Grounds your AI coding agent in a cited security baseline (OWASP/CWE/EU AI Act) and warns before risky actions. Advisory, free, read-only. Real-time blocking is Kernora Axiora.
★not rated 1 1mo agoA
tokens not measured
originalApache-2.0
Pre-execution governance for AI agents. Intercepts MCP tool calls with deterministic blocking, human-in-the-loop holds, and behavioral drift detection.
★not rated 1 2mo agoA
tokens not measured
originalMIT
Adversarial co-generation engine — generates code and adversarial attacks from the same spec, concurrently. Adds /gauntlex:run and friends, plus the gauntlex MCP server.
★not rated 1 1mo agoA
tokens not measured
originalMIT
Always-on security guardrails for AI-generated code. Catches hardcoded secrets, missing auth, insecure database rules, and the 20 things AI agents forget before you deploy.
★not rated 1 6mo agoA
tokens not measured
originalMIT
Operator skills for Forseti, the web UI and admin console for the Ory Kratos + Hydra identity stack: guided setup (with or without Docker), goal-driven reconfiguration (login providers, Linux/POSIX login, downstream OAuth clients), and a best-practice security audit of an existing deployment.
★not rated 1 26d agoA
tokens not measured
originalMIT
Verifies in compiled machine code that secret zeroization survived dead-store elimination and that constant-time logic did not regain secret-dependent branches. Ships a Ghidra headless inventory script. Use when auditing a binary, shared object, or firmware image against a source-level guarantee.
★not rated 1 27d agoA
tokens not measured
originalMIT
Agent-building practices from Anthropic's engineering blog, packaged as installable Claude Code skills, MCP servers, and safety hooks for tool-gating and prompt-injection screening. Covers the gaps no existing skill pack fills.
★not rated 1 1mo agoA
tokens not measured
originalMIT
Arcjet is the runtime security platform that ships in your AI code. Detect prompt injection, authorize agent tool calls, redact sensitive data, and block bots and abuse. Real-time security building blocks you call inside your app, before an action happens.
★not rated 1 2d agoA
tokens not measured
originalApache-2.0
Dependency and repository management skills powered by git-pkgs, brief, forge, pin, and capcheck. Track dependency history, scan for vulnerabilities, evaluate packages, generate SBOMs, work across git forges, and more.
★not rated 1 18d agoA
tokens not measured
originalMIT
Hook-enforced ground-truth verification for Claude Code. Catches fabricated package names, unpublished versions, unresolvable imports, and nonexistent git SHAs before they land in your codebase — and feeds the correction back to Claude so it fixes itself in-loop.
★not rated 1 1mo agoA
tokens not measured
originalMIT
Full health checkup for any repository: Health Score 0-100, findings across 5 dimensions (security, code quality, testing, production readiness, docs), a prioritized fix plan, and one-command fixes with /audit fix N.
★not rated 1 1mo agoA
tokens not measured
originalMIT
Enforcement + ops automation for Claude Code — Python hooks, MCP server, system management.
★not rated 1 4mo agoA
tokens not measured
AGPL-3.0
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: