MARKET RESEARCH

Security Codex plugins

Codex Plugin Stats: discover plugins, explore their skills and track catalog growth and observed changes.

Explore 5,308 plugins across 14 categories.

Security plugins 13

1–13 of 13

All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.

Discover Codex plugins by task and category
Plugin / developerCategoryFollow
Skill Risk CheckOrbralScan agent skills and plugins locally for reviewable risk patterns before installation.

Plugin name

Skill Risk Check

Show in context →
3 more matching sources

Publisher capabilities · listing

Scan local skills and plugins before install Find risky instructions, permissions, and downloads Show file-and-line evidence and remediation Export JSON, Markdown, and SARIF Never run or upload the target

Show in context →

Publisher description

Scan agent skills and plugins locally for reviewable risk patterns before installation.

Show in context →

Publisher full description

Use this before installing an agent skill or plugin. Skill Risk Check scans local files for hidden instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure, then returns ranked findings with file-and-line…

Show in context →
SecurityVersion 0.1.5
View details →
Orca SecurityOrca SecurityExtend Orca Security's reasoning into ChatGPT. That means every asset, alert, identity, and dependency is already stitched together in Or...

Publisher subtitle

Fix code, cloud & AI risks.

Show in context →
SecurityVersion 1.0.0
View details →
Prompt Injection SecurityThe Doers FirmAssess prompt injection exposure in prompts, AI workflows, retrieved content, and tool designs with evidence-based findings and mitigations.

Publisher subtitle

Assess prompt injection risks

Show in context →
1 more matching sources

Publisher full description

…, AI application designs, retrieved documents, web content, and tool workflows for prompt-injection risks. Get evidence-linked attack-path analysis, calibrated severity and confidence, layered mitigations, and safe regression tests. Results are advisory and cannot guarantee prevention. Customer supp…

Show in context →
SecurityVersion 0.1.0
View details →
Vibe Code Security ReviewerThe Doers FirmAdvanced security review for AI-generated applications, Supabase RLS, APIs, secrets, databases, and production deployments.

Publisher subtitle

Audit real security risks

Show in context →
SecurityVersion 0.1.0
View details →
Authorised OSINT ToolkitRobert LaneNine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting.

Publisher capabilities · listing

…dentity security architecture Design exposure monitoring processes Quantify and prioritise security risk Produce evidence-led security reports

Show in context →
3 more matching sources

Publisher keywords · listing

defensive-osint attack-surface exposure-analysis security risk

Show in context →

Publisher description

Nine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting.

Show in context →

Publisher full description

…-surface analysis, email and cloud exposure review, identity-security assurance, monitoring design, risk quantification and evidence-led reporting. The replacement planning, identity and exposure-analysis skills exclude credentials, account enumeration, authentication testing, exploitation, access-c…

Show in context →
SecurityVersion 1.1.0
View details →
Above SecurityAbove Security

Publisher description

…ngs your identity-security data into ChatGPT. Ask in plain language to list open incidents and high-risk identities; inspect incident timelines, evidence, and insights; look up devices, monitored applications, and audit logs; and run investigative searches across your tenant. You can also triage fro…

Show in context →
SecurityVersion 1.0.0
View details →
AJAXX Data ScrubberFORTRESS APPS LLC

Publisher description

AJAXX Data Scrubber in ChatGPT provides read-only information about digital privacy risks and data broker exposure. It explains how personal data appears online, how removal services work, and answers common questions about scans, monitoring, and protection options. This ChatGPT app…

Show in context →
SecurityVersion 1.0.0
View details →
Awesome Maintainer DefenseDUC THANG LUU

Publisher description

Read-only repository governance and GitHub Actions risk audits with reviewable patches.

Show in context →
SecurityVersion 1.1.1
View details →
BreezeBreeze Security

Publisher description

…ore their organization's security posture, connected integrations, scan status, tenants, and entity risk data through ChatGPT and Codex.

Show in context →
SecurityVersion 1.0.0
View details →
MalwarebytesMalwarebytes Inc.

Publisher description

…e numbers before you click, call, or reply. Get instant reputation insights, ownership details, and risk levels for unknown numbers, suspicious emails, shortened URLs, and unfamiliar links - right inside ChatGPT.

Show in context →
SecurityVersion 1.0.0
View details →
MCP PrecheckPolicyLayer

Publisher full description

…rvers against PolicyLayer registry records for identity, authentication posture, tool capabilities, risk grade and recent changes.

Show in context →
SecurityVersion 1.0.0
View details →
SafeguardSafeguard

Publisher description

Safeguard helps users inspect software supply chain risk from ChatGPT, including vulnerabilities, SBOMs, findings, projects, components, policies, guardrails, compliance reports, remediation plans, SCM integrations, notifications, and organization work…

Show in context →
SecurityVersion 1.0.0
View details →
SkarnSkarn Software OÜ

Publisher description

…coding sessions and assistant configs with the locally installed skarn CLI: leaked credentials and risky hooks or MCP servers, reported on this machine with every secret masked.

Show in context →
1 more matching sources

Publisher full description

…Top 10, and CWE. skarn vet reads the assistant configuration files on the same machine and reports risky declarations: hooks, MCP servers, and permission grants that could run remote code or send data off the machine. Both passes run entirely on this machine and make no network call. Neither modifi…

Show in context →
SecurityVersion 0.27.0
View details →