Skip to content

Add claude-security-audit to Security, Compliance, & Legal - #513

Open
TobiasVeiga00 wants to merge 1 commit into
ccplugins:mainfrom
TobiasVeiga00:add-claude-security-audit
Open

TobiasVeiga00 wants to merge 1 commit into
ccplugins:mainfrom
TobiasVeiga00:add-claude-security-audit

Conversation

@TobiasVeiga00

Copy link
Copy Markdown

Adds claude-security-audit — an open-source (MIT) Claude Code plugin that turns the agent into an end-to-end security auditor across web, API, mobile, cloud, code, secrets, dependencies, IaC, containers, LLM apps and the agent/MCP supply chain.

Highlights: adversarial validation (the finder never confirms its own finding), dual CVSS v3.1/v4.0, priority fused from EPSS + CISA KEV + reachability, 13 scanner importers, a CI severity gate with committed .auditignore suppressions, OpenVEX output, and a scanner for MCP servers/skills/hooks (tool poisoning, unpinned/remote servers, secrets). One alphabetical entry in the Security section.

🤖 Generated with Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant