capybara-nexus-v2
1105Skill Claude CodeCodex
Name: capybara-nexus-v2 Tier: Frontier (Capybara-class) Mandate: Autonomous Reasoning, Empirical Feedback, & Zero-Day Research.
24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.
Skill Claude CodeCodex
Name: capybara-nexus-v2 Tier: Frontier (Capybara-class) Mandate: Autonomous Reasoning, Empirical Feedback, & Zero-Day Research.
Plugin Claude Code
Bundles 3 skills, 2 hooks, 2 MCP servers · 36 tokens together
Auto-obfuscates sensitive client data during pentesting so Claude never sees real PII, hostnames, or credentials.
Skill Claude CodeCodex
Run a structured codebase audit — map architecture, assess health (compliance / tests / docs), perform deep analysis (security / performance / code quality), and synthesize a prioritized roadmap. Use this skill when the user says things like 'audit the codebase', 'understand this project', 'find problems', '/audit'…
Skill Codex
Use when hardening npm package release workflows with trusted publishing, OIDC, GitHub environments, pinned GitHub Actions, disabled publish-path caching, Changesets release PRs, direct tag-based npm publish flows, staged publishing, or npm release-supply-chain reviews.
MCP server Claude CodeCodexCursor +2
MCP interface server fronting the Vulners API (https://vulners.com). Runs locally from the vulners-mcp Python package.
ArmisSecurity/armis-appsec-mcp
Skill Claude CodeCodex
On-demand AI-powered security scanning. Use when the user asks to scan code for vulnerabilities, run a security check, scan code for security issues, scan a file, scan a diff, scan staged changes, check for security issues, check for secrets, find hardcoded credentials, or run an appsec scan. Triggers: /security-scan…
Cursor rule Cursor
End-to-end security threat modeling (STRIDE/PASTA, OWASP AppSec/API/LLM Top 10, MITRE ATT&CK/ATLAS) for AI and conventional application infrastructure, using this repo's Jira/Jenkins/ServiceNow/repo connectors.
Skill Claude CodeCodex
Inspect and remove identifying metadata and provenance marks from files — GPS coordinates, camera serial numbers, author names, editing timestamps, C2PA content credentials, and invisible Unicode carriers. Works on PNG, JPEG, WebP, PDF, DOCX, ODT, SVG, HTML, Markdown and plain text. Use when someone asks to strip…
Bhanunamikaze/Code-VulnScan-Skill
Skill Claude CodeCodex
Use this when the user wants to find security vulnerabilities in a codebase, perform a security audit, scan for CVEs, detect secrets, review React/Next.js, Go, Java/Kotlin JVM, PHP, Ruby, .NET, or Rust web services, audit architecture/application/infrastructure flaws, review auth/API/crypto/business logic, check…
popoloni/non_deterministic_sw_eng
Cursor rule Cursor
When writing code that handles authentication, authorization, or sensitive data.
Skill Claude Code
Review code for correctness, security, TypeScript quality, and performance. Run before any PR or deploy.
Skill Claude CodeCodex
Skill "android-auth-identity" from noloman/Android-AI-skills, covering android authentication & identity, hard rules, core patterns and references.
LeoKemp223/embedded-llm-guardrails
Skill Claude CodeCodex
Safety instructions for using an AI coding assistant in embedded projects, such as microcontroller, real-time operating system, driver, and board-support code. Embedded software runs on dedicated hardware, where mistakes can affect the device itself.
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Coordinates an Azure cloud-security red team assessment end to end. The user interacts with this agent; it validates engagement scope, dispatches the specialist sub-agents (recon, identity, authorization, network, compute, containers/Kubernetes, data, web, AI/Foundry, attack-surface/EASM, governance/posture…
Plugin Claude Code
Bundles 3 skills, 1 hook · 205 tokens together
Security-scan a Claude Code skill, plugin, or MCP server before installing it. SAFE / CAUTION / DANGEROUS verdict with file:line findings. Read-only, never executes the target.
macaugh/super-rouge-hunter-skills
Skill Claude Code
Systematic methodology for developing reliable exploits from vulnerability discovery to weaponization.
Plugin Claude Code
Bundles 120 skills · 9,711 tokens together
Offensive security skills collection for authorized penetration testing, CTF challenges, and security research. Includes tools for reconnaissance, exploitation, C2 frameworks, evasion, reverse engineering, and programming patterns.
lacework/forticnapp-llm-plugins
Plugin Claude Code
Bundles 3 skills, 4 hooks · 65 tokens together
Fortinet Code Security — IaC and SCA scanning for Claude Code.
Plugin Claude Code
Bundles 1 skill, 2 hooks · 55 tokens together
Blindfolds the LLM from your secrets. Stores API keys, tokens, and passwords in your OS keychain. The LLM works with placeholders, never sees actual values. Kernel-level sandbox enforcement on macOS.
Skill Claude Code
Manage WeChat channel access — edit allowlists and set DM policy. Use when the user asks to add/remove users, check who's allowed, or change policy.
MCP server Claude CodeCodexCursor +2
MCP server "rapid7-mcp-server" as configured in el95149/rapid7-mcp-server. Runs locally from the rapid7-mcp-server npm package.
MCP server Claude CodeCodexCursor +2
MCP server for APIMesh — 76 x402-payable tools for AI agents (74 APIs + wallet usage + spend caps). Covers web vitals, security headers, SEO audits, email security and verification, tech-stack detection, brand assets, redirect chains, indexability, brand. Runs locally from the @mbeato/apimesh-mcp-server npm package.…
liangjunyu2010/mcp_server_safe_content_check
MCP server Claude CodeCodexCursor +2
MCP server "mcp-server-safe-content-check" as configured in liangjunyu2010/mcpserversafecontentcheck. Runs locally from the mcp-server-safe-content-check Python package.
MCP server Claude CodeCodexCursor +2
This is an MCP server that exposes red team tools for active directory pentesting to LLMs. Runs locally from the pentestMCP Python package.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: