Security skills

17,271 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 277agent 229generative-ai 179LangChain 176hacking 175autonomous-pentesting 135cloud-security 121skills 121claude-ai 118redteam 113LLM 108security-audit 105cors-exploitation 88

codacy

1057

withoneai/one-agent-plugin

Skill Claude CodeCodex

A cloud-based code quality and static analysis tool that automatically reviews code for bugs, security issues, and style violations, tracks coverage and quality metrics across languages, and integrates with CI/CD pipelines to help teams maintain high standards and reduce technical debt. Read and write Codacy data…

not rated 1 23d ago A 119 tokens original MIT

72stack-sec

1058

Little-H-lying-flat/72stack-sec

Skill Claude CodeCodex

A Chinese-language workflow for authorized security testing and bug bounty work, where researchers look for and report vulnerabilities in websites, applications, and cloud systems.

not rated 0 changed today A 206 tokens original

twzrd-trust

1059

twzrd-sol/twzrd-trust

Skill Claude CodeCodex

Don't let your agent sign blind. Discover x402 callables then check the seller BEFORE paying. Free resource join (GET /v1/intel/resources) lists listed|live402 claims; free preflight returns a ReadinessCard (allow / warn / block) from the observed Solana x402 corpus. Composes with any x402 payer skill: discover →…

not rated 0 changed 3d ago A 361 tokens original MIT

scopegate

1060

NexgenSystemsMX/scopegate

Skill Claude CodeCodex

Use this skill whenever you (the agent) need credentials, API keys, tokens, or access to an MCP/API — or when a connection fails with auth errors. ScopeGate is the credentials gateway: you never handle secret values; you request ephemeral capabilities instead. Also use it to onboard new services ("connect X", "add the…

not rated 0 25d ago A 82 tokens original Apache-2.0

anjian-audit

1061

ck3938700-ship-it/anjian-agent

Skill Claude CodeCodex

Use AnJian MCP tools for an authorization-gated website security assessment and Chinese report.

not rated 0 1mo ago A 23 tokens original MIT

cb-analytics-security

1062

celticht32/Enterprise-Analytics-MCP

Skill Claude CodeCodex

Use this skill when the user wants to manage Couchbase users, groups, roles, or check permissions on the cluster — creating service accounts, rotating passwords, granting analytics privileges, or auditing who can do what. Trigger when they mention "user", "group", "role", "RBAC", "permission", "upsertuser"…

not rated 0 1mo ago A 96 tokens original MIT

ElusiveHacker/MCPKaliServer

Skill Claude CodeCodex

Methodology and playbook for authorized cloud, API and web-application penetration testing driven through the MCP Kali Server. Use when the user wants to plan or run a pentest engagement against cloud/API/web targets, perform reconnaissance, service enumeration or exploitation via the Kali MCP tools, or wants guidance…

not rated 0 1mo ago A 101 tokens

dependabot-triage-py

1065

akshayrao14/git-practices

Skill Codex

Triage and fix Dependabot vulnerability alerts in Python repos (pip, poetry, uv, pdm, pipenv). v2.1 workflow with Standard (defensive) and Fast-Track (low-risk) modes — defensive minimal-patched versioning (PEP 440 ranges), exposure mapping (Public/API · Internal/Dev), CI workflow inspection to detect every PM in…

not rated 0 7d ago B 194 tokens original MIT

dlp-scan

1066

cx-anand-nandeshwar/security-dlp-mcp

Skill Claude CodeCodex

Scan content for data loss prevention violations using the DLP DLP MCP server.

not rated 0 2mo ago A 20 tokens original Apache-2.0

ergoveritas1-alt/certscore.ai

Skill Claude CodeCodex

Use this when the user asks to scan a website for cookies, trackers, consent, GDPR, CCPA, or privacy risk. Run an evidence-backed privacy preflight before launch, vendor review, audit triage, or human compliance review.

not rated 0 changed 3d ago A 54 tokens

gauntlet

1068

oscarsterling/clelp-skills

Skill Claude CodeCodex

Adversarial hardening loop for security-critical code, especially hooks and guards that must never fail open. Two models from different labs attack the same code for concrete, reproducible failures; an orchestrator adjudicates; a separate fixer closes the enumerable class; repeat until both models return zero…

not rated 0 6d ago A 81 tokens original MIT

webhook-co/webhook

Skill Codex

Diagnose why an inbound webhook signature fails to verify, and write correct verification code for a named provider. Use when a signature check rejects real traffic, when a webhook works in a provider's test console but not against your server, or when you are implementing verification for Stripe, GitHub, Shopify…

not rated 0 yesterday A 112 tokens original Apache-2.0

Checkmarx/cx-agentic-ai

Skill Claude CodeCodex

Runs a Checkmarx SCA (Software Composition Analysis / OSS) scan on dependency manifests and lockfiles to detect vulnerable and malicious open-source packages, and remediates findings using the Checkmarx MCP tool. Use when a user asks to scan dependencies, check packages, audit a manifest/lockfile (package.json…

not rated 0 2d ago A 111 tokens original Apache-2.0

settlement-witness

1071

nutstrut/default-settlement-verifier

Skill Claude CodeCodex

Verify signed SAR v0.1 settlement receipts locally with Ed25519 and RFC 8785 canonicalization. Use when you need to confirm a receipt is cryptographically valid before trusting a task-complete claim, chaining to another agent output, using a receipt as evidence, or acting on a settlement-adjacent claim. Optionally…

not rated 0 10d ago A 81 tokens original MIT

proof-inbox

1072

timdoes/proof-inbox-mcp

Skill Claude CodeCodex

Verify email addresses with Proof Inbox MCP. Use when a Grok Bot must check whether an address is valid, invalid, catchall, or unknown, or when the human asks what a checkout charge paid for.

not rated 0 14d ago A 46 tokens original MIT

agent-scan

1073

BackBond/agent-scan

Skill Claude CodeCodex

Vet MCP tools/list and local AI-agent tool configuration before attachment. Use to check tool poisoning, forced invocation, confusable tool names, unconstrained shell or code inputs, risky fetch-plus-privilege combinations, delegation exposure, or elevated-permission requests with a pinned offline static gate.

not rated 0 changed 8d ago A 61 tokens original MIT

mettle

1074

Creed-Space/METTLE

Skill Claude CodeCodex

Use when a user wants to complete METTLE reverse-CAPTCHA challenges, obtain a signed result, or verify a METTLE credential.

not rated 0 changed 8d ago A 32 tokens original Apache-2.0

npx-vibe

1075

Devrajsinh-Jhala/NPM-Vibe-check

Skill Codex

Run read-only npm package safety preflights through MCP or the CLI before an agent installs, adds, executes, or recommends unfamiliar registry packages. Use for npx or npm exec commands, dependency additions, package-lock changes, and project dependency reviews.

not rated 0 changed 8d ago A 55 tokens original MIT

solana-token-intel

1076

Echolonius/token-intel-x402

Skill Claude CodeCodex

Check any Solana token for rug-pull risk before you (or your human) touch it. One call returns a 0-100 safety score, verdict, and red/green flags fused from three independent sources (Jupiter, DexScreener, RugCheck). Free demo tool; paid calls are $0.01 via x402 (USDC on Base or Solana) — no account, no API key…

not rated 0 2mo ago A 95 tokens

piqrypt-mcp-audit

1077

PiQrypt/piqrypt-mcp-server

Skill Claude CodeCodex

Outils d'aide à l'audit crypto des agents AI (Ed25519, AISS). Pour traçabilité/décision vers conformité AI Act, NIST, RGPD Art.22. npm @piqrypt/mcp-server.

not rated 0 4mo ago A 58 tokens original MIT

trustsource-domain

1078

SurfEther/TrustSourceX402

Skill Claude CodeCodex

Vet a URL or domain before transacting with or trusting it — injection-safe page fetching, a one-call CLEAR/REVIEW/BLOCK safety verdict, email spoofability grading, trust scoring, TLS/SSL cert check, HTTP security headers, and robots.txt/AI-bot policy. Seven x402-paid checks in USDC, no API keys or signup.

not rated 0 1mo ago A 76 tokens original MIT

yotta-verify-mcp

1079

YottaMeta/yotta-verify-mcp

Skill Claude CodeCodex

A local security-scanning service for checking skills, plugins, and MCP servers before they are installed or used. MCP is a way for AI assistants to call external tools.

not rated 0 changed 6d ago A 221 tokens original MIT

liquilens-evidence

1080

beepboop2025/liquilens-evidence-carrier

Skill Claude CodeCodex

Verify and rights-safely project LiquiLens Evidence Carrier, Fleet Brief, or Trade Safety Receipt JSON in local files. Use for provenance, clocks, integrity, redistribution, FDC3, OpenLineage, brief validation, or order-bound policy-receipt verification; not for collecting market data, trading, recommendations…

not rated 0 changed 8d ago A 79 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: