By zate
Hybrid security scanner: deterministic SAST tools (Semgrep, Gitleaks, Trivy) for detection, LLM for triage. Reproducible findings, provenance-labeled, zero-dependency fallback mode.
npx claudepluginhub zate/cc-plugins --plugin securityOWASP ASVS 5.0 requirements database for security audits. Provides chapter structure, control objectives, and verification requirements for all 17 ASVS domains.
Security fix patterns for authentication and authorization vulnerabilities (credentials, JWT, deserialization, access control). Provides language-specific secure implementations.
Security fix patterns for configuration and deployment vulnerabilities (path traversal, debug mode, security headers). Provides language-specific secure implementations.
Security fix patterns for cryptographic vulnerabilities (weak algorithms, insecure randomness, TLS issues). Provides language-specific secure implementations.
Security fix patterns for injection vulnerabilities (SQL, Command, XSS). Provides language-specific code examples showing vulnerable and secure implementations.
Index of security remediation skills. Routes to specialized skills for injection, cryptography, authentication, and configuration vulnerabilities.
View the most recent security scan results without re-running the scan
Run a security assessment using deterministic static analysis tools with LLM-powered triage
Install and configure security scanning tools for the security plugin
Universal vulnerability detection patterns applicable across all programming languages. Includes hardcoded secrets, SQL/command injection, path traversal, and configuration file patterns.
Language-specific vulnerability detection patterns for JavaScript/TypeScript, Python, Go, Java, Ruby, and PHP. Provides regex patterns and grep commands for common security vulnerabilities.
Index of vulnerability detection pattern skills. Routes to core patterns (universal) and language-specific patterns for security scanning.
Security best practices advisor with vulnerability detection and fixes
Open-source cybersecurity analysis agent. Scans any local project for vulnerabilities: code security (SAST), dependency CVEs (SCA), secret leaks, authentication/authorization flaws, cryptographic weaknesses, misconfigurations, supply chain risks, and CI/CD security. Covers all OWASP 2025 Top 10 and CWE Top 25 categories. Generates prioritized reports with remediation guidance. Invoke with /cyber-neo [path].
Specialized security review subagent
Security scanning, dependency CVE audits, and exposure-aware risk prioritization.
Perform security audit on codebase
The most comprehensive Claude Code plugin — 48 agents, 182 skills, 68 legacy command shims, selective install profiles, and production-ready hooks for TDD, security scanning, code review, and continuous learning
Executes bash commands
Hook triggers when Bash tool is used
Modifies files
Hook triggers on file write and edit operations
Share bugs, ideas, or general feedback.
A curated marketplace of high-quality Claude Code plugins for professional development workflows.
# Add this marketplace
/plugin marketplace add Zate/cc-plugins
# Install plugins
/plugin install devloop # Workflow engine
/plugin install ctx # Persistent memory (optional but recommended)
/devloop:plan "add user authentication" # 1. Plan - explore and design
/devloop:run # 2. Build - implement autonomously
/devloop:ship # 3. Ship - commit and PR
# Repeat # 4. Start next feature
That's it. Claude does the work. You stay in control.
Need deep exploration? Use /devloop:plan --deep "topic" for comprehensive analysis.
Context getting heavy? Use /devloop:fresh && /clear && /devloop:run every 5-10 tasks.
New to plugins? Check out the Getting Started Guide for a complete walkthrough.
| Plugin | Description | Components |
|---|---|---|
| devloop | Development workflow engine with autonomous planning and execution | 13 commands, 7 agents, 15 skills |
| ctx | Persistent memory for Claude across sessions | 3 skills |
| security | OWASP ASVS-aligned security audits | 1 command, 17 agents |
| diagrams | Text-based diagram generation (SVG, Mermaid, Excalidraw, D2) | 6 skills |
| blog-writer | Conversational blog post creator | 1 command, 2 agents |
| wsl-clipboard-fix | WSL2 clipboard image paste fix | 1 skill, hooks |
The flagship plugin for professional software development. Simple workflow: plan, build, ship, repeat.
/plugin install devloop
# The workflow
/devloop:plan "add user authentication" # Plan with autonomous exploration
/devloop:run # Execute tasks autonomously
/devloop:ship # Commit and create PR
# Variations
/devloop:plan --deep "should we use OAuth?" # Deep exploration first
/devloop:plan --quick "fix the typo" # Skip planning for tiny tasks
/devloop:plan --from-issue 42 # Start from GitHub issue
Why devloop?
v3.18 Highlights:
/devloop:runRead the full devloop documentation →
Claude Code plugins extend your development environment with:
| Component | Purpose | Example |
|---|---|---|
| Commands | Custom slash commands | /devloop:quick Fix the bug |
| Agents | Specialized subagents | code-reviewer, test-generator |
| Skills | Domain knowledge | go-patterns, security-checklist |
| Hooks | Event automation | Auto-detect project type on session start |
| MCP Servers | External integrations | Connect to databases, APIs, services |
# Add marketplace
/plugin marketplace add Zate/cc-plugins
# Install specific plugin
/plugin install devloop
# Install from local path
/plugin install /path/to/cc-plugins/plugins/devloop
# Install from GitHub
/plugin install https://github.com/Zate/cc-plugins/plugins/devloop
# List installed plugins
/plugin list
# Check plugin details
/plugin info devloop
Want to contribute a plugin? We maintain high quality standards.
# Copy the template
cp -r templates/plugin-template plugins/your-plugin-name
# Update manifest
vim plugins/your-plugin-name/.claude-plugin/plugin.json
# Test locally
/plugin install /absolute/path/to/plugins/your-plugin-name
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claim