24,395 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
A skill for using IDA and the WPeGPT plugin to analyse executable files in PE or ELF formats. It produces a structured report about the program, network indicators, suspicious functions, and possible vulnerabilities.
Production readiness audit for apps built with AI coding tools. Detects your stack, audits 5 domains, and produces a scored punch list with copy-paste fixes.
★not rated 95 8d agoA
tokens not measured
originalMIT
Web accessibility (a11y) skills for Claude Code: audit a site for WCAG 2.2 conformance, scan a page with the rule engine, run hands-on keyboard and screen-reader checks, fix violations, and catch regressions in CI.
Agentic-Security is a powerful Claude Code plugin that automatically performs Application Security Testing (SAST, SCA, secrets detection, and more). Think of it as the easy button for making your Claude-generated code safe and secure.
★not rated 93▲
+3
changed yesterdayA
tokens not measured
Pre-commit code review using code-reviewer agent for bug detection, security analysis, and quality assurance. Manual invocation only. Use before git commits to catch issues early. Blocks commits on REQUESTCHANGES verdict.
Use when an agent needs isolated, forkable compute, running untrusted or model-written code safely, or exploring several attempts in parallel (best-of-N) and keeping the winner. Mitos boots Firecracker microVMs and forks a running VM via copy-on-write snapshots, so a fan-out is cheap and each attempt is…
Authors, reviews, and hardens GitHub Actions workflows, reusable workflows, and composite actions with least-privilege GITHUBTOKEN permissions, action references pinned by commit SHA to the latest published release, injection-safe handling of untrusted event data, safe trigger and runner choices, and a structure that…
Scan the target codebase for vulnerabilities in a single category. Use grep patterns to find candidates, read code to confirm in context, eliminate false positives, and produce evidence-grounded findings.
Create tenuo warrants (capability tokens) for AI agents from natural language descriptions. Use this skill when someone wants to create, mint, design, or delegate a warrant; authorize an agent; set up agent permissions; or add tenuo to a project. Do NOT trigger for auditing, reviewing, or explaining existing warrants…
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.
Website audit tool built for AI agents. 249+ SEO, performance, security & agent readiness rules: run audits from the CLI, fix findings in code, publish reports, and connect over MCP.
★not rated 87 1mo agoA
tokens not measured
originalMIT
A task conductor for Claude Code: multi-agent orchestration with an enforced evidence contract, repo-specific learning, and update-safe local evolution.
★not rated 86▲
+1 4d agoA
tokens not measured
originalApache-2.0
Blocks destructive commands outside the project directory. Allows file operations within the project (refactoring, cleanup) but prevents accidental damage outside it.
★not rated 86 1mo agoA
tokens not measured
originalMIT
API authentication patterns including JWT, OAuth 2.0, API keys, and session-based auth. Covers token generation, validation, refresh strategies, security best practices, and when to use each pattern. Use when implementing API authentication, choosing auth strategy, securing endpoints, or debugging auth issues.…
A security review of project dependencies managed by npm, Yarn, or pnpm. It can inspect a local project directory or a remote Git repository for known dependency risks.
MCP server "kali" as configured in SeaC-25/Kali-Security-MCP. Launched with C:\Windows\py.exe -3 mcp_server.py --tool-profile harness. Needs 2 environment variables to run.
★not rated 80▲
+2 21d agoA
tokens not measured
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: