Security

24,612 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

panther-audit

697

pantheraudits/web3-sec-ai-prompts

Skill Claude CodeCodex

Automated smart contract security audit pipeline. Auto-detects codebase size and scales accordingly — standard mode for small codebases, chunk mode with persistent state for large ones. Runs context building, dual-expert review, adversarial triage, and structured reporting. Use when auditing smart contracts, reviewing…

not rated 20 6mo ago A 94 tokens

1password

698

CakeRepository/1Password-MCP

MCP server Claude CodeCodexCursor +2

MCP server for 1Password service accounts — tools and resources for vaults and credentials. Runs locally from the @takescake/1password-mcp npm package. Needs 3 environment variables to run.

not rated 20 11d ago A tokens not measured original Apache-2.0

mnvsk97/agentbreak

Skill Codex

Orchestrates end-to-end resilience testing for LLM agents with AgentBreak, including LLM infrastructure failures, prompt injection, agent skill supply-chain risk, guardrail verification, and MCP server/tool failures. Use when the user asks to "test my agent for resilience", "chaos test this agent", "find failure modes…

not rated 20 3mo ago A 97 tokens original MIT

salvo-auth

700

salvo-rs/salvo-skills

Skill Claude CodeCodex

Implement authentication and authorization using JWT, Basic Auth, or custom schemes. Use for securing API endpoints and user management.

not rated 20 2mo ago A 27 tokens

ctf-qa-validation

701

mr-pmillz/gogatoz

Skill Codex

QA testing and validation of GoGatoZ features against the local GoGatoZ CTF lab. Invoke for post-change testing, live flag validation, lab infrastructure checks, payload smoke tests, enumerate/attack/search/pivot/notify validation, or any request to confirm that GoGatoZ still works.

not rated 20 4d ago A 68 tokens

deep-review

704

ronnycoding/.claude

Command Claude Code

Run parallel specialized PR reviews (Opus 4.6 for security/architecture, Sonnet 4.6 for the rest).

not rated 20 2mo ago A 27 tokens

analyze-repo

705

miles990/claude-software-skills

Skill Claude Code

Enterprise-grade repository analysis with arc42/C4 architecture documentation, technical debt quantification, security assessment, and multi-stakeholder reporting.

not rated 20 7mo ago A 31 tokens original MIT

gophish-mcp-server

706

dan1t0/gophish-mcp

MCP server Claude CodeCodexCursor +2

MCP server "gophish-mcp-server" as configured in dan1t0/gophish-mcp. Runs locally from the gophish-mcp-server Python package.

not rated 20 3mo ago A tokens not measured original MIT

convex-security-audit

707

igor9silva/meseeks

Skill Claude CodeCodex

Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations.

not rated 20 2mo ago A 28 tokens AGPL-3.0

ci-secure

708

starslingdev/skills

Skill Claude CodeCodex

Scans a repo's GitHub Actions workflows for the ten critical CI/CD attack vectors — template injection, fork code executed with privileges (pwn requests), cache poisoning, impostor action SHAs, secrets dumps, GITHUBENV hijack, write-token untrusted triggers, credentials in caches/artifacts, unverified remote code…

not rated 20 today A SkillSpector: warn 230 tokens original MIT

safedeps

709

aldegad/safedeps

Skill Claude CodeCodex

Gate dependency installs (npm/pip/cargo/go/gem/maven/nuget) with OSV-backed advisory checks, approved-spec ledger, and post-install reorg rollback. Run safedeps check @ before any install command.

not rated 20 +1 22d ago A 62 tokens original Apache-2.0

pass-cli-mcp

710

hesreallyhim/proton-pass-community-mcp

Skill Claude CodeCodex

Canonical protocol for model-side skill behavior when orchestrating proton-pass-community-mcp tools in chat sessions.

not rated 20 +1 today A 25 tokens GPL-3.0

pe-reverse-analyzer

711

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

A general reverse-engineering toolkit for Windows programs, Android apps, iOS apps, web interfaces, and APIs. Reverse engineering means examining software to understand how it works and, where appropriate, how to modify and rebuild it.

not rated 20 +3 15d ago A 90 tokens

artemnovichkov/xcode-skills

Skill Claude CodeCodex

Audit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up…

not rated 21 +8 changed 2d ago A 111 tokens

elliot

713

ogrodev/fsociety

Plugin Claude Code

Bundles 9 skills, 24 commands, 2 agents, 4 hooks · 4,114 tokens together

Elliot — offensive security engagement plugin with Hexstrike MCP integration for Kali Linux. Provides slash commands, auto-activating skills, and subagents for systematic penetration testing workflows.

not rated 20 5mo ago A tokens not measured original MIT

edr-evasion-dev

714

AeonDave/malskill

Skill Claude CodeCodex

Auth/lab dev: Windows + Linux detection-resilience research; syscall dispatch, stack/call-chain spoofing, sleep-state, memory permissions, ETW/AMSI + eBPF/iouring/LDPRELOAD telemetry tradeoffs, kernel-visible signals, and cross-platform loader OPSEC with signal-cost budgeting.

not rated 20 +2 changed 8d ago A 70 tokens

luffy-arm

716

Ares960826/luffy-arm

Plugin Claude Code

Bundles 3 skills · 307 tokens together

Give a local AI agent a remote hand over SSH: read, run, diagnose and pull data from a remote Linux server behind a tiered, unprivileged, ACL-read-only safety model.

not rated 19 16d ago A tokens not measured original MIT

fortify

717

fortify/skills

Plugin Claude Code

Bundles 9 skills, 2 agents · 1,032 tokens together

OpenText Fortify AppSec skills. Use for SAST/DAST/SCA scanning, vulnerability triage, audit workflows, CI/CD pipeline integration, and FCLI commands. Supports Fortify on Demand (FoD) and Software Security Center (SSC).

not rated 19 1mo ago A tokens not measured original MIT

tooltrust-scanner

718

AgentSafe-AI/tooltrust-scanner

MCP server Claude CodeCodexCursor +2

Scans MCP servers for prompt injection, data exfiltration, and privilege escalation. Runs locally from the tooltrust-mcp npm package.

not rated 19 2d ago A tokens not measured original MIT

yultyyev/better-auth-firebase-auth

Skill Claude CodeCodex

Add Firebase Authentication (Phone SMS OTP, Google Sign-In, Email/Password) to a Better Auth app using the better-auth-firebase-auth plugin. Use when adding phone authentication to Better Auth without Twilio, integrating Firebase Auth with Better Auth sessions, working with the better-auth-firebase-auth package, or…

not rated 19 5d ago A 82 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: