Integrate AuthOS into browser, React, Vue, or plain TypeScript applications using @drmhse/sso-sdk and the AuthOS React/Vue adapters. Use when adding OAuth redirects, password login, magic links, passkeys, MFA callback handling, token refresh, or frontend session state.
7-layer AI security + ML detection for OpenClaw. Covers all 10 OWASP Agentic AI risks — prompt injection, tool misuse, memory poisoning, data exfiltration, and more — across ALL channels (Signal, Telegram, Discord, WhatsApp, web) simultaneously.
Server intelligence layer for RunCloud-managed Linux servers. Use when the user mentions Perch, /perch, RunCloud, nginx-rc, server intelligence, server diagnosis, WordPress site auditing, plugin vulnerability scanning, or any time they want to investigate, monitor, or heal a server they own.
Audit Codex plugins, Agent Skills, hooks, scripts, and MCP configuration for always-on triggers, context overhead, recursive invocation, subagent amplification, instruction conflicts, risky commands, excessive capabilities, exposed secrets, and malformed manifests. Use only when the user explicitly asks to audit…
QA/QC agent. Reads ALL pipeline artifacts (BA + TechLead + PM + BE + FE + Tester) and produces quality-report.md, compliance-check.md, and sign-off.md. Declares Gate 3: Release Sign-off (advisory only — operator has final authority). Part of the Virtual Team Skill pipeline.
Forces the model to always use the mcp-security demo MCP server tools instead of native capabilities. Use this skill whenever the user is working in the mcp-security project and asks to read files, count lines, write files, check npm packages, inspect npm config, verify registry, or do any file/npm operation. This…
Govern how AI agents access data through your organisation's Sealgate gateway. Use when you need to list governed MCP servers, review agent session and audit status, or check whether a tool call is allowed by policy.
Use this skill when an AI agent needs to act safely through oakallow, the runtime permission, approval, and audit layer for AI agent tool execution. Trigger it whenever you are about to take a tool action that could be risky, irreversible, or that touches another system, and you need to know whether it is allowed…
Use Airlock before installing or executing packages, running risky shell commands, committing generated code, or declaring an agent task complete. Airlock detects hallucinated/slopsquatted dependencies, destructive commands, leaked secrets, and suspicious test changes.
★not rated 1 2mo agoA✓ AI review50 tokens
originalMIT
Code Fixer subagent definition for the mcp2agy pipeline. This agent produces minimal, correct, testable fixes for verified security findings. Do NOT use this agent directly — it is invoked by the audit pipeline orchestrator.
A cloud-based code quality and static analysis tool that automatically reviews code for bugs, security issues, and style violations, tracks coverage and quality metrics across languages, and integrates with CI/CD pipelines to help teams maintain high standards and reduce technical debt. Read and write Codacy data…
A Chinese-language workflow for authorized security testing and bug bounty work, where researchers look for and report vulnerabilities in websites, applications, and cloud systems.
★not rated 0
changed todayA206 tokens
original
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: