Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

penetration-tester

819

chandrudp29/skillhub

Skill Claude CodeCodex

Authorized penetration tester persona — offensive security specialist for network, web app, cloud, and Active Directory assessments. Requires explicit authorization.

not rated 13 2mo ago A 30 tokens original MIT

mcp-diagnostics

820

lin037/mcp-diagnostics-trae

MCP server Claude CodeCodexCursor +2

Website & Server Diagnostics MCP Server. DNS, SSL, HTTP headers, security scan, performance audit. Runs locally from the mcp-diagnostics npm package.

not rated 13 1y ago A tokens not measured original MIT

sb-siem-mcp

821

Sbharadwaj05/sb-siem-mcp

MCP server Claude CodeCodexCursor +2

MCP server "sb-siem-mcp" as configured in Sbharadwaj05/sb-siem-mcp. Runs locally from the sb-siem-mcp Python package.

not rated 13 12d ago A tokens not measured

crowdstrike-mcp

822

willwebster5/crowdstrike-mcp

MCP server Claude CodeCodexCursor +2

MCP server for the CrowdStrike Falcon platform. Runs locally from the crowdstrike-mcp Python package.

not rated 13 10d ago A tokens not measured original MIT

attack-chain

823

2233admin/reverse-skill-evolver

Skill Claude CodeCodex

A security-testing skill that plans multi-stage attack paths and coordinates specialized security tasks. It covers scenarios such as moving from an external foothold toward internal systems, but is not needed for single tasks like port scanning.

not rated 13 1mo ago A ✓ AI review 0 tokens original MIT

aegis

824

getaegis/aegis

Skill Claude Code

Route API calls through the Aegis credential proxy — keeps raw API keys out of the agent context.

not rated 13 1mo ago A 24 tokens original Apache-2.0

burpwn

825

own2pwn-fr/burpwn

Plugin Claude Code

Bundles 1 skill · 116 tokens together

AI-driven intercepting proxy + rootless execution sandbox for web pentesting. Installs the burpwn skill, which teaches the agent to create a session and route target-facing network commands through burpwn exec so their traffic is captured, MITM-decrypted, searchable, replayable, and live-interceptable. Requires the.

not rated 13 +1 19d ago A tokens not measured AGPL-3.0

mitre-mcp

826

Montimage/mitre-mcp

MCP server Claude CodeCodexCursor +2

MCP server for MITRE ATT&CK framework. Runs locally from the mitre-mcp Python package.

not rated 13 9mo ago A tokens not measured original MIT

code-audit-system

827

UserB1ank/code-audit-system

Skill Claude CodeCodex

CVE-oriented multi-agent code audit system. Use when user provides a git repository URL for vulnerability discovery with the goal of submitting CVEs. This skill orchestrates subagents to find exploitable vulnerabilities (RCE, SQLi, Auth Bypass, etc.), write weaponized POCs, and generate CVE-ready reports. ALWAYS use…

not rated 13 +2 3mo ago A 97 tokens

gha-security-review

828

Threat-Vector-Security/guardian-agent

Skill Claude CodeCodex

Attack patterns and real-world examples sourced from the HackerBot Claw campaign analysis by StepSecurity (2025): https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation -->.

not rated 13 +2 3d ago A SkillSpector: pass 0 tokens original Apache-2.0

cybersecurity-lab

829

handnewb/hermes-cybersec-lab

Skill Claude CodeCodex

Turnkey cybersecurity lab — 2,077 skills, 131+ tools, 28 frameworks, and evolving methodology for security research, pentesting, forensics, and threat intelligence. Includes one-step ecosystem cloner for 8 repositories.

not rated 13 1mo ago A 54 tokens original MIT

blackbox-pentest

830

yanglittlecat/blackbox-pentest

Skill Claude CodeCodex

A set of rules for carrying out authorized black-box penetration tests, where the tester examines a system without access to its source code. It defines testing boundaries, safety limits, and the evidence needed to report a vulnerability.

not rated 13 15d ago A 152 tokens

hacker-asm-decompile

831

shangdi-w/-skills

Skill Claude CodeCodex

A toolkit for taking software apart to inspect how it works, across formats such as Android packages, Windows programs, Linux binaries, JavaScript, and firmware.

not rated 13 +3 3mo ago A 97 tokens

1Password/cursor-plugin

Skill Claude CodeCodex

Manage 1Password Developer Environments via the bundled MCP server. Use when creating, importing, or mounting .env files; listing Environment variable names; adding or updating Environment variables; renaming environments; or calling any 1Password MCP tool. On macOS/Linux, import-from-.env includes createlocalenvfile…

not rated 13 +1 25d ago A 118 tokens original MIT

codefrog7426-gzkos/responsible-disclosure

Skill Claude CodeCodex

Draft a responsible vulnerability disclosure policy for SaaS/devtools: scope, safe harbor posture, channels, timelines, and what not to do — no exploit detail. Triggers: responsible disclosure policy, vulnerability disclosure policy VDP, security.txt companion policy, report vulnerability page, coordinated disclosure.…

not rated 13 1mo ago A 118 tokens original MIT

lark-bot-permissions

834

cloveric/tarocub

Skill Claude Code needs its repo

A browser-driven helper for opening permission scopes for an existing Feishu bot app. Feishu is a workplace collaboration platform, and permission scopes control what a bot can read or do.

not rated 13 +3 yesterday A SkillSpector: warn 157 tokens original MIT

image-audit

836

xiaowu89/skill-function

Skill Claude Code

An image-safety review skill that compresses local images and sends them to an API to check for sexual, political, and violent content.

not rated 12 1mo ago A 85 tokens original MIT

code-reviewer

837

h315uk3/symbiosis

Agent Claude Code

Reviews pull requests for security vulnerabilities, logic bugs, data loss risks, and API misuse. Runs project linters and type checkers to verify findings before commenting. Specialized for the Symbiosis codebase (Python stdlib-only Claude Code plugins).

not rated 12 5mo ago A 53 tokens AGPL-3.0

scan-cca

838

33Audits/cca-audit-agent

Cursor rule Cursor

Scan Solidity contracts for Uniswap CCA vulnerabilities — core bugs and integration footguns. Invoke by asking "scan for CCA vulnerabilities" or "run CCA audit".

not rated 12 5mo ago A 0 tokens

tap

839

holonym-foundation/tap-oss

MCP server Claude CodeCodexCursor +2

Credential isolation for AI agents: placeholder secrets, policy checks, optional human approval. Remote server at mcp.tap.human.tech.

not rated 12 1mo ago A tokens not measured original Apache-2.0

ai-security

840

Renvia-code/best-cursor-rules

Cursor rule Cursor

Security best practices for LLM/AI applications - prompt injection defense, rate limiting, PII protection.

not rated 12 9mo ago A 0 tokens original CC0-1.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: