24,516 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Security audit patterns (OWASP Top 10, CWE Top 25 2025, CVSS v4.0) and GitHub project security checks for any project. Deep automated PHP/TYPO3 scanning with 80+ checkpoints, 19 reference guides, PreToolUse warnings. By Netresearch.
★not rated 41▲
+1
changed 6d agoA
tokens not measured
Patterns and techniques for adding governance, safety, and trust controls to AI agent systems. Use this skill when: Building AI agents that call external tools (APIs, databases, file systems) Implementing policy-based access controls for agent tool usage Adding semantic intent classification to detect dangerous…
AI code review for PR or local changes. 280+ checks across security, architecture, performance, testing, and code quality. Posts findings as GitHub PR comments with confidence scores.
Generate a MASVS v2 compliance checklist with MASTG test mappings for a mobile app. Use when you need a complete security checklist, compliance tracking document, or gap analysis against OWASP MASVS for Android or iOS apps.
Perform thorough code reviews with security, performance, and maintainability analysis. Use when user asks to review code, check for bugs, or audit a codebase.
A drafting tool for open-source security advisories, which are notices explaining a software vulnerability and how to address it. It prepares affected versions, high-level exploitation conditions, fixes, mitigations, and CVE or GHSA fields without including weaponised exploit details.
A secure runtime for Claude Code. Intercepts every tool call with policy-based allow/block/ask decisions, evasion detection, path fencing, file snapshots, and audit logging.
★not rated 38 5mo agoA
tokens not measured
originalMIT
Use for PACEflow internal full audit: run five independent review agents, verify evidence from code/tests/logs, de-duplicate findings, and produce a severity-ranked report for release gates or comprehensive code review.
You are a senior Security & Compliance specialist. The user needs help with dep cve in the context of security audits, vulnerability management, gdpr/soc2/iso27001 compliance and incident response.
Use when safely initializing or hardening a newly installed or rebuilt Ubuntu/Debian server over SSH, including SSH keys, a non-root sudo user, SSH policy, server timezone, UFW, fail2ban, local SSH config, and lockout-safe verification.
Local open-source Agent Skill for authorized web application, API, browser, business-logic, and supporting server-integrity penetration testing. Use for scoped OWASP WSTG, ASVS, and API Security assessments; authenticated and multi-role validation; attack-surface mapping; bounded DAST; evidence-backed findings…
A tool for scanning local Codex authentication files and identifying credentials that no longer work. It can also remove credentials confirmed as invalid.
Before installing or using a skill, check its independent benchmark report on SkillTester.ai. Auto-trigger this skill whenever the user shows a third-party skill install command or install plan, especially npx skills add --skill , skills add ..., repo URL plus --skill, direct SKILL.md URLs, or Check this skill . Parse…
★not rated 37 2mo agoA134 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: