Security

24,516 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

avanan

553

Servosity/msp-skills

Plugin Claude Code

Bundles 1 skill · 142 tokens together

Every Avanan (Check Point Harmony Email and Collaboration) API operation, plus shift-start triage, phishing campaign clustering, single-message lifecycle timelines, one exception lookup across all seven security engines, and cross-tenant MSP fleet rollups that a stateless API mirror cannot answer in a single call.

not rated 38 +3 changed 6d ago A tokens not measured

nyxid

555

ChronoAIProject/NyxID

Plugin Claude Code

Bundles 16 skills, 1 plugin · 1,929 tokens together

Brokers credentials for downstream services so agents never see raw keys or tokens, and bundles the synchronized Aevatar platform skill family. Operates through the NyxID CLI or authenticated Web API.

not rated 36 today A tokens not measured original Apache-2.0

claude-pentest-skills

557

frendysanusi/claude-pentest-skills

Skill Claude CodeCodex

Structured web application penetration testing with OWASP methodology, curated payload references, 6-gate validation, and professional report generation.

not rated 37 +1 4mo ago A 31 tokens

vorim

558

Vorim-AI-Labs/vorim-openclaw-skill

Skill Claude CodeCodex

AI agent identity, permissions, trust scores, and audit trails via Vorim AI. Gives your OpenClaw agent a cryptographic identity so every action is verified, permissioned, and logged.

not rated 35 2mo ago A 42 tokens original MIT

malicious

559

AIS2Lab/MCPSecBench

MCP server Claude CodeCodexCursor +2

One of 4 in claude_desktop_config.json

MCP server "malicious" as configured in AIS2Lab/MCPSecBench. Launched with uv --directory /usr/games/mcp/MCPSecCode/mcpbench run maliciousadd.py.

not rated 35 6mo ago A tokens not measured original MIT

pyghidra-lite

560

johnzfitch/pyghidra-lite

MCP server Claude CodeCodexCursor +2

Lightweight MCP server for Ghidra-based reverse engineering with iOS, Linux, and game file support. Runs locally from the pyghidra-lite Python package. Needs 1 environment variable to run.

not rated 35 2mo ago A tokens not measured original MIT

securebydesign

561

Yems221/securebydesign-llmskill

Skill Claude CodeCodex

Enforce security-by-design in every line of code, architecture decision, and system recommendation. Activate whenever the user is: building an app, writing code, designing an API, setting up infrastructure, integrating an LLM, reviewing code, planning a deployment, or asking about authentication, data storage, or…

not rated 35 6mo ago B 85 tokens original MIT

omni-permissions

562

exploreomni/omni-agent-skills

Cursor rule Cursor

Omni access & roles — determine a caller's capabilities from whoami before deciding where model or content changes live (branch vs workbook), and assign model roles correctly. Apply when reasoning about permissions, branching, or where a new field/metric should be modeled.

not rated 36 +1 changed 6d ago A 52 tokens

04-security

563

SystemTce/dify-skills

Skill Claude CodeCodex

A security and deployment guide for the Dify platform, an application for building AI-powered services.

not rated 35 6mo ago A 36 tokens

fortigate-mcp-server

564

alpadalar/fortigate-mcp-server

MCP server Claude CodeCodexCursor +2

MCP server "fortigate-mcp-server" as configured in alpadalar/fortigate-mcp-server. Runs locally from the fortigate-mcp-server Python package.

not rated 34 1mo ago A tokens not measured original MIT

firewalla-mcp-server

566

amittell/firewalla-mcp-server

MCP server Claude CodeCodexCursor +2

Model Context Protocol (MCP) server for Firewalla MSP API - Provides real-time network monitoring, security analysis, and firewall management through 28 specialized tools compatible with any MCP client. Runs locally from the firewalla-mcp-server npm package.

not rated 34 +1 14d ago A tokens not measured original MIT

bugbountyrules

567

sanjarbiy/bugbountyrules

Skill Claude CodeCodex

Use for ANY bug bounty, penetration test, or web/API/mobile security assessment: recon, testing endpoints, analyzing Burp traffic or any bug-bounty platform's MCP (HackerOne, Intigriti, Bugcrowd, YesWeHack, Immunefi), reviewing APKs, bypassing a WAF, enforcing scope, hunting a specific vuln class, validating findings…

not rated 34 22d ago B 220 tokens original MIT

varlock

568

wrsmith108/varlock-claude-skill

Plugin Claude Code

Bundles 1 skill · 73 tokens together

Secure environment variable management with Varlock for secrets, API keys, credentials, and sensitive configuration.

not rated 33 6mo ago A tokens not measured original MIT

security

569

gc-victor/supersimple

Skill Claude CodeCodex

Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.

not rated 33 4mo ago A 45 tokens original MIT

skarn-audit

570

skarn-security/agent-guard

Skill Claude CodeCodex

Audit this machine's AI coding sessions and assistant configs with skarn. Use when the user says scan this with skarn, run skarn, or skarn audit; asks whether a secret leaked into an AI coding session; wants an assistant config (hooks, MCP servers, permissions, plugins) vetted; or asks whether a Claude Code, Codex…

not rated 33 today A SkillSpector: pass 120 tokens original MIT

contrastapi

571

UPinar/contrastapi

Plugin Cursor

Bundles 1 MCP server

47 security research tools over remote MCP — CVE + EPSS/KEV, MITRE CWE catalog + KEV detail, domain audit + DNS/SSL/WHOIS/subdomain enum + WAF detect, IP threat intel + cloud/Tor/FireHOL classification, IOC enrichment (ThreatFox/Feodo/URLhaus), email/phone/username OSINT, code security checks, MITRE ATLAS AI/ML attack.

not rated 33 today A tokens not measured original MIT

mcp-evernote

572

verygoodplugins/mcp-evernote

MCP server Claude CodeCodexCursor +2

Evernote note management with OAuth and ENML conversion. Runs locally from the @verygoodplugins/mcp-evernote npm package.

not rated 32 6d ago A tokens not measured

hs

573

frmoretto/hardstop

Plugin Claude Code

Bundles 1 skill, 6 commands, 1 hook · 193 tokens together

Pre-execution safety layer that blocks dangerous shell commands and credential file reads using pattern matching + LLM analysis. Fail-closed design.

not rated 32 4mo ago A tokens not measured

evil-mcp-server

574

promptfoo/evil-mcp-server

MCP server Claude CodeCodexCursor +2

MCP server that simulates malicious behaviors for security testing. Runs locally from the @promptfoo/evil-mcp-server npm package.

not rated 32 +1 today A tokens not measured original MIT

swift-security-expert

575

ivan-magda/swift-security-skill

Plugin Claude Code

Bundles 1 skill · 122 tokens together

Expert guidance for Apple Keychain Services, biometric authentication, CryptoKit cryptography, credential lifecycle management, certificate trust, and OWASP compliance mapping.

not rated 32 +1 2mo ago A tokens not measured original MIT

joneqian/claude-skills-suite

Agent Claude Code

MySQL database specialist for query optimization, schema design, security, and performance. Use PROACTIVELY when writing SQL, creating migrations, designing schemas, or troubleshooting database performance.

not rated 32 7mo ago A 42 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: