Security scanning

Vulnerability scanning and rule-based security checks.

Editor's picks

anthropics/claude-plugins-official

Deep vulnerability scanning of your own code, run entirely inside your Claude Code session at a chosen effort tier, with every finding challenged before it is reported and the verification tally computed in code. Turns surviving findings into targeted patches, each verified by a panel of agents, that you apply when you choose. See the plugin README for the tiers, the report format, and the trust model.

Deep vulnerability scanning of your own code

anthropics/claude-plugins-official

Security review for Claude-generated code. Pattern-based warnings on edits, LLM-powered diff review on Stop, and an agentic commit reviewer that catches injection, XSS, SSRF, hardcoded secrets, and 25+ other vulnerability classes.

Security review for Claude-generated code

trailofbits/skills

6K

Executes Semgrep CLI scans for a specific language category and produces SARIF output. Spawned by the semgrep skill as a parallel worker — one agent per detected language.

Semgrep rule-based scanning

io.github.SonarSource/sonarqube-mcp-server

MCP

io.github.SonarSource/sonarqube-mcp-server

An MCP server that enables integration with SonarQube Server or Cloud for code quality and security.

SonarQube quality gates

No source link

Browse all in Testing & Quality

The picks above are curated. Search the full directory for everything matching “Security scanning” or related keywords.