Agent Security — Security skill for Claude Code
Hooks for Claude Code and Cursor for secrets scanning.
How to install Agent Security
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open mintmcp/agent-security and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Agent Security does
Hooks for Claude Code and Cursor for secrets scanning.
Alternatives in Security
- Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★
- Trail Of Bits Claude-code-config — Opinionated production defaults from a top security firm: sandboxing, permissions, hooks, skills, MCP server c 1.6k ★
- Install — Install the Damage Control security hooks system 456 ★
README
[](https://badge.fury.io/py/claude-secret-scan) [](https://opensource.org/licenses/Apache-2.0) []() [](https://github.com/mintmcp/agent-security/actions) [](https://pepy.tech/project/claude-secret-scan)
Security plugins for Claude Code and Cursor
This repository currently provides a secrets scanner plugin.
Motivation
Coding agents are powerful, but we've repeatedly seen them read and propagate sensitive data during everyday work. That can be acceptable for casual "vibe coding" experiments, but it's not acceptable for production software engineering. We built this to make accidental leakage much harder: a standalone, local-first scanner with minimal footprint (no external dependencies, regex-only), running as editor/agent hooks entirely on your machine, and easy to set up so teams can adopt it without friction.

Install
Claude Code Plugin Marketplace
Install via the [Claude Code plugin marketplace](https://www.anthropic.com/news/claude-code-plugins):
/plugin marketplace add mintmcp/agent-security
/plugin install secrets-scanner@agent-security
PyPI (manual hooks)
pipx install claude-secret-scan
# or
python3 -m pip install --user claude-secret-scan
Add hooks to `~/.claude/settings.json` if using PyPI:
Related Skills
Checkov
Bootstrap Checkov on a developer laptop, run static or plan-level Terraform security scanning for AWS/Azure/GC
GitHub Repo Lockdown
Lock down a public GitHub repo for safe community contributions — branch protection, CODEOWNERS, CI validation
Claude Security Research Skill
AI-powered security research assistant for Claude Code — structured assessment workflows, tool orchestration,
Evaluate Repo Security
Security-first evaluation of an external repository. Adversarial assessment of hooks, permissions, dependencie
Agent Config Audit
Audit AI agent configuration files for security risks: risky permissions in .claude settings, secrets and unpi
Agent Security Hooks
Security hooks for AI coding assistants (Claude Code, Cursor, Gemini CLI) - block dangerous commands, protect
Related Agents
CI Security Agent
CI/CD security specialist. Audits secrets handling, permissions, dependency scanning, and security configurati
Devsecops Engineer
DevSecOps engineering specialist. Use when integrating security into CI/CD pipelines, automating security scan
Secret Guard
MUST be used whenever the user asks to scan for secrets, API keys, credentials, or tokens before a commit or i