Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

ClawdStrike

745

cantinaxyz/clawdstrike-skill

Skill Claude CodeCodex

Security audit and threat model for OpenClaw gateway hosts. Use to verify OpenClaw configuration, exposure, skills/plugins, filesystem hygiene, and to produce an OK/VULNERABLE report with evidence and fixes.

not rated 18 7mo ago A 47 tokens

laravel-security

746

nklofy/code-agent-skills

Skill Claude CodeCodex

Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations.

not rated 18 +1 2mo ago A 32 tokens original Apache-2.0

skill-sentinel

747

EvolutionUnleashed/skill-sentinel

Skill Claude CodeCodex

Security scanner and threat analyzer for AI agent skills. Activate this skill whenever a new skill is added to the workspace, when the user imports or installs a skill from an external source, when asked to audit or review an existing skill for safety, or when the user mentions scanning, vetting, checking, or…

not rated 17 6mo ago D 125 tokens

ironcode

748

djfksjd/ironcode

Skill Claude CodeCodex

Production-grade engineering gate for writing OR reviewing code. Enforces security, resource safety (memory leaks, unclosed listeners/streams/timers), efficient data access (N+1, pagination/infinite-scroll, over-fetching, backend cost), defensive coding, and evidence-based verification. Use when the user invokes it…

not rated 17 1mo ago A 124 tokens original MIT

PSPDFKit-labs/pi-skills

Skill Claude CodeCodex

Multi-agent workflow (tracer/resolver/bypass) for secure code review, exploitability triage, and PoC validation in codebases. Use when conducting structured security research or penetration test analysis.

not rated 17 4mo ago A 45 tokens

lean-formal-audit

750

InternetMaximalism/lean-reinforced-concrete

Skill Claude CodeCodex

Audit and verify software systems in any domain — cryptographic protocols, ZK circuits, smart contracts, distributed systems, business logic (payments, inventory, access control), embedded systems, APIs, and more — by formalizing them in Lean 4. Use not only for auditing existing implementations but also for product…

not rated 17 2mo ago A 216 tokens

android-security

751

GoldenWing-360/claude-security-skills

Skill Claude CodeCodex

Harden Android apps against the platform-specific failure modes. Covers Android Keystore and StrongBox, encrypted local storage, network security config and certificate pinning, WebView hardening, exported components and intent hijacking, backup rules, and Play Integrity with root detection as a signal. Invoke when…

not rated 17 1mo ago A 83 tokens original MIT

hound

753

tiluckdave/hound-mcp

MCP server Claude CodeCodexCursor +2

The dependency bloodhound for AI coding agents. Zero API keys, zero config. Runs locally from the hound-mcp npm package.

not rated 17 yesterday A tokens not measured original MIT

opengrep

754

opengrep/skills

Skill Claude CodeCodex

Run Opengrep for pattern-based code search and security scanning. Use when grep is insufficient for finding code patterns that require structural understanding (function calls, data flow, nested structures). Also use for security vulnerability detection with custom YAML rules.

not rated 17 7mo ago B 51 tokens original MIT

jwt-encode

755

jsonwebtoken/jwt-skills

Skill Claude CodeCodex

Create and sign JSON Web Tokens (JWTs) for testing and development. Use when the user wants to generate, create, build, or sign a JWT — e.g. "create a JWT", "generate a test token", "sign this payload", "make a JWT with these claims", "build an access token". Supports HMAC, RSA, and ECDSA algorithms.

not rated 17 +1 5mo ago A Socket: passSnyk: fail 81 tokens

trustabl

757

trustabl/trustabl-cursor

Plugin Cursor

Bundles 1 MCP server

Bring Trustabl's AI-agent safety & reliability scanner into Cursor — scan your agents, tools, and MCP servers, get a production-readiness score with severity-ranked findings, and fix issues before they ship.

not rated 17 2d ago A tokens not measured

stackhawk-hawkscan

758

stackhawk/agent-skills

Cursor rule Claude CodeCursor

HawkScan DAST security scanning. Use when the user asks to run or perform a security or DAST scan, to test an app or API for vulnerabilities, or to verify a vulnerability is fixed — and proactively right after you complete a code change (feature, bugfix, refactor); "done" means "done and secure" (configure, scan, fix…

not rated 16 2d ago A 6,655 tokens original MIT

phantom-secrets-mcp

760

ashlrai/phantom-secrets

MCP server Claude CodeCodexCursor +2

Stop AI coding agents from leaking API keys. Local proxy swaps real secrets for phm tokens. Runs locally from the phantom-secrets-mcp npm package.

not rated 16 3d ago A tokens not measured original MIT

schemapin

761

ThirdKeyAI/SchemaPin

Skill Claude CodeCodex

Cryptographic tool schema verification to prevent MCP Rug Pull attacks — ECDSA P-256 signing, SHA-256 hashing, TOFU key pinning, .well-known discovery, signed revocation documents, and (v1.4-alpha across all four languages) signature expiration, DNS TXT cross-verification, and schema version binding (lineage chain).

not rated 16 9d ago A 75 tokens original MIT

ssp-navigator

762

kyleoliveiro/sg-gov-skills

Skill Claude CodeCodex

Determine which Singapore Government System Security Plan(s) apply to a system under the ICT&SS Policy Reform (IM8's successor) and emit the resulting control baseline — including stacking the Generative AI overlay and Digital Service Standards profiles on top of a cybersecurity SSP. Use whenever a project touches SG…

not rated 16 1mo ago A 144 tokens original MIT

dfir-orchestrator

763

samaritan0/dfir-agentic-suite

Skill Claude CodeCodex

Agentic DFIR orchestrator that autonomously investigates security incidents by chaining forensic skills (IOC extraction, Windows artifact triage, timeline correlation, YARA generation) with an autonomous reasoning loop, persistent case state, and human-in-the-loop approvals. Use this skill whenever the user mentions…

not rated 16 5mo ago A 157 tokens

tracebit-canaries

764

tracebit-com/tracebit-canary-honeytokens-skill

Skill Claude CodeCodex

Use when the user wants to protect their workspace from credential theft, prompt injection, or data exfiltration — even if they don't mention "canaries" or "honeytokens" directly. Covers deploying Tracebit security canaries (fake decoy credentials that alert on use), detecting when they're triggered via the user's…

not rated 16 5mo ago A 110 tokens

ad-attack-classes

765

Evaluris-Solutions/claude-active-directory

Skill Claude CodeCodex

Use when classifying or explaining authorized Active Directory attack techniques—Kerberos and NTLM paths, coercion awareness, delegation and RBCD, ACL and DCSync concepts, LAPS and shadow credentials, GPP, trust paths, AD-joined SQL pivots, and lateral movement by protocol. Use as a reference when writing findings or…

not rated 16 4mo ago A 85 tokens

red-team-mcp

766

skjortan23/read-team-mcp-server

MCP server Claude CodeCodexCursor +2

MCP server "red-team-mcp" as configured in skjortan23/read-team-mcp-server. Runs locally from the red-team-mcp Python package.

not rated 16 5mo ago A tokens not measured

pycti-mcp

768

ckane/pycti-mcp

MCP server Claude CodeCodexCursor +2

Model Context Protocol (MCP) Server for OpenCTI. Runs locally from the pycti-mcp Python package.

not rated 16 1y ago A tokens not measured original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: