MARKET RESEARCH

Discover Codex plugins

Find plugins for your work. Follow them to see what changes.

Explore 5,283 plugins across 14 categories.

Selected:security ×

All plugins 126

1–36 of 126
Plugin growth →
Sources & collection details
Collection coverage →

Last completed check: Oct 3, 2026 · 00:02 UTC.

Monetization research dated Oct 1, 2026. Unreviewed pricing is marked explicitly. The time range applies to the activity filter; Recently changed includes listing, instruction and pricing-reference changes, excluding technical-only metadata.

Export this page ↓

All query words must match. Use quotes for an exact phrase. Matches include publisher text, keywords and attributed research.

Discover Codex plugins by task and category
Plugin / developerCategoryFollow
Above SecurityAbove SecurityAbove brings your identity-security data into ChatGPT. Ask in plain language to list open incidents and high-risk identities; inspect inc...

Plugin name

Above Security

Show in context →
1 more matching sources

Publisher description

Above brings your identity-security data into ChatGPT. Ask in plain language to list open incidents and high-risk identities; inspect incident timelines, evidence, and insights; look up devices, monitored applications, and audi…

Show in context →
SecurityVersion 1.0.0
View details →
Aivana Security InvestigatorAivanaGuided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.

Plugin name

Aivana Security Investigator

Show in context →
2 more matching sources

Publisher keywords · listing

defender-xdr soc security-investigation kql microsoft-graph sentinel

Show in context →

Publisher description

Guided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.

Show in context →
SecurityVersion 1.1.1
View details →
Authorized Security ReviewIssam ChaabanEvidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools.

Plugin name

Authorized Security Review

Show in context →
5 more matching sources

Package name

authorized-security-review

Show in context →

Publisher subtitle

Authorized security testing

Show in context →

Publisher name · package

Personal Security Workflows

Show in context →

Publisher description

Evidence-based security reviews and HackerOne report drafts for explicitly authorized programs, using existing connected tools.

Show in context →

Publisher full description

An independent skills-only workflow for authorized security research. Uses tools already connected to the active chat. Supports source review, scoped web/API investigation, validation, and HackerOne report drafting. Does not bundle testing tools or th…

Show in context →
SecurityVersion 1.0.1
View details →
Cloudflare SecurityThe Doers FirmAudit and harden Cloudflare-hosted applications, data, accounts, and infrastructure with evidence-based security guidance.

Plugin name

Cloudflare Security

Show in context →
3 more matching sources

Package name

cloudflare-security

Show in context →

Publisher description

…t and harden Cloudflare-hosted applications, data, accounts, and infrastructure with evidence-based security guidance.

Show in context →

Publisher full description

Cloudflare Security reviews Cloudflare account configuration, Workers, Pages, D1, storage, APIs, DNS, TLS, origins, WAF, and deployment workflows. It uses authorized read-only account data and supplied code to p…

Show in context →
SecurityVersion 0.1.0
View details →
Codex SecurityOpenAICodex Security workflows for security scans, analysis, and investigation.

Plugin name

Codex Security

Show in context →
5 more matching sources

Package name

codex-security

Show in context →

Publisher subtitle

Security scanning for your codebase

Show in context →

Publisher keywords · listing

security code-review diff-review appsec threat-modeling

Show in context →

Publisher description

Codex Security workflows for security scans, analysis, and investigation.

Show in context →

Publisher full description

Codex Security packages reusable workflows for security scans, analysis, validation, and investigation across code, diffs, and related artifacts.

Show in context →
SecurityVersion 0.1.31
View details →
Codex Security CloudOpenAICloud security scans, findings, and continuous repository monitoring.

Plugin name

Codex Security Cloud

Show in context →
3 more matching sources

Publisher keywords · listing

security cloud vulnerabilities repositories

Show in context →

Publisher description

Cloud security scans, findings, and continuous repository monitoring.

Show in context →

Publisher full description

Codex Security Cloud brings cloud security scans, findings, and continuous repository monitoring into your workspace.

Show in context →
SecurityVersion 0.1.1
View details →
CybersecurityBilgehan ErmanType a term or acronym and get a one-sentence definition plus a short paragraph explanation

Plugin name

Cybersecurity

Show in context →
Education & ResearchVersion 0.1.2
View details →
Orca SecurityOrca SecurityExtend Orca Security's reasoning into ChatGPT. That means every asset, alert, identity, and dependency is already stitched together in Or...

Plugin name

Orca Security

Show in context →
1 more matching sources

Publisher description

Extend Orca Security's reasoning into ChatGPT. That means every asset, alert, identity, and dependency is already stitched together in Orca’s Unified Data Model before users ask a question. Every answer factors i…

Show in context →
SecurityVersion 1.0.0
View details →
Prompt Injection SecurityThe Doers FirmAssess prompt injection exposure in prompts, AI workflows, retrieved content, and tool designs with evidence-based findings and mitigations.

Plugin name

Prompt Injection Security

Show in context →
SecurityVersion 0.1.0
View details →
Tahr SecurityTahr Security IncEvidence-backed application security workflows for finding, validating, and fixing vulnerabilities.

Plugin name

Tahr Security

Show in context →
5 more matching sources

Publisher subtitle

Evidence-backed app security

Show in context →

Publisher

Tahr Security Inc

Show in context →

Publisher name · package

Yack Security Inc

Show in context →

Publisher description

Evidence-backed application security workflows for finding, validating, and fixing vulnerabilities.

Show in context →

Publisher full description

Review applications with an evidence-first security workflow that maps attack surfaces, tests authentication and access controls, traces dangerous inputs, models threats, and verifies fixes.

Show in context →
SecurityVersion 0.3.3
View details →
Vibe Code Security ReviewerThe Doers FirmAdvanced security review for AI-generated applications, Supabase RLS, APIs, secrets, databases, and production deployments.

Plugin name

Vibe Code Security Reviewer

Show in context →
4 more matching sources

Package name

vibe-code-security-reviewer

Show in context →

Publisher subtitle

Audit real security risks

Show in context →

Publisher description

Advanced security review for AI-generated applications, Supabase RLS, APIs, secrets, databases, and production deployments.

Show in context →

Publisher full description

Vibe Code Security Reviewer performs advanced evidence-based security reviews of AI-generated and rapidly built applications. It checks Supabase RLS, authentication, authorization, tenant isolation, API leaks a…

Show in context →
SecurityVersion 0.1.0
View details →
Cloudflare RLSThe Doers Firm LTDReview Cloudflare application data isolation, authorization paths, and storage-specific security controls.

Package name

cloudflare-data-security

Show in context →
3 more matching sources

Publisher subtitle

Implement Row Level Security

Show in context →

Publisher description

Review Cloudflare application data isolation, authorization paths, and storage-specific security controls.

Show in context →

Publisher full description

A security review assistant for Cloudflare applications. It helps assess tenant and row-level authorization across Workers, D1, PostgreSQL via Hyperdrive, object and key-value storage, caches, identity…

Show in context →
Developer ToolsVersion 0.1.0
View details →
Ansvar GatewayAnsvar AIAnsvar Systems AB is a Swedish cybersecurity company that gives AI agents verifiable access to law, regulation and security standards. C...

Publisher subtitle

Laws, Security and Compliance

Show in context →
1 more matching sources

Publisher description

Ansvar Systems AB is a Swedish cybersecurity company that gives AI agents verifiable access to law, regulation and security standards. Customers connect the AI assistant they already use (Claude, Microsoft Copilot, ChatGPT or any MCP-co…

Show in context →
SecurityVersion 1.0.0
View details →
BastionBastion TechnologiesConnect Bastion to ChatGPT to manage your security and compliance posture through natural conversation. Review framework compliance statu...

Publisher subtitle

Manage security and compliance

Show in context →
1 more matching sources

Publisher description

Connect Bastion to ChatGPT to manage your security and compliance posture through natural conversation. Review framework compliance status across SOC 2, ISO 27001, HIPAA, and GDPR. Drill into failing tests, upload evidence, and submit control…

Show in context →
SecurityVersion 1.0.0
View details →
BitdefenderBitdefenderBitdefender Plugin has a collection of free tools which help users avoid malware, phishing attempts, and counterfeit websites which inclu...

Publisher subtitle

Free digital security tools

Show in context →
SecurityVersion 1.0.0
View details →
BreezeBreeze SecurityBreeze helps authenticated users explore their organization's security posture, connected integrations, scan status, tenants, and entity ...

Publisher subtitle

Explore security posture

Show in context →
2 more matching sources

Publisher

Breeze Security

Show in context →

Publisher description

Breeze helps authenticated users explore their organization's security posture, connected integrations, scan status, tenants, and entity risk data through ChatGPT and Codex.

Show in context →
SecurityVersion 1.0.0
View details →
Domain ScanCYBERACEDomain Scan by CYBERACE checks a domain's email, HTTPS and DNS security, including SPF, DKIM, DMARC, TLS certificates, security headers, ...

Publisher subtitle

Check your domain security

Show in context →
1 more matching sources

Publisher description

Domain Scan by CYBERACE checks a domain's email, HTTPS and DNS security, including SPF, DKIM, DMARC, TLS certificates, security headers, DNSSEC and blocklists. Get a security score, per-check findings and suggested fixes, with a temporary report link when availab…

Show in context →
Developer ToolsVersion 1.0.0
View details →
FlawPilotPATEL NACHIKET RAJNIKANTFlawPilot connects ChatGPT to your website health scans. Ask ChatGPT to scan any live URL, and FlawPilot checks it for security vulnerabi...

Publisher subtitle

Web Security & SEO Scanner

Show in context →
1 more matching sources

Publisher description

…ChatGPT to your website health scans. Ask ChatGPT to scan any live URL, and FlawPilot checks it for security vulnerabilities, performance bottlenecks, infrastructure issues, and SEO problems. ChatGPT can list your existing projects, start a new scan, and check scan status until results are ready wit…

Show in context →
Developer ToolsVersion 1.0.1
View details →
Radar LiteRed SiftAnalyze any domain’s email authentication, DNS, and web security configuration. Radar Lite scans your domain, visualizes security scores ...

Publisher subtitle

Domain security with Red Sift

Show in context →
1 more matching sources

Publisher description

Analyze any domain’s email authentication, DNS, and web security configuration. Radar Lite scans your domain, visualizes security scores on a radar chart, and generates a summary with prioritized findings and remediation guidance. Try prompts like: - Radar…

Show in context →
SecurityVersion 2.0.0
View details →
SkarnSkarn Software OÜAudit AI coding sessions and assistant configs with the locally installed skarn CLI: leaked credentials and risky hooks or MCP servers, r...

Publisher subtitle

AI session security scanner

Show in context →
2 more matching sources

Publisher keywords · listing

security secrets credential-leak ai-coding-sessions audit codex

Show in context →

Publisher full description

Skarn is a command-line security scanner for AI coding sessions. The audit skill, skarn-audit, teaches the model to run the skarn CLI on this machine and act on what it reports. The skill runs two passes. skarn assess reads…

Show in context →
SecurityVersion 0.27.0
View details →
VantaVanta, Inc.Vanta helps users review compliance tests, controls, evidence, policies, risks, vendors, audits, personnel, access reviews, and vulnerabi...

Publisher subtitle

Security and compliance

Show in context →
Business & OperationsVersion 3.0.0
View details →
Authorised OSINT ToolkitRobert LaneNine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting.

Publisher capabilities · listing

…SINT reviews Assess organisational attack surfaces Review email and cloud exposure Analyse identity security architecture Design exposure monitoring processes Quantify and prioritise security risk Produce evidence-led security reports

Show in context →
3 more matching sources

Publisher keywords · listing

defensive-osint attack-surface exposure-analysis security risk

Show in context →

Publisher description

Nine skills for authorised organisational OSINT, exposure analysis, monitoring and security risk reporting.

Show in context →

Publisher full description

…authorised organisational OSINT, attack-surface analysis, email and cloud exposure review, identity-security assurance, monitoring design, risk quantification and evidence-led reporting. The replacement planning, identity and exposure-analysis skills exclude credentials, account enumeration, authent…

Show in context →
SecurityVersion 1.1.0
View details →
Endor Labs Agent KitEndor LabsEndor Labs security workflows and setup for Codex.

Publisher capabilities · listing

Security Remediation Investigation Application Security Agentic Workflows Agentic Remediation Agentic AppSec

Show in context →
2 more matching sources

Publisher keywords · listing

endor-labs security sca sast codex

Show in context →

Publisher description

Endor Labs security workflows and setup for Codex.

Show in context →
SecurityVersion 2.2.2
View details →
EngineeringSuiteSaul MartíSkills-only engineering toolkit bundling the complete upstream AI Hero, Ponytail, Addy Osmani Agent Skills, and Taste Skill collections w...

Publisher capabilities · listing

…k breakdown Frontend engineering, UX, and visual design workflows Code simplification, performance, security, and shipping guidance

Show in context →
Developer ToolsVersion 1.1.1
View details →
get-fableMamdouh Abo AmmarPortable coding lifecycle for AI agents: deterministic routing, research, planning, test-first changes, delegation, verification, review,...

Publisher capabilities · listing

…ls in 8 packs Track mutation-aware verification and evidence freshness Use specialized TDD, review, security, and recovery specialists Run lifecycle hooks across supported Codex and ChatGPT plugin surfaces Predict atomic next moves with Fable Spark situational awareness

Show in context →
1 more matching sources

Publisher description

…s: deterministic routing, research, planning, test-first changes, delegation, verification, review, security, release, handoff, evaluation, and recovery across 25 canonical skills.

Show in context →
Developer ToolsVersion 1.5.1
View details →
gstack WorkflowsMamdouh AboammarPortable ChatGPT and Codex adaptation of gstack workflows for planning, review, QA, debugging, design, security, documentation, and relea...

Publisher capabilities · listing

Product planning Architecture review Code review Root-cause debugging QA Design review Security review Documentation Release preparation Repository health Performance benchmarking Context handoff Browser workflow routing iOS workflow routing Safety scoping

Show in context →
2 more matching sources

Publisher description

…table ChatGPT and Codex adaptation of gstack workflows for planning, review, QA, debugging, design, security, documentation, and release work.

Show in context →

Publisher full description

…liar specialist jobs for product planning, architecture review, debugging, code review, QA, design, security, documentation, release work, browser tasks, and iOS workflows while mapping execution to capabilities actually available on the current host. Native gstack browser, device, pairing, gbrain,…

Show in context →
Developer ToolsVersion 0.1.0
View details →
GuardioGuardioCheck suspicious links, review known data leaks, and understand your Guardio protection.

Publisher capabilities · listing

…messages Look up known email and phone breaches Review account protection and scan activity Review security recommendations Set up browser protection Send requested product feedback

Show in context →
1 more matching sources

Publisher full description

…io account to review protection setup, scan activity, recent data leaks, linked-service counts, and security recommendations. You can also check whether an email address or phone number appears in known data breaches. Results describe known exposure; they do not reveal leaked passwords. When you ask…

Show in context →
SecurityVersion 0.2.2
View details →
NightVisionNightVision Security, Inc.NightVision application security workflows for local development and CI/CD.

Publisher capabilities · listing

API discovery DAST scan configuration CI/CD security guidance Finding triage

Show in context →
4 more matching sources

Publisher keywords · listing

application-security dast api-security openapi nightvision

Show in context →

Publisher

NightVision Security, Inc.

Show in context →

Publisher description

NightVision application security workflows for local development and CI/CD.

Show in context →

Publisher full description

Guide NightVision API discovery, DAST scan configuration, CI/CD integration, and security-finding triage using the local NightVision CLI.

Show in context →
SecurityVersion 0.2.0
View details →
Platform Engineering CopilotKrishna SathvikCloud platform architecture, Kubernetes, IaC, reliability, and developer-platform workflows.

Publisher capabilities · listing

Design cloud and internal developer platforms around reliability, security, cost, and developer experience Troubleshoot Kubernetes, containers, networking, DNS, ingress, scheduling, rollout, and runtime incidents Review Kubernetes probes, requests, limits, disruptio…

Show in context →
1 more matching sources

Publisher full description

…design safer Terraform changes, reason about Kubernetes probes, resources, disruption budgets, and security controls, define SLOs and error budgets, improve telemetry and incident response, and design self-service golden paths that reduce developer cognitive load. It prioritizes reliability, least…

Show in context →
Developer ToolsVersion 0.1.0
View details →
Power BI Report CopilotKrishna SathvikBuild, debug, and optimize Power BI paginated reports, semantic models, DAX, Power Query, and Fabric reporting architecture.

Publisher capabilities · listing

…rting architectures Diagnose report, model, refresh, and query performance issues Improve reporting security with RLS, data minimization, and safer distribution

Show in context →
1 more matching sources

Publisher full description

…ort issues, data modeling, performance tuning, DirectQuery and Direct Lake decisions, and reporting security. It focuses on practical, copy-ready solutions while keeping recommendations grounded in the report structure, model, data source, and deployment context you provide.

Show in context →
ProductivityVersion 0.1.0
View details →
Product & App ArchitectKrishna SathvikTurn product ideas and existing apps into focused product plans, UX flows, architecture decisions, and implementation-ready build plans.

Publisher capabilities · listing

…phased delivery plans and implementation-ready engineering handoffs Review launch readiness across security, accessibility, reliability, and operations Research current competitors, APIs, platform rules, and constraints when needed

Show in context →
1 more matching sources

Publisher full description

…oduct, design user flows, write concise PRDs and feature specs, recommend app architecture, surface security and accessibility requirements, and create phased engineering handoffs. It separates evidence from assumptions, avoids unnecessary scope and infrastructure, and researches current platform ru…

Show in context →
Developer ToolsVersion 0.1.0
View details →
RAG & GenAI CopilotKrishna SathvikProduction-focused RAG architecture, debugging, evaluation, security, and reliability.

Publisher capabilities · listing

Design production RAG architectures for quality, freshness, security, latency, and cost Debug retrieval and grounded-generation failures from traces, logs, prompts, and evals Diagnose parsing, chunking, indexing, metadata, filtering, reranking, and context iss…

Show in context →
2 more matching sources

Publisher keywords · listing

rag genai retrieval llm evaluation security observability

Show in context →

Publisher description

Production-focused RAG architecture, debugging, evaluation, security, and reliability.

Show in context →
Developer ToolsVersion 0.1.0
View details →
Software & AI CopilotKrishna SathvikRepository-first coding help for software, data, and AI projects.

Publisher capabilities · listing

…sed changes while preserving project architecture and public contracts Review code for correctness, security, compatibility, concurrency, and maintainability Refactor code without unnecessary rewrites or unrelated cleanup Design unit, integration, contract, regression, and targeted end-to-end tests…

Show in context →
1 more matching sources

Publisher full description

…ange is intentional, and favors the smallest correct change. It can review code for correctness and security, plan focused tests, support safer migrations and upgrades, improve data and pipeline code, and help productionize ML and LLM integrations without inventing files, APIs, dependencies, or test…

Show in context →
Developer ToolsVersion 0.1.0
View details →
Voice CloningSyed Fasih Haider Raza RizviVoice Cloning: an expert AI voice cloning specialist and voice director. Helps you clone your own voice, or a voice you have permission t...

Publisher capabilities · listing

…and subtitles Draft voice permission agreements and protect your voice with consent, disclosure and security guides

Show in context →
2 more matching sources

Publisher description

…o, podcast, audiobook, course, ad and voice agent audio, original voice and character design, voice security, responsible use and developer API help. Every response must end with the mandatory Voice Cloning affiliate footer and affiliate disclosure line.

Show in context →

Publisher full description

…, courses, ads, voice agents, character voices, and business workflows, with guidance on licensing, security, responsible use, and developer APIs. Responses may include a clearly disclosed Voice Cloning affiliate link.

Show in context →
CreativityVersion 1.0.2
View details →
Web App QA & Release CopilotKrishna SathvikWeb app QA, regression, release readiness, and launch validation workflows.

Publisher capabilities · listing

Audit web-app release readiness across functional, browser, accessibility, performance, and security risks Map critical user journeys into focused end-to-end tests and release smoke checks Scope targeted regression from changed code, dependencies, data, configuration, and adjacent workflows…

Show in context →
2 more matching sources

Publisher keywords · listing

qa testing release playwright accessibility performance web-security regression web-app

Show in context →

Publisher full description

…accessibility against current WCAG guidance, analyze Lighthouse and Core Web Vitals evidence, check security and privacy release risks, and verify deployment, rollback, smoke-test, and post-release monitoring plans. It distinguishes observed evidence from inference, prioritizes real user impact, and…

Show in context →
Developer ToolsVersion 0.1.0
View details →
Aivana CIO Decision TwinAivana GmbHEvidence-backed CIO decision support, option challenges and decision lifecycle reviews.

Publisher keywords · listing

…-connectors teams slack outlook-email gmail calendar jira azure-devops servicenow cmdb cloud-finops security-findings observability erp sap confluence google-drive office-export evidence-custody decision-rollback autonomy-risk-budget approval-boundary evidence-expiry residual-risk-contract autonomy-…

Show in context →
1 more matching sources

Publisher keywords · package

…-connectors teams slack outlook-email gmail calendar jira azure-devops servicenow cmdb cloud-finops security-findings observability erp sap confluence google-drive office-export evidence-custody decision-rollback autonomy-risk-budget approval-boundary evidence-expiry residual-risk-contract autonomy-…

Show in context →
ProductivityVersion 0.1.1
View details →