ClawdStrike
745Skill Claude CodeCodex
Security audit and threat model for OpenClaw gateway hosts. Use to verify OpenClaw configuration, exposure, skills/plugins, filesystem hygiene, and to produce an OK/VULNERABLE report with evidence and fixes.
24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.
Skill Claude CodeCodex
Security audit and threat model for OpenClaw gateway hosts. Use to verify OpenClaw configuration, exposure, skills/plugins, filesystem hygiene, and to produce an OK/VULNERABLE report with evidence and fixes.
Skill Claude CodeCodex
Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations.
EvolutionUnleashed/skill-sentinel
Skill Claude CodeCodex
Security scanner and threat analyzer for AI agent skills. Activate this skill whenever a new skill is added to the workspace, when the user imports or installs a skill from an external source, when asked to audit or review an existing skill for safety, or when the user mentions scanning, vetting, checking, or…
Skill Claude CodeCodex
Production-grade engineering gate for writing OR reviewing code. Enforces security, resource safety (memory leaks, unclosed listeners/streams/timers), efficient data access (N+1, pagination/infinite-scroll, over-fetching, backend cost), defensive coding, and evidence-based verification. Use when the user invokes it…
Skill Claude CodeCodex
Multi-agent workflow (tracer/resolver/bypass) for secure code review, exploitability triage, and PoC validation in codebases. Use when conducting structured security research or penetration test analysis.
InternetMaximalism/lean-reinforced-concrete
Skill Claude CodeCodex
Audit and verify software systems in any domain — cryptographic protocols, ZK circuits, smart contracts, distributed systems, business logic (payments, inventory, access control), embedded systems, APIs, and more — by formalizing them in Lean 4. Use not only for auditing existing implementations but also for product…
GoldenWing-360/claude-security-skills
Skill Claude CodeCodex
Harden Android apps against the platform-specific failure modes. Covers Android Keystore and StrongBox, encrypted local storage, network security config and certificate pinning, WebView hardening, exported components and intent hijacking, backup rules, and Play Integrity with root detection as a signal. Invoke when…
Plugin Claude Code
Bundles 3 skills, 1 command · 192 tokens together
Java quality toolkit — security (OWASP), performance (N+1, memory, threading), and testing (JUnit 5, Mockito, Testcontainers) for Java 8+ projects.
MCP server Claude CodeCodexCursor +2
The dependency bloodhound for AI coding agents. Zero API keys, zero config. Runs locally from the hound-mcp npm package.
Skill Claude CodeCodex
Run Opengrep for pattern-based code search and security scanning. Use when grep is insufficient for finding code patterns that require structural understanding (function calls, data flow, nested structures). Also use for security vulnerability detection with custom YAML rules.
Skill Claude CodeCodex
Create and sign JSON Web Tokens (JWTs) for testing and development. Use when the user wants to generate, create, build, or sign a JWT — e.g. "create a JWT", "generate a test token", "sign this payload", "make a JWT with these claims", "build an access token". Supports HMAC, RSA, and ECDSA algorithms.
kirollosatef/customgpt-claude-quadruple-verification
Plugin Claude Code
Quadruple verification for Claude Code — automatically blocks placeholder code, security vulnerabilities, and ensures output quality on every operation. Built by CustomGPT.ai for production teams.
Plugin Cursor
Bring Trustabl's AI-agent safety & reliability scanner into Cursor — scan your agents, tools, and MCP servers, get a production-readiness score with severity-ranked findings, and fix issues before they ship.
Cursor rule Claude CodeCursor
HawkScan DAST security scanning. Use when the user asks to run or perform a security or DAST scan, to test an app or API for vulnerabilities, or to verify a vulnerability is fixed — and proactively right after you complete a code change (feature, bugfix, refactor); "done" means "done and secure" (configure, scan, fix…
Plugin Claude Code
Bundles 1 skill · 54 tokens together
Evaluates packages, manages dependencies, and addresses supply chain security.
MCP server Claude CodeCodexCursor +2
Stop AI coding agents from leaking API keys. Local proxy swaps real secrets for phm tokens. Runs locally from the phantom-secrets-mcp npm package.
Skill Claude CodeCodex
Cryptographic tool schema verification to prevent MCP Rug Pull attacks — ECDSA P-256 signing, SHA-256 hashing, TOFU key pinning, .well-known discovery, signed revocation documents, and (v1.4-alpha across all four languages) signature expiration, DNS TXT cross-verification, and schema version binding (lineage chain).
Skill Claude CodeCodex
Determine which Singapore Government System Security Plan(s) apply to a system under the ICT&SS Policy Reform (IM8's successor) and emit the resulting control baseline — including stacking the Generative AI overlay and Digital Service Standards profiles on top of a cybersecurity SSP. Use whenever a project touches SG…
Skill Claude CodeCodex
Agentic DFIR orchestrator that autonomously investigates security incidents by chaining forensic skills (IOC extraction, Windows artifact triage, timeline correlation, YARA generation) with an autonomous reasoning loop, persistent case state, and human-in-the-loop approvals. Use this skill whenever the user mentions…
tracebit-com/tracebit-canary-honeytokens-skill
Skill Claude CodeCodex
Use when the user wants to protect their workspace from credential theft, prompt injection, or data exfiltration — even if they don't mention "canaries" or "honeytokens" directly. Covers deploying Tracebit security canaries (fake decoy credentials that alert on use), detecting when they're triggered via the user's…
Evaluris-Solutions/claude-active-directory
Skill Claude CodeCodex
Use when classifying or explaining authorized Active Directory attack techniques—Kerberos and NTLM paths, coercion awareness, delegation and RBCD, ACL and DCSync concepts, LAPS and shadow credentials, GPP, trust paths, AD-joined SQL pivots, and lateral movement by protocol. Use as a reference when writing findings or…
skjortan23/read-team-mcp-server
MCP server Claude CodeCodexCursor +2
MCP server "red-team-mcp" as configured in skjortan23/read-team-mcp-server. Runs locally from the red-team-mcp Python package.
Plugin Claude Code
AppSec Foundry plugins for application security work in Claude Code.
MCP server Claude CodeCodexCursor +2
Model Context Protocol (MCP) Server for OpenCTI. Runs locally from the pycti-mcp Python package.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: