Agent Plugins Marketplace
All plugins

security-scanning

v1.3.2

SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and automated security hardening

CodexClaude Code5 Skills

By Seth HobsonLicense: MIT39.9k GitHub starsUpdated 3 days ago

Directory evidence

Runtimes
Codex and Claude Code
Parsed components
5 skill or MCP entries
Source updated
Sep 21, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology

Install security-scanning for Codex and Claude Code

Installs for the current user
codex plugin marketplace add wshobson/agents
codex plugin marketplace upgrade claude-code-workflows
codex plugin add security-scanning@claude-code-workflows

Paste and run these commands in a terminal with Codex. They add and refresh the claude-code-workflows catalog, then install this plugin.

Compatibility: the page URL and API slug “security-scanning” remain stable.

  • Codex: security-scanning@agent-plugin-marketplacesecurity-scanning@claude-code-workflows

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/wshobson/agents

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/security-scanning/.

Plugin files

plugins/security-scanning/
├── .codex-plugin/plugin.json
├── .claude-plugin/plugin.json
├── skills/attack-tree-construction/SKILL.md
├── skills/sast-configuration/SKILL.md
├── skills/security-requirement-extraction/SKILL.md
├── skills/stride-analysis-patterns/SKILL.md
└── skills/threat-mitigation-mapping/SKILL.md

Included Skills5

attack-tree-constructionskills/attack-tree-construction/SKILL.md

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

sast-configurationskills/sast-configuration/SKILL.md

Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automating code vulnerability detection.

security-requirement-extractionskills/security-requirement-extraction/SKILL.md

Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.

stride-analysis-patternsskills/stride-analysis-patterns/SKILL.md

Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

threat-mitigation-mappingskills/threat-mitigation-mapping/SKILL.md

Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.

Plugin manifests2

plugins/security-scanning/.codex-plugin/plugin.json
{
  "name": "security-scanning",
  "version": "1.3.2",
  "description": "SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and automated security hardening",
  "skills": "./skills/",
  "author": {
    "name": "Seth Hobson",
    "email": "[email protected]"
  },
  "license": "MIT",
  "interface": {
    "displayName": "Security Scanning",
    "shortDescription": "SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and…",
    "category": "Coding"
  }
}
plugins/security-scanning/.claude-plugin/plugin.json
{
  "name": "security-scanning",
  "version": "1.3.2",
  "description": "SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and automated security hardening",
  "author": {
    "name": "Seth Hobson",
    "email": "[email protected]"
  },
  "license": "MIT"
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[security-scanning on Agent Plugins Marketplace](https://pluginsmp.com/plugins/security-scanning)