Security

24,538 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

AynOps

625

AynOps/AynOps

MCP server Claude CodeCodexCursor +2

A Model Context Protocol server that gives AI Clients real-time cybersecurity reconnaissance capabilities — WHOIS, DNS enumeration, port scanning, SSL inspection, CVE lookup, IP reputation, ASN lookup and more. Runs locally from the AynOps Python package. Needs 2 environment variables to run.

not rated 25 +1 yesterday A tokens not measured original MIT

security-review

626

JamalMohafil/claude-skills

Skill Claude CodeCodex

Run a security review of code changes exactly like Claude Code's /security-review command — but in ANY AI coding agent (Claude Code, Cursor, Codex, Windsurf, Gemini CLI, Cline…). Reviews the pending branch diff (or a specific PR, uncommitted changes, or a whole file/folder) for HIGH-CONFIDENCE, actually-exploitable…

not rated 25 +2 3d ago A SkillSpector: warn 211 tokens original MIT

shannot

627

corv89/shannot

Skill Claude CodeCodex

Run diagnostic scripts in sandbox with human approval (MCP tool).

not rated 25 5mo ago A 16 tokens original Apache-2.0 archived

gcp-credentials-audit

628

shivamsriva31093/gcp-ironclad

Skill Claude CodeCodex

Use to inventory and risk-classify every API key and user-managed service-account key across all accessible GCP projects. READ-ONLY — does not mutate cloud state. Use standalone, or as Phase 1a of the gcp-ironclad driver.

not rated 24 1mo ago A SkillSpector: pass 61 tokens original MIT

vuln-scout

629

allsmog/vuln-scout

Plugin Claude Code

Bundles 32 skills, 15 commands, 9 agents · 2,759 tokens together

Claude Code plugin for whitebox security review. Stable: deterministic offline quick scan, shared findings.json with stable keys and hotspot-aware findings, SARIF/Markdown/HTML/bundle reports, suppressions, CI fail-on gate, Kuzushi parity. Beta: deep profile with Joern/CodeQL/Slither/Trivy/Checkov when installed.…

not rated 24 2mo ago A tokens not measured original MIT

authy

630

eric8810/authy

Skill Claude CodeCodex

Inject secrets into subprocesses via environment variables. You never see secret values — authy run injects them directly. Use for any command that needs API keys, credentials, or tokens.

not rated 24 6mo ago A 40 tokens original MIT

run402

631

kychee-com/run402

Skill Claude CodeCodex

Provision Postgres + REST API + auth + content-addressed storage + serverless functions + email — paid with x402 USDC on Base. Prototype tier is free on testnet. Use when the user asks to build a webapp, deploy a site, create a database, generate images, or mentions Run402.

not rated 24 changed today A 67 tokens original MIT

pownie

632

d0gesec/pownie

Plugin Claude Code

Bundles 4 skills · 131 tokens together

Offensive security toolkit for Claude Code — Neo4j intel graph, strategic compaction, multi-agent orchestration, and post-engagement debriefs.

not rated 24 5mo ago A tokens not measured original MIT

flutter-apk-security

633

anasfik/FlutterGuard

Skill Claude CodeCodex

Review Flutter Android APK/AAB release artifacts for manifest, permission, cleartext traffic, exported component, embedded secret, signing, size, WebView, deep link, and third-party service risks.

not rated 24 17d ago A 44 tokens

Promastergame/tinyapk-lab

Skill Claude CodeCodex

Run R8/ProGuard on Android APK without Gradle — shrink, obfuscate and minify DEX using R8 that's already inside d8.jar.

not rated 24 1mo ago A SkillSpector: warn 41 tokens original MIT

santosomar/ethical-hacking-agent-skills

Skill Claude Code

Creates Nuclei YAML templates for vulnerability detection across HTTP, DNS, TCP, SSL, and other protocols. Use when converting a confirmed vulnerability, misconfiguration, or exposure into a reusable automated check — for example, turning a manual finding into a detection rule, writing a CVE check, or codifying a…

not rated 24 4mo ago A 73 tokens original Apache-2.0

slopsec

636

lachydotmcg/slopsec

Plugin Claude Code

Bundles 1 skill · 128 tokens together

Security audit and hardening for vibe-coded SaaS apps. Walks the 50 most common ways AI-generated apps get owned and produces a prioritized fix list.

not rated 24 +1 1mo ago A tokens not measured original MIT

adacore

637

AdaCore/skills

Plugin Claude Code

Bundles 5 skills · 419 tokens together

AdaCore agent skills for Ada and SPARK development: Alire (package management), GNATprove (SPARK formal verification), GNATfuzz (coverage-guided fuzzing), GNATtest (unit testing), and GNATdoc (documentation generation).

not rated 24 +1 1mo ago A tokens not measured original Apache-2.0

hidden-admin-auth

638

bishopZ/2026-Boilerplate

Skill Claude CodeCodex

Configure the private route as a hidden admin utility. Moves credentials to env vars; operator updates .env using .envTemplate instructions. No credentials passed to the skill.

not rated 24 1mo ago A 37 tokens original MIT

elastic/example-mcp-app-security

Skill Claude CodeCodex ✓ vendor

Triage Elastic Security Attack Discovery findings — fetch correlated attack narratives, assess confidence with entity risk and rule frequency signals, and present an interactive triage dashboard for approval, case creation, and acknowledgment. Use when triaging attack discoveries, reviewing correlated attacks…

not rated 24 yesterday A 114 tokens

sentinel-ai

640

MaxwellCalkin/sentinel-ai

Plugin Claude Code

Bundles 1 skill, 5 commands, 1 MCP server · 52 tokens together

Real-time safety scanning for LLM interactions. Detects prompt injection, PII leaks, harmful content, toxicity, obfuscation, secrets, and dangerous tool calls — 600-case benchmark at 100% accuracy with sub-millisecond latency.

not rated 24 +2 6mo ago A tokens not measured original Apache-2.0

prism-scanner

641

aidongise-cell/prism-scanner

Skill Claude Code

Security scanner for AI Agent skills, plugins, and MCP servers. Use when: user asks to scan a skill, check if a plugin is safe, vet an MCP server, review skill security, detect malicious code, supply chain safety, or says 'is this safe to install', 'scan this skill', 'check this MCP server', 'security scan'…

not rated 24 +4 5mo ago A 117 tokens original Apache-2.0

galyarderlabs/galyarder-framework

Cursor rule Cursor

AI governance audit using ISO 42001 standard. Ensures AI systems are developed and deployed responsibly with risk management, ethics, security, transparency, and compliance best practices.

not rated 24 +2 1mo ago A 34 tokens original MIT

Veridise/audithub-skills

Skill Codex

Coordinate full or multi-stage AuditHub OrCa fuzzing campaigns for Solidity projects. Use when a user asks to run an autonomous OrCa campaign, plan and execute setup/tuning/spec/long-run loops, resume an OrCa campaign, or coordinate target selection, deployment setup, smoke runs, callmetrics.json analysis, tuning, [V]…

not rated 23 22d ago A 89 tokens

code-security-review

644

ez-lbz/claude-code-security-skills

Skill Claude CodeCodex

Scans source code for security vulnerabilities — injection flaws, authentication bypasses, hardcoded secrets, XSS, and more — then filters false positives and ranks findings by severity and confidence. Supports all programming languages. Uses a three-phase audit-filter-report workflow with customizable scan categories…

not rated 23 4mo ago A 92 tokens

dcp-citizenship

645

dcp-ai-protocol/dcp-ai

Skill Claude CodeCodex

Digital Citizenship Protocol — identity, intent declaration, and audit trail for AI agents.

not rated 23 1mo ago A 22 tokens original Apache-2.0

depalmar/ai-dfir-toolkit

Skill Claude CodeCodex needs its repo

Research, author, and validate AI agent artifact catalog entries documenting the forensic artifacts AI agents leave on endpoints - install paths, config and credential files, MCP server configs, listening ports, process trees, registry keys, and the Windows event log records that prove a tool ran. Use this skill…

not rated 23 19d ago A SkillSpector: pass 197 tokens original Apache-2.0

nono-sandbox

647

always-further/nono-packs

Skill Claude CodeCodex

Understands nono security sandbox constraints. Use when running inside a nono sandbox, when tool operations fail with permission errors, or when the user asks about sandbox capabilities.

not rated 23 22d ago A 39 tokens

evaluator-tools

648

JeredBlu/eval-marketplace

Plugin Claude Code

Bundles 2 skills · 153 tokens together

Comprehensive security evaluation tools for agent skills and MCP servers with integrated GitHub and Bright Data access.

not rated 23 7mo ago A tokens not measured

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: