24,943 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
MCP server "burp-plus" as configured in titaniumtushar/burp-mcp-plus. Launched with /opt/homebrew/bin/uv run --directory /path/to/burp-mcp-plus burp-mcp-plus. Needs 1 environment variable to run.
★not rated 6 4mo agoA
tokens not measured
originalMIT
MCP server for Microsoft 365 and Intune management with 33 tools for Entra ID, devices, Autopilot, and more. Runs locally from the mcp-m365-mgmt Python package.
★not rated 6 10mo agoA
tokens not measured
originalMIT
Audits a code change against a 54-phase failure taxonomy and reports what it did not check, not just what it found. Domain overlays run first and force critical-path treatment.
★not rated 6 29d agoA
tokens not measured
originalMIT
A workflow for reconstructing calculations in web JavaScript from their final outputs, such as request parameters, cookies, headers, or WebSocket messages. It covers signatures, encryption, verification challenges, WebAssembly, and heavily obfuscated code.
Use when the user says something like "add login", "users need to sign in", "I want auth", "gate this behind a user account". The auth surface (login / signup / OAuth / sessions) is NOT something you build. Read this whole page before touching auth code.
Use when presenting shell commands or tool calls for user approval. Adds a human-readable explanation of intent, scope, and risk before the approval prompt.
★not rated 6 5mo agoC✓ AI review34 tokens
originalMIT
Realiza uma auditoria de segurança completa em um projeto de código (web, API, backend, mobile etc), cobrindo OWASP Top 10 e CWE, dependências desatualizadas com CVEs, segredos expostos (incluindo histórico do git), CORS, TLS/HSTS, rate limiting, WAF, autenticação e cookies, controle de acesso, exposição excessiva de…
Use the husk security scanner from Claude Code. Adds the husk MCP server (scan results, findings, packages, remediations, fresh scans) and a skill covering the husk CLI and MCP output.
★not rated 6▲
+1
changed yesterdayA
tokens not measured
originalMIT
Fill stored secrets (passwords, card numbers, API keys) into web pages through the secure-browser MCP server without ever seeing the secret values. Use when a task needs a login, checkout, payment form, or any credential entered into a website and the credentials live in a secret store rather than in the conversation.
Full site triage workflow: init → crawl → classify → security audit → synthesize → generate project → KCP manifest → report. Use when triaging a new website end-to-end, re-running a scan, or debugging pipeline failures.
Scan AI-generated Terraform for security misconfigurations, in your editor, before it is committed. Runs locally from the sovereign-observer Python package. Needs 2 environment variables to run.
★not rated 6▲
+1 6d agoA
tokens not measured
originalApache-2.0
Design authentication and authorization for the project's stack — JWT vs server sessions, refresh-token rotation, OAuth 2.1 + PKCE, magic links, passkeys (WebAuthn), TOTP/2FA + backup codes, RBAC vs ABAC vs ReBAC, secure cookie flags, mobile token storage. Use when adding sign-in to a new app, designing the token…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: