Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

burp-plus

1129

titaniumtushar/burp-mcp-plus

MCP server Claude CodeCodexCursor +2

One of 2 in claude_desktop_config.json

MCP server "burp-plus" as configured in titaniumtushar/burp-mcp-plus. Launched with /opt/homebrew/bin/uv run --directory /path/to/burp-mcp-plus burp-mcp-plus. Needs 1 environment variable to run.

not rated 6 4mo ago A tokens not measured original MIT

secret-set

1130

vaultry/claude-secrets

Command Claude Code

Store a secret via native macOS dialog (hidden input). Value never appears in chat.

not rated 6 4mo ago A 18 tokens

mem-forensics-mcp

1131

x746b/mem_forensics-mcp

MCP server Claude CodeCodexCursor +2

Unified Memory Forensics MCP Server - Multi-tier engine (Rust + Python + Vol3). Runs locally from the mem-forensics-mcp Python package.

not rated 6 9d ago A tokens not measured original MIT

mcp-guardian

1132

alexandriashai/mcp-guardian

MCP server Claude CodeCodexCursor +2

MCP security scanner - detect prompt injection in tool descriptions. Runs locally from the mcp-guardian npm package.

not rated 6 1mo ago A tokens not measured original MIT

hackerone-mcp

1133

abdugafforov-bobur/hackerone-mcp

MCP server Claude CodeCodexCursor +2

MCP server "hackerone-mcp" as configured in abdugafforov-bobur/hackerone-mcp. Runs locally from the hackerone-mcp Python package.

not rated 6 2mo ago A tokens not measured

mcp-m365-mgmt

1134

thiagogbeier/mcp-m365-mgmt

MCP server Claude CodeCodexCursor +2

MCP server for Microsoft 365 and Intune management with 33 tools for Entra ID, devices, Autopilot, and more. Runs locally from the mcp-m365-mgmt Python package.

not rated 6 10mo ago A tokens not measured original MIT

mcp-adguard-home

1135

Samik081/mcp-adguard-home

MCP server Claude CodeCodexCursor +2

Manage AdGuard Home through AI assistants. Runs locally from the @samik081/mcp-adguard-home npm package. Needs 3 environment variables to run.

not rated 6 +1 10d ago A tokens not measured original MIT

skill-audit-mcp

1136

eltociear/skill-audit-mcp

MCP server Claude CodeCodexCursor +2

Scan agent skills and MCP servers for malicious patterns before you load them. Remote server at eltociear-skill-audit.hf.space.

not rated 6 25d ago A tokens not measured

cc-safe-setup

1137

yurukusa/cc-safe-setup

Plugin Claude Code

Bundles 2 skills, 1 hook · 107 tokens together

909 safety hooks for Claude Code — prevent file deletion, credential leaks, git disasters, and token waste during autonomous AI coding sessions.

not rated 6 8d ago A tokens not measured original MIT

audit-protocol

1138

sturec5/code-audit-protocol

Plugin Claude Code

Bundles 1 skill · 133 tokens together

Audits a code change against a 54-phase failure taxonomy and reports what it did not check, not just what it found. Domain overlays run first and force critical-path treatment.

not rated 6 29d ago A tokens not measured original MIT

prompt-security

1139

meghal86/promptsonar

Cursor rule Cursor

Before generating or modifying any prompt.

not rated 6 +1 14d ago A 116 tokens original MIT

web-reverse-algorithm

1140

guccig4366/xbsReverseSkill

Skill Codex

A workflow for reconstructing calculations in web JavaScript from their final outputs, such as request parameters, cookies, headers, or WebSocket messages. It covers signatures, encryption, verification challenges, WebAssembly, and heavily obfuscated code.

not rated 6 +1 today A 226 tokens copy · 100% MIT

auth

1141

agentry-ai/agentry

Skill Claude CodeCodex

Use when the user says something like "add login", "users need to sign in", "I want auth", "gate this behind a user account". The auth surface (login / signup / OAuth / sessions) is NOT something you build. Read this whole page before touching auth code.

not rated 6 +1 1mo ago A 0 tokens original Apache-2.0

wtf-approve

1142

Sassine/wtf-approve

Skill Claude CodeCodex

Use when presenting shell commands or tool calls for user approval. Adds a human-readable explanation of intent, scope, and risk before the approval prompt.

not rated 6 5mo ago C ✓ AI review 34 tokens original MIT

bugbounty-01

1143

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

Complete bug bounty workflow: recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload…

not rated 6 +1 1mo ago A ✓ AI review 156 tokens

sentinela

1144

fonsecafns/sentinela

Cursor rule Cursor

Realiza uma auditoria de segurança completa em um projeto de código (web, API, backend, mobile etc), cobrindo OWASP Top 10 e CWE, dependências desatualizadas com CVEs, segredos expostos (incluindo histórico do git), CORS, TLS/HSTS, rate limiting, WAF, autenticação e cookies, controle de acesso, exposição excessiva de…

not rated 6 15d ago A 215 tokens

trai

1145

binpash/trai

Plugin Claude Code

Bundles 7 commands, 3 hooks · 100 tokens together

Sandbox every Bash tool call through binpash/try. Review the accumulated diff after the session and commit or discard.

not rated 6 4mo ago A tokens not measured original MIT

husk

1146

husk-security/husk

Plugin Claude Code

Bundles 1 skill, 1 MCP server · 87 tokens together

Use the husk security scanner from Claude Code. Adds the husk MCP server (scan results, findings, packages, remediations, fresh scans) and a skill covering the husk CLI and MCP output.

not rated 6 +1 changed yesterday A tokens not measured original MIT

envskill

1147

buhaistrikalo/envskill

Skill Claude CodeCodex

Use when a command needs API keys or environment secrets. Inject only named variables through envskill without reading or printing values.

not rated 6 +1 19d ago A 27 tokens original MIT

fortimanager-mcp

1148

rstierli/fortimanager-mcp

MCP server Claude CodeCodexCursor +2

MCP server "fortimanager-mcp" as configured in rstierli/fortimanager-mcp. Runs locally from the fortimanager-mcp Python package.

not rated 6 +2 14d ago A tokens not measured copy · 100% MIT

secure-browser

1149

tkhq/secure-browser-mcp

Skill Claude CodeCodex

Fill stored secrets (passwords, card numbers, API keys) into web pages through the secure-browser MCP server without ever seeing the secret values. Use when a task needs a login, checkout, payment form, or any credential entered into a website and the credentials live in a secret store rather than in the conversation.

not rated 6 2d ago A 66 tokens

scan-site

1150

Cantara/kcp-triage

Skill Claude CodeCodex

Full site triage workflow: init → crawl → classify → security audit → synthesize → generate project → KCP manifest → report. Use when triaging a new website end-to-end, re-running a scan, or debugging pipeline failures.

not rated 6 yesterday A 51 tokens

sovereign-observer-mcp

1151

kraken222/sovereign-observer-mcp

MCP server Claude CodeCodexCursor +2

Scan AI-generated Terraform for security misconfigurations, in your editor, before it is committed. Runs locally from the sovereign-observer Python package. Needs 2 environment variables to run.

not rated 6 +1 6d ago A tokens not measured original Apache-2.0

auth-patterns

1152

kouroshez/coding-os

Skill Claude CodeCodex

Design authentication and authorization for the project's stack — JWT vs server sessions, refresh-token rotation, OAuth 2.1 + PKCE, magic links, passkeys (WebAuthn), TOTP/2FA + backup codes, RBAC vs ABAC vs ReBAC, secure cookie flags, mobile token storage. Use when adding sign-in to a new app, designing the token…

not rated 6 2d ago A SkillSpector: warn 118 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: