By jassics
Security for Retrieval-Augmented Generation: pipeline review, retrieval/data poisoning testing, and vector-store isolation checks.
Test whether content planted in a RAG corpus (or otherwise retrieved) can steer the model's answers or trigger actions — i.e. indirect prompt injection and data poisoning via the retrieval path. Use on an authorized RAG app to validate ingestion/retrieval trust boundaries.
Test that retrieval enforces per-user / per-tenant authorization so one user cannot retrieve another's documents through the RAG system. Use on an authorized multi-tenant or multi-user RAG app to validate access control on retrieval.
Assess a Retrieval-Augmented Generation application end-to-end — ingestion, embedding, vector store, retrieval, prompt assembly, and generation — for poisoning, data leakage, isolation, and citation-integrity issues. Use when reviewing the security of any RAG / knowledge-base-backed LLM feature.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Generate consistent findings, pentest reports, vulnerability writeups, and executive summaries with CVSS scoring.
STRIDE / PASTA threat modeling, data flow diagrams, attack trees, and risk-ranked mitigations.
API security testing: OWASP API Security Top 10 assessment and object/function-level authorization (BOLA/BFLA) testing.
Mobile app security (Android/iOS): OWASP MASVS review and MASTG-based testing methodology.
Web application security testing: OWASP Web Top 10 assessment, access-control/IDOR testing, and injection testing.
npx claudepluginhub jassics/awesome-claude-security --plugin rag-securityComprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
A growing collection of Claude-compatible academic workflow bundles. Covers scientific figures, manuscript writing and polishing, reviewer assessment, citation retrieval, data availability, paper reading, literature search, response letters, paper-to-PPTX conversion, and evidence-grounded Chinese invention patent drafting. Rules are organized as reusable skill folders with explicit workflows and quality checks.
Complete creative writing suite with 10 specialized agents covering the full writing process: research gathering, character development, story architecture, world-building, dialogue coaching, editing/review, outlining, content strategy, believability auditing, and prose style/voice analysis. Includes genre-specific guides, templates, and quality checklists.
Comprehensive .NET development skills for modern C#, ASP.NET, MAUI, Blazor, Aspire, EF Core, Native AOT, testing, security, performance optimization, CI/CD, and cloud-native applications
Harness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
Tools to maintain and improve CLAUDE.md files - audit quality, capture session learnings, and keep project memory current.