Security

24,655 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

sast-fileupload

1033

capture0x/YeepForge

Skill Claude CodeCodex

Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first).…

not rated 8 +2 19d ago A 92 tokens

box

1034

box/box-for-ai

Cursor rule Cursor ✓ vendor

Non-negotiable safety and scope constraints for Box MCP tool usage.

not rated 7 8d ago A 629 tokens original MIT

tech-debt-mcp

1035

PierreJanineh/TechDebtMCP

Plugin Claude Code

Bundles 1 skill, 3 commands · 108 tokens together

Static technical-debt analysis across 14 languages, exposed as MCP tools and resources (SQALE ratings, debt summaries, custom rules, dependency vulnerabilities).

not rated 7 1mo ago A tokens not measured original MIT

safeagent

1036

azender1/SafeAgent

MCP server Claude CodeCodexCursor +2

MCP server "safeagent" as configured in azender1/SafeAgent. Runs safeagent_exec_guard.mcp_server with python.

not rated 7 1mo ago A tokens not measured original Apache-2.0

pre-launch-audit

1037

bzsasson/pre-launch-audit-skill

Plugin Claude Code

Bundles 1 skill · 92 tokens together

Run a comprehensive pre-launch website audit covering technical SEO, AI accessibility, security, performance, and on-page SEO.

not rated 7 4mo ago A tokens not measured copy · 86% MIT

commit

1038

piiiico/proof-of-commitment

Plugin Claude Code

Bundles 1 hook

Supply chain gate for Claude Code. Intercepts npm, pip, cargo, and go installs — blocks CRITICAL packages before they run. Powered by getcommit.dev.

not rated 7 2mo ago A tokens not measured original MIT

Judge Authentication

1039

KevinRabun/judges

Agent Claude Code

Evaluates code for proper authentication mechanisms, authorization checks, session management, token handling, and access control patterns.

not rated 7 2mo ago A 25 tokens original MIT

opa-mcp

1040

OrygnsCode/opa-mcp-server

MCP server Claude CodeCodexCursor +2

Author, validate, debug, and explain OPA Rego policies through any MCP-compatible client. Runs locally from the @orygn/opa-mcp npm package. Needs 7 environment variables to run.

not rated 7 3d ago A tokens not measured original MIT

sandbox-service

1041

Lin-A1/skills-agent

Skill Claude CodeCodex

A Docker-based service for running Python, Shell, or Bash code in an isolated environment with time and resource limits.

not rated 7 8mo ago A 44 tokens

app-audit

1042

playbookTV/Ironclad

Skill Claude CodeCodex

Evidence-driven application audit protocol for security, authorization, privacy, concurrency, state integrity, reliability, performance, accessibility, visual consistency, responsive behavior, and release readiness. Use for incremental checks, pre-merge review, pre-launch audits, high-stakes deep audits, AI-generated…

not rated 7 1mo ago A 92 tokens

codebase-health

1043

jeffrigby/somepulp-agents

Plugin Claude Code

Bundles 6 skills, 7 agents · 584 tokens together

Codebase health tools: deep audits via orchestrated specialists (security, performance, libraries, quality, dead code), safe dependency updates, dead-code cleanup, and documentation maintenance.

not rated 7 changed 2d ago A tokens not measured original MIT

dependency-guard

1045

yongquantan/dependency-guard

Plugin Claude Code

Bundles 1 skill, 1 command, 2 hooks · 0 tokens together

A dependency security plugin for Claude Code. DepGuard intercepts package installs, checks reputation with Socket.dev, runs installs in a Modal sandbox, and blocks suspicious behavior before it reaches your machine.

not rated 7 5mo ago A tokens not measured original MIT

jobverify

1047

yessGlory17/job-verify

MCP server Claude CodeCodexCursor +2

Agentic MCP server for detecting fake LinkedIn recruiter / job-offer scams using free OSINT sources. Runs locally from the jobverify-mcp Python package.

not rated 7 2mo ago A tokens not measured original MIT

hipaa-guardian

1048

1Mangesh1/hipaa-guardian

Skill Claude CodeCodex

This skill should be used when the user asks to "scan for PHI", "detect PII", "HIPAA compliance check", "audit for protected health information", "find sensitive healthcare data", "generate HIPAA audit report", "check code for PHI leakage", "scan logs for PHI", "check authentication on PHI endpoints", "scan FHIR…

not rated 7 2mo ago A 128 tokens original MIT

rune

1049

thecolourfoundation/rune

MCP server Claude CodeCodexCursor +2

Evidence-traced codebase understanding and security scanning for AI agents over MCP. Runs locally from the @moosl/rune npm package.

not rated 7 today A tokens not measured original MIT

cfgaudit

1050

cfgaudit/cfgaudit

Plugin Claude Code

Bundles 3 skills, 2 hooks · 57 tokens together

Security scanner for AI-agent configuration files — detects prompt injection, dangerous permissions, and credential exposure in settings.json, CLAUDE.md, MCP configs, and more.

not rated 7 2d ago A tokens not measured original Apache-2.0

diplomat-reviewer

1051

Diplomat-ai/diplomat-agent

Cursor rule Cursor

Reviews Python code for unguarded AI agent tool calls. Use when reviewing agent code, scanning for security issues, or checking tool call safety.

not rated 7 2mo ago A 0 tokens original Apache-2.0

knox

1053

QORIS-AI/knox

Plugin Claude Code

Bundles 8 skills, 11 hooks · 147 tokens together

Security enforcement layer for Claude Code. Blocks dangerous commands, audits every tool call, detects prompt injection.

not rated 7 1mo ago A tokens not measured

attach-guard

1054

attach-dev/attach-guard

Plugin Claude Code

Bundles 1 skill, 1 hook · 50 tokens together

Supply-chain security guard that intercepts package install commands across npm, pnpm, pip, go, and cargo ecosystems and enforces package risk policies before execution.

not rated 7 3mo ago A tokens not measured original MIT

skill-audit

1055

simplybychris/skill-audit

Skill Claude CodeCodex

Audytuje bezpieczeństwo skilla, pluginu lub agenta Claude Code przed instalacją. Warstwa statyczna (heurystyki) plus subagent-audytor tylko do odczytu wykrywają prompt injection, kradzież sekretów, exfiltrację danych, obfuskację i persistence. Pozyskuje kod do izolowanego katalogu tymczasowego, nigdy bezpośrednio do…

not rated 7 2mo ago B 131 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: