Agent Plugins Marketplace
← All plugins

hodios-security

v2026.1002.0

Hodios security entries: prompts, personas and workflows.

Claude Code5 Skills

By Hodios contributorsLicense: CC0-1.00 GitHub starsUpdated 1 hour ago

Directory evidence

Runtimes
Claude Code
Parsed components
5 skill or MCP entries
Source updated
Oct 2, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install hodios-security for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install hodios-security@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/hermes-hq/hodios-dist

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/hodios-security/.

Plugin files

plugins/hodios-security/
├── .claude-plugin/plugin.json
├── skills/audit-dependencies/SKILL.md
├── skills/handle-leaked-secret/SKILL.md
├── skills/harden-web-app-config/SKILL.md
├── skills/review-auth-flow/SKILL.md
└── skills/review-llm-app-security/SKILL.md

Included Skills5

audit-dependenciesskills/audit-dependencies/SKILL.md

Triages dependency scan findings by reachability and exploitability, gives the upgrade path, and justifies anything safe to defer. Use when a scanner reports more than the team can fix at once.

handle-leaked-secretskills/handle-leaked-secret/SKILL.md

Guides the response to a leaked credential in the right order - revoke and rotate, scope the blast radius, purge copies and prevent a repeat. Use the moment a key, token or password is exposed.

harden-web-app-configskills/harden-web-app-config/SKILL.md

Produces hardened HTTP security headers, a Content Security Policy, CORS and cookie settings for a web app, rolled out first in report-only mode. Use before launch or after a security scan.

review-auth-flowskills/review-auth-flow/SKILL.md

Reviews an authentication or session design (OAuth or OIDC, tokens, cookies, MFA, password reset) for known flaws, with attack paths and fixes. Use before building or shipping login and session code.

review-llm-app-securityskills/review-llm-app-security/SKILL.md

Reviews an LLM app for prompt injection, data exfiltration through tools, excessive agency and unsafe output handling, mapped to the OWASP LLM Top 10. Use before shipping an agent or RAG feature.

Plugin manifests1

plugins/hodios-security/.claude-plugin/plugin.json
{
  "name": "hodios-security",
  "version": "2026.1002.0",
  "description": "Hodios security entries: prompts, personas and workflows.",
  "author": {
    "name": "Hodios contributors",
    "url": "https://github.com/hermes-hq/hodios"
  },
  "homepage": "https://hermes-ide.com/prompts",
  "repository": "https://github.com/hermes-hq/hodios",
  "license": "CC0-1.0",
  "keywords": [
    "ai-security",
    "blast-radius",
    "cookies",
    "cors",
    "credential-leak",
    "csp",
    "cve",
    "excessive-agency",
    "hsts",
    "jwt",
    "mfa",
    "oauth",
    "oidc",
    "owasp",
    "owasp-llm",
    "prompt-injection",
    "sca",
    "secret-rotation",
    "secret-scanning",
    "security",
    "security-headers",
    "session-management",
    "supply-chain",
    "threat-model",
    "vex"
  ]
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[hodios-security on Agent Plugins Marketplace](https://pluginsmp.com/plugins/hodios-security)