29,002 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
AGENTS.md instructions for coconut-svsm/svsm, covering directory structure, building and testing, build recipes, igvm and formal verification with verus.
AGENTS.md instructions for Hoylon/peerbridge-mcp, a project described as: Local-first, auditable multi-agent control room for coding, review, evidence, and private remote work.
★not rated 238▲
+10 3d agoA200 tokens
originalApache-2.0
A security guide for AI agents—software that follows instructions and can use tools or data. It covers threats such as prompt injection, data leaks, unsafe code execution, unauthorized access, and compliance issues.
Search the Tor dark web, fetch .onion hidden service pages, rotate Tor identity, and run structured OSINT investigations. Use when user asks to search dark web, investigate .onion sites, find if data appeared on dark web, conduct Tor-based OSINT, look up dark web leaks, fetch any .onion URL, check for leaked…
Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification. Use when: (1) Creating threat models programmatically using Python code, (2) Generating data flow diagrams (DFDs) with automatic STRIDE threat identification…
Validate ActiveStorage attachments (content type, file size, file extension) with the activestorage-validator gem's blob validator. Use when adding validations to hasoneattached / hasmanyattached attributes.
Claude Code instructions for grisuno/LazyOwn, covering claude.md — lazyown redteam framework, 0. what lazyown is, 0.1 security contracts, security hardening sprint (sdd+tdd+bdd) and 0.2 non-negotiable: user input is hostile.
Instructions for bhavsec/autopentest-ai, covering autopentest: automated web application penetration testing, available mcp servers, wstg pentest mcp server (wstg-pentest), reference guides (read on demand during testing) and portswigger technique reference guides.
Use when analyzing packet captures or live network traffic with Wireshark MCP; choose the right workflow for triage, security hunting, incident response, or troubleshooting, then produce evidence-backed findings with exact filters, streams, frames, and next steps.
Use this agent for proactive security code review, vulnerability detection, and security best practices guidance. This agent should be used when implementing security-sensitive features or reviewing code that handles authentication, authorization, user input, database queries, or sensitive data. Examples:\n\n…
Autonomous, looping, multi-altitude security vulnerability hunt for a codebase — the RAPTOR 'Karpathy auto-research' generate -> adversarially-judge -> verify loop that finds far more bugs than a single-pass scan.
★not rated 216
changed yesterdayA
tokens not measured
originalMIT
Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research. Use when Codex is asked to run or plan a security assessment, triage a target or artifact, maintain pentest state, produce interim/final…
Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for Better Auth. Use when users need to secure their auth setup, prevent brute force attacks, or harden a Better Auth…
Development guide for the jwt JSON Web Token library for Go: signing and verifying tokens, claims and expiry, algorithm choice (HMAC/RSA/RSA-PSS/ECDSA/EdDSA), kid-based key rotation, JWKS fetch/refresh/publish, blocklisting and testing.
★not rated 211 15d agoA
tokens not measured
originalMIT
Expert guidance for ffuf web fuzzing during penetration testing, including authenticated fuzzing with raw requests, auto-calibration, and result analysis.
The Inescapable Auditor. Runs the full Feynman Auditor (Stage 1) and full State Inconsistency Auditor (Stage 2) as primary steps, then fuses their outputs in a feedback loop (Stage 3) to find bugs at the intersection that neither alone would catch. Language-agnostic. Triggers on /nemesis or nemesis audit.
★not rated 208▲
+1 yesterdayA83 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: