A cloud-based code quality and static analysis tool that automatically reviews code for bugs, security issues, and style violations, tracks coverage and quality metrics across languages, and integrates with CI/CD pipelines to help teams maintain high standards and reduce technical debt. Read and write Codacy data…
A Chinese-language workflow for authorized security testing and bug bounty work, where researchers look for and report vulnerabilities in websites, applications, and cloud systems.
Don't let your agent sign blind. Discover x402 callables then check the seller BEFORE paying. Free resource join (GET /v1/intel/resources) lists listed|live402 claims; free preflight returns a ReadinessCard (allow / warn / block) from the observed Solana x402 corpus. Composes with any x402 payer skill: discover →…
★not rated 0
changed 3d agoA361 tokens
originalMIT
Use this skill whenever you (the agent) need credentials, API keys, tokens, or access to an MCP/API — or when a connection fails with auth errors. ScopeGate is the credentials gateway: you never handle secret values; you request ephemeral capabilities instead. Also use it to onboard new services ("connect X", "add the…
Use this skill when the user wants to manage Couchbase users, groups, roles, or check permissions on the cluster — creating service accounts, rotating passwords, granting analytics privileges, or auditing who can do what. Trigger when they mention "user", "group", "role", "RBAC", "permission", "upsertuser"…
Methodology and playbook for authorized cloud, API and web-application penetration testing driven through the MCP Kali Server. Use when the user wants to plan or run a pentest engagement against cloud/API/web targets, perform reconnaissance, service enumeration or exploitation via the Kali MCP tools, or wants guidance…
Use this when the user asks to scan a website for cookies, trackers, consent, GDPR, CCPA, or privacy risk. Run an evidence-backed privacy preflight before launch, vendor review, audit triage, or human compliance review.
Adversarial hardening loop for security-critical code, especially hooks and guards that must never fail open. Two models from different labs attack the same code for concrete, reproducible failures; an orchestrator adjudicates; a separate fixer closes the enumerable class; repeat until both models return zero…
Diagnose why an inbound webhook signature fails to verify, and write correct verification code for a named provider. Use when a signature check rejects real traffic, when a webhook works in a provider's test console but not against your server, or when you are implementing verification for Stripe, GitHub, Shopify…
Runs a Checkmarx SCA (Software Composition Analysis / OSS) scan on dependency manifests and lockfiles to detect vulnerable and malicious open-source packages, and remediates findings using the Checkmarx MCP tool. Use when a user asks to scan dependencies, check packages, audit a manifest/lockfile (package.json…
Verify signed SAR v0.1 settlement receipts locally with Ed25519 and RFC 8785 canonicalization. Use when you need to confirm a receipt is cryptographically valid before trusting a task-complete claim, chaining to another agent output, using a receipt as evidence, or acting on a settlement-adjacent claim. Optionally…
Verify email addresses with Proof Inbox MCP. Use when a Grok Bot must check whether an address is valid, invalid, catchall, or unknown, or when the human asks what a checkout charge paid for.
Vet MCP tools/list and local AI-agent tool configuration before attachment. Use to check tool poisoning, forced invocation, confusable tool names, unconstrained shell or code inputs, risky fetch-plus-privilege combinations, delegation exposure, or elevated-permission requests with a pinned offline static gate.
Run read-only npm package safety preflights through MCP or the CLI before an agent installs, adds, executes, or recommends unfamiliar registry packages. Use for npx or npm exec commands, dependency additions, package-lock changes, and project dependency reviews.
Check any Solana token for rug-pull risk before you (or your human) touch it. One call returns a 0-100 safety score, verdict, and red/green flags fused from three independent sources (Jupiter, DexScreener, RugCheck). Free demo tool; paid calls are $0.01 via x402 (USDC on Base or Solana) — no account, no API key…
Outils d'aide à l'audit crypto des agents AI (Ed25519, AISS). Pour traçabilité/décision vers conformité AI Act, NIST, RGPD Art.22. npm @piqrypt/mcp-server.
Vet a URL or domain before transacting with or trusting it — injection-safe page fetching, a one-call CLEAR/REVIEW/BLOCK safety verdict, email spoofability grading, trust scoring, TLS/SSL cert check, HTTP security headers, and robots.txt/AI-bot policy. Seven x402-paid checks in USDC, no API keys or signup.
A local security-scanning service for checking skills, plugins, and MCP servers before they are installed or used. MCP is a way for AI assistants to call external tools.
Verify and rights-safely project LiquiLens Evidence Carrier, Fleet Brief, or Trade Safety Receipt JSON in local files. Use for provenance, clocks, integrity, redistribution, FDC3, OpenLineage, brief validation, or order-bound policy-receipt verification; not for collecting market data, trading, recommendations…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: