Security

24,395 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

wpegpt-analyzer

337

WPeace-HcH/WPeGPT-Analyzer

Skill Claude CodeCodex

A skill for using IDA and the WPeGPT plugin to analyse executable files in PE or ELF formats. It produces a structured report about the program, network indicators, suspicious functions, and possible vulnerabilities.

not rated 98 3mo ago A 58 tokens

android-pentest

338

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze…

not rated 97 +3 4mo ago A 87 tokens

launchworthy

339

Wunderlandmedia/launchworthy

Plugin Claude Code

Bundles 1 skill · 161 tokens together

Production readiness audit for apps built with AI coding tools. Detects your stack, audits 5 domains, and produces a scored punch list with copy-paste fixes.

not rated 95 8d ago A tokens not measured original MIT

accesslint

340

AccessLint/skills

Plugin Claude Code

Bundles 5 skills, 1 MCP server · 900 tokens together

Web accessibility (a11y) skills for Claude Code: audit a site for WCAG 2.2 conformance, scan a page with the rule engine, run hands-on keyboard and screen-reader checks, fix violations, and catch regressions in CI.

not rated 95 +2 13d ago A tokens not measured

code-review

342

arpitnath/claude-capsule-kit

Skill Claude Code

Pre-commit code review using code-reviewer agent for bug detection, security analysis, and quality assurance. Manual invocation only. Use before git commits to catch issues early. Blocks commits on REQUESTCHANGES verdict.

not rated 90 3mo ago A 45 tokens original MIT

tachi-risk-scorer

343

davidmatousek/tachi

Agent Claude Code needs its repo

Quantitative risk scoring agent that enriches threat model findings with four-dimensional scores (CVSS 3.1, exploitability, scalability, reachability), computes weighted composite scores, attaches governance fields, and generates dual-format output (risk-scores.md and risk-scores.sarif).

not rated 90 25d ago A 65 tokens original Apache-2.0

mitos-sandboxes

344

mitos-run/mitos

Skill Claude CodeCodex

Use when an agent needs isolated, forkable compute, running untrusted or model-written code safely, or exploring several attempts in parallel (best-of-N) and keeping the winner. Mitos boots Firecracker microVMs and forks a running VM via copy-on-write snapshots, so a fan-out is cheap and each attempt is…

not rated 89 1mo ago C 97 tokens original Apache-2.0

konstruktoid/hardened-images

Skill Claude CodeCodex

Authors, reviews, and hardens GitHub Actions workflows, reusable workflows, and composite actions with least-privilege GITHUBTOKEN permissions, action references pinned by commit SHA to the latest published release, injection-safe handling of untrusted event data, safe trigger and runner choices, and a structure that…

not rated 89 yesterday C 147 tokens original Apache-2.0

category-scanner

346

bluzir/claude-pipe

Agent Claude Code

Scan the target codebase for vulnerabilities in a single category. Use grep patterns to find candidates, read code to confirm in context, eliminate false positives, and produce evidence-grounded findings.

not rated 89 6mo ago A 3 tokens original MIT

tenuo-warrant

347

tenuo-ai/tenuo

Skill Claude CodeCodex

Create tenuo warrants (capability tokens) for AI agents from natural language descriptions. Use this skill when someone wants to create, mint, design, or delegate a warrant; authorize an agent; set up agent permissions; or add tenuo to a project. Do NOT trigger for auditing, reviewing, or explaining existing warrants…

not rated 89 2d ago B 77 tokens

security-reviewer

349

Jamkris/everything-gemini-code

Agent Claude Code

Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.

not rated 87 3mo ago A 52 tokens original MIT

skills

350

squirrelscan/skills

Plugin Claude Code

Bundles 2 skills, 1 MCP server · 195 tokens together

Website audit tool built for AI agents. 249+ SEO, performance, security & agent readiness rules: run audits from the CLI, fix findings in code, publish reports, and connect over MCP.

not rated 87 1mo ago A tokens not measured original MIT

tyran

351

jjanczur/tyran

Plugin Claude Code

Bundles 15 skills, 5 agents, 5 hooks · 1,196 tokens together

A task conductor for Claude Code: multi-agent orchestration with an enforced evidence contract, repo-specific learning, and update-safe local evolution.

not rated 86 +1 4d ago A tokens not measured original Apache-2.0

api-authentication

353

stefan-jansen/claude-code-toolkit

Skill Claude CodeCodex

API authentication patterns including JWT, OAuth 2.0, API keys, and session-based auth. Covers token generation, validation, refresh strategies, security best practices, and when to use each pattern. Use when implementing API authentication, choosing auth strategy, securing endpoints, or debugging auth issues.…

not rated 86 +1 2mo ago A 77 tokens original MIT

pentest

354

Strategic-Automation/violin

Skill Claude CodeCodex

Supervised authorized pentest: scope, route, validate, report.

not rated 85 +1 3d ago A 17 tokens original MIT

dependency-audit

355

BARMPlus/locklens

Skill Codex

A security review of project dependencies managed by npm, Yarn, or pnpm. It can inspect a local project directory or a remote Git repository for known dependency risks.

not rated 83 3mo ago A 56 tokens original MIT

kali

359

SeaC-25/Kali-Security-MCP

MCP server Claude CodeCodexCursor +2

One of 3 in .mcp.json

MCP server "kali" as configured in SeaC-25/Kali-Security-MCP. Launched with C:\Windows\py.exe -3 mcp_server.py --tool-profile harness. Needs 2 environment variables to run.

not rated 80 +2 21d ago A tokens not measured original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: