Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By sumeet138
SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and automated security hardening
npx claudepluginhub sumeet138/qwen-code-agents --plugin security-scanningYou are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies.
Orchestrate comprehensive security hardening with defense-in-depth strategy across all application layers
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation. Handles DevSecOps integration, compliance (GDPR/HIPAA/SOC2), and incident response. Use PROACTIVELY for security audits, DevSecOps, or compliance implementation.
Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use PROACTIVELY for security architecture reviews, threat identification, or building secure-by-design systems.
Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automating code vulnerability detection.
Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.
Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.
Uses power tools
Uses Bash, Write, or Edit tools
Share bugs, ideas, or general feedback.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Implements automated security scanning for dependencies, code, and containers using tools like Trivy, Snyk, and npm audit. Use when setting up CI/CD security gates, conducting pre-deployment audits, or meeting compliance requirements.
Open-source cybersecurity analysis agent. Scans any local project for vulnerabilities: code security (SAST), dependency CVEs (SCA), secret leaks, authentication/authorization flaws, cryptographic weaknesses, misconfigurations, supply chain risks, and CI/CD security. Covers all OWASP 2025 Top 10 and CWE Top 25 categories. Generates prioritized reports with remediation guidance. Invoke with /cyber-neo [path].
Security scanning, dependency CVE audits, and exposure-aware risk prioritization.
Comprehensive security plugin: OWASP Top 10, authentication patterns, cryptography, API security, secrets management, supply chain security, DevSecOps, container security, zero trust, and threat modeling.
Security vulnerability detection and remediation: OWASP Top 10, SAST scanning, CVE research, dependency audit, secrets detection
Agentic-Security is a powerful Claude Code plugin that automatically performs Application Security Testing (SAST, SCA, secrets detection, and more). Think of it as the easy button for making your Claude-generated code safe and secure.
LLM application development with LangGraph, RAG systems, vector search, and AI agent architectures for Claude 4.6 and GPT-5.2
Interactive debugging, developer experience optimization, and smart debugging workflows
Distributed system tracing and debugging across microservices
REST and GraphQL API scaffolding, framework selection, backend architecture, and API generation
Technical SEO optimization including meta tags, keywords, structure, and featured snippets
Adapted for Qwen Code — 77 plugins, 182 agents, 149 skills, and 96 commands now working with Qwen 3.6
A comprehensive production-ready system combining 182 specialized AI agents, 16 multi-agent workflow orchestrators, 149 agent skills, and 96 commands organized into 77 focused, single-purpose plugins — adapted for Qwen Code.
This project is a fork/adaptation of claude-code-workflows by Seth Hobson (@wshobson).
All original plugin content, agent expertise, skill knowledge, command workflows, and architectural design are the work of Seth Hobson and contributors. This adaptation converts the plugin infrastructure to work with Qwen Code instead of Claude Code, while preserving 100% of the original content and intelligence.
Original repository: github.com/wshobson/agents Original license: MIT
Claude Code is expensive. Qwen Code is free (OAuth: 60 req/min, 1000/day) or very cheap (API key). This project brings the same powerful agent orchestration system to Qwen Code so you can use 182 specialized AI agents without paying for Claude.
| Aspect | Before (Claude Code) | After (Qwen Code) |
|---|---|---|
| Cost | $3+ per 1M tokens (Sonnet) | Free (OAuth) or ~$0.02/1M tokens |
| Model for critical tasks | Claude Opus 4.6 | Qwen-Max |
| Model for complex tasks | Claude Sonnet 4.6 | Qwen-Plus |
| Model for fast tasks | Claude Haiku 4.5 | Qwen-Flash |
| Plugins | 77 | 77 (same) |
| Agents | 182 | 182 (same expertise) |
| Skills | 149 | 149 (same knowledge) |
| Commands | 96 | 96 (same workflows) |
| Agent knowledge | Identical | Identical |
| Skill content | Identical | Identical |
| Workflow automation | Identical | Identical |
| Monthly savings | Baseline | ~99% cheaper |
| Component | Changed? | Details |
|---|---|---|
| Agent system prompts | No | All 182 agents have identical expertise |
| Skill knowledge packages | No | All 149 skills with progressive disclosure |
| Command workflows | No | All 96 workflow automations |
| Plugin structure | No | Same directory organization |
model: opus references | Yes | Mapped to model: qwen-max |
model: sonnet references | Yes | Mapped to model: qwen-plus |
model: haiku references | Yes | Mapped to model: qwen-flash |
| Plugin manifest | Yes | plugin.json + qwen-extension.json |
| Context files | Added | QWEN.md per plugin |
This unified repository provides everything needed for intelligent automation and multi-agent orchestration across modern software development:
Each plugin is completely isolated with its own agents, commands, and skills:
Example: Installing python-development loads 3 Python agents, 1 scaffolding tool, and makes 16 skills available (~1000 tokens), not the entire marketplace.