Security

29,002 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

api-spectral

289

AgentSecOps/SecOpsAgentKit

Skill Claude CodeCodex

API specification linting and security validation using Stoplight's Spectral with support for OpenAPI, AsyncAPI, and Arazzo specifications. Validates API definitions against security best practices, OWASP API Security Top 10, and custom organizational standards. Use when: (1) Validating OpenAPI/AsyncAPI specifications…

not rated 205 +2 4mo ago A 138 tokens

GeniusHu-tgty/Open-tgtylab

Instructions file CodexOpenCode

A set of instructions for the GeniusHu-tgty/Open-tgtylab project. It covers reverse engineering, web security challenges, long-running Claude Code or Codex sessions, and Android application knowledge.

not rated 202 +2 1mo ago A 3,855 tokens GPL-3.0

sjkim1127/Reversecore_MCP

Instructions file CodexOpenCode

AGENTS.md instructions for sjkim1127/Reversecore_MCP, covering agent customizations for reversecoremcp, project overview, quick commands, development setup and create virtual environment.

not rated 199 +1 today A 2,563 tokens original MIT

cynative CLAUDE.md

292

cynative/cynative

Instructions file Claude Code

Claude Code instructions for cynative/cynative, a project described as: Open-source framework for security agents with live, read-only access to your infrastructure. Audit AWS, GCP, Azure, Kubernetes, GitHub and GitLab as one system for privilege escalation, public exposure, leaked credentials and more, with agents…

not rated 197 +2 today A 3 tokens copy · 100% Apache-2.0

hm-llm-guardrails

293

rodrigohighermind/highermind-code-skills

Skill Claude CodeCodex

Catálogo de 14 patterns obrigatórios para app que integra LLM (Claude/GPT/Gemini) em produção. Use antes de shippar feature LLM pra produção, quando custo da API explode sem explicação, quando user reclama de "respostas demoram demais" ou "trava no meio", ao adicionar tool calling, agentes ou chat persistente. Cobre…

not rated 192 +1 2mo ago A 149 tokens original MIT

lennney/mcp-slim-guard

Instructions file CodexOpenCode

Instructions for lennney/mcp-slim-guard, covering slim guard agent contract, scope and source of truth, repository map, product invariants and code style.

not rated 192 +15 23d ago A 1,043 tokens original MIT

playwright-bot-bypass

295

greekr4/playwright-bot-bypass

Plugin Claude Code

Bundles 1 skill · 62 tokens together

Bypass bot detection using rebrowser-playwright (Node.js) or undetected-chromedriver (Python). Passes bot.sannysoft.com fingerprint checks and automates Google without triggering CAPTCHA. Authorized-use only — respect each site's ToS.

not rated 192 10d ago A tokens not measured original MIT

erans/lunaroute

Agent Claude Code

Use this agent when you need expert review of Rust code, particularly web services, HTTP implementations, or security-critical systems. Trigger this agent after completing logical code units like implementing HTTP handlers, API endpoints, authentication systems, middleware, database operations, or any Rust web…

not rated 188 +1 1mo ago A 323 tokens original Apache-2.0

code-reviewer

297

kid-sid/claude-spellbook

Agent Claude Code

Use this agent to perform a thorough two-stage review of a pull request or set of changed files — first verifying spec compliance, then evaluating code quality, security, test coverage, and performance. Prefer this over the inline /review command when the diff spans more than 5 files or more than 300 lines.

not rated 188 +1 1mo ago A 66 tokens original MIT

idor-agent

299

BugTraceAI/BugTraceAI-CLI

Agent Claude Code

The IDOR Agent (Insecure Direct Object Reference) is a specialist agent in BugTraceAI that detects and exploits IDOR vulnerabilities. It uses a WET→DRY two-phase pipeline with LLM-powered deduplication and optional deep exploitation analysis.

not rated 184 +1 3d ago A 0 tokens original Apache-2.0

keypo-signer

300

keypo-us/keypo-cli

Skill Claude CodeCodex

Use when managing Secure Enclave signing keys or encrypted secrets. Use for creating/listing/deleting P-256 keys, signing digests, running commands with secrets injected via vault exec, storing/retrieving encrypted secrets. Also use when an agent needs API keys, private keys, or credentials injected into a subprocess…

not rated 181 5mo ago A 86 tokens

grc

301

mlunato47/claude-grc-plugin

Plugin Claude Code

Bundles 1 skill, 24 commands, 1 agent · 378 tokens together

GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.

not rated 181 +1 1mo ago A tokens not measured original MIT

vpn-setup CLAUDE.md

302

Sergei-thinker/vpn-setup

Instructions file Claude Code

A set of project instructions for deploying and explaining a multi-layer VPN service based on VLESS Reality, Xray-core, and a management panel. It includes setup requirements, client choices, and guidance for communicating in Russian.

not rated 181 +1 4mo ago A 2,498 tokens original MIT

technique-proposal

303

wiz-sec-public/SITF

Skill Claude Code

Generate a PR-ready technique proposal when an attack step doesn't map to existing SITF techniques. Use after /attack-flow identifies technique gaps.

not rated 179 +1 1mo ago A 0 tokens

production-grade

305

nagisanzenin/production-grade

Plugin Claude Code

Bundles 14 skills, 2 hooks · 690 tokens together

Enhances Claude Code from producing raw code into delivering production-ready systems. 14 specialized agents handle architecture, tested code, security audit, CI/CD, and documentation. Use for building apps/websites/services, adding features, hardening, deployment, testing, review, or architecture design.

not rated 175 17d ago A tokens not measured

prompt-guard

306

seojoonkim/prompt-guard

Skill Claude CodeCodex

600+ pattern AI agent security defense covering prompt injection, supply chain injection, memory poisoning, action gate bypass, unicode steganography, and cascade amplification. Optional API for early-access and premium patterns. Tiered loading, hash cache, 11 SHIELD categories, 10 languages.

not rated 175 +1 4mo ago B 61 tokens original MIT

agentsecrets

307

The-17/agentsecrets

Skill Claude CodeCodex

Zero-knowledge secrets infrastructure — AI agents manage the complete credential lifecycle without ever seeing values.

not rated 172 changed 2d ago A 21 tokens original MIT

vinayaklatthe/microsoft-security-skills

Skill Claude CodeCodex

Guidance for governing the identities of AI agents and non-human identities (NHIs) — Microsoft 365 Copilot Studio agents, Microsoft Foundry agents, custom AI agents, and traditional service principals/managed identities — through their full lifecycle. Covers ownership and tagging, scoped permissions and consent…

not rated 171 +1 2mo ago A 241 tokens original MIT

lyrik

309

gebruder/wirken

Skill Claude Code

Security assessment of a codebase — minimal mode for runner validation.

not rated 171 2d ago A 15 tokens original MIT

OpenWorkProof

310

dengyier/OpenWorkProof

MCP server Claude CodeCodexCursor +2

Agent work contracts and verifiable execution protocol — Ed25519-signed, offline-verifiable proof-carrying work for AI agents. Runs locally from the openworkproof Python package.

not rated 170 +60 7d ago A tokens not measured original Apache-2.0

huifer/skill-security-scan

Instructions file Claude Code

Instructions for huifer/skill-security-scan, covering claude.md, project overview, development commands, installation & setup and install dependencies.

not rated 169 +2 8mo ago A 1,490 tokens original MIT

repo-forensics

312

alexgreensh/repo-forensics

Cursor rule Cursor

Vet untrusted repos, skills, MCP servers, and packages with repo-forensics before installing them.

not rated 169 +1 9d ago A 20 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: