project-always
385Cursor rule Cursor
Core project conventions — code style, error handling, testing, security, git.
24,395 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.
Cursor rule Cursor
Core project conventions — code style, error handling, testing, security, git.
ricmmartins/azure-sre-agent-skills
Skill Claude CodeCodex
Assess security, reliability, and cost posture of Azure OpenAI and Microsoft Foundry deployments. Detects critical anti-patterns: API keys instead of Managed Identity, public endpoints without firewall, disabled content filtering, missing diagnostic settings, deprecated model versions, over-provisioned PTU, absence of…
Skill Claude Code
Full health and security audit for Rails apps, the review a principal engineer would do. Runs rubycritic, Brakeman, bundler-audit and rubyaudit, triages every finding with the LLM as judge, brings an OWASP Top 10 arsenal of checks for what scanners miss, and returns one impact-ranked action plan. Use for a Rails…
Agent Claude Code
Review changes for security vulnerabilities and trust-boundary issues.
Security-Phoenix-demo/security-skills-claude-code
Skill Claude CodeCodex
Purpose: Automated threat modeling from code analysis using STRIDE/DREAD methodologies.
yoanbernabeu/supabase-pentest-skills
Skill Claude CodeCodex
Create a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation.
Plugin Claude Code
Bundles 3 skills, 3 commands, 1 MCP server · 451 tokens together
Security skills for vibe coding — pre-coding security assessment, code vulnerability review, and threat modeling. Works without any MCP server or Jira/Confluence setup.
Skill Claude CodeCodex
Validates GitLab stack projects before deployment, ensuring proper architecture patterns, directory structure, secrets management, .env configuration, and Docker best practices. Use when users ask to validate a stack, check stack configuration, verify stack architecture, audit stack setup, or ensure stack deployment…
jrenaldi79/harness-engineering
Plugin Claude Code
Bundles 2 skills, 1 hook · 129 tokens together
Analyze and enforce best practices for AI coding agent projects. Assess codebase readiness across 8 pillars with /readiness, then scaffold enforcement with /setup: TDD, secret scanning, file size limits, auto-generated docs, and git hooks.
Skill Claude CodeCodex needs its repo
Scrub AI provenance marks from text and files using the markscrub CLI: invisible Unicode (Layer A), optional statistical rewrite (Layer B), and C2PA/EXIF/XMP/container metadata on PNG/JPEG/SVG/PDF/DOCX/HTML/MD. Use when the user asks to strip watermarks, remove Content Credentials, clean AI metadata, remove invisible…
Skill Claude CodeCodex
Search the Tor dark web, fetch .onion hidden service pages, rotate Tor identity, and run structured OSINT investigations. Use when user asks to search dark web, investigate .onion sites, find if data appeared on dark web, conduct Tor-based OSINT, look up dark web leaks, fetch any .onion URL, check for leaked…
MCP server Claude CodeCodexCursor +2
Model Context Protocol server for Vanta's security compliance platform. Runs locally from the @vantasdk/vanta-mcp-server npm package.
Skill Claude CodeCodex
AI agent security platform — audit skills, scan for threats, and run 24/7 protection with 9,700+ detection rules.
Skill Claude CodeCodex
An open-source security gateway that sits between an AI application and an LLM service. It can remove or clean sensitive information from requests and responses before they are passed through.
MCP server Claude CodeCodexCursor +2
MCP server "sonarqube" as configured in dismine/valentina. Launched with sonar run mcp --project dismine_valentina.
Skill Claude Code
Provides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP, number theory, Coppersmith, Pollard, Wiener, padding oracle, GCM, key derivation, or stream/block cipher weaknesses.
Command Claude Code
Scan for vulnerabilities, fix them, validate, and optionally create a PR.
Skill Claude CodeCodex
Analyzes security risks in the AI Agent/MCP Skill catalog. Used when users request to inspect, audit, review, or scan the Skill catalog for potential security risks, including command injection, data leakage, prompt word attacks, stealth access, remote execution, or other malicious activities within the SKILL package.
MCP server Claude CodeCodexCursor +2
Install deptrust, a local package vulnerability checker and MCP server for AI agents. Runs locally from the @clidey/deptrust npm package.
Plugin Claude Code
Bundles 8 skills · 1,216 tokens together
Sysdig's cloud security expertise, packaged as agent skills that work natively in your AI environment.
Plugin Claude Code
Bundles 1 skill · 184 tokens together
Praxen — agent behavior verifier. Compares an AI agent's declared policy (Worker Remit) against the available evidence — source code, live deployment state, or behavioral artifacts — and reports where observed behavior diverges from declared intent. Make sure your agent does its job — and only its job.
Plugin Claude Code
Bundles 1 skill, 1 plugin · 92 tokens together
Server security auditing, hardening, and fleet management. Runtime-derived audit catalog, CIS/PCI-DSS/HIPAA compliance, production hardening workflows, and first-party MCP tools. Supports Hetzner, DigitalOcean, Vultr, Linode with Coolify, Dokploy, and bare VPS modes.
app-incubator-xyz/skill-vetter
Skill Claude Code
Multi-scanner security gate. TRIGGER when: user mentions installing, adding, or reviewing a skill to Claude Code, OpenClaw, or any other AI agent. Detects malicious code, vulnerabilities, and suspicious patterns.
MCP server Claude CodeCodexCursor +2
Dependency graph + 24 MCP tools. Impact analysis, simulation, security, agent coordination. Runs locally from the depwire-cli npm package.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: