Operate BurpSuite MCP Bridge for professional, authorized web testing. Use when Codex needs to inspect Burp live/history/logger/selection traffic, prioritize one target, retrieve a decisive request/response, intercept and edit a request or response before forwarding, replay one controlled mutation, manage temporary…
Use the EnigmAgent encrypted vault to handle credentials, API keys, and private documents without those values ever appearing in your reasoning or output. Placeholders are resolved at execution time.
Install, configure, operate, and troubleshoot ToolPermit, the local-first permission policy, one-time approval, and redacted audit layer for MCP stdio tool calls. Use when Codex needs to protect or inspect an MCP server, wrap an MCP stdio command, create or review allow/ask/deny policies, manage approvals, replay…
Skill "marq" from rhaist/marq, covering marq — cyber assistant, start here — scope and domains, how to call a tool, discover tools and long-running scans.
Use when an AI coding agent must provision, inject, run, or rotate secrets without ever seeing their plaintext — you work with ss:// refs (like ss://stripe/prod/STRIPEWEBHOOKSECRET) while a local daemon resolves the real value at the last possible moment.
Threat hunting is the proactive, analyst-driven search for threats that have evaded automated detection. Unlike detection engineering (which builds rules that fire automatically), hunting is a human-led investigation that uses hypotheses, data analysis, and domain expertise to find adversary activity that does not…
Audit any repo for security holes — a web/app project, a Claude skill, a Claude Code plugin, an MCP server, or an agent. Catches the glaring stuff (exposed servicerole keys, RLS off, committed .env, secrets in the client bundle, allow read,write: if true) and the subtle stuff (IDOR, SSRF, prompt injection in a…
WordPress theme and plugin review skill. Detects whether a target path is a theme or plugin, runs security and standards checks, scores the findings, and writes a markdown report. Use when the user wants to review a WordPress theme or plugin directory, generate a code review report, inspect WordPress security posture…
A security-auditing skill for inspecting AI skills and plugins with static code analysis. Static analysis examines code without running it, while an abstract syntax tree represents its structure.
Review Claude/Cursor Skills for security issues (prompt injection, agentic/tool injection, data exfiltration, unsafe automation). Use when evaluating a Skill package/folder or SKILL.md + bundled scripts for risks like hidden instructions, tool misuse, credential theft, network exfil, destructive commands, and policy…
Pre-install security advisor. Activate when the user mentions installing a Claude Code plugin, MCP server, or any third-party agent tool. Offer to run an Assay scan against the target before they install.
Secure agent-to-agent hiring and execution skill for OpenClaw MCP with escrowed settlement, x402 facilitator payments, ERC-8004 identity/reputation checks, strict replay protection, DNS-safe endpoint validation, and MPC wallet signing. Use when building or operating production A2A workflows that require…
Analyze AWS infrastructure security using Cyntrisec MCP tools. Use when asked about AWS attack paths, security findings, IAM permissions, compliance status, or remediation recommendations. Guides tool selection and workflow patterns for comprehensive security assessments.
OpenFGA authorization modeling best practices for defining types and relations, writing relationship tuples, deriving can permissions, applying type restrictions and usersets, and authoring .fga.yaml check/listobjects/listusers tests. Use when authoring, reviewing, or refactoring OpenFGA models, tuples, permissions…
Manage AgentLair email channel access — edit sender allowlists and set policy. Use when the user asks to allow or block email senders, check who can reach them, or change access policy.
Security review of LLM applications and agents. Use when asked to review, red-team, threat-model or test an LLM feature, chatbot, RAG pipeline, MCP server or autonomous agent for prompt injection (direct or indirect), jailbreaks, system prompt or secret leakage, tool abuse, excessive agency, confused-deputy behavior…
Use when the user asks to audit a Solana or Anchor codebase, explain report-backed Solana vulnerability classes, review signer or PDA bugs, analyze CPI trust boundaries, assess Token-2022 or payment integrations, digest a public Solana audit report, investigate an exploit path, plan formal verification or invariant…
Static malware reverse-engineering and threat-intelligence triage for unknown files, Windows EXE/PE binaries, scripts, archives, ISOs, JavaScript, PowerShell, documents, and unpacked payloads. Use when a user provides a sample path, hash, filename, or file and asks whether it is malicious, benign, suspicious, contains…
Use this skill to audit an AI system for security vulnerabilities including prompt injection, sensitive data exposure, excessive agent permissions, unsafe tool calls, and insecure output handling. Grounded in OWASP GenAI LLM Top 10 (2026). Activates before production deployment of any LLM-based application, agent, or…
Evidence-first codebase audit for correctness, security, privacy, data, integration, operational, test, and docs-vs-reality risks. Use when the user asks for a Fable-5 audit, exhaustive audit, bug hunt, risk review, codebase audit, security/integration audit, or asks Codex to find issues before changing code.
Core threat analysis engine. Takes a system context profile and applies one or more threat modeling frameworks (STRIDE, PASTA, LINDDUN, VAST, Attack Trees, OCTAVE) with automatic threat actor profiling.
★not rated 4 1mo agoA52 tokens
originalApache-2.0
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: