Security-engineering (AppSec) team β 4 agents (appsec-engineer, threat-modeler, supply-chain-security-engineer, cloud-security-engineer) for building security INTO software: threat modeling (STRIDE, data-flow diagrams, trust boundaries), application security testing (SAST/DAST/IAST/SCA in CI, OWASP Top 10 web), secrets management (detection, rotation, vaulting, no plaintext), software supply-chain integrity (SBOM consumption, dependency CVEs, SLSA verification, pinning), and cloud security posture (CSPM, IAM least-privilege, network exposure). 5 skills, a decision-tree knowledge bank (vuln-triage + secrets-handling trees + a dated 2026 tooling map), 12 best-practices, 4 templates, 4 commands, 1 advisory hook. **Proposes controls; every ship/no-ship security VERDICT escalates to ravenclaude-core/security-reviewer.** Seams: API OWASP -> api-engineering, identity -> auth-identity, data privacy -> data-governance-privacy. Requires ravenclaude-core@>=0.7.0.
Audit a cloud account for misconfigurations (public exposure, IAM wildcards, missing encryption, open ports) and propose preventive guardrails.
Stand up tuned SAST/SCA/secret-scanning/DAST gates in CI with exploitability-based triage.
Threat-model a feature or system with STRIDE: DFD + trust boundaries, STRIDE per element, ranked threats, and a mitigation or routed acceptance for each.
Triage a backlog of findings by exploitability and blast radius, group by class, and route verdicts.
Use for application security: standing up and tuning SAST/DAST/SCA gates in CI, triaging findings by exploitability and blast radius (not raw CVSS), fixing OWASP Top 10 web classes at the trust boundary, and secret-scanning. Proposes controls.
Use for cloud security posture: CSPM-style misconfiguration detection (public storage, open ports, missing encryption), IAM least-privilege analysis, network-exposure closure, encryption defaults, and preventive policy-as-code guardrails.
Use for software supply-chain security from the consume side: SBOM ingestion and dependency inventory, CVE triage by reachability, dependency pinning + a deliberate update policy, SLSA provenance verification, and typosquat/dependency-confusion defense. Routes ship/no-ship to security-reviewer.
Use for threat modeling at design time: data-flow diagrams, trust-boundary identification, STRIDE-per-element analysis, attack trees, likelihoodΓimpact ranking, and mapping each threat to a mitigation or an accepted risk. Routes risk-acceptance sign-off to security-reviewer; loops in privacy.
Stand up tuned application security scanning in CI: SAST + SCA per-PR, DAST on a deployed build, secret-scanning, and triage by exploitabilityΓblast-radius rather than raw CVSS.
Playbook for detecting secrets committed to Git β pre-commit hooks, CI scanning, historical repo scanning β and the full remediation procedure when a secret is found: rotation, history rewrite, and the post-incident checklist.
Manage secrets safely: detect them in code/config/logs, vault them, federate with short-lived credentials, rotate on a schedule, and treat any committed secret as compromised (rotate, don't just delete).
Secure the software supply chain from the consume side: ingest the SBOM, triage CVEs by reachability, pin dependencies with a deliberate update cadence, verify SLSA provenance, and defend against malicious packages.
Threat-model a design with STRIDE: draw the data-flow diagram and trust boundaries, walk STRIDE per element, rank threats by likelihoodΓimpact, and map each to a mitigation or a routed accepted-risk.
Modifies files
Hook triggers on file write and edit operations
Uses power tools
Uses Bash, Write, or Edit tools
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
A private Claude Code plugin marketplace β bundled team rules, specialist agents, dispatch playbooks, and templates that travel with you across projects.
π βΆ See what RavenClaude is (
pitch.html) β the one-page pitch: the value prop, the proof, and the plugin catalog at a glance. Start here. (Or view the raw HTML source, or download and open locally β no server, no build step.)π βΆ Open the landing page (
index.html) rendered in your browser β the front door: a navigable home with the plugin catalog, the specialist roster, and a comfort-posture starter. Regenerated from the manifests on every release.(Or view the raw HTML source, or download and open locally β no server, no build step.)
π βΆ Open the RavenClaude dashboard β point-and-click editor for your
.ravenclaude/comfort-posture.yaml: set per-tool file, network, shell, and package autonomy across three levels (deny β ask β allow) β per layer (user / local / project) and per individual permission β without editing YAML by hand. (That link is the published, read-only preview; to use it for real β where Save & apply writes your repo's config β runrc dashboardfrom your project, the one canonical launcher across Claude Code, Copilot CLI, and a bare terminal.)
π₯ Working on this repo? Launch the functional local dashboard (where Save & apply actually writes this repo's config) with one command:
bash scripts/open-dashboard.sh. It kills any running dashboard server, starts a fresh one, and opens it in your browser automatically. (VS Code users: a.vscode/tasks.jsonwired as the default build task β Ctrl/Cmd+Shift+B β runs the same script;.vscode/is gitignored, so add it locally if you want the keybinding.)
π βΆ Open the RavenClaude portal β one self-contained page: browse every plugin, agent, skill, hook, rule, and template in the Marketplace section (with an βI want toβ¦β use-case lookup), tune the comfort-posture Dashboard, and more. Regenerated from the manifests on every release.
(Or view the raw HTML source, or download and open locally β no server, no build step.)
π βΆ First Workflow in 10 Minutes β install β dashboard β one governed multi-agent dispatch β
/wrap. The canonical onboarding walkthrough. Start here if you've never used RavenClaude before.
π βΆ Raven Power β β the consulting front door behind RavenClaude. This marketplace is the proof-of-craft; the website is where the engagements live.
Today this marketplace ships 163 plugins:
ravenclaude-core β domain-neutral Team Lead + 14 specialists (architect, coders, reviewers, designer, documentarian, deep-researcher, project-manager, partner-success-manager, prompt-engineer, data-engineer, etc.), plus dispatch playbooks (with a Cross-plugin dispatch section), gates, 43 skills, 16 hooks, templates, and the cross-project contribution-staging loop.power-platform β 11 Microsoft Power Platform specialists (Power Fx, flows, Power BI, Dataverse, model-driven, PCF, Copilot Studio, Power Pages, admin, ALM, tester), 21 skills, an advisory house-opinions hook covering 8 checks, and the bundled pbix-mcp MCP server.finance β 7 corporate-finance & FP&A specialists (FP&A analyst, financial modeler, controller, treasury, valuation, audit-prep, board-pack composer), 9 skills, templates, advisory anti-pattern hook.regulatory-compliance β 12 financial-regulatory specialists (6 function: AML/KYC, regulatory reporting, risk-and-controls, policy & procedure writer, examination prep, Bermuda-insurance; plus 6 jurisdiction: BMA, CIMA Cayman, Bahamas, Channel Islands, UK PRA, US), 10 skills, templates, defensive PII-scrub hook.web-design β 7 web specialists (web architect, UX, visual, frontend implementer, content strategist, accessibility auditor, performance engineer) with WCAG 2.2 AA/AAA, Core Web Vitals, SEO/AEO, and Fluent + React discipline. 11 skills, templates, advisory web anti-pattern hook.edtech-partner-success β 6 K-12 EdTech partner-success specialists (partner-success manager, success-playbook designer, learning-analytics analyst, QBR composer, partner-profile curator, FERPA comms translator) with 16 skills and a knowledge bank of operating cadences.npx claudepluginhub mcorbett51090/ravenclaude --plugin security-engineeringAI multimedia for brand & winery sites: a creative brief -> on-brand, web-optimized, license-clean images/video/3D/audio behind a mandatory human curation gate. 4 agents (generation-strategist, web-asset-pipeline-engineer, asset-provenance-guardian, brand-and-accessibility-reviewer) route a brief to the right generator (provider-neutral, Grok-lean for images where competitive; inpaint/outpaint/bg-removal/upscale first-class), turn raw output into AVIF/WebP responsive <picture> markup with LCP/CLS-safe embeds, pin commercial-use licenses (flags the FLUX-dev non-commercial trap; C2PA + a provenance ledger; EU AI Act Art.50 disclosure), and gate every asset on brand-hex/style conformance + WCAG alt text before ship. 6 skills, 4 knowledge docs (Mermaid decision trees; all prices [unverified]), 6 best-practices, 4 commands, 5 templates, 4 scripts. The shared foundation the brand-identity-studio plugin consumes. Declarative fal MCP binding (set FAL_KEY). Requires ravenclaude-core@>=0.7.0.
Corporate finance & FP&A specialist team β FP&A analyst, financial modeler, controller, treasury analyst, valuation analyst, audit-prep specialist, and board-pack composer. Ships 23 skills including the controller-autopilot: a governed close-to-report cycle (GAAP statements, COA mapping, reconciliation auto-match, reviewβapproveβlock workflow, ELT staging, consolidation, per-entity dashboard, close schedules) plus its live-integration tier (multi-currency remeasurement + CTA, OAuth GL connectors + drill-through lineage, warehouse/RLS dashboard, IdP-backed segregation of duties) and a gold-standard NetSuite close (OAuth2 M2M + SuiteQL BS/IS trial balance, COA-draft, tie-out doctor, changed-after-sign-off drift, layperson runbook). 10 templates, a knowledge bank, and 2 advisory hooks (anti-patterns + secrets/PII scan). Inherits ravenclaude-core protocols (Grounding, Structured Output, Cited-Adjudicator).
Power Platform specialist team β 11 agents (incl. power-platform-tester, power-bi-engineer) and 23 skills, with strong ALM/git coverage for solutions, flows, and PBIP. A house-opinions hook flags 8 Β§3/Β§4 violations; the knowledge bank carries production decision trees (PA-flow recovery, Dataverse token-acquisition, PCF React surface, PBI deploy/refresh, custom-connector build-path, PBIR Enhanced infinite-spinner debug + full build reference, DAX silent-zero scoring via the `Domain` pattern, sempy.fabric notebook reference, Power BI Copilot report-readiness, Code Apps connector gotchas, PBIP deployment variables + #839, PBIR reference enrichment, PBIP report fast-solve triage router [MCP-optional]) plus a real-engagement scenarios bank. Bundles the community pbix-mcp server (d0nk3yhm/pbix-mcp, MIT) for .pbix/.pbit read/write/DAX-eval (`pip install pbix-mcp`); documents (not bundles) the official Microsoft Dataverse MCP (CLAUDE.md Β§9a). Extends ravenclaude-core.
Project & delivery management team β four specialists across the predictive (PMBOK/PMP) and agile (Scrum/Kanban) tracks and the hybrid between: delivery-lead (charter, schedule, scope/change control, earned value), scrum-master (backlog, sprints, ceremonies, velocity, impediments), risk-and-raid-analyst (scored qual+quant risk, RAID depth, mitigation/contingency, issue triage), and stakeholder-comms-lead (stakeholder register, comms plan, status/exec reporting, escalation memos, steering packs). Deepens β does NOT replace β ravenclaude-core's domain-neutral project-manager (the lightweight RAID/status-hygiene default every plugin routes to); this is the deep PM craft layer. Knowledge: a predictive-vs-agile-vs-hybrid decision tree + a best-practices library. Seams: prose polish β ravenclaude-core/documentarian; system design β architect. Requires ravenclaude-core@>=0.7.0.
AI/LLM red-teaming team β 2 agents (ai-redteam-lead, adversarial-testing-engineer) for the layer answering 'can this AI system be made to do harm, leak data, or exceed its authority β and how do we harden it?': threat modeling + rules of engagement, the attack taxonomy (OWASP LLM Top 10 2025 + MITRE ATLAS), direct vs indirect prompt injection, jailbreaks (roleplay/encoding/many-shot/crescendo), data exfiltration & training-data extraction, agentic tool-abuse / excessive agency, multimodal attacks, and defense-in-depth remediation. Fluent in automated red-team harnesses (PyRIT, Garak, Promptfoo red-team, Giskard) and likelihoodΓimpact severity. 3 skills, a 2-doc knowledge bank (attack-taxonomy decision tree + 2026 patterns), and 2 templates. Distinct from llm-evaluation-engineering (quality-regression eval), trust-and-safety (content-moderation / T&S policy), and security-engineering (app/infra pentest) β the adversarial AI-security layer over model- and agent-based systems. Requires ravenclaude-core@>=0.7.0.
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Harness-native ECC operator layer - 67 agents, 278 skills, 94 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
A growing collection of Claude-compatible academic workflow bundles. Covers scientific figures, manuscript writing and polishing, reviewer assessment, citation retrieval, data availability, paper reading, literature search, response letters, paper-to-PPTX conversion, and evidence-grounded Chinese invention patent drafting. Rules are organized as reusable skill folders with explicit workflows and quality checks.
Consult multiple AI coding agents (Gemini, OpenAI, Grok, Perplexity, plus codex, antigravity, and grok CLIs when installed) to get diverse perspectives on coding problems
Comprehensive PR review agents specializing in comments, tests, error handling, type design, code quality, and code simplification
Comprehensive feature development workflow with specialized agents for codebase exploration, architecture design, and quality review