Security

29,964 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

tools-evasion-agent

217

JDArmy/Evasion-SubAgents

Agent Claude Code

Penetration testing tools evasion specialist. Analyzes tool source code, searches for detection rules (YARA, Sigma, etc.), and DIRECTLY MODIFIES source code to evade detection. Use for tools bypass, detection evasion, source modification.

not rated 315 +1 4mo ago A 57 tokens original MIT

pentest-redteam

218

0rangec3t/Black-cat

Skill Claude CodeCodex

An authorized red-team framework for testing systems through stated assumptions. Red teaming is a permitted security exercise that imitates attacks to find weaknesses.

not rated 309 +7 1mo ago A 41 tokens

review

219

apollographql/apollo-mcp-server

Skill Claude CodeCodex

Review a GitHub pull request for a Rust codebase. Focuses on security, performance, test coverage, and Rust idioms. Runs in GitHub Actions and posts comments directly to the PR.

not rated 307 today A 42 tokens original MIT

happy-app-audit

220

iamzhihuix/happy-claude-skills

Skill Claude CodeCodex

Audit a local macOS app's telemetry / reporting behavior using static analysis only. Reverse-engineers an .app bundle to identify embedded SDKs (AppLog/TEA, Parfait, TTNet, mars, MMKV, Sentry, Firebase, Bugly, Umeng, etc.), mapped upload endpoints, local on-disk queues, and privacy-relevant fields — without packet…

not rated 306 +1 4mo ago A 152 tokens original MIT

lacp-hardening

221

0xNyk/lacp

Plugin Claude Code

Bundles 3 skills, 1 command · 238 tokens together

Production hardening for AI coding agents — quality gates, security guards, continuous QA, and session memory. From the LACP (Local Agent Control Plane) framework.

not rated 302 +2 15d ago A tokens not measured original MIT

exploit-xss

222

crazyMarky/pentest-skills

Skill Claude CodeCodex

Cross-site scripting (XSS) vulnerability detection and exploitation. Supports reflected XSS, stored XSS, DOM-based XSS, and blind XSS testing. Use this skill when user mentions XSS, cross-site scripting, script injection, or needs to test JavaScript injection in parameters, forms, headers, or DOM sources.

not rated 303 +5 3mo ago A 71 tokens original Apache-2.0

superagents-lab/xcode27-skills

Skill Claude CodeCodex

Audit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up…

not rated 300 +1 2mo ago A 111 tokens

mrphrazer/agentic-malware-analysis

Skill Claude CodeCodex

Structured malware triage and reverse-engineering orchestration for PE, ELF, and Mach-O binaries with strict artifact dumping to a status folder. Use when requests involve malware sample analysis, strings triage, API/import analysis, behavioral hypothesis generation, component mapping, deep-analysis planning, Binary…

not rated 298 5mo ago A 92 tokens GPL-2.0

develop-disguise

225

cha0upup/LeoAI

Skill Claude CodeCodex

A specialised helper for creating or updating Disguises on a platform, including the code that changes and restores traffic data.

not rated 297 +7 8d ago A 72 tokens GPL-3.0

vibe-pentest

226

ok-helloworld/vibe-pentest

Skill Claude CodeCodex

An AI skill for black-box penetration testing of web applications, meaning security testing without relying on the application's source code. It uses multiple agents across steps such as identifying the application, scanning entry points and APIs, crawling it, testing for vulnerabilities, and reviewing evidence.

not rated 295 +12 changed yesterday A 126 tokens AGPL-3.0

claudit-sec CLAUDE.md

227

HarmonicSecurity/claudit-sec

Instructions file

Instructions for HarmonicSecurity/claudit-sec, covering claudit-sec — claude security audit tool, project overview, architecture, data collectors and key paths.

not rated 294 3mo ago B 2,074 tokens original Apache-2.0

semgrep

228

semgrep/skills

Skill Claude CodeCodex

Run Semgrep static analysis scans and create custom detection rules. Use when asked to scan code with Semgrep, find security vulnerabilities, write custom YAML rules, or detect specific bug patterns. IMPORTANT: Also use this skill when users ask to 'scan for bugs', 'check code quality', 'find vulnerabilities', 'static…

not rated 294 +5 1mo ago A 112 tokens

greywall CLAUDE.md

229

GreyhavenHQ/greywall

Instructions file

Instructions for GreyhavenHQ/greywall, covering greywall, build & run, test, lint & format and project structure.

not rated 290 +1 22d ago A 749 tokens original Apache-2.0

cupcake CLAUDE.md

230

eqtylab/cupcake

Instructions file

Instructions for eqtylab/cupcake, covering cupcake system overview, policy engine (wasm/rego) details, 1. routing vs. policy execution (critical), 2. opa rego v1 migration (critical) and 3. decisions & synthesis.

not rated 289 +3 6mo ago A 855 tokens original Apache-2.0

jakejarvis/domainstack.io

Instructions file CodexOpenCode

AGENTS.md instructions for jakejarvis/domainstack.io, covering repository guidelines, pre-commit checklist, skill loading, commands and development.

not rated 285 changed yesterday A 5,043 tokens original MIT

TORCH CLAUDE.md

233

Encod3d-Sec/TORCH

Instructions file

Claude Code instructions for Encod3d-Sec/TORCH, covering pentesting & bug bounty wiki: schema, quick reference, skills and tools, hunt skill auto-triggers and engagement discipline (state-first, anti-loop).

not rated 286 +2 changed yesterday A 7,786 tokens original MIT

llm-sast-scanner

234

SunWeb3Sec/llm-sast-scanner

Skill Claude CodeCodex

General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. Trigger when the user asks to: "analyze code for vulnerabilities", "review code security", "find security bugs", "do a SAST scan", "check for [vulnerability type] in code", "audit source code", or requests a security code…

not rated 283 14d ago A 100 tokens

PlamenTSV/plamen

Skill Claude CodeCodex

L1 trigger - detects non-determinism, state transition completeness violations, and safety/liveness invariant breaks in consensus code. Inject into depth-consensus-invariant or depth-state-trace.

not rated 281 +2 1mo ago A 45 tokens original MIT

ethskills

236

austintgriffith/ethskills

Plugin Claude Code

Bundles 28 skills · 1,751 tokens together

Ethereum development skills — corrects LLM blind spots on gas costs, L2s, CROPS trust review (Censorship Resistance, Open Source and Free, Privacy, Security), DeFi protocols, security, and the current tool landscape.

not rated 279 +6 16d ago A tokens not measured

XPolicyLab/XPolicyLab

Skill Claude CodeCodex

Audit a policy/ / adapter for XPolicyLab standard compliance and PR readiness — file completeness, deploy.yml, Model contract, decodeimagebit-only decoding, script conventions, static checks, debug-mode eval, README and checkpoint requirements. Use when asked to check, validate, review, or pre-flight a policy adapter…

not rated 275 +12 changed yesterday A 85 tokens original Apache-2.0

caido-mode

238

caido/skills

Skill Claude CodeCodex

Full Caido SDK integration for Claude Code. Search HTTP history with HTTPQL, test with curl proxied through Caido (caching auth in reusable static curl config files), add match & replace rules, and organize handoffs into named replay sessions and collections - all via the official @caido/sdk-client. PAT auth…

not rated 271 +4 22d ago C 70 tokens original MIT

securityclaw

239

SecurityClaw/SecurityClaw

Agent

Use for SecurityClaw orchestration, routing, skill-manifest, and investigation workflow changes.

not rated 271 +2 2d ago A 23 tokens original MIT

review-branch

240

circuit-synth/circuit-synth

Command Claude Code

Purpose: Comprehensive branch analysis for code quality, security, performance, and risk assessment before merging to main. Specialized for circuit-synth development workflows.

not rated 269 +3 6mo ago A 6 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: