apk-analysis
1129Skill Claude CodeCodex
Use this skill when the user asks to document or audit an authorized Android APK with apk-docforge.
17,271 tagged Security, measured the same way as everything else here.
Browse within: cybersecurity 473bug-bounty 254agent 228generative-ai 179LangChain 176hacking 175autonomous-pentesting 120skills 119claude-ai 116cloud-security 114LLM 105redteam 105agents 80cors-exploitation 80
Skill Claude CodeCodex
Use this skill when the user asks to document or audit an authorized Android APK with apk-docforge.
astroicers/security-weekly-mcp
Skill Claude CodeCodex
A workflow for maintaining a Taiwan-focused security glossary and producing weekly security reports. It supports Chinese-language term management, terminology checks, news collection, and report generation.
Skill Claude CodeCodex
One-click security audit for your MCP setup. Get a safety score, plain-English explanations, and fix recommendations.
Skill Claude CodeCodex
Fork, customize, deploy, or troubleshoot the Auth0 Who Am I MCP template as an Auth0 Custom Extension. Use when adapting this repository's MCP tools, publishing its generated Webtask artifacts, provisioning its Auth0 API resource server, promoting a domain-level connection, registering an MCP client, or connecting an…
Skill Claude CodeCodex
Advanced NixOS and Linux expertise for flake development, system debugging, packaging, security hardening, and innovative problem-solving. Triggers when working with NixOS configurations, Nix flakes, Linux system administration, debugging complex issues, building packages, compiler optimizations, security…
Skill Claude CodeCodex
Instructions for checking software-development compliance across pull requests, releases, and repositories. Compliance means testing whether work follows a chosen set of rules, such as SOC 2 or SLSA.
Skill Claude CodeCodex
Use when completing tasks, implementing major features, or before merging — routes code review to the appropriate specialist lens (STRIDE, OWASP, ATAM, TEMPORAL, CPT, MIGRATION, PRIVACY/SECRETS) based on detected signals, with Independent Judge for Tier 3.
Skill Claude CodeCodex
Find every account a username owns across 480+ platforms (OSINT username reconnaissance). Use when the user wants to investigate a handle, check someone's online footprint, verify an account, or do reconnaissance for AUTHORIZED security research. Returns the platforms where the handle exists plus a 0-100…
Skill Claude CodeCodex
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not…
Skill Claude CodeCodex
Tech/security research CLI for coding agents. Auto-invoke when the user asks to research, evaluate, compare, or monitor open source projects, libraries, CVEs, vulnerabilities, security advisories, GitHub repos, tech trends, Hacker News, or needs structured web research beyond a single URL fetch. Triggers: pesquisar…
Skill Claude CodeCodex
Gate an agent extension before you install it. Audits a skill, MCP server, or tool repo and returns allow, quarantine, or block with line-level evidence.
Skill Claude CodeCodex
Pre-submit council for trading tickets. Five voices review a JSON trade ticket for Kelly-cap compliance, missing stop-loss, sector or single-name concentration limits, fat-finger qty (10× typical = BLOCK, Knight Capital 2012 lesson), and Reg BI Care Obligation on retirement accounts. Returns SHIP / REWORK / BLOCK…
Space-C0wboy/OpenCTI-MCP-Server
Skill Claude CodeCodex
Use when working with the OpenCTI threat-intelligence platform via the opencti MCP tools — explains OpenCTI's STIX data model, entity types, indicators vs observables, relationships, containers, TLP markings, confidence, connectors/ingestion, and RBAC, and maps each concept to the right MCP tool. Load before creating…
sunick2009/mcp-owasp-pentesting-guide
Skill Claude CodeCodex
Query versioned OWASP testing guides through the Pentest Guide MCP for research, comparison, applicability analysis, and candidate test planning.
Skill Claude CodeCodex
🔒 Perform deep security review of the current code repository using the Kasra security engine (direct SDK or MCP).
Skill Claude CodeCodex
Review a code change for security, standards, production-readiness, and sustainability issues against a governed rule corpus, citing the rule ID and verbatim evidence for each finding. Use when reviewing, hardening, or pre-flighting code before it merges — especially AI-generated code.
manteclaw/mcp-server-bridge-security
Skill Claude CodeCodex
Cross-chain bridge security auditing toolkit exposed as an MCP server via stdio.
manteclaw/mcp-server-ai-redteam
Skill Claude CodeCodex
AI red teaming toolkit exposed as an MCP server via stdio.
manteclaw/mcp-server-onchain-forensics
Skill Claude CodeCodex
On-chain forensics toolkit exposed as an MCP server via stdio.
manteclaw/mcp-server-bug-bounty
Skill Claude CodeCodex
Automated bug bounty hunting toolkit exposed as an MCP server via stdio.
kilroyblockchain/free2pa-devtool
Skill Codex
Add Free2PA provenance and local trust checks to an agentic application. Use when a developer asks to protect an agent, OpenClaw project, ChatGPT app, MCP server, Agents SDK workflow, skills, prompts, SOUL.md, AGENTS.md, policies, or other control files from unnoticed changes or outside-group publishers.
Skill Claude CodeCodex
Provides AI agents with autonomous API key acquisition and management via MCP.
teodorofodocrispin-cmyk/sentinel-public
Skill Claude CodeCodex
Pre-execution transaction safety check for autonomous AI agents — one capability of the SENTINEL trust oracle (sentinel-agent.dev). Before signing an on-chain transaction on Base, an agent calls SENTINEL and receives a SAFE / UNSAFE / UNKNOWN verdict, a SENTINEL Score (0-100, grade AAA-D), and an ed25519-signed…
Skill Claude CodeCodex
Detect and verify subdomain takeovers with Cordon's three-step flow, then produce a responsible PoC. Use when checking for dangling DNS, takeover candidates, unclaimed cloud resources, or NS/MX delegation issues.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: