Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

screem500/prompt-injection-auditor

Skill Claude CodeCodex

Security audit of LLM system prompts, agent instruction files (SKILL.md, AGENTS.md, CLAUDE.md), and agent configurations against prompt injection attacks. Use when the user wants to (1) audit or harden a system prompt or agent instructions against prompt injection, (2) review an agent skill or system prompt for…

not rated 16 changed 8d ago A 159 tokens original Apache-2.0

google-ads

770

alifanov/scopegate

MCP server Claude CodeCodexCursor +2

MCP server "google-ads", hosted remotely at scopegate.chatindex.app, as configured in alifanov/scopegate.

not rated 16 +1 yesterday A tokens not measured original MIT

defectdojo-mcp

771

jamiesonio/defectdojo-mcp

MCP server Claude CodeCodexCursor +2

DefectDojo MCP server for integrating with DefectDojo vulnerability management system. Runs locally from the defectdojo-mcp Python package.

not rated 16 +1 1y ago A tokens not measured original MIT

docs-masked

772

kpshinnik/docs_masked

Plugin Claude Code

Bundles 1 skill · 296 tokens together

A document-privacy tool that replaces identifying information locally before a document is sent to an AI model, then restores the original values in the response.

not rated 16 +1 25d ago A tokens not measured original MIT

qualys-mcp

773

nelssec/qualys-mcp

MCP server Claude CodeCodexCursor +2

MCP server for Qualys security APIs - natural language interaction with vulnerability, asset, and cloud security data. Runs locally from the qualys-mcp Python package.

not rated 16 +1 2mo ago A tokens not measured original MIT

mikrotik-mcp

774

mikrotik-mcp/mikrotik-mcp

MCP server Claude CodeCodexCursor +2

MCP server for MikroTik RouterOS — 780+ tools over SSH for firewall, NAT, routing, DHCP, DNS, WireGuard, wireless, QoS and more. Runs locally from the @usex/mikrotik-mcp npm package.

not rated 16 +1 yesterday A tokens not measured original MIT

tie-mcp-server

775

taherkaraki/tie-mcp-server

MCP server Claude CodeCodexCursor +2

MCP server for Tenable Identity Exposure API. Runs locally from the tie-mcp-server npm package.

not rated 16 1mo ago A tokens not measured original MIT

threat-model

777

backspace-shmackspace/claude-devkit

Skill Claude CodeCodex

Use when performing threat modeling for a project, feature, or system architecture. Applies STRIDE threat categorization with DREAD risk rating to produce structured threat models in OTM JSON and markdown formats. Covers system decomposition, trust boundary mapping, data flow analysis, per-subsystem threat…

not rated 15 19d ago A SkillSpector: warn 70 tokens original MIT

audit-flow

778

ArunJRK/audit-flow

Skill Claude CodeCodex

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document…

not rated 15 6mo ago A 84 tokens copy · 100% MIT

vulhunt

780

vulhunt-re/skills

Plugin Claude Code

Bundles 7 skills · 296 tokens together

Binary analysis skills for VulHunt MCP - decompilation, dataflow analysis, pattern matching, and more.

not rated 15 6mo ago A tokens not measured

agent-shield

782

elliotllliu/agent-shield

Skill Claude CodeCodex

Scan AI agent skills, MCP servers, and plugins for security vulnerabilities. Use when: user asks to check a skill/plugin for safety, audit security, scan for backdoors/data exfiltration/credential leaks, or evaluate trust of a third-party skill. Triggers: "is this skill safe", "scan for security issues", "audit this…

not rated 15 5mo ago A 92 tokens original MIT

prodlint

783

prodlint/prodlint

MCP server Claude CodeCodexCursor +2

Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance. Runs locally from the prodlint npm package.

not rated 15 5d ago A tokens not measured original MIT

s-gw

784

sgateway/s-gw

Skill Claude CodeCodex

Use s-gw when working with credentials, private keys, API tokens, SSH identities, browser credentials, or other sensitive data in agentic coding workflows. Prefer typed handles and local approved execution over exposing raw secret values to a model.

not rated 15 2d ago A 51 tokens original Apache-2.0

security-audit

785

msradam/theodosia

Skill Claude CodeCodex

Use when auditing a web app for security vulnerabilities. Triggers on: 'audit my project', 'how could this get hacked', 'find bugs in this codebase', 'security review', 'pentest', 'bug bounty scope for X', 'GHSA collaborator invite', 'security audit this'. Handles both internal audits (sitting in your own codebase…

not rated 15 5d ago B 250 tokens original Apache-2.0

kawaiidra

786

wagonbomb/kawaiidra-mcp

MCP server Claude CodeCodexCursor +2

MCP server "kawaiidra" as configured in wagonbomb/kawaiidra-mcp. Runs run_server.py with python. Needs 1 environment variable to run.

not rated 15 6mo ago A tokens not measured original MIT

aegis

787

Acacian/aegis

MCP server Claude CodeCodexCursor +2

Auto-instrument AI agent frameworks with runtime security. One line to govern LangChain, CrewAI, OpenAI, Anthropic — injection blocking, PII masking, action policy, audit trail. Zero code changes. Runs locally from the agent-aegis Python package. Needs 1 environment variable to run.

not rated 15 14d ago A tokens not measured original MIT

avp-trust-enforcement

788

agentveil-protocol/agentveil-sdk

Skill Claude CodeCodex

AgentVeil action-control workflows for AI agent systems. Evaluate risky actions with Runtime Gate, route human approvals, resume approved execution, fetch signed receipts, inspect agent public profiles, check advisory reputation, submit signed attestations, discover agents by capability, and verify audit evidence…

not rated 15 yesterday A SkillSpector: warn 71 tokens original MIT

gh-guard

789

sbom-tool/gh-guard

Plugin Claude Code

Bundles 14 skills, 5 commands · 353 tokens together

CI/CD supply chain hardening for Rust projects — Trusted Publishing, SLSA provenance, Scorecard, cargo-deny, and more.

not rated 15 5mo ago A tokens not measured original MIT

gleicon/mcp-osv

Cursor rule Cursor

Before incorporating any external dependency, verify provenance through official registries: -- npm.org (JavaScript/TypeScript packages) -- crates.io (Rust packages) -- pypi.org (Python packages) -- GitHub (source repositories).

not rated 15 8mo ago A 910 tokens

rails-audit-skill

791

rubyroidlabs/rails-audit-skill

Skill Claude CodeCodex

Perform comprehensive technical reviews of Ruby on Rails applications. Runs automated analysis tools (RubyCritic, Brakeman, bundler-audit, Gitleaks, Debride, linters, SimpleCov, Rails stats, Rails ERD), analyzes code for architecture, security, authorization (Pundit/CanCanCan), dead code, and design issues, and…

not rated 15 +1 1mo ago B 118 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: