hodios-security
v2026.1002.0Hodios security entries: prompts, personas and workflows.
By Hodios contributorsLicense: CC0-1.00 GitHub starsUpdated 1 hour ago
Directory evidence
- Runtimes
- Claude Code
- Parsed components
- 5 skill or MCP entries
- Source updated
- Oct 2, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install hodios-security for Claude Code
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install hodios-security@agent-plugin-marketplacePaste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/hermes-hq/hodios-distClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/hodios-security/.
Plugin files
├── .claude-plugin/plugin.json├── skills/audit-dependencies/SKILL.md├── skills/handle-leaked-secret/SKILL.md├── skills/harden-web-app-config/SKILL.md├── skills/review-auth-flow/SKILL.md└── skills/review-llm-app-security/SKILL.md
Included Skills5
Triages dependency scan findings by reachability and exploitability, gives the upgrade path, and justifies anything safe to defer. Use when a scanner reports more than the team can fix at once.
Guides the response to a leaked credential in the right order - revoke and rotate, scope the blast radius, purge copies and prevent a repeat. Use the moment a key, token or password is exposed.
Produces hardened HTTP security headers, a Content Security Policy, CORS and cookie settings for a web app, rolled out first in report-only mode. Use before launch or after a security scan.
Reviews an authentication or session design (OAuth or OIDC, tokens, cookies, MFA, password reset) for known flaws, with attack paths and fixes. Use before building or shipping login and session code.
Reviews an LLM app for prompt injection, data exfiltration through tools, excessive agency and unsafe output handling, mapped to the OWASP LLM Top 10. Use before shipping an agent or RAG feature.
Plugin manifests1
{
"name": "hodios-security",
"version": "2026.1002.0",
"description": "Hodios security entries: prompts, personas and workflows.",
"author": {
"name": "Hodios contributors",
"url": "https://github.com/hermes-hq/hodios"
},
"homepage": "https://hermes-ide.com/prompts",
"repository": "https://github.com/hermes-hq/hodios",
"license": "CC0-1.0",
"keywords": [
"ai-security",
"blast-radius",
"cookies",
"cors",
"credential-leak",
"csp",
"cve",
"excessive-agency",
"hsts",
"jwt",
"mfa",
"oauth",
"oidc",
"owasp",
"owasp-llm",
"prompt-injection",
"sca",
"secret-rotation",
"secret-scanning",
"security",
"security-headers",
"session-management",
"supply-chain",
"threat-model",
"vex"
]
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[hodios-security on Agent Plugins Marketplace](https://pluginsmp.com/plugins/hodios-security)