Claude resources tagged “security”
120 curated Claude Code resources tagged security in the HeyClaude directory — mostly mcp servers, guides, and tools. 13 of them sit in the trusted tier.
Highlights from this set
Standout entries tagged security, picked by their own metadata — trust tier, provenance, documentation, and recency.
All security resources
/dependency-risk-review - Dependency Risk Review Command for Claude Code
Rank dependency supply-chain risk from OpenSSF Scorecard health signals and OSV advisories, with actions.
/pr-security-review - PR Security Review Command for Claude Code
Review a PR diff for auth, injection, secrets, and dependency security regressions before merge.
/review - Code Review Command for Claude Code
Comprehensive code review with security analysis, performance optimization, and best practices validation
/security - Vulnerability Scan Command for Claude Code
Comprehensive security audit with vulnerability detection, threat analysis, and automated remediation recommendations
AI Code Review Security Agent - Agents
AI-powered code review specialist focusing on security vulnerabilities, OWASP Top 10, static analysis, secrets detection, and automated s...
AI-Generated Path Traversal Review Rules
Review AI-generated file-handling code for path traversal: canonical paths, root confinement, upload filename sanitization, and archive extraction limits.
AI-Generated Regex Safety Review Rules
Review AI-generated regex for ReDoS and catastrophic backtracking, input bounds, anchors, escaping, validation scope, safe engines, and test evidence.
AI-Generated SQL Injection Review Rules
Review AI-generated database code for SQL injection: parameterized queries, safe identifiers, ORM escapes, dynamic SQL limits, and least-privilege access.
AI-Generated SSRF Review Rules
Review AI-generated server-side URL requests for SSRF: URL allow-lists, internal-network blocking, redirect limits, and response isolation.
Auditing MCP Client Configuration Before Team Rollout
Audit MCP client configuration before sharing it with a team.
Auth0 MCP Server for Claude
Official Auth0 MCP server for managing Auth0 tenants from Claude with read-only and scoped tool controls.
Auto Mode Hard-Deny Policies For Safe Automation
Set autoMode.hard_deny rules to block risky actions in auto mode.
AWS CloudTrail MCP Server
Connect Claude to AWS CloudTrail to look up account events, analyze user activity, track API calls, and run CloudTrail Lake SQL for audits.
AWS IAM MCP Server
Connect Claude to AWS IAM to inspect users, roles, groups, and policies, simulate permissions, and (opt-in) manage IAM — read-only mode supported.
Bifrost MCP Gateway
Aggregate MCP tools behind Bifrost's gateway, then expose them through a governed /mcp endpoint with virtual keys, auth, tool filtering, logs, and provider routing.
Build MCP Servers with Auth and Least Privilege
Design MCP servers with auth boundaries and narrow tools.
Claude Code in Regulated Finance Environments
Deploy Claude Code in security-sensitive finance environments.
Claude Code Security Guidance Remediator Agent
Audit a Claude Code setup against official security guidance and produce a ranked remediation plan: permissions, MCP trust, credentials, and hooks.
CLI MCP Server
Connect Claude to tightly scoped, allowlisted command execution.
Cloudflare MCP Server - MCP Servers
Build applications, analyze traffic, and manage security settings through Cloudflare
Codacy MCP Server
Official Codacy MCP server: inspect code-quality and security (SRM) findings, file/PR coverage and duplication, and run local Codacy CLI analysis.
Code Review Automation Capability Pack Skill
Run a local, repeatable PR review loop with severity scoring, false-positive control, and fix-ready output.
Code Reviewer Agent - Agents
Expert code reviewer that provides thorough, constructive feedback on code quality, security, performance, and best practices
ContrastAPI Security Tools
49 remote security tools for CVE risk scoring, MITRE ATLAS/D3FEND, domain audit, IP threat intel, IOC enrichment, web intelligence, and dependency scanning.
Cosign
Sign, verify, and attest containers, binaries, SBOMs, and OCI artifacts.
CVE MCP Server
Connect Claude to CVE, vulnerability, exploit, and threat-intelligence lookup tools.
Dependency Security Audit
Stop hook that runs npm audit, pip-audit, safety, or bundler-audit at session end and saves a timestamped CVE report.
Dependency Update Checker - Hooks
Automatically checks for outdated dependencies and suggests updates with security analysis.
Docker Image Security Scanner - Hooks
Comprehensive Docker image vulnerability scanning with layer analysis, base image recommendations, and security best practices enforcement.
Docker MCP Gateway
Run selected MCP servers in Docker containers, organize them into profiles, connect clients to one gateway, and manage catalogs, secrets, OAuth, tool allowlists, logging, and container limits.
ENScan_GO MCP Server
Connect Claude to ENScan_GO company, ICP, app, and public-data gathering tools.
Environment Validator
Validates environment variables, checks for required vars, and ensures proper configuration across environments.
Ethereum Base Smart Contract Security Capability Pack Skill
Deep smart contract security skill covering Solidity design, test rigor, deployment hygiene, and post-launch risk controls.
Ethereum Solidity Security Foundry Skill
Smart contract development skill focused on secure Solidity architecture, testing rigor, and safer deployment practices.
Ghidra MCP Server by bethington
Connect Claude to Ghidra through a Python bridge and Java extension with decompiler, P-code, debugger, scripting, batch-edit, and headless analysis tools.
GhidraMCP Server
Connect Claude and other MCP clients to Ghidra for assisted binary analysis and reverse engineering.
git-secrets Environment Risk Statusline
Show sensitive environment-file risk with optional git-secrets scanning.
GitHub Actions Secure CI/CD Capability Pack Skill
Deep CI/CD security and reliability skill for GitHub Actions with reusable workflows, policy checks, and hardened automation patterns.
GitHub Actions Security Review Capability Pack Skill
Review GitHub Actions workflows with token scope, secrets, and fork safety checklists.
Gitleaks
Open-source secret scanner for repositories and files.
Grype
Scan images, directories, SBOMs, PURLs, and CPEs for known vulnerabilities.
Hardcoded Secret Pre-Write Guard Hook
Block Write and Edit operations that embed common hardcoded credential shapes.
HashiCorp Vault MCP Server for Claude
HashiCorp's official MCP server: manage Vault mounts, KV secrets, and PKI from Claude.
HexStrike AI MCP Server
Run authorized pentesting and security research workflows through HexStrike AI's MCP server and security-tool orchestration layer.
IDA Pro MCP Server
Connect Claude Code and other MCP clients to IDA Pro or idalib for assisted reverse engineering.
Infisical MCP Server
Official Infisical MCP server: read/create/update/delete secrets and manage projects, environments, folders, and members via Machine Identity or token auth.
JADX AI MCP Server
Connect Claude to JADX-GUI for live Android APK reverse-engineering context.
Kubernetes DevSecOps Engineer for Claude
Expert in Kubernetes DevSecOps with GitOps workflows, pod security standards, RBAC, secret management, and automated security scanning fo...
Kubescape
Scan Kubernetes clusters, manifests, charts, repositories, and images for security risk.
Lockfile Provenance Checker - Claude Code Hook
Flag npm lockfile entries resolved outside the public registry or missing an integrity hash.
MCP Auth Surface Statusline
Show MCP auth-surface hints without exposing secrets in the terminal.
MCP Authorization Review Stack
Review remote MCP auth boundaries with guides, commands, agents, rules, and tooling.
MCP Local Tool Access Rules
Keep MCP local tool access bounded with tool inventories, root limits, transport checks, approval gates, credential separation, and privacy-safe logs.
MCP OAuth Server Hardening Capability Pack Skill
Harden MCP OAuth servers with scope pins, callback, and token storage checklists.
MCP OAuth Token Audience Checklist
Review remote MCP OAuth and token-audience handling before connecting clients.
MCP Proxy for AWS
Bridge Claude, Kiro, and Python agent frameworks to MCP servers on AWS with automatic SigV4 signing, AWS profile selection, read-only mode, retries, timeouts, and public ECR or PyPI installs.
MCP Remote Authorization Boundary Rules
Review remote MCP authorization boundaries before approving OAuth-backed servers.
MCP Remote Server Security Auditor Agent
Review MCP server adoption in Claude Code using official security documentation.
MCP Server Authoring Security Capability Pack Skill
MCP server skill for secure tool design, authorization boundaries, contract stability, and production safety controls.
MCP Server Security Hardening Skill
Harden Model Context Protocol servers with practical controls for auth, tool scope, input validation, and supply-chain risk.
MCP Server Threat Modeling Agent
Threat-model an MCP server before connecting it to Claude Code: trust, tool authority, prompt injection, credentials, and mitigations.
MCP Server URL Allowlist - Claude Code Hook
Block unreviewed remote MCP URLs before they are written into config.
MetaMCP Gateway
Host grouped MCP servers behind managed MetaMCP endpoints with namespaces, API keys, OAuth, tool overrides, inspection, and traffic controls.
Microsoft MCP for Beginners
Learn MCP through Microsoft's hands-on curriculum for servers, clients, security, transports, auth, deployment, Azure, VS Code, and cross-language examples.
Microsoft MCP Gateway
Deploy and manage MCP server adapters in Kubernetes, route clients through session-aware gateway endpoints, register tools, and control access with bearer auth and Entra ID app roles.
n8n Production Security Capability Pack Skill
Deep n8n production security skill for safe AI workflows, credential protection, and incident-ready operations.
NanoClaw Container Isolation Review Capability Pack Skill
Review NanoClaw container isolation with mount scope, credential routing, channel boundaries, and scheduled task blast-radius checklists.
NVIDIA SkillSpector
Scan AI agent skills before installing them with NVIDIA SkillSpector: static checks, optional LLM review, MCP risk analyzers, OSV lookups, and SARIF.
OAuth Patterns For MCP Server Authentication
Configure MCP OAuth with scopes, callbacks, and secure token storage patterns.
Okta MCP Server for Claude
Official Okta self-hosted MCP server for administering Okta orgs from Claude through OAuth-scoped tools and explicit destructive-operation checks.
Open Source PR Security Review Agent
Review public OSS PRs for trust-boundary, CI, secrets, dependency, provenance, and code-security risks before maintainer approval.
OpenClaw Agent Ops Hardening Skill
Production hardening for OpenClaw deployments, including permissions, network segmentation, and abuse-resistant agent controls.
OpenClaw Operator Capability Pack Skill
Deep operational OpenClaw skill for maintaining secure, reliable, and cost-aware multi-agent systems.
OpenSandbox
Sandbox runtime for AI agents with multi-language SDKs, MCP tools, Docker, Kubernetes, egress controls, credential vault, and code execution.
OSV Dependency Risk Statusline
Show dependency vulnerability count from OSV-Scanner JSON.
Package Provenance Checks Before Installing MCP Servers
Verify MCP package provenance and publisher trust before adding servers to Claude Code.
Package Vulnerability Scanner - Hooks
Scans for security vulnerabilities when package.json or requirements.txt files are modified.
Pentest AI MCP Server
Connect Claude to authorized pentest-ai engagements, tools, probes, and findings.
Permission Design for Claude Agent SDK Agents
Least-privilege Agent SDK permissions: the hooks→deny→mode→allow→canUseTool order, allow/deny rules, modes, and a dontAsk lockdown.
Permission Modes for Claude Code Teams
Understand and govern Claude Code permission modes across a team, from default to auto and bypass, with managed-settings controls.
Pinning MCP Server Packages Before Installation
Pin MCP server package versions and verify registry entries before Claude Code installation.
Pre-Write Secret Scanner - Claude Code Hook
Block writes that would commit AWS, GitHub, OpenAI, Slack, Google, or Stripe secrets before they reach disk.
Production Toolkit
Comprehensive system for ensuring code quality, security, and compliance before production deployment.
Prompt Injection Defense For Tool Connected Agents
Reduce prompt injection risk for MCP and tool-connected Claude Code agents.
Prompt Injection Defense Guardrails Skill
Implement practical prompt injection defenses with policy gates, tool constraints, and adversarial test cases.
Prompt-Injection Content Scanner - Claude Code Hook
Warn or block when generated prompt/context files contain common instruction-override, secret-exfiltration, or hidden-command patterns.
Promptfoo
Open-source prompt testing and red-teaming framework.
Protect AI
AI security platform for models and applications.
Remote MCP Server Security Review Checklist
Review remote MCP servers for OAuth, transport, and tool scope before team rollout.
Review AI-Generated Code Before Merge
Review AI-generated pull requests with repeatable security, test, and evidence checks.
Sandbox Boundary Review Agent
Review Claude Code sandbox boundaries: filesystem allow/deny, network allowlists, escape hatches, excluded commands, and credential reads.
Sandboxed Bash Setup For Autonomous Coding Agents
Configure Claude Code bash sandboxing for safer autonomous shell use.
Scrapling MCP Server
Scrape pages, dynamic sites, screenshots, and browser sessions through Scrapling MCP.
Searchcode MCP Server
Analyze and search public Git repositories through a remote code intelligence MCP server.
Secret Handling For MCP Servers And Agent Tools
Handle MCP and agent-tool secrets safely with env expansion, OAuth scopes, keychain storage, and redaction checklists.
Secure Claude Code Hooks For Team Repositories
Secure team Claude Code hooks with review, least-privilege matchers, and rollback.
Secure Claude Code Workstation
Defense-in-depth bundle of secret, dependency, audit, and MCP hardening entries for an agentic Claude Code setup.
Secure Deployment for Claude Agent SDK Applications
Securely deploy Claude Agent SDK apps: isolation choices, least privilege, the proxy credential pattern, and filesystem controls.
Securing Agentic Coding Workflows In Open Source Repos
Secure open-source repos for Claude Code agentic workflows with MCP policy, permissions, review gates, and contributor safety practices.
Security Auditor Expert - CLAUDE.md Rules for Claude Code
Configure Claude as a security expert for vulnerability assessment, penetration testing, and security best practices
Security Scanner Hook - Hooks
Automated security vulnerability scanning that integrates with development workflow to detect and prevent security issues before deployment.
Security-First React Components for Claude
Security-first React component architect with XSS prevention, CSP integration, input sanitization, and OWASP Top 10 mitigation patterns
Semgrep
Static analysis, SAST, secrets, dependency checks, and custom code rules.
Semgrep MCP Server for Claude
Official Semgrep MCP server: scan code for vulnerabilities and run custom rules from Claude.
Sensitive Data Alert Scanner - Hooks
Scans for potential sensitive data exposure and alerts immediately.
Snyk Agent Scan
Scan Claude, Cursor, Codex, Gemini, Windsurf, VS Code, and other local agent configs for MCP and skill supply-chain risks.
Snyk MCP Server for Claude
Connect Claude to Snyk Studio security scans for source code, dependencies, IaC, containers, SBOMs, AI-BOMs, and package-health checks.
Socket MCP Server for Claude
Security analysis and vulnerability scanning for dependencies
SonarQube MCP Server
Connect Claude to SonarQube Server or Cloud for code quality, security, issues, hotspots, measures, quality gates, branches, and snippets.
Stytch MCP Server for Claude
Configure and manage Stytch authentication services and workspace settings
Syft
Generate SBOMs from images, directories, files, archives, and OCI layouts.
tbxark MCP Proxy Server
Put several stdio, SSE, or Streamable HTTP MCP servers behind one proxy, configure per-server routes, auth tokens, logging, and allow/block tool filters, then serve clients over HTTP.
Threat Model MCP Servers Before Installation
Review MCP server trust boundaries before connecting them to Claude.
ToolHive MCP Platform
Run and manage MCP servers with the `thv` CLI, container isolation, registries, secrets, client setup, gateway controls, and Kubernetes operator support.
Using Claude Code in Healthcare and PHI-Sensitive Environments
The documented Claude Code data-handling controls that matter for PHI-sensitive teams.
Signal coverage
How these 120 resources score on the trust and safety signals HeyClaude reviews — counted from this set, not the directory as a whole.
A short, calm digest of reviewed Claude resources. Unsubscribe any time.