MARKET RESEARCH

Security Codex plugins

Codex Plugin Stats: discover plugins, explore their skills and track catalog growth and observed changes.

Explore 5,295 plugins across 14 categories.

Security plugins 37

1–36 of 37

All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.

Discover Codex plugins by task and category
Plugin / developerCategoryFollow
MinimusMinimusMinimus hardened-image skills (Dockerfile & Kubernetes)

Plugin name

Minimus

Show in context →
3 more matching sources

Package name

minimus

Show in context →

Publisher description

Minimus hardened-image skills (Dockerfile & Kubernetes)

Show in context →

Publisher full description

Minimus plugin that teaches AI coding tools to build Dockerfiles and Kubernetes manifests with hardened near-zero-CVE images

Show in context →
SecurityVersion 1.0.4
View details →
Awesome Maintainer DefenseDUC THANG LUURead-only repository governance and GitHub Actions risk audits with reviewable patches.

Publisher subtitle

Audit repository trust safely

Show in context →
1 more matching sources

Publisher full description

Inspect repository policy, GitHub Actions trust boundaries, and moderation automation without network access or repository mutation; generate reviewable remediation patches on request.

Show in context →
SecurityVersion 1.1.1
View details →
GuardioGuardioCheck suspicious links, review known data leaks, and understand your Guardio protection.

Publisher capabilities · listing

Check suspicious links Check links in messages Look up known email and phone breaches Review account protection and scan activity Review security recommendations Set up browser protection Send requested prod…

Show in context →
2 more matching sources

Publisher description

Check suspicious links, review known data leaks, and understand your Guardio protection.

Show in context →

Publisher full description

Guardio helps you check suspicious links and understand your online protection from ChatGPT and Codex. Check a website before opening it, or check links extracted from a suspicious message without sending the message body to…

Show in context →
SecurityVersion 0.2.2
View details →
Above SecurityAbove Security

Publisher description

…and run investigative searches across your tenant. You can also triage from chat — set incident status, verdict, and resolution notes, or add an identity to the watch list. Access requires an Above Security account and is scoped to your role and company; read and write are governed by explicit OAuth…

Show in context →
SecurityVersion 1.0.0
View details →
AccessOwlOmni Owl GmbH

Publisher description

AccessOwl lets organizations manage access to SaaS apps. Users can browse available apps and request access as needed.

Show in context →
SecurityVersion 1.0.0
View details →
Aivana Security InvestigatorAivana

Publisher description

Guided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.

Show in context →
1 more matching sources

Publisher full description

Translates user requests into transparent KQL and executes bounded, read-only Defender XDR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response…

Show in context →
SecurityVersion 1.1.1
View details →
AJAXX Data ScrubberFORTRESS APPS LLC

Publisher description

…form removals, or manage accounts. For secure account access, scans, removals, billing, or support, users are directed to the official AJAXX website.

Show in context →
SecurityVersion 1.0.0
View details →
Ansvar GatewayAnsvar AI

Publisher description

…security company that gives AI agents verifiable access to law, regulation and security standards. Customers connect the AI assistant they already use (Claude, Microsoft Copilot, ChatGPT or any MCP-compatible client) to the Ansvar Gateway and run compliance work directly in that assistant: regulator…

Show in context →
SecurityVersion 1.0.0
View details →
Atbash SafetyAtbash AI

Publisher full description

…lls against your Atbash agent's safety policy before execution. The package includes a local PreToolUse hook, the bundled production Atbash SDK, and a setup and troubleshooting skill; it does not use an MCP server. Requires a supported local Codex environment, Node.js 22.13 or newer, an Atbash accou…

Show in context →
SecurityVersion 0.3.3
View details →
Authorized Security ReviewIssam Chaaban

Publisher description

Evidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools.

Show in context →
1 more matching sources

Publisher full description

An independent skills-only workflow for authorized security research. Uses tools already connected to the active chat. Supports source review, scoped web/API investigation, validation, and HackerOne report drafting. Does not bundle testing tools or the Codex Security ba…

Show in context →
SecurityVersion 1.0.1
View details →
BastionBastion Technologies

Publisher description

…your security and compliance posture through natural conversation. Review framework compliance status across SOC 2, ISO 27001, HIPAA, and GDPR. Drill into failing tests, upload evidence, and submit controls for review. Ask your knowledge base security and compliance questions grounded in your own p…

Show in context →
SecurityVersion 1.0.0
View details →
BitdefenderBitdefender

Publisher description

Bitdefender Plugin has a collection of free tools which help users avoid malware, phishing attempts, and counterfeit websites which includes: - Link Checker - Phone Number - Password Generator - Digital Footprint Checker - Product Recommendations

Show in context →
SecurityVersion 1.0.0
View details →
BreezeBreeze Security

Publisher description

Breeze helps authenticated users explore their organization's security posture, connected integrations, scan status, tenants, and entity risk data through ChatGPT and Codex.

Show in context →
SecurityVersion 1.0.0
View details →
CalmidoCalmido

Publisher description

…number in the Netherlands, Belgium or Luxembourg: community reports, spam and scam categories, a trust verdict and the registered business, from Calmido's phone directory. Use it when someone asks who called them, whether a number is safe, spam or a scam, or which company a number belongs to.

Show in context →
SecurityVersion 1.0.0
View details →
Cloudflare SecurityThe Doers Firm

Publisher full description

…figuration, Workers, Pages, D1, storage, APIs, DNS, TLS, origins, WAF, and deployment workflows. It uses authorized read-only account data and supplied code to produce evidence-backed findings, prioritized fixes, side-effect warnings, and verification steps. Customer support: https://thedoersfirm.co…

Show in context →
SecurityVersion 0.1.0
View details →
Codex SecurityOpenAI

Publisher full description

Codex Security packages reusable workflows for security scans, analysis, validation, and investigation across code, diffs, and related artifacts.

Show in context →
SecurityVersion 0.1.31
View details →
Codex Security CloudOpenAI

Publisher description

Cloud security scans, findings, and continuous repository monitoring.

Show in context →
1 more matching sources

Publisher full description

Codex Security Cloud brings cloud security scans, findings, and continuous repository monitoring into your workspace.

Show in context →
SecurityVersion 0.1.1
View details →
CookieYesCookieYes Limited

Publisher description

…out leaving ChatGPT. Privacy laws like GDPR and CCPA require websites to get visitor consent before using cookies. CookieYes is the consent management platform (CMP) that handles this for 1.5M+ websites. This connector puts it inside your chat. Check whether your cookie banner is live. Run a cookie…

Show in context →
SecurityVersion 1.0.0
View details →
DecionisBinaries

Publisher description

…s evaluates the proposed action against organization policy and determines whether it may proceed, must be held, or requires additional authority. When human approval is required, Decionis can request verified approval through Presence and re-evaluate the action using the resulting signed evidence.…

Show in context →
SecurityVersion 1.0.1
View details →
Is It Legit by M8venM8ven Inc.

Publisher description

Is It Legit is the consumer brand-trust tool from M8ven. Given a brand name or URL, it analyzes 100+ trust signals and returns a verdict (safe / caution / avoid) with key findings. Designed for "is this site real?" / "should I buy from…

Show in context →
SecurityVersion 1.0.0
View details →
IsThisSpamUltron Developments Pty. Ltd.

Publisher description

IsThisSpam checks suspicious phone numbers, messages, links, websites, and email addresses using structured scam signals and cautious safety guidance. Results distinguish likely scams from unverified findings; no result…

Show in context →
SecurityVersion 0.1.0
View details →
Keybookailuntz

Publisher description

…logins, macOS passwords, publishing and cloud service tokens, model API keys, or SSH key paths in a user-maintained local YAML file; inject only the selected value into an authorized trusted process without printing secrets.

Show in context →
SecurityVersion 0.6.1
View details →
MalwarebytesMalwarebytes Inc.

Publisher description

…or reply. Get instant reputation insights, ownership details, and risk levels for unknown numbers, suspicious emails, shortened URLs, and unfamiliar links - right inside ChatGPT.

Show in context →
SecurityVersion 1.0.0
View details →
NightVisionNightVision Security, Inc.

Publisher full description

…NightVision API discovery, DAST scan configuration, CI/CD integration, and security-finding triage using the local NightVision CLI.

Show in context →
SecurityVersion 0.2.0
View details →
Orca SecurityOrca Security

Publisher description

…t, alert, identity, and dependency is already stitched together in Orca’s Unified Data Model before users ask a question. Every answer factors in reachability, blast radius, and business impact from the first response. For teams that want the reasoning without writing the prompts, Orca maintains the…

Show in context →
SecurityVersion 1.0.0
View details →
PalisadeSamuel Chenard

Publisher description

…ding sources, inspect DNS and SPF records, and retrieve remediation tasks with supporting evidence. Use the results to prioritize fixes and prepare DNS change plans. This plugin provides read-only access to your Palisade account: it does not publish DNS records, modify domains, send email, or manage…

Show in context →
SecurityVersion 1.0.0
View details →
PrivacyHawkPrivacyHawk, Inc

Publisher description

Use PrivacyHawk with ChatGPT to Take Control of Your Personal Data -- Manage, control, and delete your data from thousands of businesses exploiting your personal information. PrivacyHawk helps you red…

Show in context →
SecurityVersion 1.0.0
View details →
Prompt Injection SecurityThe Doers Firm

Publisher full description

…ered mitigations, and safe regression tests. Results are advisory and cannot guarantee prevention. Customer support: https://thedoersfirm.com/support.

Show in context →
SecurityVersion 0.1.0
View details →
ProofXCyberSec AI Ltd

Publisher description

…code, and text with tamper-proof cryptographic proof - Verify if content is registered with ProofX using a content ID or hash - Look up creator profiles and their protection history - Get digital fingerprints of your content How it works: 1. Connect your ProofX account (free signup at proofx.co.uk)…

Show in context →
SecurityVersion 1.0.0
View details →
RelayShield Scam ChecksRelayShield

Publisher description

RelayShield Free Scam Checks screens links, crypto wallets, suspicious emails, and email addresses against RelayShield's threat-intelligence corpus — 115 monitored Telegram marketplaces, 494K+ indicators, 7.8M+ citations — before you click, pay, or reply. Four…

Show in context →
SecurityVersion 1.0.0
View details →
SafeguardSafeguard

Publisher description

Safeguard helps users inspect software supply chain risk from ChatGPT, including vulnerabilities, SBOMs, findings, projects, components, policies, guardrails, compliance reports, remediation plans, SCM integrations,…

Show in context →
SecurityVersion 1.0.0
View details →
SkarnSkarn Software OÜ

Publisher full description

…gs and does not rotate a credential or edit a configuration on its own: the skill proposes, and the user decides. The one thing the skill can write is a baseline entry recording a finding the user has explicitly confirmed as a false positive. The skill runs a local shell command, so it is offered in…

Show in context →
SecurityVersion 0.27.0
View details →
Skill Risk CheckOrbral

Publisher full description

Use this before installing an agent skill or plugin. Skill Risk Check scans local files for hidden instructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret…

Show in context →
SecurityVersion 0.1.5
View details →
SoluverySoluvery Inc.

Publisher description

…ws you exactly which files are publicly shared or accessible by specific people. No setup needed — just ask.

Show in context →
SecurityVersion 1.0.0
View details →
Tahr SecurityTahr Security Inc

Publisher full description

…ecurity workflow that maps attack surfaces, tests authentication and access controls, traces dangerous inputs, models threats, and verifies fixes.

Show in context →
SecurityVersion 0.3.3
View details →
ToolCheck by M8venM8ven Inc.

Publisher description

ToolCheck is M8ven's trust layer for the MCP ecosystem. Give it a GitHub URL or npm package name and it returns an independent trust score (0–100) and a clear verdict (Trusted / Caution / Concern), backed by static code ana…

Show in context →
SecurityVersion 1.0.0
View details →