Security

24,516 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

agent-bom

577

msaad00/agent-bom

Skill Codex

Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS v1.0, MAESTRO layer tagging, and vector database security checks. Use when the user mentions…

not rated 31 changed yesterday A SkillSpector: warn 107 tokens original Apache-2.0

pixee-cli

578

pixee/pixee-cli

Plugin Claude Code

Bundles 12 skills · 584 tokens together

Skills for using the Pixee CLI: authentication, scans, workflows, repositories, findings, and API access.

not rated 31 today A tokens not measured

iso27001-mcp

579

Sushegaad/MCP-Server-for-ISO27001

MCP server Claude CodeCodexCursor +2

ISO 27001 compliance workspace for Claude. Risks, policies, SoA, evidence, and audit workflows. Runs locally from the iso27001-mcp npm package. Needs 4 environment variables to run.

not rated 31 +1 5d ago A tokens not measured original MIT

krivoox/agent-stack-template

Skill Claude CodeCodex

Configure multi-tenant organizations, manage members and invitations, define custom roles and permissions, set up teams, and implement RBAC using Better Auth's organization plugin. Use when users need org setup, team management, member roles, access control, or the Better Auth organization plugin.

not rated 31 20d ago A SkillSpector: warn 61 tokens original MIT

janee

581

rsdouglas/janee

Skill Claude CodeCodex

Secure API proxy that stores credentials encrypted and injects auth server-side. Use when: (1) making any external API call — "call the Stripe API", "enrich my data [from PeopleDataLabs]", "create an image [using Nano Banana API]", "use a [RapidAPI service]", (2) the user shares an API key, token, or secret — "here's…

not rated 30 5mo ago A 176 tokens original MIT

ya-frida-mcp

582

1shin-7/ya-frida-mcp

MCP server Claude CodeCodexCursor +2

Yet Another Frida MCP Server - Full-featured MCP server for Frida dynamic instrumentation. Runs locally from the ya-frida-mcp Python package.

not rated 31 2d ago A tokens not measured

gnt-check-action

583

gnt-ai/gnt

Skill Claude CodeCodex

Check a side-effectful action against this organization's approved gnt rules before taking it, and stop on a blocked or needshuman verdict.

not rated 30 +1 2d ago A SkillSpector: pass 33 tokens original Apache-2.0

pentest

584

humaidhahm/opencode-pentester

Plugin Claude Code

Bundles 1 skill, 12 agents · 464 tokens together

Full penetration testing framework - 69 attack categories across 16 domains covering OWASP, injection, authentication, cloud, and more.

not rated 30 +5 today A tokens not measured

routers

585

Scopeo/draftnrun

Cursor rule Cursor

WebSocket endpoints (runstreamrouter.py, graphdisplaystreamrouter.py, qastreamrouter.py) follow a shared pattern.

not rated 30 6d ago A 0 tokens original Apache-2.0

proteus

586

Vyntra-Research/Proteus

Skill OpenCode

Coordinate Proteus continuous vulnerability research with memory, campaigns, delegation, validation gates, and report-grade discipline.

not rated 29 changed 2d ago A 24 tokens GPL-3.0

humane-proxy

587

Vishisht16/Humane-Proxy

MCP server Claude CodeCodexCursor +2

Lightweight, plug-and-play AI safety middleware that protects humans. Runs locally from the humane-proxy Python package. Needs 2 environment variables to run.

not rated 29 1mo ago A tokens not measured original Apache-2.0

systempromptio/systemprompt-template

Skill Claude CodeCodex

Drive every stage of the governance pipeline end to end, then prove that each decision was audited. This is the guided tour of the enforcement spine: the same four stages run on every tool call in the workspace.

not rated 28 today A 0 tokens

Infisical/ai-skills

Plugin Claude Code

Bundles 1 skill · 212 tokens together

Infisical access control and governance — roles and custom permissions, granular secret actions, ABAC, temporary access, approval workflows, and audit log streaming.

not rated 28 14d ago A tokens not measured original MIT

symvault

591

danieljustus/symaira-vault

Skill Claude CodeCodex

Use Symaira Vault as the credential manager for AI agents through native MCP tools. Prefer this when storing, retrieving, generating, or rotating passwords, tokens, API keys, and TOTP codes.

not rated 28 +1 today A SkillSpector: warn 43 tokens original Apache-2.0

mcp-forensic-toolkit

592

axdithyaxo/mcp-forensic-toolkit

MCP server Claude CodeCodexCursor +2

MCP server "mcp-forensic-toolkit" as configured in axdithyaxo/mcp-forensic-toolkit. Runs locally from the mcp-forensic-toolkit Python package.

not rated 27 1y ago A tokens not measured

vouch-protocol

593

vouch-protocol/vouch

Plugin Claude Code

Bundles 1 skill · 0 tokens together

Integrate the Vouch Protocol: cryptographic identity and accountability for autonomous AI agents. Signing and verifying agent actions, did:web and did:key, Data Integrity proofs, the post-quantum proof set, delegation chains, and revocation, across SDKs on every major platform.

not rated 27 yesterday A tokens not measured

memory-shell-mcp

595

RuoJi6/memory-shell-mcp

MCP server Claude CodeCodexCursor +2

A local MCP server for detecting and cleaning memory-resident malware in Java processes. It runs from a Python package using uvx, a tool that downloads and runs Python command-line packages.

not rated 27 +1 7mo ago A tokens not measured original MIT

rafter-code-review

596

Raftersecurity/rafter-cli

Skill Claude Code

REQUIRED before declaring a task done when the diff touches user input, SQL, shell, auth, credentials, file paths, serialization, crypto, network endpoints, data deletion, or dependency surface. Judge by that surface, not the task label — research/experimental/local-only code with none of it can skip this. Walks…

not rated 27 yesterday A SkillSpector: pass 123 tokens original MIT

omni-lpr

597

habedi/omni-lpr

MCP server Claude CodeCodexCursor +2

An MCP server for automatic license plate recognition. Remote server at {baseurl}.

not rated 26 2mo ago A tokens not measured original MIT

auto-audit

598

wrxck/auto-audit

Plugin Claude Code

Bundles 9 skills, 4 agents, 1 hook · 820 tokens together

Autonomous security auditor. Scans a GitHub repo for vulnerabilities, triages false positives, writes a PoC, fixes each confirmed bug in its own PR, independently reviews the fix, and merges when the review is clean.

not rated 26 28d ago A tokens not measured

security-scan

599

x-cmd/skill

Skill Claude Code

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

not rated 26 2mo ago A 48 tokens original Apache-2.0

agent-guard

600

JeongJaeSoon/agent-guard

Plugin Claude Code

Bundles 2 skills, 2 commands, 5 hooks · 208 tokens together

Local-by-default, no-telemetry hooks inspect user prompts, supported tool inputs, outputs, and changed files in every enabled Claude Code or Codex session to block or mask secret leaks. Includes opt-in PII filtering and Git/CI backstops.

not rated 26 +1 changed 2d ago A tokens not measured copy · 86% MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: