Security

24,516 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

dep-cve

505

RestraintSound/r19-iannuttall-claude-agents-security

Command Claude Code

You are a senior Security & Compliance specialist. The user needs help with dep cve in the context of security audits, vulnerability management, gdpr/soc2/iso27001 compliance and incident response.

not rated 45 4mo ago A 0 tokens

zmustafa/AzureSupportAgent

Skill Claude CodeCodex

Explain effective access, privilege, inheritance, group paths, ownership paths, PIM, deny assignments, and safe revocation candidates.

not rated 45 4d ago A SkillSpector: pass 33 tokens original MIT

cursor

507

Synvoya/codeinspectus

Cursor rule Cursor

CodeInspectus — scan, surface findings, fix only with user consent.

not rated 45 +1 2d ago A 868 tokens original Apache-2.0

gmh5225/awesome-ai-security

Skill Claude Code

Guide for understanding and contributing to the awesome-ai-security curated resource list. Use this skill when adding resources, organizing categories, or maintaining README.md consistency (no duplicates).

not rated 45 +1 yesterday A SkillSpector: pass 39 tokens original MIT

burn-after-login

509

pbakaus/burn-after-login

Skill Claude CodeCodex

Create dev-only auth shortcuts so AI browser automation agents can authenticate instantly. Analyzes your auth system, creates guarded endpoints/scripts, detects your browser automation tools, and updates agent instructions. Use when setting up dev authentication for browser automation, or when agents struggle with…

not rated 45 +1 6mo ago A 66 tokens original MIT

apk-recon

510

abisheikM1/Tribunal

Skill Claude CodeCodex

First-pass recon net for an Android APK — hunt secrets, insecure storage, weak crypto, broken TLS, and risky configuration in one broad sweep. Fires on manifest signals (android:debuggable="true", android:allowBackup="true", android:usesCleartextTraffic="true", a networkSecurityConfig that trusts user CAs or permits…

not rated 45 +2 1mo ago A 319 tokens

awareness-pack

512

WYRE-AI/msp-claude-plugins

Plugin Claude Code

Bundles 3 skills, 3 commands, 3 agents · 537 tokens together

Cross-vendor security awareness operations — training completion tracking, phishing simulation results, and per-user risk scoring across whatever security-awareness training tools you have connected. Complements secops-pack's technical threat response with the human-layer prevention side.

not rated 45 +1 7d ago A tokens not measured original Apache-2.0

huawei-agent-rules

513

huaweicloud/huaweicloud-devkit

Cursor rule Cursor

Cursor rule "huawei-agent-rules" from huaweicloud/huaweicloud-devkit, covering huaweicloud devkit — agent rules, core principles, secret safety, iam security and network security.

not rated 45 +25 yesterday A 918 tokens original Apache-2.0

review

514

bezael/ai-workflow-kit

Skill Claude CodeCodex

Review code with real engineering criteria — logic bugs, security vulnerabilities, and technical debt. Use when the user says /review, asks for a code review, or wants the branch diff checked before opening a PR.

not rated 44 10d ago A 44 tokens

levelsio-vps-deploy

515

Avanderheyde/levelsio-vps-setup-skill

Skill Claude CodeCodex

Set up a web app on a single cheap, hardened VPS the "levels.io" way — one Hetzner/DigitalOcean box running Next.js (or any Node app) on SQLite + Caddy (auto-HTTPS) + systemd, secured with Tailscale, put behind a Cloudflare domain, and set up to charge money with Stripe. The whole "idea → app that makes money on a…

not rated 44 +1 1mo ago D 356 tokens original MIT

killvxk/cybersecurity-skills-zh

Plugin Claude Code

Bundles 58 skills · 4,355 tokens together

A Chinese-language collection of more than 734 cybersecurity skills covering areas such as web security, penetration testing, digital forensics, threat intelligence, cloud security, and malware analysis.

not rated 44 4mo ago A tokens not measured original Apache-2.0

agent-passport-system

517

aeoess/agent-passport-system

Skill Claude CodeCodex

Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when…

not rated 44 +2 changed yesterday A SkillSpector: warn 329 tokens original Apache-2.0

vulnerability-writeup

518

bex-co/bex-security

Skill Codex

Turn vulnerability notes, disclosure reports, PoCs, source code, or Codex Security findings into self-contained, sceptically validated, natural-sounding vulnerability reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional.

not rated 44 +1 2d ago A SkillSpector: warn 54 tokens original Apache-2.0

mythos-agent

519

mythos-agent/mythos-agent

MCP server Claude CodeCodexCursor +2

Open-source AI security agent: SAST, DAST, and policy-as-code over MCP. Runs locally from the mythos-agent npm package.

not rated 43 3mo ago A tokens not measured original MIT

review-advanced

520

DGouron/review-flow

Skill Claude CodeCodex

Rigorous sequential-audit code review with a dedicated security block and cited pedagogical lessons. Customize for your project.

not rated 43 +1 2d ago A SkillSpector: warn 27 tokens original MIT

clawmoat

521

darfaz/clawmoat

Skill Claude CodeCodex

Real-time AI agent security scanner. Detects prompt injection, jailbreak attempts, credential/secret leaks, PII exposure, and dangerous tool calls. Activate when: (1) scanning inbound messages or tool outputs for prompt injection, (2) checking outbound content for credential leaks or PII, (3) auditing agent session…

not rated 43 23d ago A SkillSpector: warn 107 tokens original MIT

Skills-Security-Check

522

Toolsai/Skills-Security-Check

Skill Claude CodeCodex

A security checker for coding-agent skills that uses fixed checks and AI review to find possible vulnerabilities and threats.

not rated 43 7mo ago A 73 tokens

access-control-review

523

Robotti-io/copilot-security-instructions

Skill Claude CodeCodex

Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.

not rated 42 3mo ago A 27 tokens original Apache-2.0

vulnmcp

525

vulnerability-lookup/VulnMCP

MCP server Claude CodeCodexCursor +2

MCP server "vulnmcp" as configured in vulnerability-lookup/VulnMCP. Runs locally from the vulnmcp Python package.

not rated 42 10d ago A tokens not measured AGPL-3.0

nuguard

526

NuGuardAI/nuguard

Plugin Claude Code

Bundles 2 skills, 1 agent, 1 plugin · 591 tokens together

AI application security for Claude — generate an AI Bill of Materials (AI-SBOM), run static analysis, behavioral validation, and adversarial red-team testing for AI agents and LLM-powered applications.

not rated 42 changed 4d ago A tokens not measured

ludus-mcp

527

NocteDefensor/LudusMCP

MCP server Claude CodeCodexCursor +2

MCP server for managing Ludus cybersecurity training environments through natural language commands. Runs locally from the ludus-mcp npm package.

not rated 41 4mo ago A tokens not measured GPL-3.0

auth

528

himself65/auth-spec

Plugin Claude Code

Bundles 2 skills · 93 tokens together

Auth skills for Claude Code — scaffold hand-rolled auth endpoints and audit auth code against security best practices.

not rated 41 18d ago A tokens not measured

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: