By totallyGreg
This skill should be used when identifying, analyzing, and mitigating security risks in Artificial Intelligence systems using the CoSAI (Coalition for Secure AI) Risk Map framework. Use when users ask to "assess AI security risks", "analyze AI system threats", "map risks to controls", "run a risk assessment", "check compliance with MITRE ATLAS", "generate a CoSAI report", or "profile persona risks". Supports LLM applications, ML pipelines, model training/serving infrastructure, and compliance reporting aligned with MITRE ATLAS, NIST AI RMF, OWASP Top 10 for LLM, STRIDE, and ISO 22989 frameworks.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Search CoSAI controls by keyword.
Get all controls that mitigate a specific risk.
Map a risk to external compliance frameworks.
Assess control coverage gaps for a specific risk.
Get the risk profile for a specific persona.
A comprehensive marketplace for Claude Code extensions, providing plugins with skills, commands, agents, hooks, and MCP servers to enhance your Claude development experience.
# Add the marketplace
/plugin marketplace add totallyGreg/claude-mp
# Install individual plugins
/plugin install skillsmith@totally-tools
/plugin install marketplace-manager@totally-tools
| Plugin | Version | Description |
|---|---|---|
| helm-chart-developer | 1.0.0 | Expert guide for Helm chart development, testing, and security |
| marketplace-manager | 4.0.0 | Manages Claude Code plugin marketplace operations including version syncing, skill publishing, and marketplace.json maintenance |
| skillsmith | 6.8.0 | Guide for forging effective Claude skills with marketplace integration |
| swift-dev | 1.2.0 | Swift development expert for SwiftUI, iOS/macOS frameworks, Server-side Swift, and Objective-C migration |
| terminal-guru | 4.0.0 | Terminal diagnostics, configuration, and zsh development expert with triage agent and three focused skills |
| Plugin | Version | Description |
|---|---|---|
| confluence-pages | 1.1.0 | Create, update, move, and delete Confluence pages via REST API |
| omnifocus-manager | 10.2.0 | Interface with OmniFocus to surface insights, create reusable automations and perspectives, and suggest workflow optimizations |
| archivist | 1.15.0 | Personal Knowledge Management expert for Obsidian vaults with dual-skill architecture: vault-architect (create structures) and vault-curator (evolve content) |
| slack-toolkit | 1.1.0 | Slack Web API access via Python CLI — Canvas read/create/update/rewrite, reactions, threads, and channel history without MCP dependency |
| Plugin | Version | Description |
|---|---|---|
| ai-risk-mapper | 5.1.0 | AI security risk assessment using CoSAI Risk Map framework |
| Plugin | Version | Description |
|---|---|---|
| gateway-manager | 3.0.0 | Multi-skill plugin for Kubernetes Gateway API (kgateway) and AI/LLM routing (agentgateway) — provider backends, MCP server routing, external processing, version lifecycle management, and traffic policies |
claude-mp/
├── plugins/ # Standalone plugins with commands
│ ├── skillsmith/ # Skill creation and validation
│ ├── marketplace-manager/ # Marketplace operations
│ └── gateway-manager/ # Gateway configuration (kgateway + agentgateway)
├── skills/ # Legacy skill-only plugins
│ ├── terminal-guru/
│ ├── helm-chart-developer/
│ ├── swift-dev/
│ ├── obsidian-pkm-manager/
│ ├── omnifocus-manager/
│ └── ai-risk-mapper/
├── commands/ # Shared commands
├── agents/ # Specialized AI agents
├── hooks/ # Event handlers
├── mcp-servers/ # MCP server integrations
└── .claude-plugin/ # Marketplace configuration
Standalone plugins include slash commands for common operations:
/ss-validate - Quick skill validation/ss-evaluate - Full evaluation with metrics/ss-init - Initialize new skill from template/ss-research - Research skill improvements/mp-sync - Sync versions to marketplace.json and README.md/mp-validate - Validate marketplace structure/mp-add - Add skill or create plugin/mp-list - List marketplace plugins/mp-status - Show version mismatches/gw-status - Check gateway status/gw-logs - View gateway logs/gw-debug - Debug gateway issues/gw-backend - Configure backends/gw-route - Manage routesContributions are welcome! Whether you want to:
Please feel free to open an issue or submit a pull request.
This project is licensed under the MIT License - see the LICENSE file for details.
Note: This is an independent community project and is not officially affiliated with Anthropic.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimSlack Web API access via Python CLI for Canvas CRUD, reactions, threads, and history.
Personal Knowledge Management expert for Obsidian vaults with autonomous orchestration
Multi-skill plugin for Kubernetes Gateway API (kgateway) and AI/LLM routing (agentgateway) — provider backends, MCP server routing, external processing, version lifecycle management, and traffic policies
Opinionated guidance for managing change across documents, code, and experiments. Covers git (primary), jujutsu, and historical VCS tools with strong opinions on commit craft, branching, merge strategy, and multi-agent worktree workflows.
Terminal diagnostics, configuration, zsh development, system observability, and environment composition expert for macOS/Unix systems. Includes an orchestrator agent for diagnostic triage and four focused skills: terminal-emulation (terminfo, Unicode, display), zsh-dev (autoload functions, fpath, testing, performance), signals-monitoring (macOS logging, Unix signals, file watching, notifications), and environment-composition (sesh.toml config, claude CLI integration, direnv, worktree workflows).
npx claudepluginhub totallygreg/claude-mp --plugin ai-risk-mapperRuntime security for AI agents. Blocks destructive actions before execution, routes high-risk operations through human approval, and maintains an immutable audit trail. Covers OWASP MCP Top 10, ASI Top 10, and Agentic Skills Top 10.
Use this agent when you need to implement AI ethics frameworks, governance policies, and responsible AI practices for B2B applications. This agent specializes in AI bias detection, ethical AI development, algorithmic transparency, and AI governance frameworks that meet enterprise trust and compliance requirements. Examples:
Cybersecurity skills for AI agents — code audit, cloud, recon, IR, AI security, and more
🛡️ Security Engineer — Security Engineer + Adversarial Security Specialist
Achieve flow state safely with Claude Code. Auto-approves routine work, gates risky actions, hard-blocks dangerous patterns. Dual enforcement (skill + hooks), token cap for cost governance, full audit trail. Zero dependencies.
Route upstream epistemic deficits and evaluate execution-time risks — /attend (προσοχή: attention)