Security skills

17,271 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 476bug-bounty 257agent 227generative-ai 179LangChain 176hacking 175autonomous-pentesting 123skills 119claude-ai 115cloud-security 115redteam 105LLM 104agents 80cors-exploitation 80

erc-8126-scan

1105

Cybercentry/erc-8126-scan-mcp

Skill Claude CodeCodex

Look up ERC-8004 agents in the on-chain identity index and read their Cybercentry risk scores with ERC-8126scan before trusting them.

not rated 0 21d ago A 37 tokens original MIT

concierge-hermes

1106

theconcierge99-hue/gold-panel

Skill Claude CodeCodex

Wire Hermes Agent to Concierge pay-per-call market intel + Security Desk via remote MCP and pay.sh/x402. Use for macro, wire, DeFi desks, cron briefs, and authorized security scans without Concierge API keys.

not rated 0 2d ago A 49 tokens

tabletop-exercise

1107

cjcsecurity/claude-tabletop

Skill Claude CodeCodex

Generate a polished, engaging tabletop exercise (TTX) runbook for the current project — covering cybersecurity, product security, DevOps/SRE, privacy/compliance, data/ML, or any other technical domain. Surveys the project to pick scenarios that match the actual stack and risk surface, then produces a facilitator…

not rated 0 4mo ago A 147 tokens original Apache-2.0

openclaw-backup

1108

theagentservice/skills

Skill Claude Code

Encrypted backup and restore for OpenClaw Agent workspace files (SOUL.md, MEMORY.md, IDENTITY.md, AGENTS.md, TOOLS.md). Uses tar + openssl (AES-256-CBC) encryption and soul-upload.com API. Auto-generates a new random password for each backup (DO NOT reuse passwords). Use when the user needs to: (1) Back up or upload…

not rated 0 6mo ago B Socket: failSnyk: fail 125 tokens original MIT

phishfort-mcp

1109

mychaelconnolly/phishfort-mcp

Skill Claude CodeCodex

Guides safe use of the PhishFort MCP server for client/user/document reads, incident lookup, triage, reporting, takedown or monitoring requests, evidence uploads, comments, webhook management, and webhook signature verification. Use when the user mentions PhishFort, phishing incidents, takedown workflows, monitoring…

not rated 0 1mo ago A 86 tokens original MIT

Knuckles-Team/ciso-assistant-api

Skill Claude CodeCodex

Compliance audits on the CISO Assistant platform via the ciso-assistant-api MCP server — list and read compliance assessments (audits), their frameworks, progress, computed outcome and applied controls, surface requirement gaps, and natively ingest audits into the knowledge graph as typed :Audit nodes linked to their…

not rated 0 15d ago A 129 tokens original MIT

sensitive-info-scan

1111

hawklithm/sensitive-info-mcp

Skill Claude CodeCodex

A skill for scanning content or project data for sensitive information, such as details that should not be exposed. Its description also covers when to use it, prerequisites, and a step-by-step workflow.

not rated 0 2mo ago A 0 tokens

shodan-asset-monitor

1112

GangGreenTemperTatum/shodan-mcp-server

Skill Claude CodeCodex

Monitor and track organizational assets over time using Shodan. Use for continuous security monitoring, attack surface management, and change detection. Triggers on requests for "monitor assets", "track changes", "continuous monitoring", or "attack surface management".

not rated 0 7mo ago A 54 tokens original Apache-2.0

depscan

1113

robcqm-bot/depscan-api

Skill Claude CodeCodex

Verify the health of a skill's external dependencies before installing. Checks uptime, SSL, domain reputation, and blacklists. Returns a trust score and a clear install/block verdict.

not rated 0 6mo ago A 38 tokens

solsentry-postdeploy

1114

solsentry/solsentry-mcp

Skill Claude Code

Use this skill for post-deploy Solana threat intelligence — operator risk lookups, counterparty checks before CPI, post-incident drain tracing, deployment monitoring, token-launch readiness, and bot cluster graph exploration. Backed by SolSentry's live mainnet scanner (api.solsentry.app).

not rated 0 2mo ago A 66 tokens original MIT

blueagent-x402

1116

madebyshun/blueagent-x402-services

Skill Claude CodeCodex

Security OS for autonomous agents and builders on Base. 31 pay-per-use tools across Quantum Security, Agent Safety, Research, Data, and Earn. Built for AI agents, Zero-Human Companies (ZHC), and Base ecosystem builders. Pay USDC per call via x402 protocol — no subscription, no API key needed.

not rated 0 3mo ago A 71 tokens

dobbe-vuln-resolve

1117

nareshnavinash/dobbe-mcp

Skill Claude CodeCodex

Resolve vulnerabilities in a GitHub repository with an automated scan, fix, verify, report pipeline that retries up to 3 times.

not rated 0 5mo ago A 0 tokens

xxe-testing

1118

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A security-testing guide for XXE, a flaw where an XML parser is tricked into reading files or making network requests. It covers XML inputs such as APIs, uploads, SOAP services, office documents, SVGs, and PDFs.

not rated 0 1mo ago A 19 tokens original Apache-2.0

safety_fence

1119

kkAlwaysAwaked/safety_fence_mcp

Skill Claude CodeCodex

A security boundary for OpenClaw that checks data before it leaves the local device. It allows safe data, can remove sensitive details when possible, and blocks dangerous secrets or data it cannot safely sanitize.

not rated 0 1mo ago A 72 tokens

aegis-guardrails

1120

bgigurtsis/aegis-mcp

Skill Claude CodeCodex

Trigger Aegis security checks before generating security-relevant code.

not rated 0 6mo ago A 20 tokens original MIT

secret-sentinel

1121

chadcorp/warden

Skill Claude CodeCodex

Review code or a skill bundle for the patterns that leak credentials and for least-privilege violations. This is a reasoning skill: it sharpens the agent's eye, and it needs no capabilities of its own.

not rated 0 3mo ago A ✓ AI review 0 tokens original Apache-2.0

metavision

1122

adminmetavision-rgb/metavision-mcp

Skill Claude CodeCodex

Web3 AI platform with CVE security scanning, DeFi signals, market intelligence, and 3D generation. Use when: (1) searching CVE vulnerabilities in Web3/smart contracts, (2) getting live DeFi arbitrage signals on Base network, (3) checking wallet security and rug pull detection, (4) generating 3D models from text or…

not rated 0 1mo ago A 114 tokens original MIT

zama-fhevm

1123

juSt-jeLLy/zama-fhevm-skill

Skill Claude CodeCodex

Build confidential smart contracts and dApps using Zama's fhEVM (Fully Homomorphic Encryption Virtual Machine). Covers encrypted types, FHE operations, access control, input proofs, decryption patterns, frontend integration, testing, and anti-patterns. Use this skill whenever the user wants to build with Zama…

not rated 0 4mo ago B 82 tokens

mcpvet

1124

LorenzoLombardi111/factory-mcpvet

Skill Claude CodeCodex

Vet an MCP server, Claude Code skill, or plugin for unsafe behavior (shell execution, secret access, data exfiltration, prompt injection, remote code) BEFORE installing it. Use whenever the user is about to add/install an MCP server, skill, or plugin, asks "is this safe to install", or pastes a GitHub repo / npm…

not rated 0 2mo ago A 86 tokens original MIT

assemblyline-triage

1126

SauceTaster/assemblyline-mcp

Skill Claude CodeCodex

Triage files, hashes, URLs, and alerts with AssemblyLine 4 via the assemblyline-mcp server. Use when the user asks to analyze/triage a sample, investigate a hash or IOC, assess an AssemblyLine alert, or decide if something is malicious. Requires the assemblyline-mcp MCP server to be connected.

not rated 0 8d ago A 75 tokens original MIT

blast-radius-mcp

1127

tspscale/blast-radius-mcp

Skill Claude CodeCodex

Use this skill when the user asks about dependencies, package upgrades, vulnerabilities, blast radius, or software supply chain security.

not rated 0 27d ago A 24 tokens original MIT

lobstervault

1128

lobster-kit/mcp-server-lobstervault

Skill Claude CodeCodex

Encrypted secret storage for agents. Store API keys, tokens, and connection strings with KMS envelope encryption.

not rated 0 5mo ago A 26 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: