Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

pi-security

841

pi-sloane/claude-plugin

Plugin Claude Code

Bundles 6 skills, 1 MCP server · 228 tokens together

Pi Security workflows for Claude Code and Cowork: investigate findings, review security posture, fetch remediation guidance, start design reviews, submit Markdown reports, and query secure-development playbooks through Pi's hosted MCP server.

not rated 12 17d ago A tokens not measured original MIT

willwebster5/agent-skills

Plugin Claude Code

Bundles 1 skill · 61 tokens together

Design multi-event behavioral detection rules using CrowdStrike NG-SIEM correlate() function for attack chain detections across AWS, EntraID, and CrowdStrike data sources.

not rated 12 4mo ago A tokens not measured original MIT

quality-critic

843

ensingm2/AI-threat-modeling-rulesets

Skill Claude Code

Adversarial validation for all stages. Detects fabrications, identifies analytical flaws, challenges assumptions, makes approval decisions. Seeks problems rather than confirming quality. Does NOT complete deliverables or fix issues.

not rated 12 6mo ago A 45 tokens original MIT

human-mcp-server

846

HumanSecurity/human-mcp-server

MCP server Claude CodeCodexCursor +2

Model Context Protocol (MCP) server providing comprehensive cybersecurity intelligence from HUMAN Security. Offers real-time attack monitoring, threat detection, fraud prevention, PCI DSS compliance validation, and supply chain security for AI-powered app. Runs locally from the @humansecurity/human-mcp-server npm…

not rated 12 2mo ago A tokens not measured original MIT

android-review

848

liuyi0808/android-review

Plugin Claude Code

Bundles 7 skills · 625 tokens together

Android development review skills covering OWASP MASVS security audit, Clean Architecture, performance optimization, Jetpack Compose best practices, privacy compliance auditing, and Google Play Store compliance.

not rated 12 +1 16d ago A tokens not measured original MIT

koma-gate-mcp

849

swnotmetal/Project-Koma

MCP server Claude CodeCodexCursor +2

One of 2 in server.json

Classifies prompt injection, jailbreaks, and out-of-scope user input before agents act on it. Runs locally from the koma-gate-mcp npm package. Needs 6 environment variables to run.

not rated 12 today A tokens not measured original MIT

envault-manager

850

altic-dev/envault

Plugin Claude Code

Bundles 1 skill · 35 tokens together

Use when managing environment variables across projects, working with .env files, setting up project secrets, or using the envault CLI tool for centralized env var management.

not rated 12 8mo ago A tokens not measured original Apache-2.0

yakit-hotpatch-skill

851

XiangXtreme/yakit-hotpatch-skill

Skill Claude CodeCodex

Use when creating, fixing, or reviewing Yakit Web Fuzzer hotload or Yakit MITM hotpatch scripts in Yaklang. Covers custom fuzztag functions, beforeRequest/afterRequest hooks, mirrorHTTPFlow extraction, retry/failure/mock handlers, encrypted mini-program traffic decrypt-edit-reencrypt, bizContent-style JSON wrappers…

not rated 12 +1 4mo ago A 109 tokens

ida-pro-mcp

852

QYmag1c/ida-pro-mcp-multi

MCP server Claude CodeCodexCursor +2

Vibe reversing with IDA Pro. Runs locally from the ida-pro-mcp Python package.

not rated 12 2mo ago A tokens not measured original MIT

architect-to-product

853

BernhardJackiewicz/architect-to-product

MCP server Claude CodeCodexCursor +2

One of 2 in .mcp.json

MCP server that turns software architectures into tested, secure products. Runs locally from the architect-to-product npm package.

not rated 12 11d ago A tokens not measured original MIT

security-audit

854

RewritingTheCode/workshop

Command Claude Code

Full security pass - verify, validate and harden this repo against its real threat model.

not rated 12 +2 2d ago A 17 tokens original MIT

huntbot

855

Matador-og/huntbot

Plugin Claude Code

Bundles 1 skill · 48 tokens together

Autonomous offensive security pipeline — bug bounty, pentesting, red teaming.

not rated 12 4d ago A tokens not measured

add-login

856

sso-ss/vibe-ship-it

Skill Claude CodeCodex

Adds user authentication. Triggers: 'login', 'log in', 'sign in', 'sign up', 'register', 'authentication', 'auth', 'only I can see', 'protect this page', 'private page', 'admin area', 'user accounts', 'members only', 'password protect'.

not rated 12 +2 5mo ago A 65 tokens original MIT

keeper-secrets

857

Keeper-Security/keeper-agent-kit

Plugin Claude Code

Bundles 1 skill · 184 tokens together

Retrieve, inject, and manage secrets from Keeper Vault using KSM CLI (ksm) for developer workflows, including ksm exec, interpolate, and Keeper notation.

not rated 12 +1 3mo ago A tokens not measured

bug-hunting

858

m4vic/bug-hunting

Skill Claude CodeCodex

Bug bounty hunting and penetration testing skills for Claude, Codex, and other agentic AI tools.

not rated 12 +2 18d ago A 24 tokens original MIT

encryption-file-ops

859

hebulin/mcp-read-file-server

Skill Claude CodeCodex

A guide for working with files protected by enterprise encryption software when an AI agent’s normal file tools show unreadable text.

not rated 12 +3 changed yesterday A 51 tokens original MIT

outrider-recon

860

Ap6pack/outrider-recon

Plugin Claude Code

Bundles 11 skills · 635 tokens together

Claude-native authorized external recon and ASM methodology bundle with 90 documented capabilities across 11 skills, deterministic Python controls, an optional loopback-only limited-control web plane, explicit human-reviewed finding promotion, and optional fixed policy-gated MCP enrichment. It does not provide…

not rated 12 +3 today A tokens not measured

kyvault-ops

861

webkubor/kyvault

Skill Claude CodeCodex

An encrypted local vault for storing API keys, server credentials, tokens, and device records. Agents can list, read, update, delete, and inject these secrets into local or CI commands.

not rated 12 +1 yesterday A 52 tokens original MIT

pentest

862

8NobleTruths/sabba

Command Claude Code

Recon and scan an authorized target with Sabba's security tools, then confirm findings.

not rated 11 1mo ago A 16 tokens original Apache-2.0

glassbox-framework

863

TheBarmaEffect/glassbox

MCP server Claude CodeCodexCursor +2

Runtime constitutional verification for AI answers — claim reasoning, ECS, red team, audits. Runs locally from the @glassbox-framework/mcp npm package. Needs 4 environment variables to run.

not rated 11 today A tokens not measured original Apache-2.0

vulnicheck

864

andrasfe/vulnicheck

MCP server Claude CodeCodexCursor +2

MCP server "vulnicheck" as configured in andrasfe/vulnicheck. Runs in Docker (docker.io/andrasfe/vulnicheck:main). Needs 7 environment variables to run.

not rated 11 6mo ago A tokens not measured original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: