Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By nvsecurity
Skills for working with NightVision, a DAST and API Discovery platform that finds exploitable vulnerabilities in web applications and REST APIs
npx claudepluginhub anthropics/claude-plugins-official --plugin nightvisionGuide for agents to help users extract OpenAPI specs from source code using NightVision API Discovery. Use when running swagger extract, identifying framework support, troubleshooting extraction, handling unresolved variables, comparing API specs, or understanding Code Traceback.
Guide for agents to help users integrate NightVision DAST scanning into CI/CD pipelines. Use when setting up security scans in GitHub Actions, GitLab CI, Azure DevOps, Jenkins, BitBucket, or JFrog pipelines, configuring NightVision tokens, creating targets, running scans, exporting results as SARIF/CSV, or detecting API breaking changes.
Guide for agents to help users configure NightVision DAST scans. Use when creating targets, setting up authentication (Playwright, headers, cookies), recording HTTP traffic, managing projects, configuring scope exclusions, or preparing private network scans.
Guide for agents to help users interpret and act on NightVision DAST scan results. Use when reading SARIF/CSV findings, explaining vulnerabilities, locating vulnerable code, validating findings with curl, prioritizing by severity, suggesting remediations, or marking false positives.
Your best defense is a good offense: Give Claude NightVision skills.
NightVision is a white-box-assisted DAST platform that combines API Discovery (static analysis to extract OpenAPI specs from source code), dynamic scanning (ZAP + Nuclei engines), and Code Traceback (tracing vulnerabilities back to exact source locations) to find exploitable vulnerabilities in web applications and REST APIs.
This plugin gives Claude Code the skills to run NightVision scans, triage results, and integrate security testing into your CI/CD pipelines — all from natural language.
From the terminal:
claude plugin marketplace add nvsecurity/skills
claude plugin install nightvision@nvsecurity
claude
From inside Claude Code:
/plugin marketplace add nvsecurity/skills
/plugin install nightvision@nvsecurity
You may need to restart Claude Code for the plugin to load.
| Skill | What it does |
|---|---|
scan-configuration | Set up DAST scans — create targets, configure authentication (Playwright, headers, cookies), manage projects, define scope exclusions, and prepare private network scans |
scan-triage | Interpret scan results — read SARIF/CSV findings, understand vulnerabilities, locate the vulnerable code, validate with curl, prioritize by severity, suggest fixes, and mark false positives |
api-discovery | Extract OpenAPI specs from source code via static analysis, troubleshoot extraction issues, compare specs across versions, and leverage Code Traceback |
ci-cd-integration | Wire NightVision into your pipeline — GitHub Actions, GitLab CI, Azure DevOps, Jenkins, BitBucket, and JFrog with SARIF/CSV export and breaking-change detection |
Just ask Claude what you need:
> Set up a NightVision scan for my API running on localhost:8080
> Triage the results from my last scan and suggest fixes
> Add NightVision to my GitHub Actions workflow
> Extract an OpenAPI spec from this Django project
Or invoke skills directly with slash commands:
/scan-configuration
/scan-triage
/api-discovery
/ci-cd-integration
nightvision-skills/
├── .claude-plugin/
│ └── plugin.json
├── skills/
│ ├── api-discovery/
│ │ ├── SKILL.md
│ │ └── references/
│ ├── ci-cd-integration/
│ │ ├── SKILL.md
│ │ └── references/
│ ├── scan-configuration/
│ │ └── SKILL.md
│ └── scan-triage/
│ ├── SKILL.md
│ └── references/
├── README.md
└── LICENSE
Contributions are welcome! Please open an issue or submit a pull request.
Apache License 2.0 — see LICENSE for details.
Share bugs, ideas, or general feedback.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Scan APIs for security vulnerabilities and OWASP API Top 10
Implements automated security scanning for dependencies, code, and containers using tools like Trivy, Snyk, and npm audit. Use when setting up CI/CD security gates, conducting pre-deployment audits, or meeting compliance requirements.
Security vulnerability detection and remediation: OWASP Top 10, SAST scanning, CVE research, dependency audit, secrets detection
Automated OWASP security checks — Web Top 10:2025, LLM Top 10:2025, API Security Top 10:2023
Application security testing including SAST, DAST, dependency scanning, API security, and web security headers.
DevsForge comprehensive security vulnerability scanner with automated remediation suggestions.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claim