Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add UnboundCompute/security-agent-skillsnpx agentmods add plugins/unboundcompute/security-agent-skills/security-agent-skillsgit clone --depth 1 https://github.com/UnboundCompute/security-agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/unboundcompute/security-agent-skills/security-agent-skills)<a href="https://agentmods.dev/plugins/unboundcompute/security-agent-skills/security-agent-skills"><img src="https://agentmods.dev/badge/plugins/unboundcompute/security-agent-skills/security-agent-skills.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
security-agent-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 136 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"name": "security-agent-skills",
"version": "0.14.0",
"description": "Security-testing methodology as portable agent skills, spanning white-box bug hunting, AI-agent and LLM red-teaming, cloud identity and CI/CD trust, client-app trust surfaces across browser and editor extensions and Electron, wire-protocol and token trust across gRPC, WebSocket, and JWT, enterprise identity lifecycle across SCIM and JIT provisioning, directory sync, SSO logout, MFA and key lifecycle, Kerberos delegation, and break-glass and machine-identity trust, infrastructure-as-code and container hardening, mobile app security, smart-contract and DeFi review across EVM and Move, skill and MCP supply-chain vetting, API and object-authorization depth, host privilege escalation, network-service and transport trust, firmware and embedded-software trust, web trust boundaries, authentication and session depth, rate-limiting and multi-tenant isolation, injection and resource-exhaustion depth, file-upload and content handling, defensive detection and logging, supply-chain and dependency risk, business-logic and access-control depth, the classic web-attack classes across reflected and stored XSS, server-side template and OS-command injection, XXE and XPath, path traversal, formula and include injection, HTTP parameter pollution, and CRLF, plus the web trust-boundary classes across open redirect, CSRF, host-header and URL-parsing trust, web cache deception, server-side rendering and SVG abuse, Unicode canonicalization bypass, postMessage trust, and information exposure, and appsec classics. Every skill is tool-agnostic and emits a shared finding schema.",
"author": {
"name": "UnboundCompute"
},
"homepage": "https://github.com/UnboundCompute/security-agent-skills",
"repository": "https://github.com/UnboundCompute/security-agent-skills",
"license": "MIT",
"keywords": [
"security",
"appsec",
"red-team",
"vulnerability-research",
"static-analysis",
"taint-analWhat it installs
The manifest is a name and a version. 58 skills travel with it, and installing the plugin installs all of them — 9,771 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill auditing-guard-gaps A 111 tokens
- Skill auditing-account-recovery-and-reset-trust A 183 tokens
- Skill auditing-ansible-become-and-vault-trust A 179 tokens
- Skill auditing-browser-extension-trust A 191 tokens
- Skill auditing-cors-and-cross-origin-trust A 188 tokens
- Skill auditing-datastore-exposure-and-abuse A 175 tokens
- Skill auditing-device-code-and-pkce-flows A 188 tokens
- Skill auditing-editor-extension-workspace-trust A 188 tokens
- Skill auditing-electron-ipc-trust A 189 tokens
- Skill auditing-file-upload-and-content-handling A 207 tokens
- Skill auditing-grpc-service-authorization A 182 tokens
- Skill auditing-host-mount-and-device-exposure A 169 tokens
- Skill auditing-http2-and-grpc-multiplexing-trust A 193 tokens
- Skill auditing-init-and-sidecar-injection-trust A 180 tokens
- Skill auditing-jwt-verification-and-key-trust A 185 tokens
- Skill auditing-jwt-verification-trust A 218 tokens
- Skill auditing-message-broker-topic-authorization A 166 tokens
- Skill auditing-move-resource-ownership A 197 tokens
- Skill auditing-namespace-as-tenant-boundary A 162 tokens
- Skill auditing-oauth-token-audience-and-scope-trust A 193 tokens
- Skill auditing-observability-pipeline-collector-trust A 176 tokens
- Skill auditing-payment-callback-and-amount-integrity A 184 tokens
- Skill auditing-payment-state-machine-and-idempotency A 175 tokens
- Skill auditing-randomness-and-nonce-quality A 191 tokens
- Skill auditing-saml-and-oidc-federation-trust A 183 tokens
- Skill auditing-secure-boot-and-firmware-signing A 184 tokens
- Skill auditing-session-lifecycle-and-fixation A 190 tokens
- Skill auditing-admission-control-policy-gaps A 154 tokens
- Skill auditing-android-component-exposure A 172 tokens
- Skill auditing-cicd-oidc-trust A 137 tokens
- Skill auditing-container-image-build-hardening A 171 tokens
- Skill auditing-container-image-provenance A 155 tokens
- Skill auditing-container-runtime-and-socket-exposure A 161 tokens
- Skill auditing-cross-account-role-trust-boundaries A 173 tokens
- Skill auditing-ecs-task-metadata-boundaries A 165 tokens
- Skill auditing-graphql-attack-surface A 159 tokens
- Skill auditing-iac-module-and-provider-supply-chain A 169 tokens
- Skill auditing-infrastructure-as-code-exposures A 172 tokens
- Skill auditing-kms-key-policy-and-envelope-encryption A 171 tokens
- Skill auditing-kubernetes-workload-and-rbac-hardening A 178 tokens
- Skill auditing-mobile-deeplink-trust A 192 tokens
- Skill auditing-network-policy-segmentation-gaps A 167 tokens
- Skill auditing-presigned-url-scope-abuse A 173 tokens
- Skill auditing-s3-object-ownership-trust A 175 tokens
- Skill auditing-security-logging-completeness A 178 tokens
- Skill auditing-serverless-event-source-trust A 182 tokens
- Skill auditing-service-mesh-mtls-and-authz-trust A 164 tokens
- Skill auditing-skill-and-mcp-instructions A 147 tokens
- Skill auditing-smart-contract-access-control A 180 tokens
- Skill adjudicating-dependency-cve-reachability A 122 tokens
- Skill adjudicating-taint-paths A 128 tokens
- Skill auditing-ai-agent-permissions A 116 tokens
- Skill auditing-declarative-authorization A 111 tokens
- Skill auditing-declared-vs-used-permissions A 128 tokens
- Skill auditing-mcp-tool-integrations A 130 tokens
- Skill auditing-ml-model-supply-chain A 117 tokens
- Skill auditing-saml-and-oidc-flows A 111 tokens
- Skill auditing-multi-tenant-isolation B 186 tokens
What ships with it
1 file beside plugin.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · +45 lines 1ca53fe046cd
- 5d ago First seen · 91 lines scan A 8a9b56675915
security-agent-skills is a plugin published in the GitHub repository UnboundCompute/security-agent-skills (5 stars, last pushed yesterday), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
nextjs
Official Next.js skills: adopt and optimize Cache Components, adopt Partial Prefetching, and verify runtime behavior against a running dev server.
claude-plugins-official marketplace
Directory of popular Claude Code extensions including development tools, productivity plugins, and MCP integrations.
humanizer
Rewrite AI-sounding text so it reads naturally without changing what it says.
knowledge-work-plugins marketplace
Plugin marketplace listing 98 plugins: noibu, productivity, enterprise-search, cowork-plugin-management, sales.
mattpocock-skills
Matt Pocock's agent skills for real engineering: grilling, spec/ticket flows, TDD, code review, domain modelling and more. Plug-and-play, not vibe coding.
container
Teaches Claude container's command surface and how it maps to Docker, Lima, Colima, and Podman on macOS.