scanner
913MCP server Claude CodeCodexCursor +2
Security linter and scanner for MCP servers and AI skill files. Detects toxic flows, prompt injection, tool poisoning, and supply chain attacks. Runs locally from the bawbel-scanner Python package.
24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.
MCP server Claude CodeCodexCursor +2
Security linter and scanner for MCP servers and AI skill files. Detects toxic flows, prompt injection, tool poisoning, and supply chain attacks. Runs locally from the bawbel-scanner Python package.
falcoschaefer99-eng/michael-security-agent
Skill Claude CodeCodex
Invoked via /security-audit, /michael, or when your orchestrator dispatches for security review.
Skill Claude CodeCodex
Audit the shell startup chain (the rc file + every file it sources) for hardcoded credentials, persistence-suspicious patterns, duplicate or dangling aliases, and git-baseline drift. USE WHEN the user wants to review, secure, clean up, or maintain their shell aliases or startup files; check /.zshrc / /.bashrc for…
Skill Claude Code
Read a dxkit report and execute fixes — prioritize findings by severity, plan the fix sequence, run the fix, verify the score moved, re-baseline if appropriate. Supports a SCOPED pass to burn down one category at a time (dependency/BOM vulnerabilities, security, code quality, tests, docs), and a BASELINE-CLEANUP pass…
Skill Claude CodeCodex
Aggregate SAST, SCA, DAST, secrets, API, frontend, and backend security checks into one report.
Skill Claude CodeCodex
Pre-share leak scanner for Claude Code skills (or any folder). Scans BEFORE you publish for secrets (API keys, tokens, private keys, .env values, high-entropy strings), PII (emails/phones), local machine paths (C:\Users\ , /home/ , /Users/ , UNC, internal hostnames), and client/proper-noun names from a LOCAL private…
Skill Claude Code
Use when an agent or role needs credentials on a machine that does not have them — a fresh container, a rebuilt host, a successor session — or when sealing, rotating, or verifying secrets kept in a shared object store.
ChainAware/behavioral-prediction-mcp
Skill Claude CodeCodex
Use this skill whenever a user asks about wallet safety, fraud risk, rug pull detection, wallet behavior analysis, DeFi personalization, on-chain reputation scoring, AML checks, token ranking by holder quality, airdrop screening, lending risk, token launch auditing, or AI agent trust scoring. Triggers on questions…
Skill Claude CodeCodex
ZIRAN is an open-source security testing framework for AI agents. It discovers dangerous tool chain compositions via knowledge graph analysis, detects execution-level side effects (not just text output), and runs multi-phase trust exploitation campaigns that model real attacker behavior.
asap-protocol/agentic-orchestration
Command Claude CodeCursor
You are a senior security engineer conducting a focused security review of the changes on this branch.
Skill Codex
Audit Circom circuits for soundness, completeness, privacy, and constraint bugs. Use when the user asks to audit, review, check, or find vulnerabilities in Circom code, or when they ask to run circom-auditor on a repo or specific .circom files.
Cursor rule Cursor
Respect .human file boundaries - check protection levels before editing any file.
Skill Claude CodeCodex
Agent Shielded — Agent Privacy Cloud. Private infrastructure for AI agents in one command: Ollama, n8n, Qdrant, Agent Sandbox, Tor Rotator, Privoxy, Gotify, Agent Dashboard + Prometheus, Grafana, Portainer. Zero data leaks. Triggers: 'agent shielded', 'agent privacy', 'AI agent infrastructure', 'private LLM', 'Ollama…
TheDarkMist/nis2-incident-report
Skill Claude CodeCodex
Drafts NIS2 incident reports for a small WordPress agency or freelancer, especially one acting as supply chain to a regulated client rather than as a regulated entity itself. Use this skill whenever someone needs to draft or produce a NIS2 incident notification: a 24-hour early warning, a 72-hour notification, a…
austintgriffith/evm-audit-skills
Skill Claude CodeCodex
Master index for EVM smart contract security audit skills. Load this FIRST for every audit to determine which specialized skills to load. Contains routing table and audit methodology.
the-missing-pink/ai-repository-security-baseline
Cursor rule Cursor
Security rules for preventing secret leakage, injection vulnerabilities, and unsafe code patterns.
sjhhh024-cmyk/Spider-JS-Mcp-Skills
Skill Claude CodeCodex
A general-purpose guide for examining JavaScript code to identify website encryption, request signatures, and anti-bot checks, then documenting the findings in Python.
sergekostenchuk/xray-xhttp-vpn-orchestrator
Skill Claude CodeCodex
Coordinate the local Xray/VLESS/XHTTP VPN workflow, route tasks to internal worker modules, enforce scoped alarms, and accept outputs only after evidence and review.
Skill Claude CodeCodex
Govern an AG2 multi-agent network — identity (Passport, Resume), per-agent Rule with two top-level blocks access (AccessBlock) and limits (LimitsBlock, which nests RateBlock + InboxBlock), the swappable HubArbiter / RuleBasedArbiter access-&-routing seam, AuthAdapter / AuthRegistry registration, channel-level…
Skill Claude CodeCodex
Comprehensive system check for Mastra AI agent projects. Validates configuration, agents, workflows, memory, tools, prompts, and security across 66 rules organized by priority. Use when setting up new projects, debugging issues, reviewing code, or preparing for production deployment.
Zouhair-Boulahlib/Claude-Code-Etymologiae
Agent Claude Code
Reviews code for bugs, security issues, and style problems.
brighton-labs/railguard-framework
Cursor rule Cursor
Briefly describe the purpose of this rule – Insert brief description of the secure behavior or threat mitigated.
Skill Claude CodeCodex
Not legal advice and not a compliance opinion. Israeli cybersecurity regulatory framework guidance covering INCD (Ma'arach HaSyber) national directives, Bank of Israel Directive 364, the consolidated IT, information security and cyber framework that took effect 18/05/2026 and repealed Directives 357, 361 and 363, plus…
smartchainark/skill-security-audit
Skill Claude CodeCodex
Detect malicious patterns in AI Agent skills — 13 detectors for backdoors, credential theft, data exfiltration, and supply-chain attacks. Based on SlowMist's ClawHub threat intelligence (472+ malicious skills). Pure Python, zero dependencies.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: