How Security-Focused Plugins Like agentic-security and 42crunch-api-security-testing Function in Claude Code

Security-focused plugins in the Claude Code ecosystem function as external MCP-based extensions that clone from remote repositories, register modular skills defined in the community marketplace, and execute static analysis pipelines—combining SAST, SCA, secrets detection, and OpenAPI auditing—before returning structured findings that Claude can remediate via AI-generated patches.

The anthropics/claude-plugins-community repository hosts a curated marketplace of extensions that augment Claude Code with specialized capabilities. Security-focused plugins like agentic-security and 42crunch-api-security-testing integrate directly into the editor to provide automated vulnerability scanning, transforming Claude Code into a comprehensive security audit workstation that combines static analysis with AI-assisted remediation.

Plugin Discovery and Installation Workflow

When a user executes /install <plugin-name>, Claude Code references the plugin manifest located in .claude-plugin/marketplace.json to locate the source repository.

For agentic-security, the marketplace entry points to https://github.com/Clear-Capabilities/agentic-security.git with a specific SHA reference cda40a57…. For 42crunch-api-security-testing, the entry references the sub-directory plugins/api-security-testing within the 42Crunch-AI/claude-plugins repository at version v1.0.1.

Claude Code clones the specified repository and registers the plugin's skills—mapping slash commands to executable server-side scripts that run the actual security analysis.

Command Dispatch and MCP Communication

Once installed, plugins operate via the Model Context Protocol (MCP). When a user invokes a slash command like /security-audit or /api-sec-audit, Claude Code dispatches the command to the plugin's MCP server along with the current workspace context.

This stateless communication protocol ensures that skills remain modular and reproducible. Each command triggers a specific server-side script defined in the plugin's skill configuration, which then executes the corresponding security analysis pipeline.

Static Analysis Architectures

Both plugins employ distinct static analysis methodologies tailored to their security domains.

Agentic Security Multi-Scanner Pipeline

The agentic-security plugin orchestrates a collection of open-source security scanners including Bandit, ESLint-security, and Trivy. According to the repository's [README.md](https://github.com/Clear-Capabilities/agentic-security/blob/main/README.md), the plugin unifies findings from multiple sources:

  • SAST (Static Application Security Testing): Analyzes source code for vulnerabilities like injection flaws and insecure configurations.
  • SCA (Software Composition Analysis): Scans dependencies for known CVEs and license violations.
  • Secrets Detection: Identifies hardcoded API keys, tokens, and credentials using entropy-based pattern matching.

The aggregated results are normalized into a unified JSON format that Claude Code renders as markdown tables displaying severity levels, descriptions, and affected file paths.

42Crunch OpenAPI Security Auditing

The 42crunch-api-security-testing plugin specializes in API security by parsing OpenAPI specifications and running them through the proprietary 42Crunch security engine. As documented in [plugins/api-security-testing/README.md](https://github.com/42Crunch-AI/claude-plugins/blob/main/plugins/api-security-testing/README.md), the engine identifies OWASP API Top 10 threats including:

  • BOLA (Broken Object Level Authorization): Detects endpoints lacking proper resource-level access controls.
  • BFLA (Broken Function Level Authorization): Identifies privilege escalation vulnerabilities in API operations.
  • Schema violations: Flags discrepancies between defined specifications and security best practices.

Dynamic Testing and Live Conformance

Beyond static analysis, 42crunch-api-security-testing supports live conformance testing. The plugin can spin up temporary testing environments to execute actual HTTP requests against running API endpoints, verifying that runtime behavior matches the OpenAPI contract.

This hybrid approach catches implementation bugs that static analysis misses, such as missing authentication headers in production responses or undocumented endpoints that violate the spec.

AI-Driven Remediation Workflow

Both plugins expose remediation commands (/security-fix, /api-remediate) that bridge the gap between detection and resolution. When a user requests a fix:

  1. The plugin feeds the vulnerability context back to Claude's language model.
  2. The model generates a context-aware patch addressing the specific finding.
  3. The suggested fix is presented for human review before application.

This workflow ensures that hardcoded secrets are replaced with environment variable references, insecure dependencies are upgraded, and authorization flaws receive targeted corrections—all under developer supervision.

Practical Usage Examples

Install and operate these plugins using standard Claude Code slash commands:


# Install the security plugins

/install agentic-security
/install 42crunch-api-security-testing

# Run comprehensive application security audit

/security-audit

# Returns: Table of SAST, SCA, and secrets-scan findings with severity ratings

# Remediate a specific finding by ID

/security-fix --id 12

# Returns: AI-generated patch for the identified vulnerability

# Audit an OpenAPI specification for OWASP threats

/api-sec-audit openapi.yaml

# Returns: List of BOLA, BFLA, and schema violations

# Execute live conformance testing against a running API

/api-sec-scan --base-url https://api.myservice.com

# Returns: Mismatches between OpenAPI spec and actual runtime behavior

Key Source Files and Configuration

Understanding the plugin architecture requires referencing these specific implementation files:

Summary

  • Security plugins function as MCP-based extensions discovered through the anthropics/claude-plugins-community marketplace manifest.
  • Agentic-security combines multiple open-source scanners (Bandit, Trivy, ESLint-security) for comprehensive SAST/SCA/secrets detection.
  • 42crunch specializes in API security via OpenAPI analysis and OWASP threat detection, with optional live conformance testing.
  • Both plugins return structured JSON findings that Claude Code formats into actionable markdown reports.
  • Remediation commands leverage AI to generate context-aware patches for detected vulnerabilities.
  • Installation sources are strictly version-controlled via SHA references in .claude-plugin/marketplace.json to ensure reproducible builds.

Frequently Asked Questions

How do I install security plugins in Claude Code?

Run the /install command followed by the plugin name, such as /install agentic-security or /install 42crunch-api-security-testing. Claude Code reads the repository URL and version SHA from .claude-plugin/marketplace.json, clones the source code, and registers the available slash commands automatically.

What is the difference between agentic-security and 42crunch-api-security-testing?

Agentic-security provides broad application security coverage using multiple open-source scanners to detect code vulnerabilities, dependency issues, and leaked secrets. 42crunch-api-security-testing focuses specifically on API security, analyzing OpenAPI specifications for OWASP API threats and optionally testing live endpoints for conformance. Use agentic-security for general codebases and 42crunch for API-first projects.

Can these plugins automatically fix security vulnerabilities?

Yes, both plugins support AI-assisted remediation through commands like /security-fix and /api-remediate. The plugins feed vulnerability details back to Claude, which generates specific patches to address findings. However, all patches require explicit human approval before application to ensure safety.

Does 42crunch testing require a running API server?

Static OpenAPI auditing works without a running server, but the live conformance testing feature requires an accessible API endpoint via the --base-url parameter. This dynamic analysis validates that the actual implementation matches the OpenAPI specification and catches runtime-specific security gaps.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →