Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

holistis/bug-bounty-intelligence-mcp

MCP server Claude CodeCodexCursor +2

AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates. Remote server at wazir-x402.duckdns.org.

not rated 8 today A tokens not measured original MIT

ssh-audit

1010

muchiny/bridge-mcp

Skill Claude Code

This skill should be used when the user asks to "run a security scan", "check for vulnerabilities", "audit compliance", "check certificate expiry", "scan open ports", or mentions security reviews, CIS benchmarks, or compliance assessments on remote servers.

not rated 8 4d ago A SkillSpector: pass 54 tokens original MIT

redacta

1011

nickjlamb/redacta

Skill Claude CodeCodex

Pseudonymises medical and clinical documents by replacing patient identifiers with labelled tokens (e.g. [PATIENTNAME1], [NHSNUMBER1], [DATEOFBIRTH1]) so the text can be safely processed by AI or shared, with clinical meaning intact. Combines a deterministic pattern layer (NHS numbers with Modulus-11 validation, UK…

not rated 8 2d ago A 219 tokens MIT-0

covenant-guard

1012

open-covenant/covenant

Plugin Claude Code

Bundles 1 command, 1 hook · 17 tokens together

Run Claude Code unattended: cap the spend, sandbox execution, and get a signed receipt, enforced from outside the agent's own process by the covguard binary.

not rated 8 today A tokens not measured original Apache-2.0

geniro

1013

geniro-io/geniro-claude-harness

Plugin Claude Code

Bundles 37 skills, 8 agents, 1 hook · 4,218 tokens together

Production-grade Claude Code harness with AI-driven setup, multi-agent skills, and safety hooks. Includes /setup for project-tailored configuration.

not rated 8 changed yesterday A tokens not measured original Apache-2.0

sentinel-audit

1014

wangdongzuopin/sentinel-skill

Skill Claude CodeCodex

Source code security audits, SAST, dependency review. When findings are listed or audit ends, MUST chain to sentinel-report — read skills/sentinel/sentinel-report/SKILL.md, ask save folder, Write .md + offline .html. Triggers on audit, vulnerability, security review, 审计.

not rated 8 5mo ago A 68 tokens

burpsuite-server

1016

Cyreslab-AI/burpsuite-mcp-server

MCP server Claude CodeCodexCursor +2

MCP server "burpsuite-server" as configured in Cyreslab-AI/burpsuite-mcp-server. Runs locally from the burpsuite-server npm package.

not rated 8 1y ago A tokens not measured original MIT

cyber-sentinel-mcp

1017

jx888-max/cyber-sentinel-mcp

MCP server Claude CodeCodexCursor +2

A comprehensive threat intelligence aggregation MCP server. Runs locally from the cyber-sentinel-mcp Python package.

not rated 8 1y ago A tokens not measured original MIT

cyberedu-mcp

1018

CyberEDU-Cyber-Range/cyberedu-mcp

MCP server Claude CodeCodexCursor +2

MCP server "cyberedu-mcp" as configured in CyberEDU-Cyber-Range/cyberedu-mcp. Runs locally from the cyberedu-mcp Python package.

not rated 8 7mo ago A tokens not measured

nist-nvd-mcp-server

1019

Cyreslab-AI/nist-nvd-mcp-server

MCP server Claude CodeCodexCursor +2

MCP server "nist-nvd-mcp-server" as configured in Cyreslab-AI/nist-nvd-mcp-server. Runs locally from the @cyreslab/nist-nvd-mcp-server npm package.

not rated 8 1y ago A tokens not measured original MIT

mdbp

1020

DorukYelken/Model-Database-Protocol

MCP server Claude CodeCodexCursor +2

Model Database Protocol — intent-based, secure database access for LLMs with schema validation, policy engine, data masking, and MCP server support. Runs locally from the mdbp Python package.

not rated 8 5mo ago A tokens not measured

sanctuary-framework

1021

eriknewton/sanctuary-framework

Plugin Claude Code

Bundles 1 skill, 1 MCP server · 120 tokens together

The open source standard for secure, private AI: operating-system enforcement is live on macOS today; Linux and Windows are not live enforcement yet, and your data stays under your own keys with current portability bounds called out in the Assurance Matrix. Wraps any MCP-compatible agent with encrypted state, approval.

not rated 8 today A tokens not measured original Apache-2.0

ns-private-access-mcp

1022

johnneerdael/privateaccess-mcp

MCP server Claude CodeCodexCursor +2

MCP server for Netskope's Zero Trust Network Access Platform management through LLM's. Runs locally from the @johnneerdael/ns-private-access-mcp npm package.

not rated 8 3mo ago A tokens not measured

tartinerlabs/skills

Skill Claude CodeCodex

Audit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up…

not rated 8 +1 20d ago A 111 tokens original MIT

saw_rules

1024

snyk/saw-mcp

Cursor rule Cursor

Snyk API & Web behavioral rules - safety constraints, proactive monitoring, and vulnerability handling.

not rated 8 +1 3d ago A 1,600 tokens original Apache-2.0

claude-crap

1025

ahernandez-developer/claude-crap

Plugin Claude Code

Bundles 4 skills, 5 hooks, 1 MCP server · 742 tokens together

Deterministic Quality Assurance plugin for Claude Code. Wraps every Write / Edit / Bash tool call with a PreToolUse gatekeeper, a PostToolUse verifier, and a Stop quality gate backed by CRAP index, Technical Debt Ratio, tree-sitter AST metrics, and SARIF 2.1.0 reports. Forbids the agent from writing functional code…

not rated 8 4mo ago A tokens not measured original MIT

terminal-guardian-mcp

1026

7Majesty-M/terminal-guardian-mcp

MCP server Claude CodeCodexCursor +2

Secure Model Context Protocol server for safe, sandboxed terminal access for AI assistants. Runs locally from the terminal-guardian-mcp npm package.

not rated 8 +1 3mo ago A tokens not measured original MIT

mayurrathi/awesome-agent-skills

Skill Claude CodeCodex

Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities.

not rated 8 +1 6mo ago A 27 tokens

mcp-safeguard

1028

SyedAnas01/mcp-safeguard

MCP server Claude CodeCodexCursor +2

Security scanner for MCP servers — detect prompt injection, credential leaks, exposed endpoints, tool poisoning, and source-level credential-handling flaws. Runs locally from the mcp-safeguard Python package.

not rated 8 5d ago A tokens not measured original MIT

TabletopExercise

1029

SecurityTalent/bugskill-ai

Skill Claude CodeCodex needs its repo

Comprehensive cybersecurity tabletop exercise design and facilitation framework. USE WHEN designing incident response scenarios, creating executive or technical tabletops, generating atomics for exercise runners, identifying missing SOPs/playbooks, or evaluating organizational preparedness. Includes threat model…

not rated 8 +2 today A 64 tokens original MIT

code-reviewing

1030

PacktPublishing/The-Claude-Code-Operating-Model

Skill Claude Code

Review code for security vulnerabilities, performance issues, and coding best practices. Activate when the user asks to review code, check code quality, give feedback on code changes, or audit a file.

not rated 8 +3 1mo ago A 42 tokens copy · 100% MIT

sast-fileupload

1031

capture0x/YeepForge

Skill Claude CodeCodex

Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first).…

not rated 8 +2 19d ago A 92 tokens

box

1032

box/box-for-ai

Cursor rule Cursor ✓ vendor

Non-negotiable safety and scope constraints for Box MCP tool usage.

not rated 7 8d ago A 629 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: