Verify an exact public GitHub Agent Skill commit before installation, optionally purchase fresh isolated evidence over x402, and validate the signed receipt plus live lifecycle status. Use before installing or activating an unfamiliar SKILL.md package, when prior evidence may be stale, or when policy requires…
Investigate authorized binaries and runtime behavior with HexWitness's durable evidence MCP and optional Binary Ninja or IDA live tools. Use for function or class discovery, UUID and field mapping, protocol reconstruction, capture comparison, contradiction analysis, evidence-gap planning, and promotion of live…
Lightweight AI security guard that intercepts risky install/download commands (npm, npx, pip, cargo, git clone) to block known malicious packages and scan for suspicious code. Invoke ONLY when user runs install/download/clone commands.
Routes all platform API calls through AgentValet's credential proxy. Your raw API keys and OAuth tokens are never exposed to this agent — AgentValet injects the correct credential per platform call.
Run Bumblebee supply-chain inventory and exposure scans on the local machine. Use this skill whenever the user wants to check developer endpoints for compromised npm/PyPI/Go/RubyGems/Composer packages, audit installed editor or browser extensions, inspect MCP host configs, or perform supply-chain incident response on…
Interactive wizard to configure Claude Code permission rules. Sets up granular allow/ask permissions so you can work without --dangerously-skip-permissions while keeping safety nets for destructive commands. Use when user says "configure permissions", "set up permissions", "permission settings", or "stop asking me for…
★not rated 1 6mo agoA✓ AI review65 tokens
originalMIT
End-to-end agentic engineering for iPhone apps, from idea to a secure App Store release through 8 gated phases. Use when someone wants to build, plan, or ship an iPhone/iOS app — especially a non-programmer ("vibe coder") asking to create an app, pick a tech stack (SwiftUI, React Native, Flutter), choose a backend…
A Chinese-language guide for explaining the hidden roles and trust relationships in technical systems. It clarifies who owns tokens, keys, certificates, and endpoints, who checks them, and what each party proves.
Act as a senior GitHub platform architect, open-source maintainer, DevSecOps engineer, and repository governance specialist. Produce repository systems that are understandable, maintainable, secure by default, automation-friendly, and practical for real teams.
Skill "security-claude" from rahozosman/security-claude, covering security architecture & threat modeling intelligence, how this skill is organized (progressive disclosure), 1. pick a mode, 2. core method (applies to every mode) and 3. doing a focused review.
A skill that collects recent news from RSS feeds about hackers, artificial intelligence, security, and technology, then categorises and summarises it in Traditional Chinese. RSS is a format websites use to publish updates.
The Dependency Auditor is a comprehensive toolkit for analyzing, auditing, and managing dependencies across multi-language software projects. This skill provides deep visibility into your project's dependency ecosystem, enabling teams to identify vulnerabilities, ensure license compliance, optimize dependency trees…
Review the current diff against path-scoped rules (secrets, RLS/tenant scoping, Stripe webhook verification, input validation, scope), flag changed code lacking tests, and run a quick security pass. Reports findings; nothing auto-fixed without approval.
Production-grade red-team security audit skill for AI coding assistants. Audits codebases for OWASP Top 10 vulnerabilities, auth flaws, IDOR, XSS, SSRF, JWT misuse, Supabase policies, and provides drop-in secure code replacements with zero exfiltration risk.
A deliberately malicious demo Skill that tries to exfiltrate secrets over the network and read /.ssh/idrsa. Used to show Capsule blocking the calls at the call site.
Use when a project needs the OpenSpec + Superpowers sdd-tdd (spec-to-plan-to-TDD) workflow checked, installed, and configured -- or cleanly removed -- in any coding agent (Codex, Claude Code, Cursor, Antigravity, OpenCode, Gemini CLI, Copilot CLI, or others).
Use this skill whenever the user needs SonarCloud or SonarQube issue and hotspot triage, measures, gates, profiles, settings, tags, or safe mutations with environment-variable tokens.
Full-spectrum web application Vulnerability Assessment and Penetration Testing (VAPT). Automates reconnaissance, scanning, injection testing, authentication analysis, and report generation. Supports --mode pro (terse) and --mode dev (educational). Enforces authorization gate before any active testing.
★not rated 1 5mo agoA60 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: