---
title: "security-controls"
description: "Use this plugin for application, host, and supply-chain security control workflows."
canonical: https://agentpluginsdirectory.com/plugins/security-controls
last-updated: 2026-09-12
---

# security-controls
Use this plugin for application, host, and supply-chain security control workflows.
- Slug: security-controls
- Publisher: Codex Setup
- Repository: https://github.com/mjcramerz/codex-home
- Manifest: home/marketplaces/codex-home/plugins/cache/codex-home/security-controls/local/plugin.json
- Version: 1.1.0
- Category (editorial): other
- Skills: 10 (appsec-hardening, bws-local, secops-aide, secops-auditd, secops-crowdsec, secops-supply-chain, secops-usbguard, security-best-practices, security-ownership-map, security-threat-model)
- MCP servers: 0
- Stars: 0
- Repository created: 2026-08-11
- Repository last pushed: 2026-09-12
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/security-controls
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## Skills

- appsec-hardening: Apply application security hardening controls such as input validation, authn/authz checks, safe subprocess patterns, security headers, and abuse-rate defenses. Use when the user asks to harden code paths, close security gaps, or implement secure defaults.
- bws-local: Use this skill for install, configure, and rotate Bitwarden Secrets Manager CLI (bws) for local Debian systems with keyring-backed secret storage. Use when the user asks for local BWS lifecycle operations outside CI/CD.
- secops-aide: Configure AIDE file-integrity monitoring rules, baselines, and scheduled verification runs. Use when the user asks for host file integrity monitoring or tamper-detection setup.
- secops-auditd: Configure auditd rules and log capture policies with safe performance tradeoffs and compliance alignment. Use when the user asks for Linux auditing policy design or audit event tuning.
- secops-crowdsec: Configure CrowdSec collections, parser sources, and bouncer integration with safe enforcement defaults. Use when the user asks for CrowdSec detection or remediation setup.
- secops-supply-chain: Harden software supply-chain controls through dependency pinning, lockfile discipline, SBOM generation, and CI enforcement. Use when the user asks about dependency risk, provenance, or package security posture.
- secops-usbguard: Configure USBGuard device authorization policies and rule sets for USB attack surface reduction. Use when the user asks for USB allowlist/denylist policy setup.
- security-best-practices: Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/type…
- security-ownership-map: Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in…
- security-threat-model: Use this skill for repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse pa…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
