Run local Windows security investigations: scan for malware, browser hijacking, suspicious processes, registry tampering, and network anomalies. Analyze binary files (PE, ELF, APK) with static/decompilation/sandbox tools and query Android kernel CVEs. Get structured reports with severity ratings and remediation steps.
Upload and analyze a suspicious binary file using the remote Dr. Binary MCP tools
Detect browser hijacking including homepage changes, search engine modifications, and malicious extensions
Monitor active network connections and detect suspicious network activity
Query the Android/AOSP kernel CVE database by CVE id, version, build date, or branch
Deep scan of Windows Registry for malware persistence and unauthorized modifications
Analyze binary files (exe, dll, sys, bin, ocx, scr, cpl, drv, elf, so, macho, apk) to assess if they are malicious, perform decompilation, extract strings/imports/exports, detect malware, and provide threat assessment. Use this skill when user asks to analyze, examine, check, or assess any binary file, asks if a file is malicious/suspicious/safe, or provides a file path to a binary. Trigger for phrases like "Is [file] malicious?", "Analyze [file]", "What does [binary] do?", or any request involving binary file analysis.
Query the Android/AOSP kernel CVE database to look up a specific CVE, find CVEs affecting a kernel version or build date, find unpatched CVEs in a branch, or identify exploitable vulnerabilities. Use this skill when the user asks about Android kernel CVEs, AOSP kernel vulnerabilities, which CVEs affect a kernel version/branch/build, whether a kernel is patched, or which vulnerabilities are exploitable. Trigger for phrases like "CVEs in kernel 5.10", "is android13-5.15 patched", "exploitable CVEs in <branch>", or "look up CVE-2024-XXXXX".
External network access
Connects to servers outside your machine
Uses power tools
Uses Bash, Write, or Edit tools
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
The Plugin equips Claude Code with advanced binary analysis capabilities for tasks such as incident response, malware investigation, and vulnerability assessment. It connects to the remote Dr. Binary MCP server over HTTP — no local server to install — and combines that with local system tools. To analyze a local file, Claude calls prepare_upload to obtain a one-time curl command, runs it to stream the file into a remote workspace, and then analyzes it with inspect_binary (Rizin triage), run_sandbox (rizin -qc and a full reverse-engineering toolkit), and dump_data (Ghidra decompilation). The plugin also exposes an Android/AOSP kernel CVE database for vulnerability research. Together with local Windows system scanning, browser hijacking detection, and registry/network monitoring, it transforms Claude Code into a powerful AI-assisted workspace for comprehensive system and binary security analysis.
The Claude Code Security Analysis Plugin extends Claude Code with advanced cybersecurity and binary-analysis capabilities, enabling developers and analysts to perform in-depth system investigations directly within their coding environment.
This plugin seamlessly integrates with both cloud-based analysis platforms and local security tools via the Model Context Protocol (MCP), creating a unified workspace for intelligent, AI-assisted security analysis.
Designed for incident response, malware forensics, and vulnerability research, the plugin empowers users to:
🧩 Investigate compromised systems to identify indicators of compromise (IoCs) and attack traces.
🦠 Analyze malware samples to uncover behaviors, persistence methods, and payloads.
🛡️ Perform vulnerability and exploit analysis, including Android/AOSP kernel CVE research and patch-status assessment.
⚙️ Combine cloud automation with local expertise, integrating Deepbits’ agentic binary-analysis capabilities into Claude Code.
Specialized Cybersecurity Capabilities
This plugin provides Claude Code with specialized cybersecurity features, including:
💻 Local Windows system scanning for malware, configuration weaknesses, and security issues.
🌐 Browser hijacking detection to identify malicious extensions or modified settings.
🧮 Windows Registry analysis to reveal persistence mechanisms or misconfigurations.
🧾 Suspicious file detection through behavioral and signature-based analysis.
🔗 Network connection monitoring for unusual or unauthorized communications.
🧠 Remote binary file analysis powered by Rizin/radare2, Ghidra, angr, qiling, and other advanced analysis frameworks.
Together, these capabilities transform Claude Code into a comprehensive cybersecurity co-pilot—bridging the gap between code intelligence, system defense, and binary analysis.
curl (bytes never pass through the model context)inspect_binaryrun_sandbox + rizin -qc and a full RE toolkit (radare2, binwalk, angr, qiling, qemu, apktool, jadx, …)dump_dataThe Cyber Security Analyst agent provides expert-level security analysis with:
The plugin connects directly to the remote Dr. Binary MCP server (https://mcp.deepbits.com/mcp) over HTTP — there is no local MCP server to install or run.
claude
/plugin marketplace add DeepBitsTechnology/claude-plugins
/plugin install drbinary-chat-plugin@deepbits
/mcp
Connecting to the drbinary server opens a browser-based sign-in. Log in with Google or GitHub SSO — no manual account creation is required. Once authenticated, the binary-analysis and kernel-CVE tools are available.npx claudepluginhub deepbitstechnology/claude-plugins --plugin drbinary-chat-pluginHarness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
Complete collection of battle-tested Claude Code configs from an Anthropic hackathon winner - agents, skills, hooks, and rules evolved over 10+ months of intensive daily use
Efficient skill management system with progressive discovery — 410+ production-ready skills across 33+ domains