By jassics
Attack trees, threat-model DFDs, architecture diagrams, mindmaps, and infographics for security work.
Produce a security architecture, network, or trust-boundary diagram of a system, highlighting components, zones, controls, and exposure. Use when documenting a design review, network segmentation, or cloud architecture from a security perspective.
Build an attack tree for a stated attacker goal or asset, decomposing it into AND/OR sub-goals and leaf attack steps, then render it. Use when threat modeling, planning an engagement, or explaining how an asset could be compromised.
Create a shareable single-page infographic / one-pager summarizing a security posture, assessment result, metric set, or program update for a non-technical or executive audience. Use when the ask is "make this presentable / visual / board-ready" rather than a full report.
Turn a security topic into a structured mindmap — recon surface, an attack chain, a framework breakdown, or study notes. Use when organizing or explaining a topic radially rather than as a flow or report.
Draw a Data Flow Diagram with trust boundaries for threat modeling: external entities, processes, data stores, data flows, and the boundaries between them. Use when starting a STRIDE/PASTA threat model or documenting how data moves through a system.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub jassics/awesome-claude-security --plugin security-diagrammingGenerate consistent findings, pentest reports, vulnerability writeups, and executive summaries with CVSS scoring.
STRIDE / PASTA threat modeling, data flow diagrams, attack trees, and risk-ranked mitigations.
API security testing: OWASP API Security Top 10 assessment and object/function-level authorization (BOLA/BFLA) testing.
Mobile app security (Android/iOS): OWASP MASVS review and MASTG-based testing methodology.
Web application security testing: OWASP Web Top 10 assessment, access-control/IDOR testing, and injection testing.
Efficient skill management system with progressive discovery — 410+ production-ready skills across 33+ domains
Harness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Binary reverse engineering, malware analysis, firmware security, and software protection research for authorized security research, CTF competitions, and defensive security
v9.44.1 — Patch release for Gemini environment/version detection and qwen auth gating. Run /octo:setup.
Next.js development expertise with skills for App Router, Server Components, Route Handlers, Server Actions, and authentication patterns