Scans project dependencies for known vulnerabilities using OSV Scanner and the OSV database.
Scan a directory or lockfile for vulnerable dependencies using OSV Scanner. Reports known vulnerabilities in packages and lockfiles.
AI-powered reachability triage for dependency vulnerabilities. Scans for CVEs then searches your source code to estimate whether each vulnerable API is actually called. Outputs a prioritized FOUND_IN_SOURCE / UNCERTAIN / NOT_FOUND_IN_GREP report.

A marketplace of Claude Code plugins for security-focused development: adversarial code review, dependency vulnerability scanning, and reachability triage.
1) Register the marketplace:
/plugin marketplace add alejandrosaenz117/bonfires-marketplace
2) Install a plugin:
/plugin install devils-advocate@bonfires-marketplace
/plugin install osv-scanner@bonfires-marketplace
The tenth man. When consensus forms, it is a sign of danger. This plugin peers into the fog where failure waits. The collapse. The breach. The systems failing under weight they cannot see. It reveals where light fails and why the walls will break.
Invoke: Mention "adversarial review" or "challenge the plan" as a skill, or use /devils-advocate [file|description|recent] command.
See plugins/devils-advocate/README.md for full documentation.
Integrates OSV Scanner as an MCP server, giving Claude direct access to the OSV vulnerability database. Scans your dependencies for known CVEs, fetches full advisories, and uses grep-based reachability triage to estimate which vulnerabilities actually live in your code paths.
Invoke: Mention "check my dependencies for vulnerabilities" or "scan for CVEs" as a skill, or use /osv-scanner scan [path] and /osv-scanner triage [path] commands.
See plugins/osv-scanner/README.md for full documentation.
Before the collapse, there is choice. The manager who cannot distinguish the urgent from the important becomes a captive of the fire. This skill separates signal from noise: which battles matter, which are illusions, and which investments prevent the next disaster. It names the burnout, exposes the waste, and reveals the Q2 work that breaks the reactive cycle.
Invoke: Mention "help me prioritize", "what should I focus on", or "I'm overwhelmed" when drowning in tasks, or use /prioritize [task list] command.
See plugins/eisenhower-prioritization/README.md for full documentation.
See the darkness before it sees you. Challenge consensus. Find what will break before you go hollow.
MIT. See LICENSE.
See CONTRIBUTING.md for guidelines on adding plugins and contributing.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub alejandrosaenz117/bonfires-marketplace --plugin osv-scannerAdversarial security and architectural code review. Finds the most plausible security failure in your code.
Eisenhower Matrix-based task prioritization for any workload. Prioritize any brain dump using the Eisenhower Matrix. Use this skill whenever the user provides a workload, task list, sprint dump, or mentions phrases like 'help me prioritize', 'what should I focus on', 'I'm overwhelmed with work'. Categorizes work into Urgent+Important (Q1: do now), Important+NotUrgent (Q2: schedule), Urgent+NotImportant (Q3: delegate), and Neither (Q4: delete).
Comprehensive vulnerability scanning for code, dependencies, and configurations with CVE detection
DevsForge Enterprise Dependency Management Architect delivering comprehensive package optimization, vulnerability management, and license compliance frameworks that transform dependency management from operational task into strategic business value creation and security excellence catalyst
Audit supply-chain threat landscape of project dependencies for exploitation or takeover risk
Open-source cybersecurity analysis agent. Scans any local project for vulnerabilities: code security (SAST), dependency CVEs (SCA), secret leaks, authentication/authorization flaws, cryptographic weaknesses, misconfigurations, supply chain risks, and CI/CD security. Covers all OWASP 2025 Top 10 and CWE Top 25 categories. Generates prioritized reports with remediation guidance. Invoke with /cyber-neo [path].
Security skills for vibe coding — pre-coding security assessment, code vulnerability review, and threat modeling. Works without any MCP server or Jira/Confluence setup.
Security scanning, dependency CVE audits, and exposure-aware risk prioritization.