24,354 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Claude Code plugin — 41 tools, 45 skills, 13 agents. Currency Guard keeps Claude on current docs, not stale training data. Elite SEO strategy with AI traffic tracking, IndexNow, GSC-GA4 cross-reference, CTR anomalies, brand filtering, keyword intelligence, index doctor, codebase index, pentest, ship, launch, grow…
★not rated 121 2mo agoA
tokens not measured
originalMIT
A local text decoder for identifying and reversing encodings and simple ciphers, such as Base64, hexadecimal, Caesar shifts, and Morse code. CTF means capture the flag, a type of security puzzle where hidden messages and clues must be solved.
Use when working in any FaasJS repo and no narrower FaasJS skill is already selected, or when a task spans project conventions, validation gates, security boundaries, and multiple FaasJS subsystems. For focused work, also load the relevant FaasJS skill: faasjs-project-workflow, faasjs-react-ant-design…
★not rated 121 3d agoA110 tokens
originalMITarchived
Apply the SAIL V2 (Secure AI Lifecycle) framework by Pillar Security to secure AI applications and agents — gap analyses, security roadmaps, maturity assessments, compliance checklists, control prioritization, and vendor RFPs. Grounded in the full 91-risk SAIL catalog.
Auth0 MCP Server: Manage Auth0 applications, APIs, actions, logs, and forms using natural language. Runs locally from the @auth0/auth0-mcp-server npm package.
★not rated 117▲
+2 9d agoA
tokens not measured
originalMIT
Scan code for injection, hardcoded secrets, XSS, dynamic code execution, and unsafe shell use. Use after writing or modifying code that handles user input, builds queries or commands, touches authentication, or adds a dependency — and whenever the user asks for a security check, audit, or review. Runs locally with no…
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.
Security vulnerability audit — check for OWASP top risks, hardcoded secrets, injection points, and dependency CVEs. Use when auditing code for security vulnerabilities, reviewing authentication/authorization logic, or checking for secrets leakage before merge.
Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either propose fixes and commit them or set the finding's state in Hacktron (truepositive, falsepositive, acceptedrisk, resolved).…
Systematically audit Solidity smart contract codebases for security vulnerabilities using a 4-phase approach - load a vulnerability cheatsheet, sweep code with grep and semantic analysis, deep-validate candidates against reference files, and output a severity-ranked findings.
A coordinated code-review workflow with four reviewers: one for static analysis, one for design, one for security, and one for refactoring. A pull request is a proposed set of code changes submitted for review.
SonarQube is the AI code quality and security verification platform used by millions of developers to catch bugs, vulnerabilities, and leaked secrets. This plugin enforces those standards in the agent coding loop: 7,500+ distinct issue types, secrets scanning, agentic analysis, and quality gates across 40+ languages.
Run local commands with API keys stored in EnvLatch instead of copying credentials between .env files or shell profiles. Use when an agent, CLI, script, SDK, test, or build needs a saved credential environment variable on macOS.
Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology. Use when asked to audit a smart contract repo from a URL or local path, auto-prepare the environment, find high-severity loss-of-funds vulnerabilities, validate exploitability, propose safe…
A Chinese-language assistant for IDA Pro, a program used to analyze compiled files such as Windows executables, libraries, and firmware.
★not rated 101▲
+1 2mo agoA176 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: