By enchanter-ai
OWASP Top 10 and CWE-mapped vulnerability detection in code changes.
Modifies files
Hook triggers on file write and edit operations
Uses power tools
Uses Bash, Write, or Edit tools
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub enchanter-ai/hydra --plugin vuln-detectorOPT-IN BLOCKING capability allowlist. Sibling of hydra-capability-fence (advisory). When state/capability-policy.json sets enabled:true, this shield blocks any tool call whose name is not in the active skill's declared allowed-tools frontmatter list. Default disabled — out of the box this shield does nothing.
Advisory PreToolUse gate on package install commands. Surfaces 5 supply-chain risk signals (existence, age, maintainer, typosquat, download-cliff) before npm/pip/etc. install runs. Always exit 0; never blocks.
Real-time secret detection in written files. 200+ patterns, Shannon entropy, Aho-Corasick matching.
Session-start scanning for malicious repository configuration files.
Pre-execution classification and blocking of dangerous Bash commands.
Harness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
Complete collection of battle-tested Claude Code configs from an Anthropic hackathon winner - agents, skills, hooks, and rules evolved over 10+ months of intensive daily use
Efficient skill management system with progressive discovery — 410+ production-ready skills across 33+ domains