The Claude AI Community Discord is open.Join us

Endor Labs

Set up endorctl and use Endor Labs to scan, prioritize, and fix security risks across your software supply chain

Install

Run in your terminal

claude plugin install ai-plugins@claude-plugins-official

Claude Code already includes the claude-plugins-official marketplace, so this installs directly. Start a new Claude Code session to use it.

Already in a Claude Code session?

Install

/plugin install ai-plugins@claude-plugins-official

Published in Anthropic's claude-plugins-official marketplace (anthropics/claude-plugins-official).

Related plugins

Security Guidance

Security review for Claude-generated code. Pattern-based warnings on edits, LLM-powered diff review on Stop, and an agentic commit reviewer that catches injection, XSS, SSRF, hardcoded secrets, and 25+ other vulnerability classes.

Plugin · by Anthropic · 242k marketplace installs

Semgrep

Semgrep catches security vulnerabilities in real-time and guides Claude to write secure code from the start.

Plugin · by Semgrep · 20k marketplace installs

Claude Security

Deep vulnerability scanning of your own code, run entirely inside your Claude Code session at a chosen effort tier, with every finding challenged before it is reported and the verification tally computed in code. Turns surviving findings into targeted patches, each verified by a panel of agents, that you apply when you choose.

Plugin · by Anthropic · 8.6k marketplace installs

Sonatype Guide

Sonatype Guide MCP server for software supply chain intelligence and dependency security. Analyze dependencies for vulnerabilities, get secure version recommendations, and check component quality metrics.

Plugin · by Sonatype · 7.5k marketplace installs

Aikido Security

Aikido Security scanning for Claude Code — SAST, secrets, and IaC vulnerability detection powered by the Aikido MCP server.

Plugin · by Aikido Security · 7.3k marketplace installs

Sonarqube

Automatically enforce SonarQube code quality and security in the agent coding loop — 7,000+ rules, secrets scanning, agentic analysis, and quality gates across 40+ languages. PostToolUse hooks run analysis after every file edit. Pre-tool secrets scanning prevents 450+ patterns from reaching the LLM. Slash commands give on-demand access to quality gate status, coverage, duplication, and dependency risks. Includes SonarQube CLI, MCP Server, skills, hooks, and slash commands.

Plugin · by SonarSource · 6.4k marketplace installs