Security

24,395 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

PostHog/skills

Skill Claude Code

Signals scout for Content Security Policy violations. Watches $cspviolation events for blocked-URL clusters, per-directive bursts, post-deploy regressions, and suspicious third- party domains.

not rated 60 changed 3d ago A SkillSpector: warn 49 tokens original MIT

php-unserialize-audit

410

califio/skills

Plugin Claude Code

Bundles 1 skill, 1 command · 268 tokens together

Audit PHP engine deserialization surface (unserialize, session decoders, WDDX, phar metadata, custom ce->unserialize handlers) for UAF, type confusion, partial-object destruct, signed-length heap overflow, and parse inconsistency.

not rated 59 4mo ago A tokens not measured original MIT

yara-skill

411

YARAHQ/yara-rule-skill

Skill Claude CodeCodex

Expert YARA rule authoring, review, and optimization. Use when writing new YARA rules, reviewing existing rules for quality issues, optimizing rule performance, or converting detection logic to YARA syntax. Covers rule naming conventions, string selection, condition optimization, performance tuning, and automated…

not rated 59 7mo ago A 68 tokens

preflight

412

preflightsh/preflight

Skill Claude CodeCodex

This skill should be used when the user asks to "run Preflight", "scan launch readiness", "check production readiness", "audit before deploy", "fix preflight findings", "set up preflight.yml", "wire Preflight into CI", or mentions the Preflight.sh CLI.

not rated 59 today B SkillSpector: warn 61 tokens original MIT

zettelforge

413

ThreatRecall/zettelforge

Skill Claude CodeCodex

ZettelForge v2.0.0 — Production CTI agentic memory system. Hybrid TypeDB (STIX 2.1 ontology) + LanceDB (vector search). Zero external AI dependencies: fastembed for embeddings, llama-cpp-python for LLM. 75% accuracy on CTI queries, 18% on LOCOMO. Use when agents need persistent memory, threat intel retrieval, entity…

not rated 60 +1 24d ago A SkillSpector: pass 97 tokens original MIT

ai-data-privacy

414

UnitOneAI/SecuritySkills

Skill Claude Code

Reviews AI/ML systems for data privacy and governance risks including training data privacy, PII exposure in prompts and completions, data retention policies, model memorization risks, and regulatory compliance. Auto-invoked when reviewing systems that process personal data through LLMs, train or fine-tune models on…

not rated 60 +1 2mo ago A 106 tokens original MIT

clawseccheck

415

gl0di/clawseccheck

Skill Claude CodeCodex

Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills — read-only against your OpenClaw setup, plus a bounded host-security scan; writes only its own local report/history (removable with --purge). Scores your setup…

not rated 58 1mo ago A 203 tokens original MIT

solana-scanner

416

0x-Shashi/WEB3-AUDIT-SKILLS

Skill Claude CodeCodex

Use when auditing Solana programs for security vulnerabilities, reviewing Anchor or Pinocchio/native Rust smart contracts, checking CPI safety, PDA validation, account ownership, signer verification, or Token-2022 security.

not rated 59 +1 6mo ago A 41 tokens

trustabl

417

trustabl/trustabl

Plugin Claude Code

Bundles 2 skills, 1 agent, 1 hook, 1 MCP server · 310 tokens together

Self-audit AI agent, tool, and MCP-server code for security and reliability misconfigurations with Trustabl, the agent reliability scanner for the OpenAI Agents SDK, Claude Agent SDK, Google ADK, and MCP. Ships two skills (trustabl-scan and trustabl-enrich) and a subagent (trustabl) that together form a scan → enrich…

not rated 58 +11 3d ago A tokens not measured original Apache-2.0

di-ting-audit

419

L-Serim/webauto-audit-skiils

Skill Claude CodeCodex

A web security audit system for PHP, Java, .NET, and Node.js applications. It identifies the technology used, checks code and runtime behaviour for common weaknesses, and documents fixes.

not rated 57 3mo ago A 37 tokens original Apache-2.0

dep-cve

420

timenavigatorrage/r16-voltagent-awesome-agent-skills-security

Command Claude Code

You are a senior Security & Compliance specialist. The user needs help with dep cve in the context of security audits, vulnerability management, gdpr/soc2/iso27001 compliance and incident response.

not rated 57 4mo ago A 0 tokens

privacy-scanner

421

maluta/privacy-scanner

Plugin Claude Code

Bundles 1 skill · 123 tokens together

Scan WiFi networks to detect hidden cameras and surveillance devices in rental accommodations.

not rated 57 5mo ago A tokens not measured original Apache-2.0

wrdn-gha-workflows

422

getsentry/warden-skills

Skill Claude Code needs its repo

Detects exploitable GitHub Actions workflow vulnerabilities, including pullrequesttarget pwn requests, unsafe PR checkout, expression injection in run steps and actions/github-script blocks, workflowdispatch and workflowcall input command injection, comment- and discussion-triggered commands, TOCTOU between approval…

not rated 57 16d ago A SkillSpector: warn 151 tokens original MIT

1claw

424

lxyeternal/MalSkillBench

Skill Claude CodeCodex

HSM-backed secret management for AI agents — store, retrieve, rotate, and share secrets via the 1Claw vault without exposing them in context.

not rated 57 +1 2mo ago A 35 tokens

fusion-workflows

425

eth0izzle/security-skills

Plugin Claude Code

Bundles 2 skills · 240 tokens together

Create, validate, import, execute, and export CrowdStrike Falcon Fusion SOAR workflows using natural language.

not rated 56 4mo ago A tokens not measured original MIT

selfhost-emem-guard

426

Vortx-AI/emem

Skill Claude CodeCodex needs its repo

Stand up an emem-guard verdict server, verify it against the conformance checks, and point any agent at it. Use when asked to self-host emem-guard, add a grounding gate to an agent on any model or framework, wire a checkpoint into Claude Code or Claude Enterprise or MCP, or run a signed allow/deny server for…

not rated 56 today A SkillSpector: warn 81 tokens original Apache-2.0

sc-recon

427

ersinkoc/security-check

Skill Claude CodeCodex

Codebase discovery and architecture mapping for security analysis.

not rated 56 2mo ago A SkillSpector: pass 13 tokens original MIT

code-scanner

428

solygambas/python-openai-projects

Agent Claude Code

Use this agent when you need to audit a Next.js codebase for security vulnerabilities, performance bottlenecks, code quality issues, or opportunities to refactor code into smaller components. This agent focuses on actual implemented code and does not flag missing features or unimplemented…

not rated 55 5mo ago A 383 tokens

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC teams need to scale malware analysis beyond manual sandbox…

not rated 56 +2 9d ago A SkillSpector: warn 72 tokens original MIT

mcp

430

snyk/studio-mcp

MCP server Claude CodeCodexCursor +2

Easily find and fix security issues in your applications leveraging Snyk platform capabilities. Runs locally from the snyk npm package.

not rated 55 19d ago A tokens not measured original Apache-2.0

sfz009900/kalilinuxmcp

MCP server Claude CodeCodexCursor +2

MCP server "kali-pentest-mcp-server" as configured in sfz009900/kalilinuxmcp. Runs locally from the kali-pentest-mcp-server npm package.

not rated 55 11mo ago A tokens not measured

xuansenpa1/skillrevise

Skill Claude CodeCodex

Generate structured CSV security audit reports from vulnerability data with proper filtering and formatting. This skill covers CSV schema design for security reports, using Python csv.DictWriter, severity-based filtering, and field mapping from JSON to tabular format.

not rated 55 2d ago A SkillSpector: pass 52 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: