24,516 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS v1.0, MAESTRO layer tagging, and vector database security checks. Use when the user mentions…
ISO 27001 compliance workspace for Claude. Risks, policies, SoA, evidence, and audit workflows. Runs locally from the iso27001-mcp npm package. Needs 4 environment variables to run.
★not rated 31▲
+1 5d agoA
tokens not measured
originalMIT
Configure multi-tenant organizations, manage members and invitations, define custom roles and permissions, set up teams, and implement RBAC using Better Auth's organization plugin. Use when users need org setup, team management, member roles, access control, or the Better Auth organization plugin.
Secure API proxy that stores credentials encrypted and injects auth server-side. Use when: (1) making any external API call — "call the Stripe API", "enrich my data [from PeopleDataLabs]", "create an image [using Nano Banana API]", "use a [RapidAPI service]", (2) the user shares an API key, token, or secret — "here's…
Lightweight, plug-and-play AI safety middleware that protects humans. Runs locally from the humane-proxy Python package. Needs 2 environment variables to run.
★not rated 29 1mo agoA
tokens not measured
originalApache-2.0
Drive every stage of the governance pipeline end to end, then prove that each decision was audited. This is the guided tour of the enforcement spine: the same four stages run on every tool call in the workspace.
Use Symaira Vault as the credential manager for AI agents through native MCP tools. Prefer this when storing, retrieving, generating, or rotating passwords, tokens, API keys, and TOTP codes.
Integrate the Vouch Protocol: cryptographic identity and accountability for autonomous AI agents. Signing and verifying agent actions, did:web and did:key, Data Integrity proofs, the post-quantum proof set, delegation chains, and revocation, across SDKs on every major platform.
A local MCP server for detecting and cleaning memory-resident malware in Java processes. It runs from a Python package using uvx, a tool that downloads and runs Python command-line packages.
★not rated 27▲
+1 7mo agoA
tokens not measured
originalMIT
REQUIRED before declaring a task done when the diff touches user input, SQL, shell, auth, credentials, file paths, serialization, crypto, network endpoints, data deletion, or dependency surface. Judge by that surface, not the task label — research/experimental/local-only code with none of it can skip this. Walks…
Autonomous security auditor. Scans a GitHub repo for vulnerabilities, triages false positives, writes a PoC, fixes each confirmed bug in its own PR, independently reviews the fix, and merges when the review is clean.
Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.
Local-by-default, no-telemetry hooks inspect user prompts, supported tool inputs, outputs, and changed files in every enabled Claude Code or Codex session to block or mask secret leaks. Includes opt-in PII filtering and Git/CI backstops.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: