Skill Claude CodeCodex
Use when auditing OpenClaw agents, workspaces, or hosts for production readiness, safety, backup/GitHub, memory/recall, skills, heartbeat, crons, watchdog, security, access, runtime bloat, or course baseline fit.
24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.
Skill Claude CodeCodex
Use when auditing OpenClaw agents, workspaces, or hosts for production readiness, safety, backup/GitHub, memory/recall, skills, heartbeat, crons, watchdog, security, access, runtime bloat, or course baseline fit.
Command Claude Code
You are evaluating a repository intended for use in or alongside Claude Code, where certain features (such as hooks, commands, scripts, or automation) may execute implicitly or with elevated trust once enabled by a user.
Skill Claude CodeCodex
Detect and redact PII from text files. Supports 15 categories including credit cards, SSNs, emails, API keys, addresses, and more — with zero dependencies.
Skill Claude CodeCodex
Enforce exact, pinned package versions across a JavaScript/TypeScript repo and its agent tooling. Scans package.json dependencies, npm scripts, MCP server configs (.mcp.json, Claude/Cursor settings), and CI workflows for unpinned specs (^, , , latest, missing versions on npx). Pins everything to exact versions…
Agent Claude Code needs its repo
AI-driven taint analysis agent that traces attacker-controlled data through cross-module callgraphs, identifies where tainted inputs reach dangerous sinks without adequate validation, and maps trust boundary crossings.
dungnotnull/hybrid-harness-chaos-process-prm
Plugin Claude Code
Bundles 37 skills, 4 commands · 4,202 tokens together
A 36-skill agentic workflow for platform engineering — spanning CI/CD, security, chaos engineering, observability, governance, compliance, deep research, system optimization, documentation, and adversarial critique. Purpose-built for AI-assisted development.
Plugin Claude Code
Bundles 4 skills · 106 tokens together
Auxiliary skills for threat modeling - with and without OWASP pytm.
MCP server Claude CodeCodexCursor +2
MCP server "xuanmu-bugbounty-mcp" as configured in guaidao2/Xuanmu-Bugbounty-mcp. Runs locally from the xuanmu-bugbounty-mcp Python package.
sector-b79/Malware-And-Reverse-Engineering-Skill-for-AI-Agents
Skill Claude CodeCodex
Defensive malware analysis and reverse-engineering workflow. Use for authorized lab analysis of suspicious Windows executables, DLLs, shellcode, packed samples, malicious documents, indicators of compromise, static and dynamic triage, IDA/Ghidra/debugger reasoning, anti-analysis handling, unpacking, host/network…
Plugin Claude Code
Bundles 1 skill · 214 tokens together
Generates a complete production-ready deployment setup for any app in one pass: Dockerfile, docker-compose, CI/CD pipeline, security hardening, and scalability config. Also audits existing Dockerfiles and CI setups with a static scoring script.
Plugin Claude Code
Bundles 4 skills · 346 tokens together
Four free security skills for AI-built apps. Run lictor-security-check before you ship to scan for leaked API keys, exposed databases, broken access control (IDOR), injection (SQL/XSS/command), SSRF, exposed admin/debug surfaces, missing rate limits, and prompt-injection in AI features. Then lictor-explain, lictor-fix.
Skill Claude CodeCodex
Mapick — Skill recommendation & privacy protection for OpenClaw. Scans your local skills, suggests what you're missing, and keeps other skills from seeing your sensitive data.
Plugin Claude Code
Bundles 1 skill, 5 hooks · 29 tokens together
Memory → Evaluation → Credential → Access Control for AI agents. Persistent memory with W3C Verifiable Credentials, capability-based access control, drift detection, and FSRS-6 spaced repetition.
MCP server Claude CodeCodexCursor +2
Runtime proxy for MCP security, cost governance & audit. Runs locally from the @mastyf_ai/server npm package. Needs 3 environment variables to run.
Plugin Claude Code
Validate VAST, VMAP, and DAAST ad tags against IAB Tech Lab specs. Hosted MCP at https://vastlint.org/mcp. Auth none for public tools.
MCP server Claude CodeCodexCursor +2
One of 2 in server.json
Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend… Remote server at server.smithery.ai.
Skill Claude CodeCodex
Use when developer is implementing authentication, building login/logout flows, writing JWT validation, adding middleware, creating role-based access control, building permission systems, or asking how to protect routes. Also triggers on keywords: auth, bearer token, JWT, session, middleware, permissions, roles…
Skill Claude CodeCodex
Privacy tools and alternatives to mainstream services with verified details on licensing, ads, and pricing.
AgentConnect/awiki-agent-id-message
Skill Claude Code
Verifiable DID identity and end-to-end encrypted inbox for AI Agents. Built on ANP (Agent Network Protocol) and did:wba. Provides self-sovereign identity, Handle (short name) registration, content pages publishing, federated messaging, group communication, and HPKE-based E2EE — Web-based, not blockchain. Designed…
Plugin Claude Code
Bundles 3 skills · 247 tokens together
Evidence-first engineering and production audits for secure, efficient, scalable systems.
MCP server Claude CodeCodexCursor +2
MITM proxy manager with MCP integration. Runs locally from the mitmproxy-mcp Python package.
Skill Claude Code needs its repo
Indicator pivoting methodology — how to use one known indicator to discover related infrastructure across the IOC graph. Decision tree by indicator type with concrete /lookup- commands per pivot, a worked multi-hop example, pivot-quality scoring, and routing into the rigor pipeline. Use when the user asks "what else…
Plugin Claude Code
Bundles 1 skill · 132 tokens together
183+ pentesting and OSINT tools (nmap, nuclei, amass, subfinder, httpx, sherlock, maigret, trufflehog, sqlmap, impacket, and more) wired into Claude Code as a single skill. Runs locally on any OS via native Bash, WSL, or purpose-built Docker images (instrumentisto/nmap, projectdiscovery/nuclei, caffix/amass, etc.).…
Skill Codex
Enforce zero-daemon Landlock/Seatbelt security boundaries, network isolation, and subagent capability controls when executing untrusted commands or running subagents. Use when running terminal commands, testing untrusted scripts, isolating AI subagent workflows, or performing read-only session recovery for Codex and…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: