By crashbytes
InfoSec Engineer skill for Claude Code. Runs STRIDE threat modeling with DREAD scoring, performs OWASP Top 10 security reviews, audits code for vulnerabilities, and guides incident response. Includes slash commands: /threat-model, /security-review.
A Claude Code plugin that teaches Claude to act as an InfoSec Engineer. Runs STRIDE threat modeling, performs OWASP Top 10 security reviews, audits code for vulnerabilities, and guides incident response.
| Command | Description |
|---|---|
/threat-model | Run STRIDE threat analysis with DREAD scoring on a system or feature |
/security-review | Security-focused code review checking OWASP Top 10 and secure coding patterns |
/plugin install infosec-engineer@claude-plugin-directory
Or install directly:
/plugin install-from https://github.com/CrashBytes/claude-infosec-engineer
Connect development and communication tools:
| Platform | Setup |
|---|---|
| GitHub | claude mcp add github -- npx -y @modelcontextprotocol/server-github |
| GitLab | claude mcp add gitlab -- npx -y @modelcontextprotocol/server-gitlab |
| Jira | claude mcp add atlassian-mcp-server --transport streamable-http --url https://mcp.atlassian.com/v1/sse |
| Pusher Channels | claude mcp add pusher -- npx -y @AshDevFr/pusher-channels-mcp-server |
Apache 2.0
Runs pre-commands
Contains inline bash commands via ! syntax
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub crashbytes/claude-infosec-engineerProduct Owner skill for Claude Code. Writes user stories with acceptance criteria, manages backlogs, applies prioritization frameworks (RICE, MoSCoW, WSJF), and plans releases. Includes slash commands: /user-story, /backlog-prioritize.
Product Manager skill for Claude Code. Drafts PRDs, builds roadmaps, conducts market analysis (TAM/SAM/SOM), defines OKRs, and plans go-to-market strategy. Includes slash commands: /prd, /roadmap.
7 role-based professional skills for software teams: Scrum Master, Product Owner, Product Manager, UX/UI Developer, InfoSec Engineer, DevOps Engineer, and Software Migration Engineer. Each skill includes MCP integration support for Jira, Azure DevOps, GitHub, GitLab, Linear, and Trello.
Migration Engineer skill for Claude Code. Assesses legacy systems, plans technology migrations using the 7 Rs framework, implements strangler fig patterns, and designs database migration strategies. Includes slash commands: /migrate, /legacy-audit.
UX/UI Developer skill for Claude Code. Designs component systems, runs WCAG 2.1 AA accessibility audits, applies Nielsen's heuristics, implements responsive layouts, and evaluates usability. Includes slash commands: /accessibility-audit, /design-system.
Security skills for vibe coding — pre-coding security assessment, code vulnerability review, and threat modeling. Works without any MCP server or Jira/Confluence setup.
A team of AI security specialists embedded in your coding workflow. 8 agents covering every phase of the Secure SDLC: requirements, threat modelling, code review, IaC security, compliance, and release gating. Works with Claude Code, Cursor, Windsurf, and any MCP-compatible tool.
Application security threat modeling plugin. Provides AppSec-focused agents and skills for threat modeling, STRIDE analysis, dependency scanning, QA review, and security context resolution.
Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
AI-powered cybersecurity code review with 8 specialist agents, OWASP Top 10:2021, CWE Top 25:2024, MITRE ATT&CK v15, and framework-aware false-positive suppression
Application security engineering assistant for vulnerability triage, threat modeling, and secure code analysis at Bitwarden.