By bridge-mind
Senior security engineer instincts for AI coding agents. Find vulnerabilities. Ship secure.
npx claudepluginhub bridge-mind/bridgesecuritySenior security-engineer instincts for AI coding agents. Activate whenever the agent reads, writes, reviews, or refactors code — backend, frontend, infrastructure-as-code, CI/CD pipelines, container manifests, or cloud config. Detects and prevents vulnerabilities across OWASP Top 10, OWASP API Top 10, OWASP LLM Top 10, and CWE Top 25: injection (SQLi, NoSQLi, command, template), SSRF, XSS, CSRF, IDOR/BOLA/BOPLA, path traversal, insecure deserialization, auth/authz flaws, JWT misuse, weak crypto, secrets exposure, supply-chain risks, container/Kubernetes hardening, cloud misconfig (S3, IAM, RDS), GitHub Actions injection, prototype pollution, ReDoS, race conditions, mass assignment, open redirect, XXE, Server Action authorization, hydration data leaks. Covers JavaScript/ TypeScript, Python, Go, Rust, Java/Spring, Ruby/Rails, PHP, React/Next.js. Critical for any agent shipping code to production.
Audit a file, directory, repository, or PR diff for security vulnerabilities. Use when reviewing code for OWASP Top 10 / CWE Top 25 issues, identifying injection / XSS / SSRF / IDOR / authentication flaws, scanning for hardcoded secrets, reviewing infrastructure-as-code (Terraform, Kubernetes manifests, Dockerfiles), auditing CI/CD configurations (GitHub Actions, GitLab CI), or performing a pre-merge security review. Outputs a structured report with severity, CWE/OWASP mapping, file:line references, exploitable scenario, and fix recommendations.
Comprehensive .NET development skills for modern C#, ASP.NET, MAUI, Blazor, Aspire, EF Core, Native AOT, testing, security, performance optimization, CI/CD, and cloud-native applications
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Next.js development expertise with skills for App Router, Server Components, Route Handlers, Server Actions, and authentication patterns
Battle-tested Claude Code plugin for engineering teams — 53 agents, 203 skills, 69 legacy command shims, production-ready hooks, and selective install workflows evolved through continuous real-world use
Share bugs, ideas, or general feedback.
Access thousands of AI prompts and skills directly in your AI coding assistant. Search prompts, discover skills, save your own, and improve prompts with AI.
Binary reverse engineering, malware analysis, firmware security, and software protection research for authorized security research, CTF competitions, and defensive security
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claim