24,516 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Analyze blockchain attack transactions end-to-end: pull chain-specific artifacts first (EVM: traces, contract source, opcodes, selectors; Solana: transaction/meta payloads, instructions, logs, accounts, invoked program metadata), then perform the full EVM-oriented 6-phase root cause analysis with deep trust boundary…
Build internal apps and AI agents on RootCX — the open-source platform with shared PostgreSQL, auto-generated CRUD APIs, OIDC SSO, role-based access control, audit logging, scheduled jobs, message queuing, encrypted secrets, file storage, managed deployment, and pre-built integrations. Get everything you need to ship…
CVE hunting harness for open source security research. A 5-agent team that systematically finds, validates, and reports real vulnerabilities in open source packages.
★not rated 48▲
+1 5mo agoA
tokens not measured
originalApache-2.0
Create or update reusable workflow DAGs. Use when authoring or revising saved workflows. Must be mandatorily used before calling the createworkflow tool.
You are a senior Security & Compliance specialist. The user needs help with dep cve in the context of security audits, vulnerability management, gdpr/soc2/iso27001 compliance and incident response.
Part of the agentcheck package for automated code review. Analyzes security implications of code changes. Runs when user finishes commit work or requests agentic review. Relevant after any changes involving authentication, data handling, or external APIs. Focuses on new security risks introduced by modifications.…
Walk a client through a Responsible AI assessment questionnaire and score their answers 0-5 across eight RAI dimensions (Governance, Privacy & Security, Safety, Veracity & Robustness, Controllability, Fairness, Explainability, Transparency). Use when a user asks to run a Responsible AI assessment, RAI scorecard…
Use when building, changing, or deploying an instancez backend - editing instancez.yaml (tables, RLS, auth, storage, rpc, functions), running the inz CLI, or debugging why a query is denied. instancez is a single-binary Supabase-compatible backend defined by one YAML file.
You are a senior Security & Compliance specialist. The user needs help with dep cve in the context of security audits, vulnerability management, gdpr/soc2/iso27001 compliance and incident response.
A source-code security audit tool for web projects written in Go, Java, Python, PHP, or JavaScript. It checks for high- and medium-risk flaws and writes reports in the audited project’s reports/ folder.
Éco-conception de services numériques (RGESN 2024 / GR491 / Green Software Foundation) appliquée pendant que Claude Code écrit ou revoit du code, avec un audit déterministe et des pratiques d'usage responsable maintenues par le projet. Présentation : https://institut-du-numerique-responsable.github.io/green-claude/.
★not rated 46▲
+1
changed 3d agoA
tokens not measured
originalMIT
Use when auditing an AI agent plugin, skill bundle, or MCP tool package for supply chain integrity — generate deterministic SHA-256 manifests, detect modified or untracked files, flag unpinned dependencies, and gate promotion to production.
Agentic malware analysis: Claude runs the static tooling, parses exported VM evidence, writes and tests detection rules, and drafts the report across triage, dynamic analysis, specialized file analysis, detection engineering, and reporting.
★not rated 46▲
+1 4d agoA
tokens not measured
originalMIT
Capability-aware MCP client for a Docker-hosted Kali Linux tools API. Runs locally from the zebbern-kali-mcp Python package. Needs 1 environment variable to run.
Offline compliance and hygiene scanning of an AAB or APK with gplay preflight — manifest flags, restricted permissions, 64-bit and 16 KB page alignment, listing assets, secrets, billing, privacy SDKs, target API floor, and size. Use before uploading a build, as a CI gate, or when diagnosing a Play rejection. Runs…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: