31,002 mods in this category, of every kind an agent can take.
Each one carries what it costs per session, what the scan found, and
whether it is the original.
Run deepsec, an AI-powered cyber-security vulnerability scanner. Activates when the user invokes /deepsec, asks to run deepsec, or wants to scan their repo, branch, or uncommitted changes for vulnerabilities.
Proactive threat hunt over web/application logs — no alert in hand. Profiles the corpus, runs a hypothesis-driven hunt loop with a mandatory written ledger, confirms suspects in source, detonates a local PoC, and writes INCIDENTS.json + INCIDENTREPORT.md. Use when asked to "hunt the logs", "find the campaign", "look…
Triage a batch of raw security findings. Verify each is real, collapse duplicates, re-rank by derived exploitability, and tag with an owner. Takes a directory or file of scanner output and writes TRIAGE.json + TRIAGE.md sorted by what actually needs engineering attention. Use when asked to "triage findings", "validate…
Claude Code instructions for anthropics/defending-code-reference-harness, covering claude for securing source code, vuln-pipeline, when the user asks you to run it, running it and watching a run.
You are a security specialist reviewing a code diff. Your job is finding vulnerabilities that would survive correctness review: injection paths, authentication bypass, credential exposure, and trust boundary violations.
Claude Code instructions for trailofbits/skills, a project described as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows.
Add a DeepChat LLM provider through explicit reviewed source changes. Use when a developer asks Codex to add a provider, provider profile, upstream provider config, model catalog mapping, provider auth behavior, or a special provider adapter in this repository.
Review Rust code changes for unsafe correctness, security and robustness, documentation quality, and C-to-Rust porting fidelity. Use this when you want to review Rust changes before merging.
A planning agent for authorized, non-destructive security testing. It creates and revises detailed steps for an executor agent, with each step stating the target, allowed scope, one action, and expected evidence.
A method for finding attack chains by combining smaller capabilities such as reading files, writing files, making server requests, or using credentials. It treats a serious outcome as a sequence of separately gained abilities.
A collection of cybersecurity playbooks for investigating and exploiting specific systems, including GoEdge CDN, ARP man-in-the-middle attacks, BT Panel, OCS, MinIO, and CDN-to-S3 access chains.
Chinese-language project instructions for AI-Infra-Guard, a security-scanning platform for AI infrastructure. It combines Go services with Python scanners, security rules, databases, and Docker deployment files.
Claude Code instructions for Tencent/AI-Infra-Guard, covering claude.md, project overview, build commands, build web server binary and build agent binary.
An automation procedure for deploying a Model Context Protocol (MCP) program from source code. MCP is a standard way for an AI client to connect to tools or data services.
A static security-audit agent for MCP projects. Static analysis examines source code without running it, focusing on vulnerabilities that could be reached through network inputs.
A security-review agent that checks vulnerability reports for real, reproducible threats and filters out false positives. A false positive is an alleged problem that is not actually exploitable or harmful in the stated environment.
A guide for authorized security testing of AI products, agents, connectors, skills, plugins, code repositories, and related infrastructure. It uses harmless checks and collected evidence to identify and describe security risks.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: