Security

24,354 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

ultraship

313

Houseofmvps/ultraship

Plugin Claude Code

Bundles 45 skills, 16 commands, 13 agents, 3 hooks, 2 MCP servers · 2,579 tokens together

Claude Code plugin — 41 tools, 45 skills, 13 agents. Currency Guard keeps Claude on current docs, not stale training data. Elite SEO strategy with AI traffic tracking, IndexNow, GSC-GA4 cross-reference, CTR anomalies, brand filtering, keyword intelligence, index doctor, codebase index, pentest, ship, launch, grow…

not rated 121 2mo ago A tokens not measured original MIT

ebctf-decode

314

Henglie/EBCTFCodeBox

Skill Claude CodeCodex

A local text decoder for identifying and reversing encodings and simple ciphers, such as Base64, hexadecimal, Caesar shifts, and Morse code. CTF means capture the flag, a type of security puzzle where hidden messages and clues must be solved.

not rated 121 +4 11d ago A 100 tokens original Apache-2.0

faasjs-best-practices

315

faasjs/faasjs

Skill Claude CodeCodex

Use when working in any FaasJS repo and no narrower FaasJS skill is already selected, or when a task spans project conventions, validation gates, security boundaries, and multiple FaasJS subsystems. For focused work, also load the relevant FaasJS skill: faasjs-project-workflow, faasjs-react-ant-design…

not rated 121 3d ago A 110 tokens original MIT archived

malchela-marketplace

317

dwmetz/MalChela

Plugin Claude Code

MalChela — A YARA & Malware Analysis Toolkit with Claude MCP integration for DFIR analysts.

not rated 118 24d ago A tokens not measured original MIT

sail

318

pillar-labs/sail-skill

Plugin Claude Code

Bundles 1 skill, 4 commands · 318 tokens together

Apply the SAIL V2 (Secure AI Lifecycle) framework by Pillar Security to secure AI applications and agents — gap analyses, security roadmaps, maturity assessments, compliance checklists, control prioritization, and vendor RFPs. Grounded in the full 91-risk SAIL catalog.

not rated 118 +2 2mo ago A tokens not measured

mcp

319

auth0/auth0-mcp-server

MCP server Claude CodeCodexCursor +2 ✓ vendor

Auth0 MCP Server: Manage Auth0 applications, APIs, actions, logs, and forms using natural language. Runs locally from the @auth0/auth0-mcp-server npm package.

not rated 117 +2 9d ago A tokens not measured original MIT

skills-janitor

320

khendzel/skills-janitor

Plugin Claude Code

Bundles 6 skills · 365 tokens together

6 skill hygiene tools: health report, auto-fix + prune, value (honest token split + usage), security scan (prompt injection + malicious patterns), discover (search + precheck), swipe (interactive triage).

not rated 115 26d ago A tokens not measured original MIT

dvalin-security-scan

321

arthurpanhku/dvalincode

Skill Claude CodeCodex

Scan code for injection, hardcoded secrets, XSS, dynamic code execution, and unsafe shell use. Use after writing or modifying code that handles user input, builds queries or commands, touches authentication, or adds a dependency — and whenever the user asks for a security check, audit, or review. Runs locally with no…

not rated 114 changed yesterday A 77 tokens original MIT

security-reviewer

322

GGGODLIN/claude-pr-review

Agent Claude Code

Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.

not rated 114 +3 14d ago A 52 tokens original MIT

security-audit

323

hardness1020/Leeway

Skill Claude CodeCodex

Security vulnerability audit — check for OWASP top risks, hardcoded secrets, injection points, and dependency CVEs. Use when auditing code for security vulnerabilities, reviewing authentication/authorization logic, or checking for secrets leakage before merge.

not rated 113 3mo ago A 49 tokens original MIT

chaitin-cli

324

chaitin/chaitin-cli

Skill Claude CodeCodex

Use when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability scanner (scan tasks, results, assets), CodeInsight (projects, repository configs, scan tasks, reports), CodeForce (projects, AI tasks, denoise…

not rated 113 16d ago A 112 tokens GPL-3.0

finding-triage

325

HacktronAI/skills

Skill Claude Code

Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either propose fixes and commit them or set the finding's state in Hacktron (truepositive, falsepositive, acceptedrisk, resolved).…

not rated 113 3mo ago A 120 tokens original MIT

frida-mcp

326

zhizhuodemao/frida-mcp

MCP server Claude CodeCodexCursor +2

Model Context Protocol implementation for Frida. Runs locally from the frida-mcp Python package.

not rated 113 +1 10mo ago A tokens not measured

cls-certify

329

CatREFuse/cls-certify

Skill Claude CodeCodex

A security-review skill for examining agent skills across code, runtime behaviour, dependencies, network traffic, privacy, and threat intelligence.

not rated 110 +2 5mo ago A ✓ AI review 106 tokens

scv-scan

330

kadenzipfel/scv-scan

Skill Claude CodeCodex

Systematically audit Solidity smart contract codebases for security vulnerabilities using a 4-phase approach - load a vulnerability cheatsheet, sweep code with grep and semantic analysis, deep-validate candidates against reference files, and output a severity-ranked findings.

not rated 106 +1 5mo ago A 51 tokens

kali-pentest

331

x-glacier/kali-pentest

Skill Claude Code

Execute authorized penetration testing via Kali Linux CLI tools over SSH or Docker. Covers: information gathering, vulnerability analysis, sniffing & spoofing, web/API testing, exploitation, password attacks, wireless, cloud-native security, RFID/NFC, VoIP/ICS, reverse engineering, forensics, post-exploitation/C2, and…

not rated 105 +3 2mo ago A 73 tokens original Apache-2.0

code-review-team

332

revfactory/harness-engineering-with-cc

Skill Claude Code

A coordinated code-review workflow with four reviewers: one for static analysis, one for design, one for security, and one for refactoring. A pull request is a proposed set of code changes submitted for review.

not rated 103 +2 3mo ago A 66 tokens original Apache-2.0

sonarqube

333

SonarSource/sonarqube-agent-plugins

Plugin Claude Code

Bundles 9 skills, 1 agent · 400 tokens together

SonarQube is the AI code quality and security verification platform used by millions of developers to catch bugs, vulnerabilities, and leaked secrets. This plugin enforces those standards in the agent coding loop: 7,500+ distinct issue types, secrets scanning, agentic analysis, and quality gates across 40+ languages.

not rated 102 23d ago A tokens not measured

envlatch

334

Raylinkh/envlatch

Skill Codex

Run local commands with API keys stored in EnvLatch instead of copying credentials between .env files or shell profiles. Use when an agent, CLI, script, SDK, test, or build needs a saved credential environment variable on macOS.

not rated 101 22d ago A 51 tokens original MIT

smart-contract-audit

335

greatpie/smart-contract-audit-skill

Skill Claude CodeCodex

Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology. Use when asked to audit a smart contract repo from a URL or local path, auto-prepare the environment, find high-severity loss-of-funds vulnerabilities, validate exploitability, propose safe…

not rated 101 6mo ago A 80 tokens

ida-reverse

336

haikow/claude-reverse-skills

Skill Claude CodeCodex

A Chinese-language assistant for IDA Pro, a program used to analyze compiled files such as Windows executables, libraries, and firmware.

not rated 101 +1 2mo ago A 176 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: