Security & Compliance Agent Plugins

Security & Compliance is the 11th-largest category in agentpluginsdirectory.com's verified index: 22 of the 524 distinct Agent Plugins verified on 2026-08-09, or 4% of the directory. It covers plugins for defending software: vulnerability scanning, dependency and supply-chain auditing, secrets detection, authentication and authorisation, threat modelling, privacy and regulatory compliance. Of these 22, 20 ship at least one Agent Skill and 9 declare MCP servers.

The goal is finding or preventing a security or compliance problem, even when the technique is code review or infrastructure work. Agent Plugins 1.0.0 defines no category field, so this grouping is editorial, not read from the manifest — the verification claim covers the plugin, not the category.

22 plugins · sorted by stars
  1. agentic-bundle-aas-privacy-compliance-engineeringPortable skills-only "AAS Privacy & Compliance Engineering" plugin from Agentic Awesome Skills.sickn33★ 44,677
  2. agentic-bundle-aas-secure-app-builderPortable skills-only "AAS Secure App Builder" plugin from Agentic Awesome Skills.sickn33★ 44,677
  3. agentic-bundle-aas-security-engineerPortable skills-only "AAS Security Engineer" plugin from Agentic Awesome Skills.sickn33★ 44,677
  4. agentic-bundle-security-developerPortable skills-only "Security Developer" plugin from Agentic Awesome Skills.sickn33★ 44,677
  5. agentic-bundle-security-engineerPortable skills-only "Security Engineer" plugin from Agentic Awesome Skills.sickn33★ 44,677
  6. aws-agents-for-devsecopsInvestigate incidents, review code and execute UAT for release readiness, scan code for vulnerabilities, and run penetration tests with AWS DevOps Agent and AWS Security Agent.aws★ 2,277
  7. security-auditSecurity audit patterns (OWASP Top 10, CWE Top 25 2025, CVSS v4.0) and GitHub project security checks for any project. Deep automated PHP/TYPO3 scanning with 80+ checkpoints, 19 reference guides, PreToolUse warnings. By Netresearch.netresearch★ 33
  8. enterprise-readinessAssess and enhance software projects for enterprise-grade security, quality, and automationnetresearch★ 4
  9. mcp-security-proxyInstallable Agent Plugins demo for the deny-by-default MCP Security Proxy.0disoft★ 2
  10. vord-guardrailGates every Edit/Write in this session against vord's Agent Permission Policy (vord-policy.toml) before the bytes reach disk.pmaojo★ 2
  11. vord-guardrailDenies an agent's write before it reaches disk when it introduces a security finding or touches a protected path. Deterministic: the verdict comes from a static analyzer, not from a model asked to check its own work.pmaojo★ 2
  12. whisper-graphInvestigation playbooks for the WhisperGraph internet-infrastructure graph: indicator triage that reads coverage before it reports a verdict, bulk triage over a SIEM export, Cypher that passes the server's validator, and brand-protection sweeps.whisper-sec★ 1
  13. cloudpeekConnect your agent to CloudPeek, the AI security teammate. Triage the 5% of alerts that matter, run investigations, and manage incidents through the hosted CloudPeek MCP gateway.Cloud-Peek
  14. damage-control損害控制 (Damage Control) 安全系統 - 透過 PreToolUse 鉤子封鎖危險指令並保護敏感檔案RDCrystalLab
  15. legalcode-claude-codeLegalcode for Claude Code with public Legalcode MCP access and 13 legal skills (incl. private legal radar and Icelandic gold-plating analysis).RobertHH-IS
  16. legalcode-codexLegalcode for Codex with public Legalcode MCP access and 13 legal skills (incl. private legal radar and Icelandic gold-plating analysis).RobertHH-IS
  17. legalcode-pro-claude-codeLegalcode Pro for Claude Code with Pro MCP access, 13 legal skills (incl. private legal radar and Icelandic gold-plating analysis), and CLI install helper.RobertHH-IS
  18. legalcode-pro-codexLegalcode Pro for Codex with Pro MCP access, 13 legal skills (incl. private legal radar and Icelandic gold-plating analysis), and CLI install helper.RobertHH-IS
  19. mcp-securityModel Context Protocol (MCP) security auditing for RCE, STDIO injection, and supply chain vulnerabilities.ghchinoy
  20. securityProject-agnostic security skills for repository audits, diff review, deterministic scanning, supply chain, threat modeling, smart contracts, and AI systems.akoita
  21. seekritZero-knowledge secrets manager for AI agents — bundles seekrit's local crypto-plane and hosted metadata-plane MCP servers.seekritdev
  22. seudonimizador-clinico-juridicoSeudonimiza casos clínicos y jurídicos para estudio, supervisión o formación: conserva la utilidad analítica y elimina identificadores directos, reduciendo los indirectos hasta un nivel auditado. Cuatro modos (clínico, jurídico, generalización extrema y auditoría). No sustituye la anonimización formal que exigen el RGPD y la LOPDGDD.novanoticia

Verified on 2026-08-09