Security

29,857 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

sub2api-admin

26

Wei-Shaw/sub2api

Skill Claude CodeCodex

Manage Sub2API admin APIs for accounts, redeem codes, groups, proxies, error passthrough rules, TLS fingerprint profiles, imports, exports, batch updates, and raw administrator API calls. Use when the user mentions Sub2API, admin API keys, account management, redeem code management, recharge codes, invitation codes…

not rated 40k +213 2d ago A 101 tokens LGPL-3.0

novuhq/novu

Command Cursor

Comprehensive checklist for conducting thorough code reviews to ensure quality, security, and maintainability.

not rated 40k +9 today A 0 tokens

zhaoxuya520/reverse-skill

Skill Claude CodeCodex

Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.

not rated 34k +2.1k changed today A 51 tokens original MIT

OWASP/CheatSheetSeries

Agent Claude Code

Duplication and placement reviewer for OWASP cheat sheet changes. Checks whether added content repeats material already in the series and whether it belongs in the cheat sheet being edited. Invoked by /review-cheatsheet-pr.

not rated 33k +11 yesterday A 52 tokens CC-BY-SA-4.0

OWASP/CheatSheetSeries

Agent Claude Code

Language and editorial reviewer for OWASP cheat sheet changes. Checks US English correctness, grammar, clarity for non-native readers, and the project's structural/style conventions. Invoked by /review-cheatsheet-pr.

not rated 33k +11 yesterday A 48 tokens CC-BY-SA-4.0

OWASP/CheatSheetSeries

Agent Claude Code

Link and source-quality auditor for OWASP cheat sheet changes. Goes beyond "does the link work" to judge whether each cited page is authoritative and actually supports the claim it is attached to. Invoked by /review-cheatsheet-pr.

not rated 33k +11 yesterday A 56 tokens CC-BY-SA-4.0

OWASP/CheatSheetSeries

Command Claude Code

Aggressively review an OWASP cheat sheet PR across security, practicality, links/sources, duplication, and language; produce a single MERGE/REQUESTCHANGES/CLOSE verdict.

not rated 33k +11 yesterday A 37 tokens CC-BY-SA-4.0

OWASP/CheatSheetSeries

Instructions file CodexOpenCode

AGENTS.md instructions for OWASP/CheatSheetSeries, covering non-negotiable rules, 1. sources must be real, read, and supportive, 3. stay in scope — one topic, one pr, one branch, 4. don't duplicate — link instead and 5. architecture over code — for general topics.

not rated 33k +11 yesterday A 1,982 tokens CC-BY-SA-4.0

OWASP/CheatSheetSeries

Instructions file

Claude Code instructions for OWASP/CheatSheetSeries, covering claude.md and for maintainers.

not rated 33k +11 yesterday A 112 tokens CC-BY-SA-4.0

lev

38

block/buzz

Agent ✓ vendor

Security reviewer — threat models, auth, injection, data exposure.

not rated 32k +340 today A 15 tokens original Apache-2.0

add-dial-tool

39

nanocoai/nanoclaw

Skill Claude CodeCodex

Give chosen NanoClaw agents a real phone number as a container tool — the dial CLI baked into the agent image plus OneCLI credential injection for api.getdial.ai, scoped per agent, so the agents you pick can send SMS, place AI voice calls, and receive verification codes from inside the sandbox. Independent of the Dial…

not rated 31k +32 today A 117 tokens original MIT

nanoclaw AGENTS.md

40

nanocoai/nanoclaw

Instructions file CodexOpenCode

AGENTS.md instructions for nanocoai/nanoclaw, a project described as: A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK.

not rated 31k +32 today A 4 tokens copy · 100% MIT

component-reviewer

41

davila7/claude-code-templates

Agent Claude Code

Expert component reviewer for Claude Code Templates. Use PROACTIVELY when adding or modifying components in cli-tool/components/ directory (agents, commands, MCPs, hooks, settings, skills, loops). Validates format, required fields, naming conventions, and security.

not rated 31k +27 today A 57 tokens original MIT

agentscope-ai/agentscope

Instructions file GitHub Copilot

Copilot instructions for agentscope-ai/agentscope, covering agentscope code review guide, 1. code quality, 2. [must] code security, 3. [must] testing & dependencies and 4. code standards.

not rated 31k +218 today A 741 tokens original Apache-2.0

picoclaw-agent

43

sipeed/picoclaw

Skill Claude CodeCodex

Configure, extend, debug, or contribute to PicoClaw itself. Use when the task is about PicoClaw CLI commands, config.json, gateway, auth, models, skills, MCP servers, cron, routing, sessions, self-evolution, built-in slash commands, or repository internals. Use PicoClaw-native workflows, terminology, paths, and…

not rated 30k +12 today A 79 tokens original MIT

review-pr

44

nrwl/nx

Skill Claude CodeCodex

Deep code review of a single open PR in nrwl/nx. Checks the PR out only inside an isolated sandbox, then runs four fixed reviewers: implementation (correctness, errors, types, performance), verification (tests, ticket grounding, comments, and docs), approach, and security. A reproduce-verifier executes a runnable…

not rated 29k +11 changed today A 118 tokens original MIT

reviewer

45

can1357/oh-my-pi

Agent

Code review specialist for quality/security analysis.

not rated 29k +464 today A 10 tokens original MIT

security-reviewer

46

can1357/oh-my-pi

Agent

Read-only security specialist for evidence-backed repository vulnerability discovery.

not rated 29k +464 today A 14 tokens original MIT

langchain-ai/deepagents

Instructions file CodexOpenCode ✓ vendor

AGENTS.md instructions for langchain-ai/deepagents, covering global development guidelines for the deep agents monorepo, corridor security analysis, development workflow, suppressing ruff rules and pr conventions.

not rated 29k +104 today A 2,268 tokens original MIT

dep-updates

48

trufflesecurity/trufflehog

Skill Claude CodeCodexCursor

Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review. Use when the user asks to update dependencies, refresh modules for security alerts, or run dependency vulnerability scans.

not rated 28k today A 51 tokens AGPL-3.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: