Security

29,729 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

cloudflare

02

anomalyco/opencode

Skill Claude CodeCodex

Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and infrastructure-as-code (Terraform, Pulumi). Use for any Cloudflare development task.

not rated 204k +504 today A 68 tokens original MIT

langchain AGENTS.md

03

langchain-ai/langchain

Instructions file CodexOpenCode ✓ vendor

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

not rated 146k +166 today A 4,345 tokens original MIT

langchain CLAUDE.md

04

langchain-ai/langchain

Instructions file ✓ vendor

Claude Code instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

not rated 146k +166 today A 4,345 tokens copy · 100% MIT

electron/electron

Skill Claude CodeCodex

End-to-end Chrome security backport for an Electron release branch. Given a Chrome Releases blog URL and a branch (e.g. 41-x-y), determines which CVE fixes are missing from the actual synced source, writes the cherry-pick patches locally, validates them with e sync --3 + lint --patches, then pushes a single PR. Use…

not rated 123k 4d ago A 121 tokens original MIT

safe-sql-execution

06

supabase/supabase

Skill Claude CodeCodex ✓ vendor

Use whenever code will build, return, fetch, or execute SQL that runs against a user's real Postgres database — even when the request reads like an ordinary feature or bug fix and never says "security," "injection," or "SafeSqlFragment." This covers: writing or editing any pg-meta function, query builder, or endpoint…

not rated 109k +80 changed today A 221 tokens original Apache-2.0

review-pr

07

denoland/deno

Skill Claude CodeCodex ✓ vendor

Review a Deno runtime pull request for correctness, tests, security, and conventions. Use when asked to review a PR or when a PR number/URL is provided for review.

not rated 108k +20 today A 39 tokens original MIT

pi AGENTS.md

08

earendil-works/pi

Instructions file CodexOpenCode

AGENTS.md instructions for earendil-works/pi, covering development rules, conversational style, code quality, commands and dependency and install security.

not rated 101k +1.2k today A 2,804 tokens original MIT

reviewer

09

earendil-works/pi

Agent

Code review specialist for quality and security analysis.

not rated 101k +1.2k today A 11 tokens original MIT

securityengineer

10

paperclipai/paperclip

Agent

Use this template when hiring security engineers who own security posture: threat-model systems, review auth/crypto/input handling, triage supply-chain and LLM-agent risk, and drive concrete remediations.

not rated 80k +145 today A 0 tokens original MIT

code-review

11

shareAI-lab/learn-claude-code

Skill Claude CodeCodex

Perform thorough code reviews with security, performance, and maintainability analysis. Use when user asks to review code, check for bugs, or audit a codebase.

not rated 76k +172 8d ago A 35 tokens original MIT

review-work

12

code-yeongyu/oh-my-openagent

Skill Claude CodeCodex

Post-implementation review orchestrator. Launches 5 parallel background sub-agents: Oracle (goal/constraint verification), Oracle (code quality), Oracle (security), unspecified-high (hands-on QA execution), unspecified-high (context mining from GitHub/git/Slack/Notion). All must pass for review to pass. MUST USE…

not rated 69k +71 today A 125 tokens

strix AGENTS.md

13

usestrix/strix

Instructions file CodexOpenCode

AGENTS.md instructions for usestrix/strix, covering strix — agent guide, using strix from an agent and contributing to this repo.

not rated 60k +541 changed yesterday C 1,845 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Security-test a REST, GraphQL, or gRPC API with Strix — autonomous agents that enumerate endpoints from an OpenAPI/GraphQL schema (or by crawling), then actually exploit the API-specific vulnerability classes in the OWASP API Security Top 10 (2023) — broken object-level authorization (BOLA/IDOR), broken object…

not rated 60k +541 changed yesterday A 144 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Fix security vulnerabilities found by a Strix pentest (open-source CLI or app.strix.ai cloud) — triage by severity, patch the root cause rather than the symptom, and re-run Strix to prove each fix actually closes the exploit. Handles injection, XSS, SSRF, broken access control, IDOR, and other validated findings. Use…

not rated 60k +541 changed yesterday A 124 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Test an application against the OWASP Top 10 with Strix — autonomous AI agents that attempt real exploits for each category of the current OWASP Top 10:2025 (broken access control including SSRF, security misconfiguration, software supply chain failures, cryptographic failures, injection, insecure design…

not rated 60k +541 changed yesterday A 151 tokens original Apache-2.0

aaif-goose/goose

Instructions file GitHub Copilot

Copilot instructions for aaif-goose/goose, covering github copilot code review instructions, review philosophy, priority areas (review these), security & safety and correctness issues.

not rated 54k +112 today A 1,077 tokens original Apache-2.0

metabase/metabase

Instructions file GitHub Copilot

Copilot instructions for metabase/metabase, covering metabase developer assistant instructions, code review standards, security critical issues, performance red flags and code quality essentials.

not rated 49k +37 today A 377 tokens

review

19

KeygraphHQ/shannon

Command Claude Code

Review code changes for Shannon-specific patterns, security, and common mistakes.

not rated 48k +229 2d ago A 13 tokens AGPL-3.0

streamlit/streamlit

Agent Claude Code

Review the current branch's changes for code quality, test coverage, security, best practices, and product/API alignment. Use when asked to perform a code review.

not rated 46k +15 today A 38 tokens original Apache-2.0

payload

21

payloadcms/payload

Skill Claude CodeCodex

Use when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.

not rated 45k today A 43 tokens original MIT

security-advisory

22

colinhacks/zod

Skill Claude CodeCodex

Triage a draft security advisory in colinhacks/zod — a private vulnerability report from the Security tab, named by GHSA id (GHSA-xxxx-xxxx-xxxx) or reached from "the draft advisories", "the security reports", "the vulnerability queue". Use instead of the triage skill whenever the ticket is an advisory rather than a…

not rated 44k today A 0 tokens original MIT

triage

23

colinhacks/zod

Skill Claude CodeCodex

Investigate a GitHub issue or pull request in colinhacks/zod and write up a durable verdict. Use whenever asked to triage, investigate, review, evaluate, or form an opinion on an issue or PR (by number, URL, or "the open PR queue"), and when sweeping many of them in bulk. For a draft SECURITY ADVISORY (a GHSA id, the…

not rated 44k today A 239 tokens original MIT

core

24

vercel-labs/agent-browser

Skill Claude CodeCodex ✓ vendor

Core agent-browser usage guide. Read this before running any agent-browser commands. Covers the snapshot-and-ref workflow, navigating pages, interacting with elements (click, fill, type, select), extracting text and data, taking screenshots, managing tabs, handling forms and auth, waiting for content, running multiple…

not rated 42k +137 changed yesterday A 112 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: