Agent Plugins Marketplace
← All plugins

pm-security

v1.0.0

Hands-on application & operational security skills: Threat Model (STRIDE), Security Review, Vulnerability Triage (CVSS), Security Incident Response, and Pentest Report. Defensive security and authorized testing for systems you own or are permitted to assess.

Claude Code6 Skills

By Mohit AggarwalLicense: MIT1.4k GitHub starsUpdated 2 days ago

Directory evidence

Runtimes
Claude Code
Parsed components
6 skill or MCP entries
Source updated
Oct 4, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install pm-security for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install pm-security@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/mohitagw15856/pm-claude-skills

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/pm-security/.

Plugin files

plugins/pm-security/
├── .claude-plugin/plugin.json
├── skills/pentest-report/SKILL.md
├── skills/security-incident-response/SKILL.md
├── skills/security-review/SKILL.md
├── skills/skill-vetting/SKILL.md
├── skills/threat-model/SKILL.md
└── skills/vuln-triage/SKILL.md

Included Skills6

pentest-reportskills/pentest-report/SKILL.md

Write a clear penetration-test report from findings of an authorized engagement. Use when documenting a pentest, security assessment, or authorized red-team engagement — turning findings into a report clients act on. Produces an executive summary, scope & methodology, findings with severity/evidence/reproduction/remediation, and a risk-ranked remediation plan. For authorized testing only.

security-incident-responseskills/security-incident-response/SKILL.md

Run or document a security incident response — contain, eradicate, recover, and learn. Use when responding to a breach/compromise/security incident, writing an IR plan or runbook, or producing a post-incident report. Produces a phase-by-phase response (triage, contain, eradicate, recover, post-incident) with the immediate actions, comms, evidence-handling, and a blameless review. For incidents on systems you own or defend.

security-reviewskills/security-review/SKILL.md

Review a design, PR, or feature for security issues before it ships. Use when asked to do a security review, security-review a change/PR, or check a feature for vulnerabilities. Produces a structured review across the common risk areas (authn/authz, input handling, secrets, data exposure, dependencies), findings ranked by severity with concrete fixes, and a ship / fix-first verdict. For code and systems you own or are authorized to review.

skill-vettingskills/skill-vetting/SKILL.md

Vet an agent skill before installing it — read the SKILL.md and any scripts for the red-flag patterns (credential access, obfuscation, exfiltration, prompt injection), audit its blast radius, and produce a risk-tiered verdict. Use when asked is this skill safe to install, vet this SKILL.md, review this skill from a marketplace, or check what this skill can do to my machine. Produces the risk classification with quoted evidence, the permission-surface audit, the red-flag checklist results, and an install/sandbox/reject recommendation.

threat-modelskills/threat-model/SKILL.md

Threat-model a system or feature to find where it could be attacked, before you build it. Use when asked to threat-model, do a security design review, identify attack surface, or apply STRIDE to a design. Produces a structured threat model: assets, trust boundaries and data flows, threats enumerated by category (STRIDE), and prioritized mitigations. Defensive security for systems you own or are authorized to assess.

vuln-triageskills/vuln-triage/SKILL.md

Triage a vulnerability or scanner finding — assess real severity, exploitability, and how urgently to fix. Use when asked to triage a CVE, prioritize scanner/pentest findings, assess a vuln's risk, or decide what to patch first. Produces a triage verdict: CVSS-informed severity adjusted for your context, exploitability, real risk, a fix/mitigation, and an SLA — so you fix what matters, not just what's red.

Plugin manifests1

plugins/pm-security/.claude-plugin/plugin.json
{
  "$schema": "https://anthropic.com/claude-code/plugin.schema.json",
  "name": "pm-security",
  "version": "1.0.0",
  "description": "Hands-on application & operational security skills: Threat Model (STRIDE), Security Review, Vulnerability Triage (CVSS), Security Incident Response, and Pentest Report. Defensive security and authorized testing for systems you own or are permitted to assess.",
  "author": {
    "name": "Mohit Aggarwal",
    "email": "[email protected]"
  },
  "homepage": "https://github.com/mohitagw15856/pm-claude-skills",
  "license": "MIT",
  "keywords": [
    "security",
    "appsec",
    "threat-modeling",
    "stride",
    "vulnerability",
    "incident-response",
    "pentest",
    "owasp"
  ]
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[pm-security on Agent Plugins Marketplace](https://pluginsmp.com/plugins/pm-security)