Security

24,395 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

project-always

385

sunnykgupta/AI-Helpers

Cursor rule Cursor

Core project conventions — code style, error handling, testing, security, git.

not rated 70 1mo ago A 1,703 tokens original MIT

ricmmartins/azure-sre-agent-skills

Skill Claude CodeCodex

Assess security, reliability, and cost posture of Azure OpenAI and Microsoft Foundry deployments. Detects critical anti-patterns: API keys instead of Managed Identity, public endpoints without firewall, disabled content filtering, missing diagnostic settings, deprecated model versions, over-provisioned PTU, absence of…

not rated 70 13d ago A SkillSpector: warn 142 tokens original MIT

nuke-on-rails

387

nuke-on-rails/nuke-on-rails

Skill Claude Code

Full health and security audit for Rails apps, the review a principal engineer would do. Runs rubycritic, Brakeman, bundler-audit and rubyaudit, triages every finding with the LLM as judge, brings an OWASP Top 10 arsenal of checks for what scanners miss, and returns one impact-ranked action plan. Use for a Rails…

not rated 70 +1 1mo ago A 105 tokens original MIT

security-reviewer

388

heggria/taskflow

Agent Claude Code

Review changes for security vulnerabilities and trust-boundary issues.

not rated 70 +2 4d ago A 14 tokens original MIT

yoanbernabeu/supabase-pentest-skills

Skill Claude CodeCodex

Create a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation.

not rated 68 7mo ago A Socket: passSnyk: fail 40 tokens

rknall/claude-skills

Skill Claude CodeCodex

Validates GitLab stack projects before deployment, ensuring proper architecture patterns, directory structure, secrets management, .env configuration, and Docker best practices. Use when users ask to validate a stack, check stack configuration, verify stack architecture, audit stack setup, or ensure stack deployment…

not rated 67 +1 10mo ago A 61 tokens

harness-engineering

393

jrenaldi79/harness-engineering

Plugin Claude Code

Bundles 2 skills, 1 hook · 129 tokens together

Analyze and enforce best practices for AI coding agent projects. Assess codebase readiness across 8 pillars with /readiness, then scaffold enforcement with /setup: TDD, secret scanning, file size limits, auto-generated docs, and git hooks.

not rated 66 5mo ago A tokens not measured original MIT

remove-ai-marks

394

anshaneja5/markscrub

Skill Claude CodeCodex needs its repo

Scrub AI provenance marks from text and files using the markscrub CLI: invisible Unicode (Layer A), optional statistical rewrite (Layer B), and C2PA/EXIF/XMP/container metadata on PNG/JPEG/SVG/PDF/DOCX/HTML/MD. Use when the user asks to strip watermarks, remove Content Credentials, clean AI metadata, remove invisible…

not rated 66 +1 4d ago A SkillSpector: fail 91 tokens original MIT

onionclaw

395

JacobJandon/OnionClaw

Skill Claude CodeCodex

Search the Tor dark web, fetch .onion hidden service pages, rotate Tor identity, and run structured OSINT investigations. Use when user asks to search dark web, investigate .onion sites, find if data appeared on dark web, conduct Tor-based OSINT, look up dark web leaks, fetch any .onion URL, check for leaked…

not rated 64 2mo ago B 82 tokens

vanta-mcp-server

396

VantaInc/vanta-mcp-server

MCP server Claude CodeCodexCursor +2

Model Context Protocol server for Vanta's security compliance platform. Runs locally from the @vantasdk/vanta-mcp-server npm package.

not rated 64 2mo ago A tokens not measured original MIT archived

panguard

397

panguard-ai/panguard-ai

Skill Claude CodeCodex

AI agent security platform — audit skills, scan for threats, and run 24/7 protection with 9,700+ detection rules.

not rated 63 15d ago A 30 tokens original MIT

AegisGate

398

ax128/AegisGate

Skill Claude CodeCodex

An open-source security gateway that sits between an AI application and an LLM service. It can remove or clean sensitive information from requests and responses before they are passed through.

not rated 63 +1 8d ago B 0 tokens original MIT

sonarqube

399

dismine/valentina

MCP server Claude CodeCodexCursor +2

MCP server "sonarqube" as configured in dismine/valentina. Launched with sonar run mcp --project dismine_valentina.

not rated 63 +1 yesterday A tokens not measured GPL-3.0

ctf-crypto

400

DekaPrayoga/AurixAgent

Skill Claude Code

Provides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP, number theory, Coppersmith, Pollard, Wiener, padding oracle, GCM, key derivation, or stream/block cipher weaknesses.

not rated 63 +1 1mo ago A 78 tokens

snyk-fix

401

snyk/studio-recipes

Command Claude Code

Scan for vulnerabilities, fix them, validate, and optionally create a PR.

not rated 62 4d ago A 20 tokens original Apache-2.0

behavioral-analysis

402

HuTa0kj/vetix

Skill Claude CodeCodex

Analyzes security risks in the AI Agent/MCP Skill catalog. Used when users request to inspect, audit, review, or scan the Skill catalog for potential security risks, including command injection, data leakage, prompt word attacks, stealth access, remote execution, or other malicious activities within the SKILL package.

not rated 61 1mo ago C 65 tokens original MIT

deptrust

403

clidey/deptrust

MCP server Claude CodeCodexCursor +2

Install deptrust, a local package vulnerability checker and MCP server for AI agents. Runs locally from the @clidey/deptrust npm package.

not rated 61 19d ago A tokens not measured original MIT

sysdig/skills

Plugin Claude Code

Bundles 8 skills · 1,216 tokens together

Sysdig's cloud security expertise, packaged as agent skills that work natively in your AI environment.

not rated 60 1mo ago A tokens not measured

praxen

405

open-agent-ai-security/praxen

Plugin Claude Code

Bundles 1 skill · 184 tokens together

Praxen — agent behavior verifier. Compares an AI agent's declared policy (Worker Remit) against the available evidence — source code, live deployment state, or behavioral artifacts — and reports where observed behavior diverges from declared intent. Make sure your agent does its job — and only its job.

not rated 60 2d ago A tokens not measured original Apache-2.0

kastell

406

kastelldev/kastell

Plugin Claude Code

Bundles 1 skill, 1 plugin · 92 tokens together

Server security auditing, hardening, and fleet management. Runtime-derived audit catalog, CIS/PCI-DSS/HIPAA compliance, production hardening workflows, and first-party MCP tools. Supports Hetzner, DigitalOcean, Vultr, Linode with Coolify, Dokploy, and bare VPS modes.

not rated 60 yesterday A tokens not measured original Apache-2.0

skill-vetter

407

app-incubator-xyz/skill-vetter

Skill Claude Code

Multi-scanner security gate. TRIGGER when: user mentions installing, adding, or reviewing a skill to Claude Code, OpenClaw, or any other AI agent. Detects malicious code, vulnerabilities, and suspicious patterns.

not rated 60 +1 6mo ago A 49 tokens

depwire

408

depwire/depwire

MCP server Claude CodeCodexCursor +2

Dependency graph + 24 MCP tools. Impact analysis, simulation, security, agent coordination. Runs locally from the depwire-cli npm package.

not rated 60 7d ago A tokens not measured

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: