Vet a Model Context Protocol (MCP) server for safety before installing or connecting it. Use when the user wants to check, audit, scan, or review an MCP server for prompt-injection, data-exfiltration, or malicious capabilities — given a directory, npm package, GitHub repo, or a tools/list JSON dump.
Scan the current project for security vulnerabilities using Data Hogo, an open-source local security scanner. Use this when the user asks to check for security issues, run a security scan, review code for vulnerabilities before deploying/shipping, or audit a repo for secrets/misconfigurations. Also use proactively…
Verify AI-generated code before shipping. Run Umbra's Trust Score scan before committing or finishing any coding task, treat findings as blocking issues, and re-scan until clean. Use when finishing a task, before a commit, or when reviewing code written by an agent.
Skill da REST API do Captcha Solver na MCP.AI: 6 endpoints em /api/captcha. Resolve reCAPTCHA v2/v3, hCaptcha, Cloudflare Turnstile e captchas de imagem. Hospedado pela plataforma, sem credenciais, pague por solve com crédito pré-pago. Autentique com workspace API key (sklive) gerada em app.mcp.ai/settings/api-keys.…
Skill da REST API do Interpol na MCP.AI: 1 endpoint em /api/interpol. Verifica se um nome consta nas notificações da Interpol, a partir do nome, sobrenome e data de nascimento, para diligência de compliance e AML. Hospedado pela plataforma, sem credenciais, pague por consulta com crédito pré-pago. Autentique com…
SBOMApp is a remote MCP server that provides Software Bill of Materials (SBOM) generation, vulnerability scanning, and dependency analysis capabilities to AI assistants. It enables any MCP-compatible AI client to analyze software projects for security risks, license compliance, and dependency health — directly from…
Use when asked who to trust, what to use, which URL, product, organisation, MCP, or agent to recommend or wire. Call Trust Switchboard before any recommend. Fail closed. Empty list honest. Never invent a winner.
Redact PDFs and audit redactions on-device with Omitly. Use when the user wants to remove sensitive data (SSNs, emails, names, account numbers) from a PDF, check whether an already-"redacted" PDF still leaks data underneath its black boxes, or locate PII in a document — all without uploading the file anywhere.…
Before you act on or pay a token/wallet on Base (or any EVM chain), get a VERIFIABLE trust verdict — is this contract the genuine issuer's or a look-alike? is this address known-bad? — instead of guessing. Fail-closed, non-custodial, re-verifiable on-chain. Use it as the pre-flight check before a buy, a swap, a…
Hunt vulnerabilities like an expert, not a linear software engineer: come at a target from the overlooked angle, reason by analogy and transfer proven attack mechanisms, attack the hidden assumptions and the seams between systems, drill to the mechanism, then keep it honest with proof and persistence (acceptance !=…
Map a project's third-party dependencies to public vendor trust center records using the trustlists directory. Produces a documentation-visibility inventory without treating directory absence as security risk. Use when asked to audit dependencies, review the software supply chain, or inventory third-party services.
Wire Hermes Agent to Concierge pay-per-call market intel + Security Desk via remote MCP and pay.sh/x402. Use for macro, wire, DeFi desks, cron briefs, and authorized security scans without Concierge API keys.
Generate a polished, engaging tabletop exercise (TTX) runbook for the current project — covering cybersecurity, product security, DevOps/SRE, privacy/compliance, data/ML, or any other technical domain. Surveys the project to pick scenarios that match the actual stack and risk surface, then produces a facilitator…
Encrypted backup and restore for OpenClaw Agent workspace files (SOUL.md, MEMORY.md, IDENTITY.md, AGENTS.md, TOOLS.md). Uses tar + openssl (AES-256-CBC) encryption and soul-upload.com API. Auto-generates a new random password for each backup (DO NOT reuse passwords). Use when the user needs to: (1) Back up or upload…
Guides safe use of the PhishFort MCP server for client/user/document reads, incident lookup, triage, reporting, takedown or monitoring requests, evidence uploads, comments, webhook management, and webhook signature verification. Use when the user mentions PhishFort, phishing incidents, takedown workflows, monitoring…
Compliance audits on the CISO Assistant platform via the ciso-assistant-api MCP server — list and read compliance assessments (audits), their frameworks, progress, computed outcome and applied controls, surface requirement gaps, and natively ingest audits into the knowledge graph as typed :Audit nodes linked to their…
A skill for scanning content or project data for sensitive information, such as details that should not be exposed. Its description also covers when to use it, prerequisites, and a step-by-step workflow.
★not rated 0 2mo agoA0 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: