Sponsor Suno AI Music arrow_forward
Plugin

Security Pro Pack

Professional security tools for Claude Code: vulnerability scanning, compliance, cryptography audit, container & API security

Type
Plugin
GitHub stars
2.8k
License
MIT
Repo last updated
Sep 27, 2026
Version
1.31.0
Author
Jeremy Longshore

What Security Pro Pack is

Security Pro Pack is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”

A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.

Installing Security Pro Pack adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.

How to install Security Pro Pack

Claude Code

  1. Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
  2. Install the plugin: claude plugin install security-pro-pack@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
  3. Restart the session if the new skills or commands don't appear straight away.

Claude Cowork

  1. Open Customize → Plugins and choose Add marketplace.
  2. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
  3. Find Security Pro Pack in the list, click Install, then connect any connectors it needs from its Connectors tab.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/packages/security-pro-pack/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.

Professional security tools for Claude Code developers

Version 1.0.0 | 10 Plugins | Security & Compliance Focus

Overview

The Security Pro Pack is a comprehensive collection of security-focused plugins for Claude Code, providing automated vulnerability scanning, compliance checking, cryptography review, and infrastructure security analysis.

Perfect for:

  • Security engineers and DevSecOps teams
  • Developers building secure applications
  • Companies preparing for compliance audits (HIPAA, PCI DSS, GDPR, SOC 2)
  • Organizations requiring security-first development practices

What's Included

Core Security (3 plugins)

  • Security Auditor Expert (Agent) - OWASP Top 10 vulnerability detection specialist
  • Penetration Tester (Agent) - Ethical hacking and offensive security expert
  • Security Scan Quick (Command, /ss) - Fast automated security scanning (2-5 min)

Compliance (2 plugins)

  • Compliance Checker (Agent) - Multi-framework regulatory compliance (HIPAA, PCI DSS, GDPR, SOC 2)
  • Compliance Docs Generate (Command, /cdg) - Automated compliance documentation generation

Cryptography (2 plugins)

  • Crypto Expert (Agent) - Cryptographic implementation specialist (AES, RSA, bcrypt, Argon2)
  • Crypto Audit (Command, /ca) - Automated cryptographic code review

Infrastructure Security (3 plugins)

  • Threat Modeler (Agent) - STRIDE threat modeling and architectural security
  • Docker Security Scan (Command, /dss) - Container vulnerability scanning
  • API Security Audit (Command, /asa) - REST/GraphQL API security testing

Total: 5 AI agents + 5 commands = 10 professional security tools

Quick Start

# Install the pack
claude plugin install security-pro-pack

# Run your first security scan
/ss

# Scan a Docker container
/dss nginx:latest

# Audit an API
/asa https://api.example.com

# Get OWASP Top 10 analysis
# In Claude Code session:
"Please use Security Auditor Expert to review this authentication code"

See QUICK_START.md for detailed walkthrough

Key Features

Automated Security Scanning

  • Detects hardcoded secrets (API keys, passwords, tokens)
  • Identifies known CVEs in dependencies
  • Finds security misconfigurations
  • Reports severity-rated findings (Critical → Low)
  • Provides actionable remediation steps

Compliance Made Easy

  • Generate audit-ready documentation in minutes
  • Multi-framework support (HIPAA, PCI DSS, GDPR, SOC 2)
  • Gap analysis against compliance requirements
  • Policy and procedure templates
  • Risk assessment frameworks

Cryptography Security

  • Reviews encryption implementations (AES, RSA, ECC)
  • Validates password hashing (Argon2, bcrypt)
  • Detects weak algorithms (MD5, SHA-1, DES)
  • Checks for hardcoded keys and IV reuse
  • TLS/SSL configuration analysis

Infrastructure Protection

  • STRIDE threat modeling for architectural security
  • Container security scanning (vulnerabilities, misconfigurations)
  • Docker image hardening recommendations
  • API security testing (OWASP API Top 10)
  • Kubernetes pod security analysis

Real-World Value

Time Savings

  • Quick Security Scan: 2-5 minutes (vs. 2-4 hours manual review)
  • Compliance Documentation: 15-30 minutes (vs. 40-80 hours)
  • Container Security: 5-10 minutes per image (vs. 1-2 hours)
  • API Security Audit: 15-30 minutes (vs. 4-8 hours)

Total time saved: 40-80 hours per month

Cost Savings

  • Replaces external security audit: $3,000-$5,000 per assessment
  • Compliance consultant savings: $15,000-$25,000 per framework
  • Prevents data breaches: Millions in potential losses
  • Avoids regulatory fines: $50,000+ per HIPAA violation, €20M GDPR fine

Risk Reduction

  • Identify vulnerabilities before attackers do
  • Achieve compliance before audits
  • Prevent data breaches and security incidents
  • Protect customer data and company reputation

Who Should Use This

Security Engineers

  • Automate security reviews
  • Scale security across teams
  • Implement security gates in CI/CD
  • Perform threat modeling efficiently

Development Teams

  • Shift security left (find issues early)
  • Learn security best practices
  • Meet compliance requirements
  • Ship secure code faster

Compliance Officers

  • Generate audit-ready documentation

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Security Pro Pack?

Security Pro Pack is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Professional security tools for Claude Code: vulnerability scanning, compliance, cryptography audit, container & API security

How do I install Security Pro Pack in Claude Code?

Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install security-pro-pack@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.

Can I use Security Pro Pack in Claude Cowork?

Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Security Pro Pack in the list, click Install, then connect any connectors it needs from its Connectors tab.

Is Security Pro Pack safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.