Agent Claude Code
Verifies threat mitigations from PLAN.md threat model exist in implemented code. Produces SECURITY.md. Spawned by /gsd-secure-phase.
24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.
Agent Claude Code
Verifies threat mitigations from PLAN.md threat model exist in implemented code. Produces SECURITY.md. Spawned by /gsd-secure-phase.
Skill Claude CodeCodex
Write publication-ready papers for top security, privacy, and cryptography venues (IEEE S&P, ACM CCS, USENIX Security, NDSS, PETS, CRYPTO, Eurocrypt, TCC). Use when drafting papers from research repos in these areas, structuring threat models and security claims, writing game-based or simulation-based proofs, or…
Skill Claude CodeCodex
Never read .env files or write secrets to .squad/ committed files.
Skill Claude CodeCodex
Multi-agent adversarial code review for pull requests.
Plugin Claude Code
Bundles 37 commands, 10 agents, 28 hooks · 2,298 tokens together
Shell-level guardrails for Claude Code. Command blocking, code security scanner, self-teaching, token economy, agent routing, MCP profiles, and session memory.
Skill Claude CodeCodex
Use when writing or running Google Security Operations (SecOps/Chronicle) SIEM queries or investigations — UDM filter queries, stats/aggregation, event-event joins, raw log search, reference list lookups, entity investigations (users, hosts, IPs, files, domains), enriched data queries (geolocation, VirusTotal), entity…
Skill Claude CodeCodex
Use before installing, trusting, or running any third-party OpenClaw skill, and when the user says "scan this skill", "is this skill safe", "vet/check this skill", "should I install this", "audit my skills", or "clawvet". Also use when reviewing a SKILL.md pulled from ClawHub or an untrusted source.
Skill Claude CodeCodex
An asset-discovery workflow that searches Fofa, checks which results are reachable, removes duplicates, and exports the results. Fofa is a search engine for internet-connected systems and services.
Skill Claude CodeCodex
An AI-assisted workflow for diagnosing and fixing coding errors, agent problems, and security issues. CyberHuaTuo is the name of the included AI clinic concept.
MCP server Claude CodeCodexCursor +2
MCP server "joesandboxmcp" as configured in joesecurity/joesandboxMCP. Runs locally from the joesandboxMCP Python package.
Plugin Claude Code
Bundles 1 skill · 27 tokens together
Intelligent Linux system assistant for Cinnamon-based desktops. Directive-based workflows for security hardening, system updates, GPU management, desktop customization, performance tuning, and troubleshooting.
Plugin Claude Code
Bundles 10 skills, 5 commands, 1 hook · 778 tokens together
Software Development Lifecycle standards and requirements for project quality, security, and compliance.
Skill Claude CodeCodex
This skill teaches Claude Code how to write detection rules for the AI Traffic Control rule engine. Read this before creating or modifying anything in rules/. The full rule schema is Rule in packages/schema/src/zod/rule.ts — it is the source of truth for every field below.
MCP server Claude CodeCodexCursor +2
quantakrypto MCP — post-quantum readiness for AI coding agents via the Model Context Protocol. Zero runtime dependencies (stdio JSON-RPC implemented in-house). Runs locally from the @quantakrypto/mcp npm package.
Skill Claude Code
OSINT investigation toolkit for profiling individuals. Uses Holehe for email-to-account discovery, Sherlock for username-to-social-media mapping, and GHunt for Gmail account intelligence. All tool outputs are saved to files for analysis.
Skill Claude CodeCodex
Use when a user asks to scan a repository for dependency vulnerabilities, insecure code patterns, CVEs, or OWASP Top 10 risks.
lingfengz/llm-dengbao-assessment
Skill Claude CodeCodex
A Chinese-language assessment method for checking large-language-model systems against China’s classified cybersecurity protection requirements and related AI security standards.
Skill Codex
Use when assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, or agent tool abuse. Covers MITRE ATLAS technique mapping, injection signature detection, and adversarial robustness scoring.
securityfortech/hacking-skills
Plugin Claude Code
Bundles 28 skills · 2,564 tokens together
Web application security skills covering recon, authentication, authorization, session management, injection, client-side attacks, and business logic. Distilled from OWASP WSTG, security research, and bug bounty writeups.
Skill Claude CodeCodex
Design and implement authentication and authorization systems. Use when setting up user login, JWT tokens, OAuth, session management, or role-based access control. Handles password security, token management, SSO integration.
NovaCode37/claude-security-skills
Plugin Claude Code
Bundles 8 skills · 690 tokens together
Security skills for Claude Code: secret scanning, Python SAST, prompt-injection testing, and HTTP, JWT, Dockerfile, CORS and dependency auditing. Runs on the standard library with no runtime dependencies.
Plugin Cursor
Bundles 31 skills, 1 MCP server · 1,499 tokens together
ControlKeel governance for Cursor — validation, findings, budgets, proofs, memory, agent routing, and human review via MCP.
snyk/agentic-integration-wrappers
Plugin Gemini CLI
MCP configuration declaring 1 server: snyk.
google/chrome-enterprise-premium-mcp
Plugin Gemini CLI ✓ vendor
Bring AI agents to Chrome Enterprise Premium security management.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: