Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

scanner

913

bawbel/scanner

MCP server Claude CodeCodexCursor +2

Security linter and scanner for MCP servers and AI skill files. Detects toxic flows, prompt injection, tool poisoning, and supply chain attacks. Runs locally from the bawbel-scanner Python package.

not rated 10 2mo ago A tokens not measured

shell-audit

915

akasecurity/claude-tools

Skill Claude CodeCodex

Audit the shell startup chain (the rc file + every file it sources) for hardcoded credentials, persistence-suspicious patterns, duplicate or dangling aliases, and git-baseline drift. USE WHEN the user wants to review, secure, clean up, or maintain their shell aliases or startup files; check /.zshrc / /.bashrc for…

not rated 10 1mo ago A 112 tokens original MIT

dxkit-action

916

vyuh-labs/dxkit

Skill Claude Code

Read a dxkit report and execute fixes — prioritize findings by severity, plan the fix sequence, run the fix, verify the score moved, re-baseline if appropriate. Supports a SCOPED pass to burn down one category at a time (dependency/BOM vulnerabilities, security, code quality, tests, docs), and a BASELINE-CLEANUP pass…

not rated 10 yesterday A SkillSpector: warn 201 tokens original MIT

web-security-auditor

917

0x-Professor/Agent-Skills-Hub

Skill Claude CodeCodex

Aggregate SAST, SCA, DAST, secrets, API, frontend, and backend security checks into one report.

not rated 10 6mo ago A 30 tokens original Apache-2.0

skill-sanitizer

918

animaresearch/skills

Skill Claude CodeCodex

Pre-share leak scanner for Claude Code skills (or any folder). Scans BEFORE you publish for secrets (API keys, tokens, private keys, .env values, high-entropy strings), PII (emails/phones), local machine paths (C:\Users\ , /home/ , /Users/ , UNC, internal hostnames), and client/proper-noun names from a LOCAL private…

not rated 10 2mo ago A 193 tokens

sealed-secrets

919

ashfulcra/fulcra-tools

Skill Claude Code

Use when an agent or role needs credentials on a machine that does not have them — a fresh container, a rebuilt host, a successor session — or when sealing, rotating, or verifying secrets kept in a shared object store.

not rated 10 yesterday A SkillSpector: warn 49 tokens original MIT

ChainAware/behavioral-prediction-mcp

Skill Claude CodeCodex

Use this skill whenever a user asks about wallet safety, fraud risk, rug pull detection, wallet behavior analysis, DeFi personalization, on-chain reputation scoring, AML checks, token ranking by holder quality, airdrop screening, lending risk, token launch auditing, or AI agent trust scoring. Triggers on questions…

not rated 10 1mo ago A 440 tokens original MIT

ziran

921

taoq-ai/ziran

Skill Claude CodeCodex

ZIRAN is an open-source security testing framework for AI agents. It discovers dangerous tool chain compositions via knowledge graph analysis, detects execution-level side effects (not just text output), and runs multi-phase trust exploitation campaigns that model real attacker behavior.

not rated 10 4d ago A 0 tokens original Apache-2.0

circom-auditor

923

zksecurity/zk-skills

Skill Codex

Audit Circom circuits for soundness, completeness, privacy, and constraint bugs. Use when the user asks to audit, review, check, or find vulnerabilities in Circom code, or when they ask to run circom-auditor on a repo or specific .circom files.

not rated 10 1mo ago A 63 tokens original MIT

humanfile

924

zhangyu94/humanfile

Cursor rule Cursor

Respect .human file boundaries - check protection levels before editing any file.

not rated 10 5mo ago A 869 tokens original MIT

agent-shielded

925

Michae2xl/freedom-stack

Skill Claude CodeCodex

Agent Shielded — Agent Privacy Cloud. Private infrastructure for AI agents in one command: Ollama, n8n, Qdrant, Agent Sandbox, Tor Rotator, Privoxy, Gotify, Agent Dashboard + Prometheus, Grafana, Portainer. Zero data leaks. Triggers: 'agent shielded', 'agent privacy', 'AI agent infrastructure', 'private LLM', 'Ollama…

not rated 10 5mo ago B 123 tokens

nis2-incident-report

926

TheDarkMist/nis2-incident-report

Skill Claude CodeCodex

Drafts NIS2 incident reports for a small WordPress agency or freelancer, especially one acting as supply chain to a regulated client rather than as a regulated entity itself. Use this skill whenever someone needs to draft or produce a NIS2 incident notification: a 24-hour early warning, a 72-hour notification, a…

not rated 10 3mo ago A 185 tokens

evm-audit-master

927

austintgriffith/evm-audit-skills

Skill Claude CodeCodex

Master index for EVM smart contract security audit skills. Load this FIRST for every audit to determine which specialized skills to load. Contains routing table and audit methodology.

not rated 10 2mo ago A 38 tokens

JS Reverse Analyzer

929

sjhhh024-cmyk/Spider-JS-Mcp-Skills

Skill Claude CodeCodex

A general-purpose guide for examining JavaScript code to identify website encryption, request signatures, and anti-bot checks, then documenting the findings in Python.

not rated 10 7mo ago A 37 tokens original Apache-2.0

ag2ai/ag2-skills

Skill Claude CodeCodex

Govern an AG2 multi-agent network — identity (Passport, Resume), per-agent Rule with two top-level blocks access (AccessBlock) and limits (LimitsBlock, which nests RateBlock + InboxBlock), the swappable HubArbiter / RuleBasedArbiter access-&-routing seam, AuthAdapter / AuthRegistry registration, channel-level…

not rated 10 1mo ago A 264 tokens original Apache-2.0

mastra-system-check

932

goldk3y/mastra-system-check

Skill Claude CodeCodex

Comprehensive system check for Mastra AI agent projects. Validates configuration, agents, workflows, memory, tools, prompts, and security across 66 rules organized by priority. Use when setting up new projects, debugging issues, reviewing code, or preparing for production deployment.

not rated 10 7mo ago A 59 tokens original MIT

skills-il/security-compliance

Skill Claude CodeCodex

Not legal advice and not a compliance opinion. Israeli cybersecurity regulatory framework guidance covering INCD (Ma'arach HaSyber) national directives, Bank of Israel Directive 364, the consolidated IT, information security and cyber framework that took effect 18/05/2026 and repealed Directives 357, 361 and 363, plus…

not rated 10 10d ago A SkillSpector: pass 206 tokens original MIT

skill-security-audit

936

smartchainark/skill-security-audit

Skill Claude CodeCodex

Detect malicious patterns in AI Agent skills — 13 detectors for backdoors, credential theft, data exfiltration, and supply-chain attacks. Based on SlowMist's ClawHub threat intelligence (472+ malicious skills). Pure Python, zero dependencies.

not rated 10 7mo ago A 55 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: