Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

skillrx

961

felipeinf/skillRx

Plugin Claude Code

Bundles 1 command · 11 tokens together

Security scanner for AI agent skills and plugins (Claude Code, Codex, Cursor, and 40+ more).

not rated 9 4mo ago A tokens not measured

vibeguard-sql-safety

962

MuddySheep/vibeguard-local

Skill Claude CodeCodex

MANDATORY pre-flight for ALL SQL operations. Fire this skill IMMEDIATELY whenever the conversation involves SQL of any kind — writing it, proposing it, executing it, reviewing it, or even talking about it concretely. Triggers include any of these keywords appearing in user input or your own draft output…

not rated 9 4mo ago A 268 tokens original Apache-2.0

pickysteve

963

KernelLord/pickysteve

Plugin Claude Code

Bundles 1 MCP server

Skill router and context picker for coding agents — picks the right skill per prompt, scans both the request and every retrieved doc for prompt injection.

not rated 9 1mo ago A tokens not measured original MIT

review-all

964

paultyng/skill-issue

Skill Claude CodeCodex

Use when the user asks for a deep review, full review, comprehensive review, production readiness assessment, full audit, multi-domain audit, "security and reliability and code review", or "review everything". Also use when the user explicitly requests performance review alongside the comprehensive request (e.g.…

not rated 9 1mo ago A 102 tokens original MIT

security-kb

965

dinosn/security-knowledge-base

Skill Codex

Read, search, and inspect evidence in a Security Knowledge Base v1 repository, then validate or stage evidence-cited, revision-bound claim and finding proposals. Use when a task refers to a repository containing kb.json and the kb CLI, asks to check or update the security KB, or supplies an skb.context-packet/v1. Stop…

not rated 9 1mo ago A 92 tokens original MIT

tsm

967

tashian/tsm

Plugin Claude Code

Bundles 1 skill · 37 tokens together

Touch-ID-gated secrets for AI coding agents. Provides safe credential injection for tools and MCP servers.

not rated 9 3mo ago A tokens not measured original MIT

agent-inspector

968

cylestio/agent-inspector

Cursor rule Cursor

Agent Inspector - AI Agent Security Analysis (scan, correlate static ↔ dynamic).

not rated 9 8mo ago A 0 tokens

code-review-agent

969

DollhouseMCP/collection

Agent Claude Code

Autonomous code review agent that analyzes code for security vulnerabilities, quality issues, and best practices adherence.

not rated 9 1mo ago A 23 tokens

prereview

970

singhharsh1708/kitbash

Skill Claude CodeCodex

Review the current diff against this team's conventions and invariants before it ships. Invoke with /prereview before opening a PR, or run as a pre-push gate.

not rated 9 today A 0 tokens original Apache-2.0

trentina

971

crunchtools/mcp-trentina

MCP server Claude CodeCodexCursor +2

Secure MCP gateway and quarantine for AI agent traffic — three-layer defense against prompt injection. Runs locally from the mcp-trentina-crunchtools Python package.

not rated 9 6d ago A tokens not measured AGPL-3.0

case-uco-sdk

972

vulnmaster/CASE-UCO-SDK

Cursor rule Cursor

CASE/UCO SDK usage patterns for building digital forensics investigation graphs.

not rated 9 2d ago A 1,772 tokens original Apache-2.0

xfstudio/skills

Skill Claude CodeCodex

Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities.

not rated 9 6mo ago A 29 tokens

ai_llm_attacks

974

1ikeadragon/awesome-offsec-claude

Skill Claude CodeCodex

Elite AI/LLM exploitation specialist - prompt injection, jailbreaking, agent exploitation, RAG poisoning, multi-modal attacks, model extraction, and system prompt leakage for CTF and red team engagements.

not rated 9 5mo ago A ✓ AI review 45 tokens

slartz/agent-security-awareness-training

Skill Claude CodeCodex

Mandatory security awareness onboarding for AI agents. Run this skill at the start of EVERY agent session, before performing any task — especially tasks involving tools, credentials, external content, email, file systems, cloud resources, or production systems. Also run it whenever the security policy file changes…

not rated 9 3mo ago A 117 tokens original MIT

authz-recipe

976

tr4m0ryp/shor

Skill Claude CodeCodex

Broken Access Control is OWASP #1, but there is no drop-in CLI (Autorize / AuthMatrix are Burp extensions). This is the procedure that carries the whole category: an authorization-matrix + A/B session-replay method driving curl, the playwright skill (per-identity sessions), and ffuf (ID enumeration). Live →…

not rated 9 1mo ago A 62 tokens

resource-index

978

ArianHobson333/claude-bug-bounty-stack

Skill Claude CodeCodex

Curated index of external hacking resources — meta-lists, frameworks, wordlists, payload banks, recon/OSINT, network, exploitation, and CTF tooling. Load when the user asks "what's the tool for X", "where do I find payloads for Y", "is there a wordlist for Z", or when planning which external resource to pull for a…

not rated 9 5mo ago A 92 tokens

terraform-hardening

979

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when changing or reviewing the Terraform-backed GitHub repository hardening workspace under config/infra, including provider pins, rulesets, default branch protection, required checks, secret scanning, Dependabot security updates, token handling, plan/apply behavior, and infra documentation. Do not use for…

not rated 9 changed 5d ago A 89 tokens

openclaw

980

edimuj/vexscan

Skill Claude CodeCodex

Scans extensions, skills, and code for security threats: prompt injection, malicious code, obfuscation, data exfiltration. Also scans inbound messages for injection patterns automatically.

not rated 9 4mo ago A 0 tokens original Apache-2.0

pentest-findings

981

jayelbotvibe-web/hermes-pentest-lab

Skill Claude CodeCodex needs its repo

Pentest finding interpretation encyclopedia — maps tool output to finding severity, CVSS scoring rules, and report-ready language. Answers 'What severity is this? What's the CVSS? How do I write this up?'.

not rated 9 18d ago A SkillSpector: warn 47 tokens original MIT

ai-engineer-lead

982

Friz-zy/ai-capability-registry

Agent Claude Code

Never place secrets, credentials, tokens, PII, or production data in any field; reference affected files by redacted path only.

not rated 10 changed 4d ago A 22 tokens original MIT

AI45Lab/SentrySkills

Skill Claude CodeCodex

Establish security boundaries before execution. Trigger this skill whenever involving command execution, file writing, sensitive data reading, external tool result adoption, or potential unauthorized requests; first output risk assessment and allowed/forbidden action lists.

not rated 9 2mo ago A 50 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: