# How Security-Focused Plugins Like agentic-security and 42crunch-api-security-testing Function in Claude Code

> Discover how security plugins like agentic-security and 42crunch function in Claude Code. Learn about their use of SAST, SCA, and OpenAPI auditing for enhanced code security.

- Repository: [Anthropic/claude-plugins-community](https://github.com/anthropics/claude-plugins-community)
- Tags: deep-dive
- Published: 2026-09-02

---

**Security-focused plugins in the Claude Code ecosystem function as external MCP-based extensions that clone from remote repositories, register modular skills defined in the community marketplace, and execute static analysis pipelines—combining SAST, SCA, secrets detection, and OpenAPI auditing—before returning structured findings that Claude can remediate via AI-generated patches.**

The anthropics/claude-plugins-community repository hosts a curated marketplace of extensions that augment Claude Code with specialized capabilities. Security-focused plugins like **agentic-security** and **42crunch-api-security-testing** integrate directly into the editor to provide automated vulnerability scanning, transforming Claude Code into a comprehensive security audit workstation that combines static analysis with AI-assisted remediation.

## Plugin Discovery and Installation Workflow

When a user executes `/install <plugin-name>`, Claude Code references the plugin manifest located in [`.claude-plugin/marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json) to locate the source repository.

For **agentic-security**, the marketplace entry points to [`https://github.com/Clear-Capabilities/agentic-security.git`](https://github.com/Clear-Capabilities/agentic-security.git) with a specific SHA reference [`cda40a57…`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json#L724-L731). For **42crunch-api-security-testing**, the entry references the sub-directory `plugins/api-security-testing` within the [`42Crunch-AI/claude-plugins`](https://github.com/42Crunch-AI/claude-plugins) repository at version [`v1.0.1`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json#L54-L61).

Claude Code clones the specified repository and registers the plugin's skills—mapping slash commands to executable server-side scripts that run the actual security analysis.

## Command Dispatch and MCP Communication

Once installed, plugins operate via the **Model Context Protocol (MCP)**. When a user invokes a slash command like `/security-audit` or `/api-sec-audit`, Claude Code dispatches the command to the plugin's MCP server along with the current workspace context.

This stateless communication protocol ensures that skills remain modular and reproducible. Each command triggers a specific **server-side script** defined in the plugin's skill configuration, which then executes the corresponding security analysis pipeline.

## Static Analysis Architectures

Both plugins employ distinct static analysis methodologies tailored to their security domains.

### Agentic Security Multi-Scanner Pipeline

The **agentic-security** plugin orchestrates a collection of open-source security scanners including Bandit, ESLint-security, and Trivy. According to the repository's [[`README.md`](https://github.com/anthropics/claude-plugins-community/blob/main/README.md)](https://github.com/Clear-Capabilities/agentic-security/blob/main/README.md), the plugin unifies findings from multiple sources:

- **SAST (Static Application Security Testing)**: Analyzes source code for vulnerabilities like injection flaws and insecure configurations.
- **SCA (Software Composition Analysis)**: Scans dependencies for known CVEs and license violations.
- **Secrets Detection**: Identifies hardcoded API keys, tokens, and credentials using entropy-based pattern matching.

The aggregated results are normalized into a unified JSON format that Claude Code renders as markdown tables displaying severity levels, descriptions, and affected file paths.

### 42Crunch OpenAPI Security Auditing

The **42crunch-api-security-testing** plugin specializes in API security by parsing OpenAPI specifications and running them through the proprietary **42Crunch security engine**. As documented in [[`plugins/api-security-testing/README.md`](https://github.com/anthropics/claude-plugins-community/blob/main/plugins/api-security-testing/README.md)](https://github.com/42Crunch-AI/claude-plugins/blob/main/plugins/api-security-testing/README.md), the engine identifies OWASP API Top 10 threats including:

- **BOLA (Broken Object Level Authorization)**: Detects endpoints lacking proper resource-level access controls.
- **BFLA (Broken Function Level Authorization)**: Identifies privilege escalation vulnerabilities in API operations.
- **Schema violations**: Flags discrepancies between defined specifications and security best practices.

## Dynamic Testing and Live Conformance

Beyond static analysis, **42crunch-api-security-testing** supports **live conformance testing**. The plugin can spin up temporary testing environments to execute actual HTTP requests against running API endpoints, verifying that runtime behavior matches the OpenAPI contract.

This hybrid approach catches implementation bugs that static analysis misses, such as missing authentication headers in production responses or undocumented endpoints that violate the spec.

## AI-Driven Remediation Workflow

Both plugins expose remediation commands (`/security-fix`, `/api-remediate`) that bridge the gap between detection and resolution. When a user requests a fix:

1. The plugin feeds the vulnerability context back to Claude's language model.
2. The model generates a context-aware patch addressing the specific finding.
3. The suggested fix is presented for human review before application.

This workflow ensures that hardcoded secrets are replaced with environment variable references, insecure dependencies are upgraded, and authorization flaws receive targeted corrections—all under developer supervision.

## Practical Usage Examples

Install and operate these plugins using standard Claude Code slash commands:

```bash

# Install the security plugins

/install agentic-security
/install 42crunch-api-security-testing

# Run comprehensive application security audit

/security-audit

# Returns: Table of SAST, SCA, and secrets-scan findings with severity ratings

# Remediate a specific finding by ID

/security-fix --id 12

# Returns: AI-generated patch for the identified vulnerability

# Audit an OpenAPI specification for OWASP threats

/api-sec-audit openapi.yaml

# Returns: List of BOLA, BFLA, and schema violations

# Execute live conformance testing against a running API

/api-sec-scan --base-url https://api.myservice.com

# Returns: Mismatches between OpenAPI spec and actual runtime behavior

```

## Key Source Files and Configuration

Understanding the plugin architecture requires referencing these specific implementation files:

- **Agentic Security README**: [[`README.md`](https://github.com/anthropics/claude-plugins-community/blob/main/README.md)](https://github.com/Clear-Capabilities/agentic-security/blob/main/README.md) documents the modular scanner architecture, supported security tools, and command specifications.
- **42Crunch Plugin README**: [[`plugins/api-security-testing/README.md`](https://github.com/anthropics/claude-plugins-community/blob/main/plugins/api-security-testing/README.md)](https://github.com/42Crunch-AI/claude-plugins/blob/main/plugins/api-security-testing/README.md) details the OpenAPI audit flow, OWASP threat detection capabilities, and live testing procedures.
- **Marketplace Manifest**: [`.claude-plugin/marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json) lines [724-731](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json#L724-L731) define agentic-security's repository URL and version pinning, while lines [54-61](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json#L54-L61) specify 42crunch's sub-directory installation path.

## Summary

- **Security plugins function as MCP-based extensions** discovered through the anthropics/claude-plugins-community marketplace manifest.
- **Agentic-security combines multiple open-source scanners** (Bandit, Trivy, ESLint-security) for comprehensive SAST/SCA/secrets detection.
- **42crunch specializes in API security** via OpenAPI analysis and OWASP threat detection, with optional live conformance testing.
- **Both plugins return structured JSON findings** that Claude Code formats into actionable markdown reports.
- **Remediation commands leverage AI** to generate context-aware patches for detected vulnerabilities.
- **Installation sources are strictly version-controlled** via SHA references in [`.claude-plugin/marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json) to ensure reproducible builds.

## Frequently Asked Questions

### How do I install security plugins in Claude Code?

Run the `/install` command followed by the plugin name, such as `/install agentic-security` or `/install 42crunch-api-security-testing`. Claude Code reads the repository URL and version SHA from [`.claude-plugin/marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json), clones the source code, and registers the available slash commands automatically.

### What is the difference between agentic-security and 42crunch-api-security-testing?

**Agentic-security** provides broad application security coverage using multiple open-source scanners to detect code vulnerabilities, dependency issues, and leaked secrets. **42crunch-api-security-testing** focuses specifically on API security, analyzing OpenAPI specifications for OWASP API threats and optionally testing live endpoints for conformance. Use agentic-security for general codebases and 42crunch for API-first projects.

### Can these plugins automatically fix security vulnerabilities?

Yes, both plugins support AI-assisted remediation through commands like `/security-fix` and `/api-remediate`. The plugins feed vulnerability details back to Claude, which generates specific patches to address findings. However, all patches require explicit human approval before application to ensure safety.

### Does 42crunch testing require a running API server?

Static OpenAPI auditing works without a running server, but the **live conformance testing** feature requires an accessible API endpoint via the `--base-url` parameter. This dynamic analysis validates that the actual implementation matches the OpenAPI specification and catches runtime-specific security gaps.