24,655 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first).…
Author, validate, debug, and explain OPA Rego policies through any MCP-compatible client. Runs locally from the @orygn/opa-mcp npm package. Needs 7 environment variables to run.
★not rated 7 3d agoA
tokens not measured
originalMIT
Codebase health tools: deep audits via orchestrated specialists (security, performance, libraries, quality, dead code), safe dependency updates, dead-code cleanup, and documentation maintenance.
★not rated 7
changed 2d agoA
tokens not measured
originalMIT
A dependency security plugin for Claude Code. DepGuard intercepts package installs, checks reputation with Socket.dev, runs installs in a Modal sandbox, and blocks suspicious behavior before it reaches your machine.
★not rated 7 5mo agoA
tokens not measured
originalMIT
Agentic MCP server for detecting fake LinkedIn recruiter / job-offer scams using free OSINT sources. Runs locally from the jobverify-mcp Python package.
★not rated 7 2mo agoA
tokens not measured
originalMIT
This skill should be used when the user asks to "scan for PHI", "detect PII", "HIPAA compliance check", "audit for protected health information", "find sensitive healthcare data", "generate HIPAA audit report", "check code for PHI leakage", "scan logs for PHI", "check authentication on PHI endpoints", "scan FHIR…
Security scanner for AI-agent configuration files — detects prompt injection, dangerous permissions, and credential exposure in settings.json, CLAUDE.md, MCP configs, and more.
★not rated 7 2d agoA
tokens not measured
originalApache-2.0
Supply-chain security guard that intercepts package install commands across npm, pnpm, pip, go, and cargo ecosystems and enforces package risk policies before execution.
★not rated 7 3mo agoA
tokens not measured
originalMIT
Audytuje bezpieczeństwo skilla, pluginu lub agenta Claude Code przed instalacją. Warstwa statyczna (heurystyki) plus subagent-audytor tylko do odczytu wykrywają prompt injection, kradzież sekretów, exfiltrację danych, obfuskację i persistence. Pozyskuje kod do izolowanego katalogu tymczasowego, nigdy bezpośrednio do…
Automate TTPForge TTP creation, validation, and management for adversary simulation.
★not rated 7 7mo agoA
tokens not measured
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: