Security

29,002 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

SCStelz/security-investigator

Instructions file GitHub Copilot

Copilot instructions for SCStelz/security-investigator, covering github copilot - security investigation integration, 📑 table of contents, ⚠️ critical workflow rules - read first ⚠️, 🔧 environment configuration and prerequisites.

not rated 244 yesterday A 22,159 tokens original MIT

HCL_Terraform_rules

266

wiz-sec-public/secure-rules-files

Cursor rule Cursor

Enforce secure infrastructure-as-code best practices for HCL/Terraform configurations to prevent common cloud security misconfigurations.

not rated 240 +1 8mo ago A 1,211 tokens

svsm AGENTS.md

267

coconut-svsm/svsm

Instructions file CodexOpenCode

AGENTS.md instructions for coconut-svsm/svsm, covering directory structure, building and testing, build recipes, igvm and formal verification with verus.

not rated 239 4d ago A 4,005 tokens original MIT

Hoylon/peerbridge-mcp

Instructions file CodexOpenCode

AGENTS.md instructions for Hoylon/peerbridge-mcp, a project described as: Local-first, auditable multi-agent control room for coding, review, evidence, and private remote work.

not rated 238 +10 3d ago A 200 tokens original Apache-2.0

ai-agent-security

269

ProgrammerAnthony/Expert-Coding-Harness

Skill Cursor

A security guide for AI agents—software that follows instructions and can use tools or data. It covers threats such as prompt injection, data leaks, unsafe code execution, unauthorized access, and compliance issues.

not rated 236 +1 3mo ago A 39 tokens original MIT

onionclaw

270

christinminor459/OnionClaw

Skill Claude CodeCodex

Search the Tor dark web, fetch .onion hidden service pages, rotate Tor identity, and run structured OSINT investigations. Use when user asks to search dark web, investigate .onion sites, find if data appeared on dark web, conduct Tor-based OSINT, look up dark web leaks, fetch any .onion URL, check for leaked…

not rated 236 2d ago B 82 tokens

maintenance

271

erikdarlingdata/PerformanceStudio

Skill Claude Code

Quarterly maintenance pass (every 1-3 months) — dependency/security audit, build health, and repo hygiene for PerformanceMonitor and PerformanceStudio.

not rated 236 yesterday A 31 tokens original MIT

SecSkills CLAUDE.md

272

Arenbai/SecSkills

Instructions file Claude Code

A security testing guide for SecSkills, a library of practical penetration-testing techniques and reference material.

not rated 234 +1 3mo ago A 1,616 tokens original MIT

pytm

273

rohunj/claude-build-workflow

Skill Claude CodeCodex

Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification. Use when: (1) Creating threat models programmatically using Python code, (2) Generating data flow diagrams (DFDs) with automatic STRIDE threat identification…

not rated 231 +1 7mo ago A 125 tokens

aki77/activestorage-validator

Skill Claude CodeCodex

Validate ActiveStorage attachments (content type, file size, file extension) with the activestorage-validator gem's blob validator. Use when adding validations to hasoneattached / hasmanyattached attributes.

not rated 226 2mo ago A 48 tokens original MIT

LazyOwn CLAUDE.md

275

grisuno/LazyOwn

Instructions file Claude Code

Claude Code instructions for grisuno/LazyOwn, covering claude.md — lazyown redteam framework, 0. what lazyown is, 0.1 security contracts, security hardening sprint (sdd+tdd+bdd) and 0.2 non-negotiable: user input is hostile.

not rated 225 changed yesterday A 11,032 tokens GPL-3.0

bhavsec/autopentest-ai

Instructions file Claude Code

Instructions for bhavsec/autopentest-ai, covering autopentest: automated web application penetration testing, available mcp servers, wstg pentest mcp server (wstg-pentest), reference guides (read on demand during testing) and portswigger technique reference guides.

not rated 225 +2 6mo ago B 29,523 tokens original Apache-2.0

bx33661/Wireshark-MCP

Skill Codex

Use when analyzing packet captures or live network traffic with Wireshark MCP; choose the right workflow for triage, security hunting, incident response, or troubleshooting, then produce evidence-backed findings with exact filters, streams, frames, and next steps.

not rated 225 +6 20d ago A 56 tokens original MIT

Agent Author

278

agentgg-dev/agentgg

Agent Claude Code

Distills a past security report into a reusable agentgg agent that catches the same anti-pattern if it recurs in this codebase.

not rated 223 +9 4d ago A 30 tokens original Apache-2.0

security-auditor

279

pgEdge/pgedge-postgres-mcp

Agent Claude Code

Use this agent for proactive security code review, vulnerability detection, and security best practices guidance. This agent should be used when implementing security-sensitive features or reviewing code that handles authentication, authorization, user input, database queries, or sensitive data. Examples:\n\n…

not rated 222 +1 yesterday A 0 tokens PostgreSQL

claude-cybersecurity

281

AgriciDaniel/claude-cybersecurity

Plugin Claude Code

Bundles 1 skill · 201 tokens together

AI-powered cybersecurity code review with 8 specialist agents, OWASP Top 10:2021, CWE Top 25:2024, MITRE ATT&CK v15, and framework-aware false-positive suppression.

not rated 218 +1 4mo ago A tokens not measured original MIT

raptor-loop-hunt

282

dinosn/raptor-loop-hunt

Plugin Claude Code

Bundles 1 skill · 165 tokens together

Autonomous, looping, multi-altitude security vulnerability hunt for a codebase — the RAPTOR 'Karpathy auto-research' generate -> adversarially-judge -> verify loop that finds far more bugs than a single-pass scan.

not rated 216 changed yesterday A tokens not measured original MIT

penetration-flow

283

lingbol088-spec/ReiPenFlow

Skill Codex

Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research. Use when Codex is asked to run or plan a security assessment, triage a target or artifact, maintain pentest state, produce interim/final…

not rated 212 +2 1mo ago A 144 tokens original MIT

better-auth/skills

Skill Claude CodeCodex

Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for Better Auth. Use when users need to secure their auth setup, prevent brute force attacks, or harden a Better Auth…

not rated 212 5d ago A 70 tokens

jwt

285

kataras/jwt

Plugin Claude Code

Bundles 2 skills · 266 tokens together

Development guide for the jwt JSON Web Token library for Go: signing and verifying tokens, claims and expiry, algorithm choice (HMAC/RSA/RSA-PSS/ECDSA/EdDSA), kid-based key rotation, JWKS fetch/refresh/publish, blocklisting and testing.

not rated 211 15d ago A tokens not measured original MIT

ffuf-web-fuzzing

286

jthack/ffuf_claude_skill

Skill Claude CodeCodex

Expert guidance for ffuf web fuzzing during penetration testing, including authenticated fuzzing with raw requests, auto-calibration, and result analysis.

not rated 210 10mo ago A 34 tokens

nemesis-auditor

288

NeverSight/learn-skills.dev

Skill Claude CodeCodex

The Inescapable Auditor. Runs the full Feynman Auditor (Stage 1) and full State Inconsistency Auditor (Stage 2) as primary steps, then fuses their outputs in a feedback loop (Stage 3) to find bugs at the intersection that neither alone would catch. Language-agnostic. Triggers on /nemesis or nemesis audit.

not rated 208 +1 yesterday A 83 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: