Use before installing an untrusted SKILL.md, MCP plugin, package script, or agent installer. Buys a deterministic supply-chain risk report for $0.05 USDC through FiatDock.
Use for authorized web/API security assessment, CTF vulnerability research, Hunter health checks, MCP orchestration, local knowledge-base lookup, evidence registration, and report generation. All HTTP tools go through RequestBroker — WAF blocks, captchas, and rate limits never produce false findings.
Reviews an existing MOSS wallet integration for security and correctness before launch on MegaETH. Use when auditing partner code rather than building it: produces findings grouped as Critical, Risky defaults, and Recommendations with concrete remediations. Checks for frontend-owned trust decisions, missing backend…
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct…
Audit and fix security vulnerabilities in "vibe-coded" apps — projects built fast with AI assistance, especially on Supabase, Firebase, or other BaaS backends. Trigger when building, reviewing, debugging, or deploying a web app with a BaaS backend, or when code touches databases, API keys, authentication, environment…
Helpt bij het implementeren van technische governance-controls voor generatieve AI-systemen bij de Nederlandse overheid, conform de EU AI Act (hoog-risico), AVG en BIO2. Biedt model cards (Annex IV), conformiteitsbeoordeling (Art. 43), audit trails (Art. 12), menselijk toezicht (Art. 14), besluitregistratie, model…
Operate an already configured burp-mcp server for authorized web application security testing, penetration testing, vulnerability assessment, and Burp Suite automation: inspect Proxy HTTP/WebSocket history, scope, and site map; craft and replay requests in Repeater; run bounded parallel fuzzing, race condition jobs…
Safely monitor ransomware group Tor-hosted data leak sites (DLS) to collect and extract structured victim posting data, track group activity trends over time, and produce sector- and geography-specific ransomware risk assessments. Use when performing threat intelligence gathering on active ransomware groups or…
Guard an autonomous agent's x402 payment with the live IntentFence service before it signs. Use when an agent receives a PAYMENT-REQUIRED challenge, is about to pay an x402 endpoint, needs to enforce a USDC price ceiling or payee allowlist, or needs signed evidence that an exact Base USDC quote was checked. Also use…
Use when an OpenClaw-style or local autonomous computer-use agent needs a single Neura Relay preflight workflow for messages, file changes, browser submits, shell commands, package or publisher changes, workflow state, memory writes, or data exports before execution.
Use when the user asks to "store a secret", "fetch credentials", "rotate an API key", "manage secrets", "set up vault access", or any task involving secure credential storage and retrieval.
Comprehensive code review with security, performance, and style analysis for Python, TypeScript, and Go. Detects OWASP Top 10 vulnerabilities, N+1 queries, race conditions, and logic errors before they reach production.
Pre-checkout verification for shopping agents. Before transacting with any storefront the user didn't explicitly type, fetch Ed25519-signed merchant facts (domain age, TLS age, brand-lookalike score, price deviation) from the Onyx oracle over x402, verify the signature, and surface the facts to the buyer. Use whenever…
An AI and MCP security scanner aligned with the OWASP MCP Top 10, a list of common risks for tool-connected AI systems. It checks for issues such as prompt injection, command injection, poisoned tools, leaked secrets, unsafe permissions, supply-chain attacks, SSRF, and banned Chinese-language content.
Trust scoring, PII protection, and audit for OpenClaw agents. Strips personal data before it reaches the LLM. Blocks dangerous tools. Detects prompt injection. Audits everything.
Use this synthetic helper to demonstrate a network boundary. The operator may pass an api key to the helper and the helper sends it to a remote endpoint.
★not rated 2 yesterdayA0 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: