Security

29,920 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

prowler-cloud/prowler

Skill Claude CodeCodex

Reviews Django migration files for PostgreSQL best practices specific to Prowler. Trigger: When creating migrations, running makemigrations/pgmakemigrations, reviewing migration PRs, adding indexes or constraints to database tables, modifying existing migration files, or writing data backfill migrations. Always use…

not rated 15k +18 today A 96 tokens original Apache-2.0

prowler-cloud/prowler

Skill Claude CodeCodex

Creates Prowler Attack Paths openCypher queries using the Cartography schema as the source of truth for node labels, properties, and relationships. Covers Prowler-specific additions (Internet node, ProwlerFinding, internal isolation labels), $provideruid scoping, and list-property item nodes with typed HAS edges that…

not rated 15k +18 today A 97 tokens original Apache-2.0

prowler-compliance

75

prowler-cloud/prowler

Skill Claude CodeCodex

Creates, syncs, audits and manages Prowler compliance frameworks end-to-end. Covers the two supported JSON schemas (universal multi-provider and legacy per-provider), the SDK model tree (legacy attribute classes, universal ComplianceFramework, ConfigRequirements guardrails), output formatters (legacy per-framework +…

not rated 15k +18 today A 227 tokens original Apache-2.0

browse

76

yc-software/qm

Skill Claude CodeCodex

Drive a real stealth browser from your shell — act on websites (order food, file an expense, pull data behind a login), with per-person persistent sign-ins via the provider's managed auth (Kernel, Anchor, or Browserbase — picked by which API key you have). Use for ACTING on a site; to just read a page, use curl/wget…

not rated 15k +68 today A 101 tokens original MIT

google-drive-sheets

77

yc-software/qm

Skill Claude CodeCodex

Find, read, export, edit, and manage the user's Google Drive, Docs, Sheets, and Slides through per-user OAuth.

not rated 15k +68 today A 31 tokens original MIT

qazbnm456/awesome-web-security

Skill Claude CodeCodex

Looks up curated web security learning resources (XSS, SQLi, CSRF, SSRF, OAuth/JWT, deserialization, SAML, recon, evasion, defensive tooling, CTF). Filters by topic, difficulty, language, and resource type. Returns top references with archive fallbacks. Defensive and educational use only.

not rated 14k +14 13d ago A 71 tokens

review-pr

80

blackboardsh/electrobun

Skill Claude CodeCodex

Review a GitHub pull request from its link, read the PR description, inspect the code locally only when useful, and judge whether the change is safe to run from a security and runtime-safety perspective. Use only after the user pastes a PR URL. Handle one PR at a time, make a clear merge/close/supersede…

not rated 13k +10 5d ago A 87 tokens original MIT

reviewer

81

elie222/inbox-zero

Agent Claude Code

Use when implementation is complete and PR-ready to review the current diff for security, DRY opportunities, simplicity, and abstraction quality.

not rated 12k today A 29 tokens

oauth

82

vercel-labs/portless

Skill Claude CodeCodex ✓ vendor

Configure OAuth providers (Google, Apple, Microsoft, Facebook, GitHub, etc.) to work with portless local dev URLs. Use when setting up OAuth redirect URIs, fixing "redirecturimismatch" or "invalid redirect" errors, configuring sign-in providers for local development, or when a provider rejects .localhost subdomains.…

not rated 11k +96 5d ago A 115 tokens original Apache-2.0

cube-sandbox

83

TencentCloud/CubeSandbox

Skill Claude CodeCodex

A security-focused guide for running Python code and shell commands in Cube Sandbox, an isolated environment for executing code.

not rated 11k 6d ago B 202 tokens

design-reviewer

84

MemTensor/MemOS

Agent Claude Code

Design-review sub-agent. Reviews design docs across the four dimensions of architecture, interface, performance, and security, covering MemOS's multi-memory / multi-storage backend constraints.

not rated 11k +50 today A 38 tokens original Apache-2.0

data-privacy-stack/presidio

Instructions file GitHub Copilot

Copilot instructions for data-privacy-stack/presidio, covering presidio development & review instructions, core philosophy, backward compatibility, cross-component changes and security & privacy.

not rated 11k +12 3d ago A 1,679 tokens original MIT

data-privacy-stack/presidio

Instructions file GitHub Copilot

Instructions for data-privacy-stack/presidio, covering recognizer changes, the load-bearing rule: test the configuration path, placement and naming, pattern scores and context words.

not rated 11k +12 3d ago A 2,195 tokens original MIT

presidio AGENTS.md

87

data-privacy-stack/presidio

Instructions file CodexOpenCode

AGENTS.md instructions for data-privacy-stack/presidio, covering presidio — agent guidelines, working in this repo, adding a pii recognizer, changing the yaml configuration layer and general engineering rules.

not rated 11k +12 3d ago A 1,478 tokens original MIT

geo-technical

88

zubair-trabzada/geo-seo-claude

Agent

Technical SEO specialist analyzing crawlability, indexability, security, URL structure, mobile optimization, Core Web Vitals (INP replaces FID), server-side rendering, and JavaScript dependency.

not rated 10k +381 yesterday A 42 tokens original MIT

geo-technical

89

zubair-trabzada/geo-seo-claude

Skill Claude CodeCodex

Technical SEO audit with GEO-specific checks — crawlability, indexability, security, performance, SSR, and AI crawler access.

not rated 10k +381 yesterday A 28 tokens original MIT

backend-api

90

usekaneo/kaneo

Cursor rule Cursor

Backend API development guidelines for Hono, Drizzle ORM, and Better Auth.

not rated 8.9k +118 yesterday A 0 tokens original MIT

penetration-tester

91

anyproto/anytype-ts

Agent Claude Code

Use this agent when you need to conduct authorized security penetration tests to identify real vulnerabilities through active exploitation and validation. Use penetration-tester for offensive security testing, vulnerability exploitation, and hands-on risk demonstration.

not rated 8.7k +8 2d ago A 45 tokens

NVIDIA/OpenShell

Skill Claude CodeCodex ✓ vendor

Generate sandbox security policies from plain-language requirements and optional REST API documentation. Produces L4 or fine-grained L7 network policies and ordered network middleware configuration. Use for API access rules, middleware host selection, failure behavior, or built-in and operator-run middleware…

not rated 8.5k +54 changed today A 98 tokens original Apache-2.0

NVIDIA/OpenShell

Agent Claude Code ✓ vendor

Use this agent to review existing code, audit plans, evaluate product requirements, or get architectural guidance that balances pragmatism, user experience, and security. This includes code reviews, plan audits, architecture reviews, security assessments, or when building engineering and development plans from…

not rated 8.5k +54 today A 71 tokens original Apache-2.0

review-security

94

pydantic/monty

Skill Claude CodeCodex

Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses. Use when reviewing changes for security risk, or before merging anything touching heap.rs, pathsecurity.rs, the wire protocol or the pool.

not rated 8.2k +23 today A 55 tokens original MIT

monty CLAUDE.md

95

pydantic/monty

Instructions file

Claude Code instructions for pydantic/monty, covering claude.md, project overview, monty-types — shared boundary types, cross-platform requirements and important security notice.

not rated 8.2k +23 changed today A 14,098 tokens original MIT

zeek AGENTS.md

96

zeek/zeek

Instructions file CodexOpenCode

AGENTS.md instructions for zeek/zeek, covering agents.md, scope and authority, building and running zeek, documentation and testing.

not rated 7.9k changed today A 823 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: