Security

24,516 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

attack-tx-analysis

481

BradMoonUESTC/TxAnalyzer

Skill Claude CodeCodex

Analyze blockchain attack transactions end-to-end: pull chain-specific artifacts first (EVM: traces, contract source, opcodes, selectors; Solana: transaction/meta payloads, instructions, logs, accounts, invoked program metadata), then perform the full EVM-oriented 6-phase root cause analysis with deep trust boundary…

not rated 49 4mo ago C 130 tokens GPL-3.0

rootcx

482

RootCX/RootCX

Skill Claude CodeCodex

Build internal apps and AI agents on RootCX — the open-source platform with shared PostgreSQL, auto-generated CRUD APIs, OIDC SSO, role-based access control, audit logging, scheduled jobs, message queuing, encrypted secrets, file storage, managed deployment, and pre-built integrations. Get everything you need to ship…

not rated 48 yesterday B 76 tokens

iac-analysis

483

senaykt/iac-security-scan-skills

Skill Claude CodeCodex

Foundational repository intelligence. Maps IaC architecture, environments, exposure, and trust boundaries. Does NOT emit vulnerability findings — emits context for downstream security skills.

not rated 48 3mo ago A 34 tokens original MIT

find-cve-agent

485

ByamB4/find-cve-agent

Plugin Claude Code

Bundles 21 skills, 7 commands, 5 agents · 1,048 tokens together

CVE hunting harness for open source security research. A 5-agent team that systematically finds, validates, and reports real vulnerabilities in open source packages.

not rated 48 +1 5mo ago A tokens not measured original Apache-2.0

workflow-creator

486

accuknox/agentZ

Skill Claude CodeCodex

Create or update reusable workflow DAGs. Use when authoring or revising saved workflows. Must be mandatorily used before calling the createworkflow tool.

not rated 48 +4 yesterday A SkillSpector: pass 36 tokens original Apache-2.0

dep-cve

487

TeamArtisanThrive/r03-anthropics-skills-security

Command Claude Code

You are a senior Security & Compliance specialist. The user needs help with dep cve in the context of security audits, vulnerability management, gdpr/soc2/iso27001 compliance and incident response.

not rated 47 +1 4mo ago A 0 tokens

api

488

panther-labs/mcp-panther

Cursor rule Cursor

Write detections, investigate alerts, and query logs from your favorite AI agents.

not rated 47 3mo ago A 91 tokens original Apache-2.0

security-checker

489

devlyai/AgentCheck

Agent Claude Code

Part of the agentcheck package for automated code review. Analyzes security implications of code changes. Runs when user finishes commit work or requests agentic review. Relevant after any changes involving authentication, data handling, or external APIs. Focuses on new security risks introduced by modifications.…

not rated 47 1y ago A 76 tokens original MIT

aws-samples/sample-agent-skills-for-builders

Skill Claude CodeCodex ✓ vendor

Walk a client through a Responsible AI assessment questionnaire and score their answers 0-5 across eight RAI dimensions (Governance, Privacy & Security, Safety, Veracity & Robustness, Controllability, Fairness, Explainability, Transparency). Use when a user asks to run a Responsible AI assessment, RAI scorecard…

not rated 47 13d ago A SkillSpector: pass 118 tokens original Apache-2.0

deny-ctg

493

sayanarijit/cottage

Cursor rule Cursor

Deny ctg/ctgx command execution and secret file access.

not rated 47 3d ago A 207 tokens original Apache-2.0

instancez

494

instancez/instancez

Skill Claude CodeCodex

Use when building, changing, or deploying an instancez backend - editing instancez.yaml (tables, RLS, auth, storage, rpc, functions), running the inz CLI, or debugging why a query is denied. instancez is a single-binary Supabase-compatible backend defined by one YAML file.

not rated 47 3d ago C 64 tokens original Apache-2.0

workos

497

workos/skills

Plugin Claude Code

Bundles 2 skills · 295 tokens together

WorkOS integration skills for AuthKit, SSO, Directory Sync, RBAC, Vault, Audit Logs, migrations, and API references.

not rated 46 today A tokens not measured original MIT

armorclaude

498

armoriq/armorClaude

Plugin Claude Code

Bundles 1 command, 8 hooks, 1 MCP server · 0 tokens together

ArmorIQ intent-based security enforcement for Claude Code: policy-based tool access control, intent verification, CSRG cryptographic proofs, and audit logging.

not rated 46 2d ago A tokens not measured original MIT

web-vuln-audit

499

zhiyuwang720-dev/CodeAuditSkill

Skill Claude CodeCodex

A source-code security audit tool for web projects written in Go, Java, Python, PHP, or JavaScript. It checks for high- and medium-risk flaws and writes reports in the audited project’s reports/ folder.

not rated 46 +1 2mo ago A 172 tokens original MIT

green-claude

500

Institut-du-Numerique-Responsable/green-claude

Plugin Claude Code

Bundles 1 skill · 125 tokens together

Éco-conception de services numériques (RGESN 2024 / GR491 / Green Software Foundation) appliquée pendant que Claude Code écrit ou revoit du code, avec un audit déterministe et des pratiques d'usage responsable maintenues par le projet. Présentation : https://institut-du-numerique-responsable.github.io/green-claude/.

not rated 46 +1 changed 3d ago A tokens not measured original MIT

agent-supply-chain

501

drvoss/everything-copilot-cli

Skill Claude CodeCodex

Use when auditing an AI agent plugin, skill bundle, or MCP tool package for supply chain integrity — generate deterministic SHA-256 manifests, detect modified or untracked files, flag unpinned dependencies, and gate promotion to production.

not rated 46 +1 13d ago A SkillSpector: warn 51 tokens original MIT

malware-analysis

502

gl0bal01/malware-analysis-claude-skills

Plugin Claude Code

Bundles 6 skills · 453 tokens together

Agentic malware analysis: Claude runs the static tooling, parses exported VM evidence, writes and tests detection rules, and drafts the report across triage, dynamic analysis, specialized file analysis, detection engineering, and reporting.

not rated 46 +1 4d ago A tokens not measured original MIT

kali-tools

503

zebbern/zebbern-kali-mcp

MCP server Claude CodeCodexCursor +2

Capability-aware MCP client for a Docker-hosted Kali Linux tools API. Runs locally from the zebbern-kali-mcp Python package. Needs 1 environment variable to run.

not rated 46 +1 4d ago A Socket: warn tokens not measured original MIT

gplay-preflight

504

tamtom/gplay-cli-skills

Skill Claude CodeCodex needs its repo

Offline compliance and hygiene scanning of an AAB or APK with gplay preflight — manifest flags, restricted permissions, 64-bit and 16 KB page alignment, listing assets, secrets, billing, privacy SDKs, target API floor, and size. Use before uploading a build, as a CI gate, or when diagnosing a Play rejection. Runs…

not rated 45 1mo ago A SkillSpector: pass 83 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: