Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

okjpg/skill-checkup-openclaw

Skill Claude CodeCodex

Use when auditing OpenClaw agents, workspaces, or hosts for production readiness, safety, backup/GitHub, memory/recall, skills, heartbeat, crons, watchdog, security, access, runtime bloat, or course baseline fit.

not rated 19 4mo ago A 58 tokens

evaluate-repository

722

Aero-Vance/awesome-cl-code

Command Claude Code

You are evaluating a repository intended for use in or alongside Claude Code, where certain features (such as hooks, commands, scripts, or automation) may execute implicitly or with elevated trust once enabled by a user.

not rated 19 5mo ago B 0 tokens

sanitize

723

agentward-ai/agentward

Skill Claude CodeCodex

Detect and redact PII from text files. Supports 15 categories including credit cards, SSNs, emails, API keys, addresses, and more — with zero dependencies.

not rated 19 2mo ago A 36 tokens

pin-guard

724

walidboulanouar/pin-guard

Skill Claude CodeCodex

Enforce exact, pinned package versions across a JavaScript/TypeScript repo and its agent tooling. Scans package.json dependencies, npm scripts, MCP server configs (.mcp.json, Claude/Cursor settings), and CI workflows for unpinned specs (^, , , latest, missing versions on npx). Pins everything to exact versions…

not rated 19 3mo ago A 156 tokens original MIT

taint-scanner

725

marcosd4h/DeepExtractRuntime

Agent Claude Code needs its repo

AI-driven taint analysis agent that traces attacker-controlled data through cross-module callgraphs, identifies where tainted inputs reach dangerous sinks without adequate validation, and maps trust boundary crossings.

not rated 19 4mo ago A 40 tokens original MIT

tm-skills

727

izar/tm_skills

Plugin Claude Code

Bundles 4 skills · 106 tokens together

Auxiliary skills for threat modeling - with and without OWASP pytm.

not rated 19 2mo ago A tokens not measured original MIT

xuanmu-bugbounty-mcp

728

guaidao2/Xuanmu-Bugbounty-mcp

MCP server Claude CodeCodexCursor +2

MCP server "xuanmu-bugbounty-mcp" as configured in guaidao2/Xuanmu-Bugbounty-mcp. Runs locally from the xuanmu-bugbounty-mcp Python package.

not rated 19 +1 2mo ago A tokens not measured

sector-b79/Malware-And-Reverse-Engineering-Skill-for-AI-Agents

Skill Claude CodeCodex

Defensive malware analysis and reverse-engineering workflow. Use for authorized lab analysis of suspicious Windows executables, DLLs, shellcode, packed samples, malicious documents, indicators of compromise, static and dynamic triage, IDA/Ghidra/debugger reasoning, anti-analysis handling, unpacking, host/network…

not rated 19 4mo ago A 75 tokens

vibe-ship

730

sudais-khalid/vibe-ship

Plugin Claude Code

Bundles 1 skill · 214 tokens together

Generates a complete production-ready deployment setup for any app in one pass: Dockerfile, docker-compose, CI/CD pipeline, security hardening, and scalability config. Also audits existing Dockerfiles and CI setups with a static scoring script.

not rated 18 1mo ago A tokens not measured original MIT

lictor-security-suite

731

Raffa-jarrl/Lictor-AI

Plugin Claude Code

Bundles 4 skills · 346 tokens together

Four free security skills for AI-built apps. Run lictor-security-check before you ship to scan for leaked API keys, exposed databases, broken access control (IDOR), injection (SQL/XSS/command), SSRF, exposed admin/debug surfaces, missing rate limits, and prompt-injection in AI features. Then lictor-explain, lictor-fix.

not rated 18 1mo ago A tokens not measured original Apache-2.0

mapick

732

mapick-ai/mapick

Skill Claude CodeCodex

Mapick — Skill recommendation & privacy protection for OpenClaw. Scans your local skills, suggests what you're missing, and keeps other skills from seeing your sensitive data.

not rated 18 3mo ago C 37 tokens original MIT

ai-iq

733

kobie3717/ai-iq

Plugin Claude Code

Bundles 1 skill, 5 hooks · 29 tokens together

Memory → Evaluation → Credential → Access Control for AI agents. Persistent memory with W3C Verifiable Credentials, capability-based access control, drift detection, and FSRS-6 spaced repetition.

not rated 18 2mo ago A tokens not measured original MIT

mastyf.ai

734

mastyf-ai/mastyf.ai

MCP server Claude CodeCodexCursor +2

Runtime proxy for MCP security, cost governance & audit. Runs locally from the @mastyf_ai/server npm package. Needs 3 environment variables to run.

not rated 18 7d ago A tokens not measured AGPL-3.0

vastlint

735

aleksUIX/vastlint

Plugin Claude Code

Bundles 2 MCP servers

Validate VAST, VMAP, and DAAST ad tags against IAB Tech Lab specs. Hosted MCP at https://vastlint.org/mcp. Auth none for public tools.

not rated 18 yesterday A tokens not measured

Nekzus/npm-sentinel-mcp

MCP server Claude CodeCodexCursor +2

One of 2 in server.json

Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend… Remote server at server.smithery.ai.

not rated 18 18d ago A tokens not measured original MIT

auth-rbac-scaffold

737

apisec-inc/apisec-skills

Skill Claude CodeCodex

Use when developer is implementing authentication, building login/logout flows, writing JWT validation, adding middleware, creating role-based access control, building permission systems, or asking how to protect routes. Also triggers on keywords: auth, bearer token, JWT, session, middleware, permissions, roles…

not rated 18 6mo ago A 98 tokens original MIT

privacy

738

gpdir16/tabyAgent

Skill Claude CodeCodex

Privacy tools and alternatives to mainstream services with verified details on licensing, ads, and pricing.

not rated 18 12d ago A 20 tokens AGPL-3.0

AgentConnect/awiki-agent-id-message

Skill Claude Code

Verifiable DID identity and end-to-end encrypted inbox for AI Agents. Built on ANP (Agent Network Protocol) and did:wba. Provides self-sovereign identity, Handle (short name) registration, content pages publishing, federated messaging, group communication, and HPKE-based E2EE — Web-based, not blockchain. Designed…

not rated 18 5mo ago A 155 tokens original Apache-2.0

shipproof

740

kingggg5/shipproof

Plugin Claude Code

Bundles 3 skills · 247 tokens together

Evidence-first engineering and production audits for secure, efficient, scalable systems.

not rated 18 yesterday A tokens not measured original MIT

mitmproxy-mcp

741

lucasoeth/mitmproxy-mcp

MCP server Claude CodeCodexCursor +2

MITM proxy manager with MCP integration. Runs locally from the mitmproxy-mcp Python package.

not rated 18 1y ago A tokens not measured

indicator-pivoting

742

Liberty91LTD/cti-skills

Skill Claude Code needs its repo

Indicator pivoting methodology — how to use one known indicator to discover related infrastructure across the IOC graph. Decision tree by indicator type with concrete /lookup- commands per pivot, a worked multi-hop example, pivot-quality scoring, and routing into the rigor pipeline. Use when the user asks "what else…

not rated 18 +1 1mo ago A 103 tokens original MIT

hackingtool

743

MAXZL1/hackingtool-plugin

Plugin Claude Code

Bundles 1 skill · 132 tokens together

183+ pentesting and OSINT tools (nmap, nuclei, amass, subfinder, httpx, sherlock, maigret, trufflehog, sqlmap, impacket, and more) wired into Claude Code as a single skill. Runs locally on any OS via native Bash, WSL, or purpose-built Docker images (instrumentisto/nmap, projectdiscovery/nuclei, caffix/amass, etc.).…

not rated 18 +2 2d ago A tokens not measured

vetto-sandbox

744

shleder/vetto

Skill Codex

Enforce zero-daemon Landlock/Seatbelt security boundaries, network isolation, and subagent capability controls when executing untrusted commands or running subagents. Use when running terminal commands, testing untrusted scripts, isolating AI subagent workflows, or performing read-only session recovery for Codex and…

not rated 18 +5 yesterday A SkillSpector: pass 67 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: