Security

24,538 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

sandbox

673

ubie-oss/dbt-data-privacy

Cursor rule Cursor

Enforce parity between Claude Code and Cursor sandbox settings.

not rated 22 9d ago A 0 tokens original Apache-2.0

gemtracker

674

spaquet/gemtracker

Skill Claude CodeCodex

Analyze Ruby gem dependencies, vulnerabilities, outdated packages, maintenance health, and insecure gem sources with the gemtracker CLI. Use when asked to audit Ruby gems, check Gemfile.lock security, review dependency health, or run gemtracker.

not rated 22 10d ago A SkillSpector: pass 49 tokens original MIT

presio

675

benedict-armstrong/presio

MCP server Claude CodeCodexCursor +2

Present PDFs from the browser: upload to start a slideshow or validate Presio sidecars. No auth. Remote server at presio.xyz.

not rated 22 today A tokens not measured original MIT

crowdsec-local-mcp

676

crowdsecurity/crowdsec-local-mcp

MCP server Claude CodeCodexCursor +2

An MCP exposing prompts and tools to help users write WAF rules, scenarios etc. Runs locally from the crowdsec-local-mcp Python package.

not rated 22 29d ago A tokens not measured original MIT

nslookup

677

NsLookup-io/nslookup-mcp

MCP server Claude CodeCodexCursor +2

DNS lookups, health reports, SSL certs, security scans, GEO scoring, uptime checks. Runs locally from the @nslookup-io/mcp-server npm package.

not rated 22 1mo ago A tokens not measured original Apache-2.0

bb-huge

678

ShulkwiSEC/bb-huge

Skill Codex needs its repo

Bug bounty findings secretary, tracker, and workspace initializer for the bb-huge portal. Use this skill for web security research, vulnerability hunting, and hunt workspace setup. Triggers on: "log finding", "save finding", "add to bb-huge", "record vulnerability", "update finding", "show findings", "bb-huge stats"…

not rated 22 2mo ago A 204 tokens original MIT

blue-team-defender

679

lucasrosati/claude-security-agents

Agent Claude Code

Defensive security specialist. Use to apply vulnerability fixes, security hardening, security headers implementation, rate limiting, and automated security tests. Works on top of red-team-scanner reports.

not rated 22 +1 4mo ago A 42 tokens original MIT

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Use this skill whenever you need to audit, test, or fix Authentication Failures (OWASP A07:2025) in Python web applications — especially FastAPI and Flask. Triggers include: any mention of JWT security, session management, brute force protection, credential stuffing, password policy, MFA enforcement, login rate…

not rated 22 +1 5mo ago A 166 tokens original MIT

mcp-review

682

stacklok/toolhive-catalog

Skill Claude Code

Review MCP server specifications and updates for compliance, security, and quality. Use when evaluating server.json files, PRs adding/updating servers, or assessing MCP server changes. NOT for creating new entries (use add-mcp-server instead).

not rated 22 2d ago A SkillSpector: warn 51 tokens original Apache-2.0

atlassian/forge-skills

Cursor rule Cursor ✓ vendor

Detect missing authorization checks in Forge resolvers for sensitive operations.

not rated 22 +1 2d ago A 11 tokens original Apache-2.0

reconbridge

684

lm060719/reconbridge

Skill Claude CodeCodex

Drive the ReconBridge toolchain to reverse-engineer / recon / tamper Android apps on a rooted (KernelSU) device from the PC side. Use whenever the task involves: pulling an APK or native .so off a device, decompiling with jadx, locating classes/methods with DexKit/androguard, Ghidra native analysis, hooking or tracing…

not rated 22 +2 1mo ago A 196 tokens original MIT

trust-center-outline

685

neodeer3244-w5dry/trust-center-outline

Skill Claude CodeCodex

A planning guide for a public security and trust section on a SaaS or developer-tool website. It covers the site structure, page notes, evidence links, owners, and information gaps.

not rated 22 1mo ago A 109 tokens original MIT

maven-mcp

686

kirich1409/krozov-ai-tools

Plugin Claude Code

Bundles 21 skills, 2 hooks · 1,758 tokens together

Maven dependency intelligence — dependency updates, vulnerability and license scanning, transitive dependency graphs, version compatibility checks, artifact search, and version-catalog management, exposed as skills and an MCP server. Works in Claude Code and Grok Build without any NPM setup.

not rated 22 4d ago A tokens not measured original MIT

meltedinhex/analyst-ai-pack

Skill Claude CodeCodex

Builds a safe, isolated environment for detonating and analyzing malware using virtualization, host-only or simulated networking, and snapshotting. Activates for requests about creating a malware lab, sandbox VM, isolated analysis environment, or safe detonation setup.

not rated 22 2mo ago A 60 tokens original Apache-2.0

krait

688

ZealynxSecurity/krait

Command Claude Code

Run a complete multi-phase security audit on the target codebase.

not rated 21 +1 1mo ago A 0 tokens original MIT

akira

689

kalpmodi/akira

Cursor rule Cursor

Akira pentest skill suite - activates for security testing, bug bounty, and CTF tasks.

not rated 21 2mo ago A 19 tokens original MIT

code-review

690

vox-ai-app/vox

Skill Claude CodeCodex

Reviews code for bugs, security issues, and best practices. Suggests improvements with concrete examples.

not rated 21 2mo ago A 22 tokens original MIT

cockroachlabs/cockroachdb-skills

Skill Claude CodeCodex

Audits the security posture of a CockroachDB cluster (Cloud or self-hosted) across network, authentication, authorization, encryption, audit logging, and backup dimensions. Use when assessing cluster security readiness, preparing for compliance reviews, or investigating security configuration gaps.

not rated 21 1mo ago A 59 tokens original Apache-2.0

PreToolUse

692

meloncafe/claude-code-hooks

Hook Claude Code

One of 7 in settings.json

Runs before the agent uses a tool for Write, Edit, Update, Bash, WebFetch and WebSearch tool calls, executing token_manager.py, command_restrictor.py, pattern_enforcer.py, no_mock_code.py, secret_scanner.py, timestamp_validator.py and validate_git_commit.py via python3 (11 commands). From meloncafe/claude-code-hooks.

not rated 21 20d ago A tokens not measured original MIT

woohyun212/security-skill

Skill Claude CodeCodex

Multi-chain smart contract security for Solana, Algorand, Cairo, Cosmos, Substrate, and TON with pre-audit readiness checks.

not rated 21 4mo ago A 34 tokens original MIT

rails-security

694

jorgegorka/ariadna

Skill Claude CodeCodex

Ruby on Rails security conventions — authentication, authorization, OWASP protections, CSRF, input validation. Use when implementing auth, handling sensitive data, or reviewing security.

not rated 21 +1 5mo ago A 36 tokens original MIT

thomast1906/github-copilot-skills-terraform

Agent Claude Code

Reviews Terraform Azure configurations against Microsoft Cloud Adoption Framework (CAF) and Azure Well-Architected Framework (WAF). Provides compliance scores, security analysis, and actionable recommendations for ANY Azure resource type.

not rated 21 +1 6mo ago A 43 tokens

vibe-architecture

696

jgnoonan/vibeArchitecture

Skill Claude CodeCodex

Apply architectural guardrails when building software. Runs an intake questionnaire to determine the project's tier, then enforces security, reliability, and best practice rules appropriate to the tier while writing code.

not rated 21 +1 10d ago A SkillSpector: warn 42 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: