forge-kit-security
v0.14.8security-auditor and api-security-tester agents, the OWASP API checklist and opt-in privacy-regime skills, and the leak-guard for a repo about to go public.
By agigante800 GitHub starsUpdated 1 hour ago
Directory evidence
- Runtimes
- Claude Code
- Parsed components
- 3 skill or MCP entries
- Source updated
- Oct 2, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install forge-kit-security for Claude Code
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install forge-kit-security@agent-plugin-marketplacePaste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/agigante80/forge-kitClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/forge-kit-security/.
Plugin files
├── .claude-plugin/plugin.json├── skills/leak-guard/SKILL.md├── skills/owasp-api-security/SKILL.md└── skills/privacy-regime/SKILL.md
Included Skills3
Stop the developer's own machine leaking into a repository that is about to be made public. Home paths, "~/" roots and email addresses are caught in the open by a CI-runnable scanner; private project names are caught by a list held OUTSIDE the repository, because a committed denylist of the names you are hiding is an index pointing at them. Use when setting up a repo that will go public, when a scan reports a hit, or when someone asks how to remove something already pushed.
OWASP API Security Top 10 testing patterns, injection payloads, auth bypass vectors, and security test generation for REST APIs. Use when writing security tests, reviewing API endpoints for vulnerabilities, or auditing input validation.
Name this project's privacy regime and its concrete obligations, so the ticket gate asks the RIGHT compliance questions instead of a default jurisdiction's. Use when setting up governance for a project that stores personal data, when the gate's personal-data questions do not match your jurisdiction, or when asked about GDPR, UK GDPR, CCPA, CPRA, LGPD, PIPEDA, APPI or any other privacy regime.
Plugin manifests1
{
"name": "forge-kit-security",
"description": "security-auditor and api-security-tester agents, the OWASP API checklist and opt-in privacy-regime skills, and the leak-guard for a repo about to go public.",
"version": "0.14.8",
"author": {
"name": "agigante80",
"url": "https://github.com/agigante80"
}
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[forge-kit-security on Agent Plugins Marketplace](https://pluginsmp.com/plugins/forge-kit-security)