Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungBreeze TTS 2 vs ElevenLabs: Open Source TTS Verdict(23.09.2026 um 05:44 Uhr)
Sichere ProgrammierungAgentic AI vs Generative AI: The 2026 Verdict(23.09.2026 um 05:44 Uhr)
Sichere ProgrammierungI made my agent prove every quote against the source document(23.09.2026 um 05:45 Uhr)
Sichere Programmierung8mb.video Alternative: Skip the Line, Skip the Upsell(23.09.2026 um 05:47 Uhr)
Sichere ProgrammierungBuilding a GTA 6 JSON API for entities and current status(23.09.2026 um 05:52 Uhr)
Sichere ProgrammierungEvery filter needs a documented exception(23.09.2026 um 06:01 Uhr)
Sichere ProgrammierungBreeze TTS 2 vs ElevenLabs: Open Source TTS Verdict(23.09.2026 um 05:44 Uhr)
Sichere ProgrammierungAgentic AI vs Generative AI: The 2026 Verdict(23.09.2026 um 05:44 Uhr)
Sichere ProgrammierungI made my agent prove every quote against the source document(23.09.2026 um 05:45 Uhr)
Sichere Programmierung8mb.video Alternative: Skip the Line, Skip the Upsell(23.09.2026 um 05:47 Uhr)
Sichere ProgrammierungBuilding a GTA 6 JSON API for entities and current status(23.09.2026 um 05:52 Uhr)
Sichere ProgrammierungEvery filter needs a documented exception(23.09.2026 um 06:01 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

I built an audit plugin to audit Claude Code plugins

Claude Code’s plugin system is incredibly powerful, but it’s easy to lose track of what’s actually running in your environment. After a week of adding marketplace tools and writing custom local agents, I ran into two issues: Command Amne…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Claude Code’s plugin system is incredibly powerful, but it’s easy to lose track of what’s actually running in your environment. After a week of adding marketplace tools and writing custom local agents, I ran into two issues:





  1. Command Amnesia: Forgetting the exact names of tools and how to invoke them.


  2. Hidden Hooks: Not knowing which plugins registered PostToolUse hooks or high-risk permissions like raw Bash access.



To solve this, I built plugin-audit — a tool designed to give you a clear inventory and security overview of your workspace.






🛠️ The Commands



The plugin provides a complete toolkit to bring transparency to your setup:





  • /audit: The global scan. Lists every command, skill, agent, and hook in a clean table.


  • /audit-risk: Heuristic scoring for permissions (e.g., Critical for Bash, Low for Read).


  • /audit-diff: Snapshot comparison to see exactly what changed after adding a new plugin.


  • /audit-help <name>: Get the detailed metadata for a specific capability (very useful for debugging hooks).






🚀 Example Output














































































Name Type Source Provider Invocation
frontend-design skill plugin:frontend-design claude-plugins-official Auto-triggered by model
setup_semgrep_plugin command plugin:semgrep-plugin claude-plugins-official /setup_semgrep_plugin
code-review command plugin:code-review claude-plugins-official /code-review
code-simplifier agent plugin:code-simplifier claude-plugins-official Use code-simplifier agent
revise-claude-md command plugin:claude-md-management claude-plugins-official /revise-claude-md
audit command plugin:plugin-audit nestedcat-claude-marketplace /audit
PostToolUse:Write/Edit hook plugin:semgrep-plugin claude-plugins-official Auto-trigger
planner agent user Use planner agent
tdd-guide agent user Use tdd-guide agent





📦 Quick Start



Install it via the marketplace directly in Claude Code:




/plugins marketplace add nestedcat/nestedcat-claude-marketplace
/plugins install plugin-audit@nestedcat-claude-marketplace






Check out the source on GitHub:

👉 https://github.com/nestedcat/plugin-audit



How many plugins are you currently running?

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten I built an audit plugin to audit Claude Code plugins

Thematisch verwandte Begriffe: built, audit, plugin, Claude · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-18163 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick