Official DryRunSecurity skills for AI coding assistants. Covers vulnerability remediation, API-driven finding remediation, and the full PR/MR review workflow.
npx claudepluginhub dryrunsecurity/external-plugin-marketplaceFix security vulnerabilities identified by DryRunSecurity. Provides guided remediation for SQL injection, XSS, SSRF, IDOR, and other security findings.
Pull DryRunSecurity findings via API and remediate them on a fresh branch with a new PR. Supports PR scan findings, deepscan code findings, and SCA advisory findings.
Official skills for AI coding assistants (Claude Code, Cursor, Windsurf, Codex) to help fix security vulnerabilities identified by DryRunSecurity.
When DryRunSecurity scans your pull request and leaves a comment about a security vulnerability, this skill helps your AI coding assistant understand and fix the issue. Instead of just telling you there's a problem, you get guided remediation.
The Flow:
DryRunSecurity finds vulnerability → Comments on your PR →
You ask your AI assistant to fix it → Skill guides contextual fix →
You push the fix → DryRunSecurity approves
Context is King. DryRunSecurity spends significant effort understanding your codebase to identify real vulnerabilities. This remediation skill does the same - it guides AI assistants to:
No static cheat sheets. No generic examples. Fixes grounded in your code.
Download to your project (always latest):
curl -o .cursorrules https://raw.githubusercontent.com/DryRunSecurity/external-plugin-marketplace/main/standalone/.cursorrules
Or pin to a specific version:
curl -o .cursorrules https://raw.githubusercontent.com/DryRunSecurity/external-plugin-marketplace/v1.0.0/standalone/.cursorrules
Download to your project (always latest):
curl -o .windsurfrules https://raw.githubusercontent.com/DryRunSecurity/external-plugin-marketplace/main/standalone/.windsurfrules
Or pin to a specific version:
curl -o .windsurfrules https://raw.githubusercontent.com/DryRunSecurity/external-plugin-marketplace/v1.0.0/standalone/.windsurfrules
# Add the marketplace
/plugin marketplace add DryRunSecurity/external-plugin-marketplace
# Install the remediation plugin
/plugin install dryrun-remediation@dryrunsecurity
Download or copy standalone/RULES.md into your AI assistant's system prompt or rules configuration.
All skill files include a version number in their header:
# Version: 1.0.0
main branch - Always contains the latest versionv1.0.0, v1.1.0, etc.) - Pinned releasesOption 1: Always latest (recommended for most users)
# Re-run the curl command to get the latest
curl -o .cursorrules https://raw.githubusercontent.com/DryRunSecurity/external-plugin-marketplace/main/standalone/.cursorrules
Option 2: Pin to a version
# Use a specific tag
curl -o .cursorrules https://raw.githubusercontent.com/DryRunSecurity/external-plugin-marketplace/v1.0.0/standalone/.cursorrules
Look at the top of your rules file:
# DryRunSecurity Vulnerability Remediation
# Version: 1.0.0
Compare with the latest release.
Once installed, share the DryRunSecurity finding with your AI assistant:
"DryRunSecurity found a SQL injection vulnerability in my PR.
Here's the comment: [paste comment]. Can you help me fix it?"
Or point directly to the file:
"Fix the SQL injection in src/handlers/user.go line 45"
The skill guides the assistant to:
The skill works for any vulnerability DryRunSecurity identifies, including:
Claude Code marketplace entries for the plugin-safe Agentic Awesome Skills library and its compatible editorial bundles.
Production-ready workflow orchestration with 94 marketplace plugins, 203 local specialized agents, and 175 local skills - optimized for granular installation and minimal token usage
Directory of popular Claude Code extensions including development tools, productivity plugins, and MCP integrations