By bridge-mind
Senior security engineer instincts for AI coding agents. Find vulnerabilities. Ship secure.
Senior security-engineer instincts for AI coding agents. Activate whenever the agent reads, writes, reviews, or refactors code — backend, frontend, infrastructure-as-code, CI/CD pipelines, container manifests, or cloud config. Detects and prevents vulnerabilities across OWASP Top 10, OWASP API Top 10, OWASP LLM Top 10, and CWE Top 25: injection (SQLi, NoSQLi, command, template), SSRF, XSS, CSRF, IDOR/BOLA/BOPLA, path traversal, insecure deserialization, auth/authz flaws, JWT misuse, weak crypto, secrets exposure, supply-chain risks, container/Kubernetes hardening, cloud misconfig (S3, IAM, RDS), GitHub Actions injection, prototype pollution, ReDoS, race conditions, mass assignment, open redirect, XXE, Server Action authorization, hydration data leaks. Covers JavaScript/ TypeScript, Python, Go, Rust, Java/Spring, Ruby/Rails, PHP, React/Next.js. Critical for any agent shipping code to production.
Audit a file, directory, repository, or PR diff for security vulnerabilities. Use when reviewing code for OWASP Top 10 / CWE Top 25 issues, identifying injection / XSS / SSRF / IDOR / authentication flaws, scanning for hardcoded secrets, reviewing infrastructure-as-code (Terraform, Kubernetes manifests, Dockerfiles), auditing CI/CD configurations (GitHub Actions, GitLab CI), or performing a pre-merge security review. Outputs a structured report with severity, CWE/OWASP mapping, file:line references, exploitable scenario, and fix recommendations.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
BridgeSecurity
A Claude Code plugin from BridgeMind that gives your AI agents the instincts of a senior application security engineer.
Stop shipping classic vulnerabilities — start shipping production-secure code.
AI coding agents write functional code, but they keep shipping the same classic vulnerabilities — SQL injection, XSS, IDOR, hardcoded secrets, missing auth on Server Actions, public S3 buckets, pull_request_target with checkout-of-fork-code. The bugs that have headlined CVEs for fifteen years.
BridgeSecurity fixes this. It's a set of detection patterns, vulnerability taxonomies, threat-modeling discipline, and a specialized auditor agent that teach your AI teammates to think like a senior security engineer — find the trust boundary, match input to sink, check auth on every state-changing path, treat every secret as already leaked, fail closed.
x-middleware-subrequest bypass classMath.random() for tokens, ECB mode, hardcoded keys, JWT alg: none, HS256/RS256 confusion, === for HMAC comparefile:// / TOCTOUpath.join without prefix-check, send_file with raw inputpickle.loads, yaml.load, ObjectInputStream, vm2*:*, 0.0.0.0/0:22, IMDSv1, missing encryptionprivileged: true, runAsUser: 0, hostNetwork, /var/run/docker.sock mount, image:latestpull_request_target + checkout-fork-code, mutable Action tags (CVE-2025-30066 class), shell-injection via PR title//evil.com bypass class| Component | Type | What It Does |
|---|---|---|
bridgesecurity | Skill | Core security discipline — auto-loaded when your agent reads, writes, or reviews code. Five Disciplines, threat-model checklist, detection cheat-sheet. |
security-audit | Skill | Slash-command audit. Scans a file/dir/PR/repo for vulnerabilities, returns severity-ranked report with CWE/OWASP mapping. |
security-auditor | Agent | Read-only senior security engineer subagent. Cannot write, edit, or delete. Walks every file with the OWASP Top 10 + CWE Top 25 + threat model. |
The skill ships with eight deep reference docs (~50 pages of practitioner-grade content):
claude plugin install bridgesecurity@bridgemind-plugins
# Project-level
mkdir -p .claude/skills .claude/agents
cp -r skills/bridgesecurity .claude/skills/
cp -r skills/security-audit .claude/skills/
cp agents/security-auditor.md .claude/agents/
npx claudepluginhub bridge-mind/bridgesecuritySkeptical-reading and prompt-injection defense for AI coding agents. Trust nothing. Ship safely.
Give AI coding agents a voice. Text-to-speech for Claude Code, Hermes, and OpenClaw via OpenAI's gpt-realtime-2.
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Harness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
Access thousands of AI prompts and skills directly in your AI coding assistant. Search prompts, discover skills, save your own, and improve prompts with AI.
Binary reverse engineering, malware analysis, firmware security, and software protection research for authorized security research, CTF competitions, and defensive security
Complete developer toolkit for Claude Code
Intelligent draw.io diagramming plugin with AI-powered diagram generation, multi-platform embedding (GitHub, Confluence, Azure DevOps, Notion, Teams, Harness), conditional formatting, live data binding, and MCP server integration for programmatic diagram creation and management.