Security skills

17,271 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 277agent 229generative-ai 179LangChain 176hacking 175autonomous-pentesting 135cloud-security 121skills 121claude-ai 118redteam 113LLM 108security-audit 105cors-exploitation 88

heimdall

1081

caglarbozkurt/mcp-heimdall

Skill Claude CodeCodex

Vet a Model Context Protocol (MCP) server for safety before installing or connecting it. Use when the user wants to check, audit, scan, or review an MCP server for prompt-injection, data-exfiltration, or malicious capabilities — given a directory, npm package, GitHub repo, or a tools/list JSON dump.

not rated 0 2mo ago A 71 tokens original MIT

mcp-pcapy-ng

1082

daedalus/mcp-pcapy-ng

Skill Claude CodeCodex

MCP server exposing pcapy-ng packet capture functionality.

not rated 0 4mo ago A 0 tokens original MIT

mcp-pwntools

1083

daedalus/mcp-pwntools

Skill Claude CodeCodex

MCP server exposing pwntools functionality for binary exploitation.

not rated 0 4mo ago A 0 tokens original MIT

mcp-recon-ng

1084

daedalus/mcp-recon-ng

Skill Claude CodeCodex

MCP server exposing full recon-ng OSINT framework functionality.

not rated 0 4mo ago A 0 tokens original MIT

mcp-smbmap

1085

daedalus/mcp-smbmap

Skill Claude CodeCodex

MCP server exposing SMB enumeration functionality.

not rated 0 4mo ago A 0 tokens original MIT

datahogo

1086

datahogo/datahogo

Skill Claude CodeCodex

Scan the current project for security vulnerabilities using Data Hogo, an open-source local security scanner. Use this when the user asks to check for security issues, run a security scan, review code for vulnerabilities before deploying/shipping, or audit a repo for secrets/misconfigurations. Also use proactively…

not rated 0 2mo ago A 79 tokens AGPL-3.0

mcp-scorecard

1087

davidmosiah/mcp-scorecard

Skill Claude CodeCodex

Audit any MCP server for agent-readiness — get a 0–100 score across 10 checks with the exact fixes. Local-first, zero credentials.

not rated 0 5d ago A 0 tokens original MIT

umbra-trust-review

1088

elberacasa/umbra

Skill Claude CodeCodex

Verify AI-generated code before shipping. Run Umbra's Trust Score scan before committing or finishing any coding task, treat findings as blocking issues, and re-scan until clean. Use when finishing a task, before a commit, or when reviewing code written by an agent.

not rated 0 1mo ago A 60 tokens original MIT

captcha-mcp

1089

mcp-dir/captcha-mcp

Skill Claude CodeCodex

Skill da REST API do Captcha Solver na MCP.AI: 6 endpoints em /api/captcha. Resolve reCAPTCHA v2/v3, hCaptcha, Cloudflare Turnstile e captchas de imagem. Hospedado pela plataforma, sem credenciais, pague por solve com crédito pré-pago. Autentique com workspace API key (sklive) gerada em app.mcp.ai/settings/api-keys.…

not rated 0 13d ago A 103 tokens original MIT

interpol-mcp

1090

mcp-dir/interpol-mcp

Skill Claude CodeCodex

Skill da REST API do Interpol na MCP.AI: 1 endpoint em /api/interpol. Verifica se um nome consta nas notificações da Interpol, a partir do nome, sobrenome e data de nascimento, para diligência de compliance e AML. Hospedado pela plataforma, sem credenciais, pague por consulta com crédito pré-pago. Autentique com…

not rated 0 28d ago A 113 tokens original MIT

sbomapp-mcp-server

1091

mcpsbom/sbomapp-mcp-server

Skill Claude CodeCodex

SBOMApp is a remote MCP server that provides Software Bill of Materials (SBOM) generation, vulnerability scanning, and dependency analysis capabilities to AI assistants. It enables any MCP-compatible AI client to analyze software projects for security risks, license compliance, and dependency health — directly from…

not rated 0 6mo ago A 0 tokens

trust-switchboard

1092

paul-salviani/a2a

Skill Claude CodeCodex

Use when asked who to trust, what to use, which URL, product, organisation, MCP, or agent to recommend or wire. Call Trust Switchboard before any recommend. Fail closed. Empty list honest. Never invent a winner.

not rated 0 13d ago A 51 tokens original MIT

omitly-redaction

1093

omitly/omitly-mcp

Skill Claude CodeCodex

Redact PDFs and audit redactions on-device with Omitly. Use when the user wants to remove sensitive data (SSNs, emails, names, account numbers) from a PDF, check whether an already-"redacted" PDF still leaks data underneath its black boxes, or locate PII in a document — all without uploading the file anywhere.…

not rated 0 10d ago A 115 tokens

base-token-trust

1094

philpof102-svg/biii

Skill Claude CodeCodex

Before you act on or pay a token/wallet on Base (or any EVM chain), get a VERIFIABLE trust verdict — is this contract the genuine issuer's or a look-alike? is this address known-bad? — instead of guessing. Fail-closed, non-custodial, re-verifiable on-chain. Use it as the pre-flight check before a buy, a swap, a…

not rated 0 23d ago A 99 tokens

rnwy

1095

rnwy/mcp

Skill Claude CodeCodex

RNWY trust intelligence for AI agents. Use when querying trust scores, interpreting sybil data, analyzing reviewer wallets, comparing agents, or assessing transaction risk. Trigger phrases: "trust score", "sybil", "reviewer analysis", "wallet age", "trust check", "risk tier", "attestation", "reviewer wallet", "compare…

not rated 0 5mo ago A 97 tokens

bug-bounty-hunting

1096

rozetyp/vuln-intel-mcp

Skill Claude CodeCodex

Hunt vulnerabilities like an expert, not a linear software engineer: come at a target from the overlooked angle, reason by analogy and transfer proven attack mechanisms, attack the hidden assumptions and the seams between systems, drill to the mechanism, then keep it honest with proof and persistence (acceptance !=…

not rated 0 1mo ago A 263 tokens

audit-dependencies

1097

trustlists/trustlists-plugin

Skill Claude CodeCodex

Map a project's third-party dependencies to public vendor trust center records using the trustlists directory. Produces a documentation-visibility inventory without treating directory absence as security risk. Use when asked to audit dependencies, review the software supply chain, or inventory third-party services.

not rated 0 13d ago A 56 tokens original Apache-2.0

erc-8126-scan

1098

Cybercentry/erc-8126-scan-mcp

Skill Claude CodeCodex

Look up ERC-8004 agents in the on-chain identity index and read their Cybercentry risk scores with ERC-8126scan before trusting them.

not rated 0 21d ago A 37 tokens original MIT

concierge-hermes

1099

theconcierge99-hue/gold-panel

Skill Claude CodeCodex

Wire Hermes Agent to Concierge pay-per-call market intel + Security Desk via remote MCP and pay.sh/x402. Use for macro, wire, DeFi desks, cron briefs, and authorized security scans without Concierge API keys.

not rated 0 2d ago A 49 tokens

tabletop-exercise

1100

cjcsecurity/claude-tabletop

Skill Claude CodeCodex

Generate a polished, engaging tabletop exercise (TTX) runbook for the current project — covering cybersecurity, product security, DevOps/SRE, privacy/compliance, data/ML, or any other technical domain. Surveys the project to pick scenarios that match the actual stack and risk surface, then produces a facilitator…

not rated 0 4mo ago A 147 tokens original Apache-2.0

openclaw-backup

1101

theagentservice/skills

Skill Claude Code

Encrypted backup and restore for OpenClaw Agent workspace files (SOUL.md, MEMORY.md, IDENTITY.md, AGENTS.md, TOOLS.md). Uses tar + openssl (AES-256-CBC) encryption and soul-upload.com API. Auto-generates a new random password for each backup (DO NOT reuse passwords). Use when the user needs to: (1) Back up or upload…

not rated 0 6mo ago B Socket: failSnyk: fail 125 tokens original MIT

phishfort-mcp

1102

mychaelconnolly/phishfort-mcp

Skill Claude CodeCodex

Guides safe use of the PhishFort MCP server for client/user/document reads, incident lookup, triage, reporting, takedown or monitoring requests, evidence uploads, comments, webhook management, and webhook signature verification. Use when the user mentions PhishFort, phishing incidents, takedown workflows, monitoring…

not rated 0 1mo ago A 86 tokens original MIT

Knuckles-Team/ciso-assistant-api

Skill Claude CodeCodex

Compliance audits on the CISO Assistant platform via the ciso-assistant-api MCP server — list and read compliance assessments (audits), their frameworks, progress, computed outcome and applied controls, surface requirement gaps, and natively ingest audits into the knowledge graph as typed :Audit nodes linked to their…

not rated 0 15d ago A 129 tokens original MIT

sensitive-info-scan

1104

hawklithm/sensitive-info-mcp

Skill Claude CodeCodex

A skill for scanning content or project data for sensitive information, such as details that should not be exposed. Its description also covers when to use it, prerequisites, and a step-by-step workflow.

not rated 0 2mo ago A 0 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: