Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By backbay-labs
Enforce runtime security policies on AI coding agents in Claude Code sessions, generating chronological audit trails, conducting threat hunts on events, reviewing risky code changes, scanning MCP servers for vulnerabilities, and assessing overall security posture with grades and recommendations.
npx claudepluginhub backbay-labs/clawdstrike --plugin clawdstrikeShow security audit trail for the current session
Show active security policy and guard details
Assess overall security posture with a letter grade
Scan MCP server configurations for security issues
Run ClawdStrike self-test to verify all components are working
Matches all tools
Hooks run on every tool call, not just specific ones
Admin access level
Server config contains admin-level keywords
Share bugs, ideas, or general feedback.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Security controls for AI agents — deterministic policy enforcement, OWASP ASI10 scanning, and audit trails.
Runtime security plugin for Claude Code with balanced default hooks plus the Stallion inline MCP gateway for shell, git, MCP, secret, and exfiltration risks.
A secure runtime for Claude Code. Intercepts every tool call with policy-based allow/block/ask decisions, evasion detection, path fencing, file snapshots, and audit logging.
Command Line Agent Safety Harness. All interactions with clash policy should go through this plugin
Safety for Agents - Agent Detection & Response (ADR) for Claude Code
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations (Claude Code Action, Gemini CLI, OpenAI Codex, GitHub AI Inference)
The claw strikes back.
At the boundary between intent and action,
it watches what leaves, what changes, what leaks.
Not "visibility." Not "telemetry." Not "vibes." Logs are stories; proof is a signature.
If the tale diverges, the receipt won't sign.
EDR for the age of the swarm.
Fail closed. Sign the truth.
Capabilities · Guards · Enterprise · Quick Start