Security

31,002 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

deepsec

97

vercel-labs/deepsec

Skill Claude CodeCodex ✓ vendor

Run deepsec, an AI-powered cyber-security vulnerability scanner. Activates when the user invokes /deepsec, asks to run deepsec, or wants to scan their repo, branch, or uncommitted changes for vulnerabilities.

not rated 7.9k +29 8d ago A 48 tokens original Apache-2.0

dnr-hunt

99

anthropics/defending-code-reference-harness

Skill Claude CodeCodex ✓ vendor

Proactive threat hunt over web/application logs — no alert in hand. Profiles the corpus, runs a hypothesis-driven hunt loop with a mandatory written ledger, confirms suspects in source, detonates a local PoC, and writes INCIDENTS.json + INCIDENTREPORT.md. Use when asked to "hunt the logs", "find the campaign", "look…

not rated 7.4k +9 28d ago A 109 tokens

patch

100

anthropics/defending-code-reference-harness

Skill Claude CodeCodex ✓ vendor

Generate candidate fixes for verified security findings. Consumes TRIAGE.json (preferred), VULN-FINDINGS.json, INCIDENTS.json, or a vuln-pipeline results directory. Pipeline input is delegated to the execution-verified vuln-pipeline patch ladder; static-analysis input gets a per-finding patch subagent + independent…

not rated 7.4k +9 28d ago A 134 tokens

triage

101

anthropics/defending-code-reference-harness

Skill Claude CodeCodex ✓ vendor

Triage a batch of raw security findings. Verify each is real, collapse duplicates, re-rank by derived exploitability, and tag with an owner. Takes a directory or file of scanner output and writes TRIAGE.json + TRIAGE.md sorted by what actually needs engineering attention. Use when asked to "triage findings", "validate…

not rated 7.4k +9 28d ago A 99 tokens

code-review

103

kyegomez/swarms

Skill Claude CodeCodex

Perform comprehensive code reviews focusing on best practices, security vulnerabilities, performance optimization, and maintainability.

not rated 7.1k +10 today A 21 tokens original Apache-2.0

reviewer-security

104

tw93/Waza

Agent

You are a security specialist reviewing a code diff. Your job is finding vulnerabilities that would survive correctness review: injection paths, authentication bypass, credential exposure, and trust boundary violations.

not rated 6.9k +11 today A 0 tokens original MIT

trailofbits/skills

Plugin Claude Code

Lists 12 plugins

Plugin marketplace listing 42 plugins: audit-context-building, building-secure-contracts, burpsuite-project-parser, claude-in-chrome-troubleshooting, constant-time-analysis.

not rated 7.0k +18 changed 2d ago A tokens not measured CC-BY-SA-4.0

skills CLAUDE.md

106

trailofbits/skills

Instructions file

Claude Code instructions for trailofbits/skills, a project described as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows.

not rated 7.0k +18 yesterday A 5 tokens CC-BY-SA-4.0

osmedeus-expert

107

j3ssie/osmedeus

Skill Claude CodeCodex

Expert guide for the Osmedeus security automation workflow engine. Use when: (1) writing or editing YAML workflows (modules and flows), (2) running osmedeus CLI commands (scan, workflow management, installation, server), (3) configuring steps, runners, triggers, or template variables, (4) debugging workflow execution…

not rated 6.5k +1 26d ago A 113 tokens original MIT

add-provider

108

ThinkInAIXYZ/deepchat

Skill Claude CodeCodex

Add a DeepChat LLM provider through explicit reviewed source changes. Use when a developer asks Codex to add a provider, provider profile, upstream provider config, model catalog mapping, provider auth behavior, or a special provider adapter in this repository.

not rated 6.3k +9 today A 52 tokens original Apache-2.0

rust-review

109

RediSearch/RediSearch

Skill Claude CodeCodex

Review Rust code changes for unsafe correctness, security and robustness, documentation quality, and C-to-Rust porting fidelity. Use this when you want to review Rust changes before merging.

not rated 6.2k +3 today A 39 tokens

Ed1s0nZ/CyberStrikeAI

Agent

A planning agent for authorized, non-destructive security testing. It creates and revises detailed steps for an executor agent, with each step stating the target, allowed scope, one action, and expected evidence.

not rated 6.3k +151 9d ago A 70 tokens original Apache-2.0

Ed1s0nZ/CyberStrikeAI

Skill Claude CodeCodex

A skill for examining Android packages, Windows executables, native libraries, and some cross-platform app binaries to understand how they work.

not rated 6.3k +151 9d ago A 70 tokens original Apache-2.0

Ed1s0nZ/CyberStrikeAI

Skill Claude CodeCodex

A method for finding attack chains by combining smaller capabilities such as reading files, writing files, making server requests, or using credentials. It treats a serious outcome as a sequence of separately gained abilities.

not rated 6.3k +151 9d ago A 67 tokens original Apache-2.0

Ed1s0nZ/CyberStrikeAI

Skill Claude CodeCodex

A collection of cybersecurity playbooks for investigating and exploiting specific systems, including GoEdge CDN, ARP man-in-the-middle attacks, BT Panel, OCS, MinIO, and CDN-to-S3 access chains.

not rated 6.3k +151 9d ago A 91 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Instructions file CodexOpenCode ✓ vendor

Chinese-language project instructions for AI-Infra-Guard, a security-scanning platform for AI infrastructure. It combines Go services with Python scanners, security rules, databases, and Docker deployment files.

not rated 6.1k +24 today A 998 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Instructions file ✓ vendor

Claude Code instructions for Tencent/AI-Infra-Guard, covering claude.md, project overview, build commands, build web server binary and build agent binary.

not rated 6.1k +24 today A 1,179 tokens original Apache-2.0

build_preview

117

Tencent/AI-Infra-Guard

Agent ✓ vendor

An automation procedure for deploying a Model Context Protocol (MCP) program from source code. MCP is a standard way for an AI client to connect to tools or data services.

not rated 6.1k +24 today A 0 tokens original Apache-2.0

code_audit

118

Tencent/AI-Infra-Guard

Agent ✓ vendor

A static security-audit agent for MCP projects. Static analysis examines source code without running it, focusing on vulnerabilities that could be reached through network inputs.

not rated 6.1k +24 today A 0 tokens original Apache-2.0

vuln_review

119

Tencent/AI-Infra-Guard

Agent ✓ vendor

A security-review agent that checks vulnerability reports for real, reproducible threats and filters out false positives. A false positive is an alleged problem that is not actually exploitable or harmful in the stated environment.

not rated 6.1k +24 today A 0 tokens original Apache-2.0

aig-agent-redteam

120

Tencent/AI-Infra-Guard

Skill Claude CodeCodex ✓ vendor

A guide for authorized security testing of AI products, agents, connectors, skills, plugins, code repositories, and related infrastructure. It uses harmless checks and collected evidence to identify and describe security risks.

not rated 6.1k +24 today A 164 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: