Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

tene

793

tene-ai/tene

Cursor rule Cursor

Secret management with tene.

not rated 15 2mo ago A 549 tokens original MIT

ouroboros-pentest

794

g4sk0/mergen-mcp

Skill Claude CodeCodex

Use when the user sends BB:, CTF:, Target:, or Pentest: followed by a domain or IP — activates autonomous JSON-only daemon mode for authorized penetration testing, bug bounty, and CTF challenges.

not rated 15 +1 6mo ago A 47 tokens original MIT

tenable/cyberagents-exchange

Agent Claude Code

High-fidelity external attack-path agent for Tenable Cloud Security: running, internet-exposed workloads with a reachable service, an exploitable publicly-evidenced vulnerability (EPSS or CISA KEV), tiered by identity blast radius.

not rated 15 +1 yesterday A 55 tokens

Baiyajing/HarnessRisk

Skill Claude CodeCodex needs its repo

Controlled mock service tools for OpenClaw safety evaluation. Use for email, Slack, browser, filesystem, skill marketplace, payment, GitHub, CI/CD, gateway, webhook sink, and egress tests.

not rated 15 +3 24d ago A 49 tokens original MIT

CrowdStrike/fusion-skills

Plugin Claude Code

Bundles 7 skills, 3 hooks · 593 tokens together

CrowdStrike Falcon Fusion skills for authoring, deploying, and executing Fusion workflows. Includes live action discovery, YAML authoring with schema validation, workflow import and release, execution monitoring, and Falcon Next-Gen SIEM lookup files.

not rated 14 changed 3d ago A tokens not measured original MIT

MartinPuli/createAnApp

Skill Codex

Audit an app, website, metadata, SDKs, and marketing for privacy, security, AI transparency, consumer claims, subscriptions, content rights, user-generated content, children, health, financial, export, and platform-policy risks. Use before TestFlight, submission, release, paid marketing, or after adding tracking…

not rated 14 23d ago A 84 tokens original MIT

corsair

799

grcorsair/corsair

Skill Claude CodeCodex

Cryptographic compliance verification. Sign security tool output into verifiable CPOEs (JWT-VC), verify vendor proofs via trust.txt, detect drift with diff, and assess third-party risk. Use when the user mentions compliance proofs, CPOE, trust.txt, SCITT, vendor assessment, GRC evidence, or compliance drift.

not rated 14 6mo ago A 70 tokens original Apache-2.0

supply-chain-guard

800

ZarK/ai-supply-chain-guard

Skill Claude CodeCodex

Use before installing, updating, auditing, or executing dependencies, package-manager commands, project generators, CI actions/workflows, release jobs, IDE extensions, MCP servers, or AI-agent tools. Also use when investigating suspected compromise or advisories, debugging publish or release authentication, or…

not rated 14 13d ago A 71 tokens original MIT

sidclaw-governance

801

sidclawhq/platform

Skill Claude CodeCodex

Add policy evaluation, human approval, and audit trails to any tool. Powered by SidClaw.

not rated 14 5d ago A 27 tokens original Apache-2.0

mailfathom

802

Krzysztof318/MailFathom

MCP server Claude CodeCodexCursor +2

Security-first, self-hosted email archive with search, cited answers, and sending for AI agents. Remote server at {mailfathom_host}.

not rated 14 today A tokens not measured original AGPL-3.0

JiuNian3219/architext

Skill Claude Code

Decompose requirements into roadmap tasks. Must run in isolated context/subagent. Protocol-invoked only; do not auto-trigger from casual user requests.

not rated 14 4mo ago A 37 tokens original MIT

humanbound-test

804

humanbound/plugins

Plugin Claude Code

Bundles 4 skills, 6 commands · 402 tokens together

Run adversarial / security tests against your local AI agent. Detects your FastAPI server, exposes it via ngrok, you author bot-config.json with your endpoints / auth / payload, the plugin dispatches via the humanbound MCP — results delivered by email (or run /humanbound-test:resume to watch the polling loop and f.

not rated 14 4d ago A tokens not measured original Apache-2.0

claudii-exploratores

805

SOsintOps/claudii-exploratores

Skill Claude CodeCodex

OSINT investigation toolkit. Use when the user wants to investigate or gather open-source intelligence on an indicator — a person's name, email, username, domain, IP address, phone number, company, coordinates, IBAN, or crypto address — and needs the right set of curated OSINT search links, or wants to validate an…

not rated 14 +1 2mo ago A 168 tokens AGPL-3.0

osquery

806

kousen/OsqueryMcpServer

Skill Claude Code

System diagnostics using osquery. Use when asked about CPU usage, memory consumption, network connections, running processes, disk I/O, fan speeds, temperatures, or system security. Triggers: "why is my computer slow", "what's using memory", "what's using CPU", "network connections", "suspicious processes", "system…

not rated 14 2mo ago A 126 tokens original MIT

palo-alto-mcp

807

cdot65/pan-os-mcp

MCP server Claude CodeCodexCursor +2

MCP server "palo-alto-mcp" as configured in cdot65/pan-os-mcp. Runs locally from the palo-alto-mcp Python package.

not rated 14 1y ago A tokens not measured

fortianalyzer-mcp

808

rstierli/fortianalyzer-mcp

MCP server Claude CodeCodexCursor +2

MCP server "fortianalyzer-mcp" as configured in rstierli/fortianalyzer-mcp. Runs locally from the fortianalyzer-mcp Python package.

not rated 14 +2 10d ago A tokens not measured original MIT

prodcheck-review

809

FarzamHabibi/pre-production-checklist

Skill Claude CodeCodex

Review this codebase against the prodcheck pre-production checklists — security, performance, scale, integrations and post-launch readiness. Use when asked to check whether a project is ready to ship, to audit an area before launch, or to work through a specific checklist. Produces evidence with file:line citations…

not rated 14 +3 4d ago A 70 tokens

cube-sandbox

810

runzhliu/aik8s

Skill Claude CodeCodex

Execute requested Python code inside an isolated CubeSandbox MicroVM. Use when the user explicitly asks for CubeSandbox, MicroVM isolation, offline execution, or proof that code did not run on the DSH host.

not rated 14 +5 yesterday A 46 tokens

bb-strategist

812

YX-hueimie/claude-omni

Agent Claude Code

Vulnerability-hunting strategist. The main agent spawns six concurrent instances of this subagent when stuck, hitting walls, showing quit semantics, or about to ask the user "what next" during hunting. Each instance carries one of six thinking perspectives (Chainer / Skeptic / Lateral / DevPsych / Scope-Expander /…

not rated 13 1mo ago A 112 tokens

synapse-layer

813

SynapseLayer/synapse-layer

Skill Claude CodeCodex

AES-256-GCM encrypted persistent memory layer for Hermes Agent. Provides encrypted cross-session memory, Trust Quotient (TQ) scoring, and automatic recall across ALL channels (Telegram, WhatsApp, CLI, Discord).

not rated 13 7d ago A SkillSpector: warn 48 tokens original Apache-2.0

sigil-preflight

814

Ju571nK/sigil

Skill Claude CodeCodex

Before running a risky shell command, check it with Sigil's assess and refuse anything Sigil would block. Use whenever you are about to execute a destructive, privileged, or unfamiliar command.

not rated 13 yesterday A ✓ AI review 46 tokens original Apache-2.0

linux-security-audit

815

jonaslejon/linux-security-audit-plugin

Plugin Claude Code

Bundles 1 skill · 149 tokens together

Audit a Linux host's security hardening posture and produce a risk-ranked report, using both passive config inspection and active service probing. Runs against a live host, a mounted image (--root), or a container.

not rated 13 29d ago A tokens not measured original MIT

skill-checker

816

maludb-ed/skill-safety-checker

Plugin Claude Code

Bundles 1 skill · 79 tokens together

Security-audits installed Claude Code skills and marketplace plugins for data capture, secret exfiltration, prompt injection, and malicious code. Always leads with a disclaimer that detection cannot be guaranteed complete.

not rated 13 29d ago A tokens not measured

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: