MARKET RESEARCH

Security Codex plugins

Codex Plugin Stats: discover plugins, explore their skills and track catalog growth and observed changes.

Explore 5,308 plugins across 14 categories.

Security plugins 28

1–28 of 28

All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.

Discover Codex plugins by task and category
Plugin / developerCategoryFollow
AJAXX Data ScrubberFORTRESS APPS LLCAJAXX Data Scrubber in ChatGPT provides read-only information about digital privacy risks and data broker exposure. It explains how perso...

Plugin name

AJAXX Data Scrubber

Show in context →
2 more matching sources

Publisher subtitle

Remove exposed personal data

Show in context →

Publisher description

AJAXX Data Scrubber in ChatGPT provides read-only information about digital privacy risks and data broker exposure. It explains how personal data appears online, how removal services work, and answers co…

Show in context →
SecurityVersion 1.0.0
View details →
Codex SecurityOpenAICodex Security workflows for security scans, analysis, and investigation.

Plugin name

Codex Security

Show in context →
3 more matching sources

Package name

codex-security

Show in context →

Publisher description

Codex Security workflows for security scans, analysis, and investigation.

Show in context →

Publisher full description

Codex Security packages reusable workflows for security scans, analysis, validation, and investigation across code, diffs, and related artifacts.

Show in context →
SecurityVersion 0.1.31
View details →
Codex Security CloudOpenAICloud security scans, findings, and continuous repository monitoring.

Plugin name

Codex Security Cloud

Show in context →
2 more matching sources

Publisher subtitle

Find and fix vulnerabilities across your repositories

Show in context →

Publisher full description

Codex Security Cloud brings cloud security scans, findings, and continuous repository monitoring into your workspace.

Show in context →
SecurityVersion 0.1.1
View details →
ProofXCyberSec AI LtdProofX protects your digital content with cryptographic signatures. What you can do: - Protect your articles, poems, scripts, code, and ...

Plugin name

ProofX

Show in context →
1 more matching sources

Publisher description

ProofX protects your digital content with cryptographic signatures. What you can do: - Protect your articles, poems, scripts, code, and text with tamper-proof cryptographic proof - Verify if content is reg…

Show in context →
SecurityVersion 1.0.0
View details →
Aivana Security InvestigatorAivanaGuided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.

Package name

aivana-xdr-investigator

Show in context →
3 more matching sources

Publisher capabilities · listing

Direct OAuth/OBO Defender XDR KQL API Read-only cross-domain investigations Evidence packages and analyst review

Show in context →

Publisher keywords · listing

defender-xdr soc security-investigation kql microsoft-graph sentinel

Show in context →

Publisher full description

Translates user requests into transparent KQL and executes bounded, read-only Defender XDR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response execution.

Show in context →
SecurityVersion 1.1.1
View details →
Tahr SecurityTahr Security IncEvidence-backed application security workflows for finding, validating, and fixing vulnerabilities.

Package name

tahr-codex-plugin

Show in context →
2 more matching sources

Publisher description

Evidence-backed application security workflows for finding, validating, and fixing vulnerabilities.

Show in context →

Publisher full description

…, tests authentication and access controls, traces dangerous inputs, models threats, and verifies fixes.

Show in context →
SecurityVersion 0.3.3
View details →
Authorised OSINT ToolkitRobert LaneNine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting.

Publisher subtitle

Authorised exposure analysis

Show in context →
4 more matching sources

Publisher capabilities · listing

Plan lawful defensive OSINT reviews Assess organisational attack surfaces Review email and cloud exposure Analyse identity security architecture Design exposure monitoring processes Quantify and prioritise security risk Produce evidence-led security reports

Show in context →

Publisher keywords · listing

defensive-osint attack-surface exposure-analysis security risk

Show in context →

Publisher description

Nine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting.

Show in context →

Publisher full description

A nine-skill toolkit for authorised organisational OSINT, attack-surface analysis, email and cloud exposure review, identity-security assurance, monitoring design, risk quantification and evidence-led reporting. The replacement planning, identity and exposure-analysis skills exclude credentials, acc…

Show in context →
SecurityVersion 1.1.0
View details →
BreezeBreeze SecurityBreeze helps authenticated users explore their organization's security posture, connected integrations, scan status, tenants, and entity ...

Publisher subtitle

Explore security posture

Show in context →
1 more matching sources

Publisher description

Breeze helps authenticated users explore their organization's security posture, connected integrations, scan status, tenants, and entity risk data through ChatGPT and Codex.

Show in context →
SecurityVersion 1.0.0
View details →
CalmidoCalmidoLook up who is behind a phone number in the Netherlands, Belgium or Luxembourg: community reports, spam and scam categories, a trust verd...

Publisher subtitle

Look up Benelux phone numbers

Show in context →
1 more matching sources

Publisher description

Look up who is behind a phone number in the Netherlands, Belgium or Luxembourg: community reports, spam and scam categories, a trust verdict and the registered business, from Calmido's phone directory. Use it when someone asks who called them, whether a number is safe,…

Show in context →
SecurityVersion 1.0.0
View details →
DecionisBinariesDecionis is an execution-authority layer for AI agents. Before an agent takes a consequential action, Decionis evaluates the proposed act...

Publisher subtitle

Execution Authority

Show in context →
1 more matching sources

Publisher description

Decionis is an execution-authority layer for AI agents. Before an agent takes a consequential action, Decionis evaluates the proposed action against organization policy and determines whether it may proceed, must be…

Show in context →
SecurityVersion 1.0.1
View details →
Orca SecurityOrca SecurityExtend Orca Security's reasoning into ChatGPT. That means every asset, alert, identity, and dependency is already stitched together in Or...

Publisher subtitle

Fix code, cloud & AI risks.

Show in context →
1 more matching sources

Publisher description

Extend Orca Security's reasoning into ChatGPT. That means every asset, alert, identity, and dependency is already stitched together in Orca’s Unified Data Model before users ask a question. Every answe…

Show in context →
SecurityVersion 1.0.0
View details →
Skill Risk CheckOrbralScan agent skills and plugins locally for reviewable risk patterns before installation.

Publisher capabilities · listing

…ll Find risky instructions, permissions, and downloads Show file-and-line evidence and remediation Export JSON, Markdown, and SARIF Never run or upload the target

Show in context →
2 more matching sources

Publisher keywords · listing

plugin-security agent-skills pre-install-scan prompt-injection supply-chain sarif codex claude-code

Show in context →

Publisher full description

…tructions, broad permissions, suspicious downloads, prompt-injection patterns, and possible secret exposure, then returns ranked findings with file-and-line evidence and remediation. Do not use it as a safety certification; it never runs, installs, enables, or uploads the target.

Show in context →
SecurityVersion 0.1.5
View details →
Atbash SafetyAtbash AIAutomatically guards supported Codex tool calls with Atbash safety judgments and provides secure local setup guidance.

Publisher keywords · listing

atbash codex safety policy guardrails

Show in context →
2 more matching sources

Publisher description

Automatically guards supported Codex tool calls with Atbash safety judgments and provides secure local setup guidance.

Show in context →

Publisher full description

Atbash Safety checks supported Codex tool calls against your Atbash agent's safety policy before execution. The package includes a local PreToolUse hook, the bundled production Atbash SDK, and a setup and troubleshooting skill; it does…

Show in context →
SecurityVersion 0.3.3
View details →
Endor Labs Agent KitEndor LabsEndor Labs security workflows and setup for Codex.

Publisher keywords · listing

endor-labs security sca sast codex

Show in context →
1 more matching sources

Publisher description

Endor Labs security workflows and setup for Codex.

Show in context →
SecurityVersion 2.2.2
View details →
SkarnSkarn Software OÜAudit AI coding sessions and assistant configs with the locally installed skarn CLI: leaked credentials and risky hooks or MCP servers, r...

Publisher keywords · listing

security secrets credential-leak ai-coding-sessions audit codex

Show in context →
1 more matching sources

Publisher full description

…I coding assistants have already written to disk and reports leaked credentials, prompt injection, exfiltration attempts, and the chains that connect them; each finding carries the standards mappings that apply to it, drawn from MITRE ATLAS, the OWASP Top 10 for LLM Applications 2025, the OWASP Agen…

Show in context →
SecurityVersion 0.27.0
View details →
Above SecurityAbove Security

Publisher description

…s an Above Security account and is scoped to your role and company; read and write are governed by explicit OAuth consent.

Show in context →
SecurityVersion 1.0.0
View details →
Authorized Security ReviewIssam Chaaban

Publisher description

Evidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools.

Show in context →
1 more matching sources

Publisher full description

…investigation, validation, and HackerOne report drafting. Does not bundle testing tools or the Codex Security backend.

Show in context →
SecurityVersion 1.0.1
View details →
CertScore.ai Privacy ScannerCertScore.ai, LLC

Publisher description

…ded Accept and Reject observations, policy signals, and HTTPS/TLS. Results preserve provenance and explicit coverage limitations for human review; they are not legal advice, certification, or a compliance determination.

Show in context →
SecurityVersion 2.0.0
View details →
Cloudflare SecurityThe Doers Firm

Publisher full description

…horized read-only account data and supplied code to produce evidence-backed findings, prioritized fixes, side-effect warnings, and verification steps. Customer support: https://thedoersfirm.com/support. It cannot guarantee complete security.

Show in context →
SecurityVersion 0.1.0
View details →
GuardioGuardio

Publisher full description

Guardio helps you check suspicious links and understand your online protection from ChatGPT and Codex. Check a website before opening it, or check links extracted from a suspicious message without sending the message body to Guardio. Connect your Guardio account to review protection setup, scan acti…

Show in context →
SecurityVersion 0.2.2
View details →
Neura Relay MCPRoman Pelevin

Publisher description

Neura Relay MCP helps ChatGPT-connected workflows review proposed agent actions before execution. It returns Decision Receipts, trace refs, and Registry context without executing downstream actions or exposing private payloads.

Show in context →
SecurityVersion 1.0.0
View details →
PalisadeSamuel Chenard

Publisher description

…F records, and retrieve remediation tasks with supporting evidence. Use the results to prioritize fixes and prepare DNS change plans. This plugin provides read-only access to your Palisade account: it does not publish DNS records, modify domains, send email, or manage billing. A Palisade account is…

Show in context →
SecurityVersion 1.0.0
View details →
PrivacyHawkPrivacyHawk, Inc

Publisher description

…ontrol of Your Personal Data -- Manage, control, and delete your data from thousands of businesses exploiting your personal information. PrivacyHawk helps you reduce your digital footprint, decrease spam, and protect yourself from identity theft, scams, and hacks. Key Features: - Delete your data fr…

Show in context →
SecurityVersion 1.0.0
View details →
Prompt Injection SecurityThe Doers Firm

Publisher description

Assess prompt injection exposure in prompts, AI workflows, retrieved content, and tool designs with evidence-based findings and mitigations.

Show in context →
SecurityVersion 0.1.0
View details →
Radar LiteRed Sift

Publisher description

…zed findings and remediation guidance. Try prompts like: - Radar Lite Evaluate the DNS security of example.com - Radar Lite Compare the DMARC configuration of domain1.com to domain2.com - Radar Lite Give me an assessment of the overall security posture of domain1.com, domain2.com and domain3.com You…

Show in context →
SecurityVersion 2.0.0
View details →
SoluverySoluvery Inc.

Publisher description

Soluvery scans your Google Drive in real time and shows you exactly which files are publicly shared or accessible by specific people. No setup needed — just ask.

Show in context →
SecurityVersion 1.0.0
View details →
ToolCheck by M8venM8ven Inc.

Publisher description

…ted / Caution / Concern), backed by static code analysis, runtime behavioral observation in a sandbox, CVE scanning, and a semantic check comparing the tool's declared behavior against what its code actually does — catching the gap between "read-only market data" and code that can move your funds.

Show in context →
SecurityVersion 1.0.0
View details →
Vibe Code Security ReviewerThe Doers Firm

Publisher full description

…uthorization, tenant isolation, API leaks and misuse, inputs, secrets, uploads, dependencies, data exposure, AI tools, deployment configuration, and abuse paths, then prioritizes findings with practical remediation and verification steps.

Show in context →
SecurityVersion 0.1.0
View details →