security-scanning
SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, and container security hardening.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for security-scanning, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
A Claude Code plugin from the claude-code-workflows marketplace bundling security subagents and commands for static analysis (SAST), dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and automated hardening. It runs security tooling over the codebase and dependencies, squarely on the security surface.
Key features and capabilities
- SAST + dependency scanning
- OWASP Top 10 compliance checks
- Container security hardening
Use cases
- Scan a codebase for vulnerabilities
- Harden containers and dependencies