Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

gsd-security-auditor

889

mrmyothet/zach-hair-studio

Agent Claude Code

Verifies threat mitigations from PLAN.md threat model exist in implemented code. Produces SECURITY.md. Spawned by /gsd-secure-phase.

not rated 11 28d ago A 37 tokens original MIT

euzun/security-paper-writing

Skill Claude CodeCodex

Write publication-ready papers for top security, privacy, and cryptography venues (IEEE S&P, ACM CCS, USENIX Security, NDSS, PETS, CRYPTO, Eurocrypt, TCC). Use when drafting papers from research repos in these areas, structuring threat models and security claims, writing game-based or simulation-based proofs, or…

not rated 11 3mo ago A 94 tokens

secret-handling

891

swigerb/squad-pod

Skill Claude CodeCodex

Never read .env files or write secrets to .squad/ committed files.

not rated 11 4mo ago A 19 tokens

pr-reviewer

892

synaptent/aragora

Skill Claude CodeCodex

Multi-agent adversarial code review for pull requests.

not rated 11 today A SkillSpector: pass 13 tokens original MIT

secops-siem-search

894

googleSandy/secops-skills

Skill Claude CodeCodex

Use when writing or running Google Security Operations (SecOps/Chronicle) SIEM queries or investigations — UDM filter queries, stats/aggregation, event-event joins, raw log search, reference list lookups, entity investigations (users, hosts, IPs, files, domains), enriched data queries (geolocation, VirusTotal), entity…

not rated 11 6d ago A 109 tokens

clawvet

895

MohibShaikh/clawvet

Skill Claude CodeCodex

Use before installing, trusting, or running any third-party OpenClaw skill, and when the user says "scan this skill", "is this skill safe", "vet/check this skill", "should I install this", "audit my skills", or "clawvet". Also use when reviewing a SKILL.md pulled from ClawHub or an untrusted source.

not rated 11 changed 9d ago A 78 tokens original MIT

asset_hunt

896

intimatep/PenTestClaw

Skill Claude CodeCodex

An asset-discovery workflow that searches Fofa, checks which results are reachable, removes duplicates, and exports the results. Fofa is a search engine for internet-connected systems and services.

not rated 11 5mo ago A 29 tokens

CyberHuaTuo Rescue

897

JinNing6/CyberHuaTuo

Skill Claude CodeCodex

An AI-assisted workflow for diagnosing and fixing coding errors, agent problems, and security issues. CyberHuaTuo is the name of the included AI clinic concept.

not rated 11 today A SkillSpector: pass 52 tokens original Apache-2.0

joesandboxmcp

898

joesecurity/joesandboxMCP

MCP server Claude CodeCodexCursor +2

MCP server "joesandboxmcp" as configured in joesecurity/joesandboxMCP. Runs locally from the joesandboxMCP Python package.

not rated 11 1y ago A tokens not measured original MIT

mint

899

AgriciDaniel/claude-mint

Plugin Claude Code

Bundles 1 skill · 27 tokens together

Intelligent Linux system assistant for Cinnamon-based desktops. Directive-based workflows for security hardening, system updates, GPU management, desktop customization, performance tuning, and troubleshooting.

not rated 11 5mo ago A tokens not measured original MIT

write-detection-rule

901

akasecurity/ai-tc

Skill Claude CodeCodex

This skill teaches Claude Code how to write detection rules for the AI Traffic Control rule engine. Read this before creating or modifying anything in rules/. The full rule schema is Rule in packages/schema/src/zod/rule.ts — it is the source of truth for every field below.

not rated 11 today A SkillSpector: warn 0 tokens original Apache-2.0

quantakrypto

902

quantakrypto/pqc-tools

MCP server Claude CodeCodexCursor +2

quantakrypto MCP — post-quantum readiness for AI coding agents via the Model Context Protocol. Zero runtime dependencies (stdio JSON-RPC implemented in-house). Runs locally from the @quantakrypto/mcp npm package.

not rated 11 18d ago A tokens not measured original Apache-2.0

osint-investigation

903

sumba101/OSINT-AI-Agent

Skill Claude Code

OSINT investigation toolkit for profiling individuals. Uses Holehe for email-to-account discovery, Sherlock for username-to-social-media mapping, and GHunt for Gmail account intelligence. All tool outputs are saved to files for analysis.

not rated 11 +1 8mo ago A 48 tokens original MIT

security-scan

904

Ray0907/security-scan

Skill Claude CodeCodex

Use when a user asks to scan a repository for dependency vulnerabilities, insecure code patterns, CVEs, or OWASP Top 10 risks.

not rated 11 +1 13d ago A 32 tokens original MIT

lingfengz/llm-dengbao-assessment

Skill Claude CodeCodex

A Chinese-language assessment method for checking large-language-model systems against China’s classified cybersecurity protection requirements and related AI security standards.

not rated 11 1mo ago A 234 tokens original MIT

ai-security

906

bestagentkits/agency-skills

Skill Codex

Use when assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, or agent tool abuse. Covers MITRE ATLAS technique mapping, injection signature detection, and adversarial robustness scoring.

not rated 11 +1 2mo ago A 48 tokens original MIT

web

907

securityfortech/hacking-skills

Plugin Claude Code

Bundles 28 skills · 2,564 tokens together

Web application security skills covering recon, authentication, authorization, session management, injection, client-side attacks, and business logic. Distilled from OWASP WSTG, security research, and bug bounty writeups.

not rated 11 6mo ago A tokens not measured

authentication-setup

908

autohandai/community-skills

Skill Claude CodeCodex

Design and implement authentication and authorization systems. Use when setting up user login, JWT tokens, OAuth, session management, or role-based access control. Handles password security, token management, SSO integration.

not rated 11 +1 1mo ago A 44 tokens original Apache-2.0

NovaCode37/claude-security-skills

Plugin Claude Code

Bundles 8 skills · 690 tokens together

Security skills for Claude Code: secret scanning, Python SAST, prompt-injection testing, and HTTP, JWT, Dockerfile, CORS and dependency auditing. Runs on the standard library with no runtime dependencies.

not rated 11 3d ago A tokens not measured original MIT

Snyk

911

snyk/agentic-integration-wrappers

Plugin Gemini CLI

MCP configuration declaring 1 server: snyk.

not rated 11 3d ago A tokens not measured original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: