Security Pro Pack
Professional security tools for Claude Code: vulnerability scanning, compliance, cryptography audit, container & API security
- Type
- Plugin
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Version
- 1.31.0
- Author
- Jeremy Longshore
What Security Pro Pack is
Security Pro Pack is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Security Pro Pack adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Security Pro Pack
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
- Install the plugin: claude plugin install security-pro-pack@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
- Find Security Pro Pack in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/packages/security-pro-pack/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
Professional security tools for Claude Code developers
Version 1.0.0 | 10 Plugins | Security & Compliance Focus
Overview
The Security Pro Pack is a comprehensive collection of security-focused plugins for Claude Code, providing automated vulnerability scanning, compliance checking, cryptography review, and infrastructure security analysis.
Perfect for:
- Security engineers and DevSecOps teams
- Developers building secure applications
- Companies preparing for compliance audits (HIPAA, PCI DSS, GDPR, SOC 2)
- Organizations requiring security-first development practices
What's Included
Core Security (3 plugins)
- Security Auditor Expert (Agent) - OWASP Top 10 vulnerability detection specialist
- Penetration Tester (Agent) - Ethical hacking and offensive security expert
- Security Scan Quick (Command, /ss) - Fast automated security scanning (2-5 min)
Compliance (2 plugins)
- Compliance Checker (Agent) - Multi-framework regulatory compliance (HIPAA, PCI DSS, GDPR, SOC 2)
- Compliance Docs Generate (Command, /cdg) - Automated compliance documentation generation
Cryptography (2 plugins)
- Crypto Expert (Agent) - Cryptographic implementation specialist (AES, RSA, bcrypt, Argon2)
- Crypto Audit (Command, /ca) - Automated cryptographic code review
Infrastructure Security (3 plugins)
- Threat Modeler (Agent) - STRIDE threat modeling and architectural security
- Docker Security Scan (Command, /dss) - Container vulnerability scanning
- API Security Audit (Command, /asa) - REST/GraphQL API security testing
Total: 5 AI agents + 5 commands = 10 professional security tools
Quick Start
# Install the pack
claude plugin install security-pro-pack
# Run your first security scan
/ss
# Scan a Docker container
/dss nginx:latest
# Audit an API
/asa https://api.example.com
# Get OWASP Top 10 analysis
# In Claude Code session:
"Please use Security Auditor Expert to review this authentication code"See QUICK_START.md for detailed walkthrough
Key Features
Automated Security Scanning
- Detects hardcoded secrets (API keys, passwords, tokens)
- Identifies known CVEs in dependencies
- Finds security misconfigurations
- Reports severity-rated findings (Critical → Low)
- Provides actionable remediation steps
Compliance Made Easy
- Generate audit-ready documentation in minutes
- Multi-framework support (HIPAA, PCI DSS, GDPR, SOC 2)
- Gap analysis against compliance requirements
- Policy and procedure templates
- Risk assessment frameworks
Cryptography Security
- Reviews encryption implementations (AES, RSA, ECC)
- Validates password hashing (Argon2, bcrypt)
- Detects weak algorithms (MD5, SHA-1, DES)
- Checks for hardcoded keys and IV reuse
- TLS/SSL configuration analysis
Infrastructure Protection
- STRIDE threat modeling for architectural security
- Container security scanning (vulnerabilities, misconfigurations)
- Docker image hardening recommendations
- API security testing (OWASP API Top 10)
- Kubernetes pod security analysis
Real-World Value
Time Savings
- Quick Security Scan: 2-5 minutes (vs. 2-4 hours manual review)
- Compliance Documentation: 15-30 minutes (vs. 40-80 hours)
- Container Security: 5-10 minutes per image (vs. 1-2 hours)
- API Security Audit: 15-30 minutes (vs. 4-8 hours)
Total time saved: 40-80 hours per month
Cost Savings
- Replaces external security audit: $3,000-$5,000 per assessment
- Compliance consultant savings: $15,000-$25,000 per framework
- Prevents data breaches: Millions in potential losses
- Avoids regulatory fines: $50,000+ per HIPAA violation, €20M GDPR fine
Risk Reduction
- Identify vulnerabilities before attackers do
- Achieve compliance before audits
- Prevent data breaches and security incidents
- Protect customer data and company reputation
Who Should Use This
Security Engineers
- Automate security reviews
- Scale security across teams
- Implement security gates in CI/CD
- Perform threat modeling efficiently
Development Teams
- Shift security left (find issues early)
- Learn security best practices
- Meet compliance requirements
- Ship secure code faster
Compliance Officers
- Generate audit-ready documentation
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Security Pro Pack?
Security Pro Pack is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Professional security tools for Claude Code: vulnerability scanning, compliance, cryptography audit, container & API security
How do I install Security Pro Pack in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install security-pro-pack@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Security Pro Pack in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Security Pro Pack in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Security Pro Pack safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Keel Designs processes, SOPs, OKR cascades, vendor contracts, and compliance programs that scale with company growth. Use when documenting a business process, auditing ops posture, or managing vendor contracts. Trigger with \"write a SOP\", \"build our OKR framework\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Klingai Pack Kling AI skill pack - 30 skills for AI video generation, image-to-video, text-to-video, and production workflows Plugin · jeremylongshore/tons-of-skills-marketplace
- Kube Designs and audits Kubernetes cluster architectures — RBAC policies, CNI networking, workload configuration, and operators with explicit reliability tradeoffs. Use when designing a cluster, auditing RBAC, or rightsizing workloads. Trigger with \"design a Kubernetes cluster\", \"audit our RBAC\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Kubernetes Deployment Creator Create Kubernetes deployments, services, and configurations with best practices Plugin · jeremylongshore/tons-of-skills-marketplace
- Security Test Scanner Automated security vulnerability testing covering OWASP Top 10, SQL injection, XSS, CSRF, and authentication issues Plugin · jeremylongshore/tons-of-skills-marketplace
- Security Audit Reporter Generate comprehensive security audit reports Plugin · jeremylongshore/tons-of-skills-marketplace
- Sentry Pack Claude Code skill pack for Sentry (30 skills) Plugin · jeremylongshore/tons-of-skills-marketplace
- Secrets Manager Integrator Integrate with secrets managers (Vault, AWS Secrets Manager, etc) Plugin · jeremylongshore/tons-of-skills-marketplace