evidence-based security reviews of AI-generated and rapidly built applications. It checks Supabase RLS, authentication, authorization, tenant isolation, API leaks and misuse…

Show in context →
SecurityVersion 0.1.0
View details →
Aivana Security InvestigatorAivanaGuided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.

Publisher capabilities · listing

…OAuth/OBO Defender XDR KQL API Read-only cross-domain investigations Evidence packages and analyst review

Show in context →
1 more matching sources

Publisher full description

…DR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response execution.

Show in context →
SecurityVersion 1.1.1
View details →
Authorised OSINT ToolkitRobert LaneNine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting.

Publisher capabilities · listing

Plan lawful defensive OSINT reviews Assess organisational attack surfaces Review email and cloud exposure Analyse identity security architecture Design exposure monitoring processes Quantify and prioritise security risk Produce…

Show in context →
1 more matching sources

Publisher full description

…kill toolkit for authorised organisational OSINT, attack-surface analysis, email and cloud exposure review, identity-security assurance, monitoring design, risk quantification and evidence-led reporting. The replacement planning, identity and exposure-analysis skills exclude credentials, account enu…

Show in context →
SecurityVersion 1.1.0
View details →
GuardioGuardioCheck suspicious links, review known data leaks, and understand your Guardio protection.

Publisher capabilities · listing

Check suspicious links Check links in messages Look up known email and phone breaches Review account protection and scan activity Review security recommendations Set up browser protection Send requested product feedback

Show in context →
2 more matching sources

Publisher description

Check suspicious links, review known data leaks, and understand your Guardio protection.

Show in context →

Publisher full description

…m a suspicious message without sending the message body to Guardio. Connect your Guardio account to review protection setup, scan activity, recent data leaks, linked-service counts, and security recommendations. You can also check whether an email address or phone number appears in known data breach…

Show in context →
SecurityVersion 0.2.2
View details →
Codex SecurityOpenAICodex Security workflows for security scans, analysis, and investigation.

Publisher keywords · listing

security code-review diff-review appsec threat-modeling

Show in context →
SecurityVersion 0.1.31
View details →
Atbash SafetyAtbash AI

Publisher full description

…ent private key and exact organization name in the local Atbash configuration file, then explicitly review and trust the hook in Codex. Never paste private keys into chat. Once configured, enabled, and trusted, the hook sends tool-call details through the SDK to Atbash for a judgment. ALLOW permits…

Show in context →
SecurityVersion 0.3.3
View details →
Awesome Maintainer DefenseDUC THANG LUU

Publisher description

Read-only repository governance and GitHub Actions risk audits with reviewable patches.

Show in context →
1 more matching sources

Publisher full description

…trust boundaries, and moderation automation without network access or repository mutation; generate reviewable remediation patches on request.

Show in context →
SecurityVersion 1.1.1
View details →
BastionBastion Technologies

Publisher description

…ect Bastion to ChatGPT to manage your security and compliance posture through natural conversation. Review framework compliance status across SOC 2, ISO 27001, HIPAA, and GDPR. Drill into failing tests, upload evidence, and submit controls for review. Ask your knowledge base security and compliance…

Show in context →
SecurityVersion 1.0.0
View details →
CertScore.ai Privacy ScannerCertScore.ai, LLC

Publisher description

…icy signals, and HTTPS/TLS. Results preserve provenance and explicit coverage limitations for human review; they are not legal advice, certification, or a compliance determination.

Show in context →
SecurityVersion 2.0.0
View details →
Cloudflare SecurityThe Doers Firm

Publisher full description

Cloudflare Security reviews Cloudflare account configuration, Workers, Pages, D1, storage, APIs, DNS, TLS, origins, WAF, and deployment workflows. It uses authorized read-only account data and supplied code to produce ev…

Show in context →
SecurityVersion 0.1.0
View details →
CookieYesCookieYes Limited

Publisher description

…hether your cookie banner is live. Run a cookie scan to find every cookie and tracker on your site. Review your GDPR and CCPA compliance settings. Update your cookie banner in seconds. Typical requests: "Audit my site for GDPR compliance", "Is my cookie banner active?", "Run a cookie scan and show m…

Show in context →
SecurityVersion 1.0.0
View details →
Endor Labs Agent KitEndor Labs

Publisher full description

…ged AppSec workflows for SCA remediation, AI SAST triage, CI/CD posture, malware response, findings review, Endor Labs setup, and more.

Show in context →
SecurityVersion 2.2.2
View details →
Neura Relay MCPRoman Pelevin

Publisher description

Neura Relay MCP helps ChatGPT-connected workflows review proposed agent actions before execution. It returns Decision Receipts, trace refs, and Registry context without executing downstream actions or exposing private payloads.

Show in context →
SecurityVersion 1.0.0
View details →
PalisadeSamuel Chenard

Publisher description

Palisade helps email teams investigate SPF, DKIM, DMARC, and MTA-STS issues. Review monitored domains, DMARC pass rates and sending sources, inspect DNS and SPF records, and retrieve remediation tasks with supporting evidence. Use the results to prioritize fixes and prepare DN…

Show in context →
SecurityVersion 1.0.0
View details →
Prompt Injection SecurityThe Doers Firm

Publisher full description

Review prompts, AI application designs, retrieved documents, web content, and tool workflows for prompt-injection risks. Get evidence-linked attack-path analysis, calibrated severity and confidence, l…

Show in context →
SecurityVersion 0.1.0
View details →
SkarnSkarn Software OÜ

Publisher full description

…n file, and every credential value in the output is masked, so a finding names a rule and a masked preview and never the credential itself. Skarn surfaces findings and does not rotate a credential or edit a configuration on its own: the skill proposes, and the user decides. The one thing the skill c…

Show in context →
SecurityVersion 0.27.0
View details →
Skill Risk CheckOrbral

Publisher description

Scan agent skills and plugins locally for reviewable risk patterns before installation.

Show in context →
SecurityVersion 0.1.5
View details →
Tahr SecurityTahr Security Inc

Publisher full description

Review applications with an evidence-first security workflow that maps attack surfaces, tests authentication and access controls, traces dangerous inputs, models threats, and verifies fixes.

Show in context →
SecurityVersion 0.3.3
View details →