Semgrep
Semgrep catches security vulnerabilities in real-time and guides Claude to write secure code from the start.
Plugin · by Semgrep · 20k marketplace installs
Security review for Claude-generated code. Pattern-based warnings on edits, LLM-powered diff review on Stop, and an agentic commit reviewer that catches injection, XSS, SSRF, hardcoded secrets, and 25+ other vulnerability classes.
Run in your terminal
claude plugin install security-guidance@claude-plugins-officialClaude Code already includes the claude-plugins-official marketplace, so this installs directly. Start a new Claude Code session to use it.
Install
/plugin install security-guidance@claude-plugins-officialPublished in Anthropic's claude-plugins-official marketplace (anthropics/claude-plugins-official).
Semgrep catches security vulnerabilities in real-time and guides Claude to write secure code from the start.
Plugin · by Semgrep · 20k marketplace installs
Deep vulnerability scanning of your own code, run entirely inside your Claude Code session at a chosen effort tier, with every finding challenged before it is reported and the verification tally computed in code. Turns surviving findings into targeted patches, each verified by a panel of agents, that you apply when you choose.
Plugin · by Anthropic · 8.6k marketplace installs
Sonatype Guide MCP server for software supply chain intelligence and dependency security. Analyze dependencies for vulnerabilities, get secure version recommendations, and check component quality metrics.
Plugin · by Sonatype · 7.5k marketplace installs
Aikido Security scanning for Claude Code — SAST, secrets, and IaC vulnerability detection powered by the Aikido MCP server.
Plugin · by Aikido Security · 7.3k marketplace installs
Automatically enforce SonarQube code quality and security in the agent coding loop — 7,000+ rules, secrets scanning, agentic analysis, and quality gates across 40+ languages. PostToolUse hooks run analysis after every file edit. Pre-tool secrets scanning prevents 450+ patterns from reaching the LLM. Slash commands give on-demand access to quality gate status, coverage, duplication, and dependency risks. Includes SonarQube CLI, MCP Server, skills, hooks, and slash commands.
Plugin · by SonarSource · 6.4k marketplace installs
Enterprise-grade auth, easy to implement. Add login, SSO, MFA, and access control to any app with framework-aware guidance.
Plugin · by Auth0 · 4.7k marketplace installs