24,655 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Enforces secure database access in C# applications using the full RAILGUARD framework. Covers safe use of ADO.NET, Entity Framework Core, parameterized queries, credential management, and logging hygiene.
Authorized penetration tester persona — offensive security specialist for network, web app, cloud, and Active Directory assessments. Requires explicit authorization.
A security-testing skill that plans multi-stage attack paths and coordinates specialized security tasks. It covers scenarios such as moving from an external foothold toward internal systems, but is not needed for single tasks like port scanning.
★not rated 13 1mo agoA✓ AI review0 tokens
originalMIT
AI-driven intercepting proxy + rootless execution sandbox for web pentesting. Installs the burpwn skill, which teaches the agent to create a session and route target-facing network commands through burpwn exec so their traffic is captured, MITM-decrypted, searchable, replayable, and live-interceptable. Requires the.
★not rated 13▲
+1 19d agoA
tokens not measured
AGPL-3.0
CVE-oriented multi-agent code audit system. Use when user provides a git repository URL for vulnerability discovery with the goal of submitting CVEs. This skill orchestrates subagents to find exploitable vulnerabilities (RCE, SQLi, Auth Bypass, etc.), write weaponized POCs, and generate CVE-ready reports. ALWAYS use…
Attack patterns and real-world examples sourced from the HackerBot Claw campaign analysis by StepSecurity (2025): https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation -->.
★not rated 13▲
+2 3d agoASkillSpector: pass0 tokens
originalApache-2.0
A set of rules for carrying out authorized black-box penetration tests, where the tester examines a system without access to its source code. It defines testing boundaries, safety limits, and the evidence needed to report a vulnerability.
A toolkit for taking software apart to inspect how it works, across formats such as Android packages, Windows programs, Linux binaries, JavaScript, and firmware.
Manage 1Password Developer Environments via the bundled MCP server. Use when creating, importing, or mounting .env files; listing Environment variable names; adding or updating Environment variables; renaming environments; or calling any 1Password MCP tool. On macOS/Linux, import-from-.env includes createlocalenvfile…
Draft a responsible vulnerability disclosure policy for SaaS/devtools: scope, safe harbor posture, channels, timelines, and what not to do — no exploit detail. Triggers: responsible disclosure policy, vulnerability disclosure policy VDP, security.txt companion policy, report vulnerability page, coordinated disclosure.…
A browser-driven helper for opening permission scopes for an existing Feishu bot app. Feishu is a workplace collaboration platform, and permission scopes control what a bot can read or do.
Reviews pull requests for security vulnerabilities, logic bugs, data loss risks, and API misuse. Runs project linters and type checkers to verify findings before commenting. Specialized for the Symbiosis codebase (Python stdlib-only Claude Code plugins).
Scan Solidity contracts for Uniswap CCA vulnerabilities — core bugs and integration footguns. Invoke by asking "scan for CCA vulnerabilities" or "run CCA audit".
Security best practices for LLM/AI applications - prompt injection defense, rate limiting, PII protection.
★not rated 12 9mo agoA0 tokens
originalCC0-1.0
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: