Agent Plugins Marketplace
← All plugins

security-audit

v0.3.0

Scan codebases for hardcoded secrets, credentials, API keys, and common security vulnerabilities

Claude Code1 Skill

By Kuoshih YangLicense: Apache-2.05 GitHub starsUpdated 1 hour ago

Directory evidence

Runtimes
Claude Code
Parsed components
1 skill or MCP entry
Source updated
Sep 28, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install security-audit for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install security-audit-2@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/YangKuoshih/security-audit

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The repository root is the plugin root.

Plugin files

security-audit/
├── .claude-plugin/plugin.json
└── skills/security-audit/SKILL.md

Included Skills1

security-auditskills/security-audit/SKILL.md

Run a lightweight, local security scan of source repositories for hardcoded secrets, risky tracked files, and common vulnerability patterns, then triage redacted findings and produce Markdown, JSON, or SARIF. Use for secret scans, incremental security checks, repository security audits, or GitHub Code Scanning output. Do not use as a dependency-CVE scanner, a substitute for a full SAST/DAST assessment, or for ordinary non-security code review.

Plugin manifests1

.claude-plugin/plugin.json
{
  "name": "security-audit",
  "version": "0.3.0",
  "description": "Scan codebases for hardcoded secrets, credentials, API keys, and common security vulnerabilities",
  "author": {
    "name": "Kuoshih Yang"
  },
  "license": "Apache-2.0",
  "keywords": [
    "security",
    "secrets",
    "scanning",
    "audit",
    "owasp",
    "vulnerabilities"
  ]
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[security-audit on Agent Plugins Marketplace](https://pluginsmp.com/plugins/security-audit-2)