---
title: "secure-code"
description: "Security guardian: blocks secrets and dangerous commands before they land, scans for OWASP Top 10 patterns, and guides fast, minimal fixes so code ships safely."
canonical: https://agentpluginsdirectory.com/plugins/secure-code
last-updated: 2026-10-01
---

# secure-code
Security guardian: blocks secrets and dangerous commands before they land, scans for OWASP Top 10 patterns, and guides fast, minimal fixes so code ships safely.
- Slug: secure-code
- Publisher: OctoCAT Platform Team
- Repository: https://github.com/sekar3s/octocat-agent-plugins-demo
- Manifest: plugins/secure-code/plugin.json
- Version: 1.0.0
- License: MIT
- Category (editorial): other
- Skills: 1 (secure-code-review)
- MCP servers: 1 (vuln-scout)
- Stars: 0
- Repository created: 2026-09-29
- Repository last pushed: 2026-09-30
- Publisher type: User
- Listing: https://agentpluginsdirectory.com/plugins/secure-code
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What secure-code does, in the publisher's words

Security guardian that helps you ship faster. It blocks hard-coded secrets and destructive commands before they land, flags OWASP Top 10 patterns as code is written, audits your supply chain, and guides minimal, tested fixes.

> These rules are fast, offline heuristics for the inner loop. They complement, and don't replace, GitHub code scanning (CodeQL), Dependabot, and secret scanning with push protection.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/sekar3s/octocat-agent-plugins-demo/HEAD/plugins/secure-code/README.md

## Skills

- secure-code-review: Security review for code changes or a whole repository, finds hard-coded secrets, OWASP Top 10 / CWE-mapped vulnerabilities (SQL injection, XSS, command injection, weak crypto, TLS bypass, permissive CORS), and supply-chain risks, then proposes minimal fixes. Use when the user asks for a security r…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

## MCP servers

- vuln-scout: transport: stdio; command: node ${PLUGIN_ROOT}/servers/vuln-scout.mjs

Read from the plugin's own mcp.json. Environment variable names only, never values.
