Security

24,395 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

scammer

361

naxiaoduo/Scammer.skill

Skill Claude Code

A scam-message checker that analyzes suspicious texts, images, or conversation descriptions. It can identify the likely stage of a scam and suggest what the sender may try next.

not rated 78 5mo ago A 50 tokens original MIT

fort

362

djadmin/fort

Plugin Claude Code

Bundles 1 skill, 3 commands · 181 tokens together

Audit your Mac's security posture from Claude Code, understand what each finding means and why it matters, then fix what's safe. Drives the fort CLI over your shell and remediates only what you approve. Read-only by default. Findings map to SOC 2 / ISO 27001 / NIST / CIS when you need audit evidence.

not rated 78 1mo ago A tokens not measured original MIT

slb

363

Dicklesworthstone/slb

Skill Claude CodeCodex

Simultaneous Launch Button - Two-person rule for destructive commands. Use when coordinating dangerous operations between agents, requiring peer review for rm -rf, git push --force, kubectl delete, DROP TABLE, or terraform destroy.

not rated 78 yesterday E 48 tokens

review

364

lkimuk/Wuwe

Skill Claude CodeCodex

Review the supplied artifact for correctness, security, maintainability, and test coverage. Report concrete findings before general suggestions, and distinguish verified defects from risks.

not rated 78 +1 4d ago A 0 tokens original Apache-2.0

resemble-detect

365

resemble-ai/detect-skill

Skill Claude CodeCodex

Deepfake detection and media safety — detect AI-generated audio, images, video, and text, trace synthesis sources, and analyze media intelligence using direct Resemble AI API calls.

not rated 78 +7 changed 3d ago A 40 tokens original Apache-2.0

security-audit-rlm

366

mitkox/megacode

Skill Claude CodeCodex

Run and troubleshoot privacy-preserving, local DSPy RLM security audits for large legacy .NET codebases. Use when asked to scan repositories for vulnerabilities, tune RLM/tool limits, fix truncation/stall issues, or produce actionable markdown/json audit outputs without loading entire codebases into model context.

not rated 78 6mo ago A 67 tokens original MIT

ipc

367

SFARPak/AliFullStack

Cursor rule Cursor

You're building an Electron app following good security practices.

not rated 77 +1 1mo ago A 1,342 tokens original Apache-2.0

password-attacks

368

mukul975/Threatswarm

Agent Claude Code

Password cracking and credential attack specialist. Use when working with password hashes, hash cracking, wordlist attacks, credential analysis, or password auditing. Triggers on: password, hash, crack, hashcat, john, wordlist, NetNTLMv2, Kerberoast, NTLM, bcrypt, credential, ASREP, JWT crack, mask attack, rule…

not rated 77 4mo ago A 88 tokens original MIT

deepsafe-scan

369

XiaoYiWeio/deepsafe-scan

Skill Claude Code

Preflight security scanner for AI coding agents — scans deployment config, skills/MCP servers, memory/sessions, and AI agent config files (hooks injection) for secrets, PII, prompt injection, and dangerous patterns. Runs 4 model behavior probes (persuasion, sandbagging, deception, hallucination). Supports LLM-enhanced…

not rated 76 3mo ago A 120 tokens

authz-security

370

superagent-ai/skills

Skill Claude CodeCodex

Review application source code for broken authorization — IDOR / Broken Object Level Authorization (OWASP API1), Broken Function Level Authorization (API5), mass assignment (API3), multi-tenant isolation gaps, and privilege escalation. Reads routes, controllers, resolvers, and data models offline and reports the…

not rated 76 22d ago A 150 tokens original MIT

dep-cve

371

sparkfinderoven/r01-hesreallyhim-awesome-claude-code-security

Command Claude Code

You are a senior Security & Compliance specialist. The user needs help with dep cve in the context of security audits, vulnerability management, gdpr/soc2/iso27001 compliance and incident response.

not rated 75 4mo ago A 0 tokens

dotfiles-bootstrap

372

sebastienrousseau/dotfiles

Skill Claude CodeCodex

Bootstrap a workstation with the dotfiles framework. Takes a GitHub user / owner+repo / explicit clone URL and runs dot init (which shells out to chezmoi) with the right safety prompts. Honors the active agent profile (ask / plan / apply / audit) so it defaults to dry-run in safer modes and full apply in apply.

not rated 75 3d ago A 88 tokens original Apache-2.0

security

373

Netxeo/skill-file-security

Cursor rule Cursor

Security Skill — Enterprise-grade security engineering.

not rated 74 +1 2mo ago A 238 tokens

network-ai

374

Jovancoding/Network-AI

Plugin Claude Code

Bundles 1 skill, 4 commands, 1 MCP server · 116 tokens together

Gives Claude Code a multi-agent coordination layer over MCP — an atomic shared blackboard (locked propose/validate/commit), permission gating with HMAC/Ed25519-signed tokens, federated token-budget tracking, and append-only audit-log queries. Backed by an orchestrator with 32 framework adapters (LangChain, AutoGen…

not rated 74 +2 6d ago A tokens not measured copy · 94% MIT

stealthy-auto-browse

375

psyb0t/docker-stealthy-auto-browse

Plugin Claude Code

Bundles 1 skill · 52 tokens together

Headless-detection-resistant browser automation in Docker — Camoufox stealth browser, OS-level input via PyAutoGUI, HTTP API and MCP server, for authorized QA and defensive security testing.

not rated 74 5d ago A tokens not measured WTFPL

system-control

376

iammm0/secbot

Skill Claude CodeCodex

Comprehensive system control operations for security testing. Use this skill when you need unified access to file operations, process management, system information, and command execution through a single interface during authorized penetration testing.

not rated 73 5d ago A 43 tokens

vorim-mcp-server

377

Vorim-AI-Labs/vorim-mcp-server

MCP server Claude CodeCodexCursor +2

AI agent identity, permissions, trust scores, and tamper-evident audit trails via Vorim AI. Runs locally from the @vorim/mcp-server npm package. Needs 2 environment variables to run.

not rated 73 24d ago A tokens not measured original MIT

ywh

379

yeswehack/claude-kit

Plugin Claude Code

Bundles 3 skills, 1 hook · 189 tokens together

Produce triager-grade YesWeHack reports instead of AI slop: always-on drafting discipline plus three on-demand skills (write, triage, gotchas).

not rated 73 +13 12d ago A tokens not measured GPL-3.0

report

380

v-yun/vuln-report-skill

Skill Claude CodeCodex

A procedure for turning a confirmed security vulnerability into a submission-ready DOCX report. DOCX is the Microsoft Word document format.

not rated 72 +11 17d ago A 183 tokens copy · 89% MIT

cloud-audit

381

gebalamariusz/cloud-audit

MCP server Claude CodeCodexCursor +2

Open-source, read-only AWS security scanner. 110 checks across 25 services, 31 attack-chain rules, 64 IAM escalation methods (incl. lateral AssumeRole graph), Proof Mode exploitability verification, data perimeter and Bedrock AgentCore checks, Blast Radius CLI, Threat Feed, What-If simulator, AI-SPM, 6 compliance…

not rated 72 +3 1mo ago A tokens not measured original MIT

dependency-auditor

382

UseAI-pro/openclaw-skills-security

Skill Claude CodeCodex

Audit npm, pip, and Go dependencies that OpenClaw skills try to install. Checks for known vulnerabilities, typosquatting, and malicious packages.

not rated 71 6mo ago A Socket: passSnyk: warn 36 tokens original MIT

bug-reaper

383

shaniidev/bug-reaper

Skill Claude CodeCodex

Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF, IDOR, auth bypass, RCE, SSTI, LFI, XXE, CORS, CSRF, prototype pollution, subdomain takeover, HTTP smuggling, open…

not rated 71 6mo ago A 192 tokens original MIT

Cluster Doctor

384

microsoftgbb/agentic-platform-engineering

Agent Claude Code

An expert Kubernetes administrator agent specializing in cluster troubleshooting, networking, NetworkPolicy, security posture, admission controllers, and GitOps workflows. The agent assesses initial reports, independently verifies or rejects claims, triages root causes, and proposes or applies fixes (including GitOps…

not rated 71 2mo ago A 61 tokens fork Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: