holistis/bug-bounty-intelligence-mcp
MCP server Claude CodeCodexCursor +2
AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates. Remote server at wazir-x402.duckdns.org.
24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.
holistis/bug-bounty-intelligence-mcp
MCP server Claude CodeCodexCursor +2
AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates. Remote server at wazir-x402.duckdns.org.
Skill Claude Code
This skill should be used when the user asks to "run a security scan", "check for vulnerabilities", "audit compliance", "check certificate expiry", "scan open ports", or mentions security reviews, CIS benchmarks, or compliance assessments on remote servers.
Skill Claude CodeCodex
Pseudonymises medical and clinical documents by replacing patient identifiers with labelled tokens (e.g. [PATIENTNAME1], [NHSNUMBER1], [DATEOFBIRTH1]) so the text can be safely processed by AI or shared, with clinical meaning intact. Combines a deterministic pattern layer (NHS numbers with Modulus-11 validation, UK…
Plugin Claude Code
Bundles 1 command, 1 hook · 17 tokens together
Run Claude Code unattended: cap the spend, sandbox execution, and get a signed receipt, enforced from outside the agent's own process by the covguard binary.
geniro-io/geniro-claude-harness
Plugin Claude Code
Bundles 37 skills, 8 agents, 1 hook · 4,218 tokens together
Production-grade Claude Code harness with AI-driven setup, multi-agent skills, and safety hooks. Includes /setup for project-tailored configuration.
Skill Claude CodeCodex
Source code security audits, SAST, dependency review. When findings are listed or audit ends, MUST chain to sentinel-report — read skills/sentinel/sentinel-report/SKILL.md, ask save folder, Write .md + offline .html. Triggers on audit, vulnerability, security review, 审计.
Plugin Claude Code
Bundles 19 skills, 4 agents, 1 hook · 501 tokens together
Automated code review enforcement. Runs autofix, architecture verification, and conversation review -- and blocks sessions from finishing until they pass.
Cyreslab-AI/burpsuite-mcp-server
MCP server Claude CodeCodexCursor +2
MCP server "burpsuite-server" as configured in Cyreslab-AI/burpsuite-mcp-server. Runs locally from the burpsuite-server npm package.
MCP server Claude CodeCodexCursor +2
A comprehensive threat intelligence aggregation MCP server. Runs locally from the cyber-sentinel-mcp Python package.
CyberEDU-Cyber-Range/cyberedu-mcp
MCP server Claude CodeCodexCursor +2
MCP server "cyberedu-mcp" as configured in CyberEDU-Cyber-Range/cyberedu-mcp. Runs locally from the cyberedu-mcp Python package.
Cyreslab-AI/nist-nvd-mcp-server
MCP server Claude CodeCodexCursor +2
MCP server "nist-nvd-mcp-server" as configured in Cyreslab-AI/nist-nvd-mcp-server. Runs locally from the @cyreslab/nist-nvd-mcp-server npm package.
DorukYelken/Model-Database-Protocol
MCP server Claude CodeCodexCursor +2
Model Database Protocol — intent-based, secure database access for LLMs with schema validation, policy engine, data masking, and MCP server support. Runs locally from the mdbp Python package.
eriknewton/sanctuary-framework
Plugin Claude Code
Bundles 1 skill, 1 MCP server · 120 tokens together
The open source standard for secure, private AI: operating-system enforcement is live on macOS today; Linux and Windows are not live enforcement yet, and your data stays under your own keys with current portability bounds called out in the Assurance Matrix. Wraps any MCP-compatible agent with encrypted state, approval.
johnneerdael/privateaccess-mcp
MCP server Claude CodeCodexCursor +2
MCP server for Netskope's Zero Trust Network Access Platform management through LLM's. Runs locally from the @johnneerdael/ns-private-access-mcp npm package.
Skill Claude CodeCodex
Audit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up…
Cursor rule Cursor
Snyk API & Web behavioral rules - safety constraints, proactive monitoring, and vulnerability handling.
ahernandez-developer/claude-crap
Plugin Claude Code
Bundles 4 skills, 5 hooks, 1 MCP server · 742 tokens together
Deterministic Quality Assurance plugin for Claude Code. Wraps every Write / Edit / Bash tool call with a PreToolUse gatekeeper, a PostToolUse verifier, and a Stop quality gate backed by CRAP index, Technical Debt Ratio, tree-sitter AST metrics, and SARIF 2.1.0 reports. Forbids the agent from writing functional code…
7Majesty-M/terminal-guardian-mcp
MCP server Claude CodeCodexCursor +2
Secure Model Context Protocol server for safe, sandboxed terminal access for AI assistants. Runs locally from the terminal-guardian-mcp npm package.
mayurrathi/awesome-agent-skills
Skill Claude CodeCodex
Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities.
MCP server Claude CodeCodexCursor +2
Security scanner for MCP servers — detect prompt injection, credential leaks, exposed endpoints, tool poisoning, and source-level credential-handling flaws. Runs locally from the mcp-safeguard Python package.
Skill Claude CodeCodex needs its repo
Comprehensive cybersecurity tabletop exercise design and facilitation framework. USE WHEN designing incident response scenarios, creating executive or technical tabletops, generating atomics for exercise runners, identifying missing SOPs/playbooks, or evaluating organizational preparedness. Includes threat model…
PacktPublishing/The-Claude-Code-Operating-Model
Skill Claude Code
Review code for security vulnerabilities, performance issues, and coding best practices. Activate when the user asks to review code, check code quality, give feedback on code changes, or audit a file.
Skill Claude CodeCodex
Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first).…
Cursor rule Cursor ✓ vendor
Non-negotiable safety and scope constraints for Box MCP tool usage.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: