Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

hardening

1177

Cholulaa/claude-code-hardening-skill

Skill Claude Code

Complete security hardening of a Linux server based on CIS Benchmarks, NIST 800-123, and ANSSI BP-028. Smart service discovery to avoid disruption. 4 hardening levels (minimal/standard/enhanced/paranoid). Installs open-source security tools, hardens SSH/kernel/firewall/systemd/permissions, runs all scans, generates a…

not rated 5 5mo ago B 80 tokens original MIT

Newmcpe/ida-reverse-engineering-skill

Skill Claude CodeCodex

Drive IDA Pro through the IDA Pro MCP like a senior reverse engineer: don't just narrate decompiler output, transform the database. Use this whenever the user is reverse engineering, analyzing malware, working a crackme or CTF, or doing binary/firmware analysis with IDA Pro over an MCP connection (mrexodia/ida-pro-mcp…

not rated 5 3mo ago A 243 tokens WTFPL

security-audit

1180

YangKuoshih/security-audit

Plugin Claude Code

Bundles 1 skill · 163 tokens together

Scan codebases for hardcoded secrets, credentials, API keys, and common security vulnerabilities.

not rated 5 6mo ago A tokens not measured original Apache-2.0

agent-security

1181

olanokhin/agent-security-skill

Skill Codex

Use when reviewing or writing LLM, RAG, MCP, tool, or agent code for OWASP-aligned security issues; triggered by "owasp my code", "owasp this PR", AI security review, PR review, or changes to AI system code.

not rated 5 3mo ago A 57 tokens original MIT

ctf

1182

zebbern/termstack

Agent Claude Code

CTF Coordinator — Triages CTF challenges by category and delegates to specialized agents (web, crypto, forensics, binary, reversing, misc, bonus). user-invocable: true argument-hint: 'Challenge info — e.g.

not rated 5 4mo ago A 53 tokens

security-iac-triage

1183

ch0ks/hackarandas-claude-toolbelt

Skill Claude Code

Triage security findings from Semgrep Pro and Claude security-code-review using IaC files as deployment context (Terraform, Kubernetes, Docker Compose, CloudFormation, Azure Pipelines). Detects whichever IaC files are present, extracts deployment facts, scores each finding with CVSS 4.0 with per-vector justification…

not rated 5 4mo ago A 168 tokens original MIT

plutosecurity/secure-flow

Command Claude CodeCursor

Fix CISA Known Exploited Vulnerabilities (KEV) if exists in your codebase. Search for vulnerabilities that are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog using Trivy filesystem scanning. If any of these vulnerabilities are found, fix them by the CVE notes.

not rated 5 9mo ago A 0 tokens

production-readiness

1185

Meghshyams/Production-Readiness

Plugin Claude Code

Bundles 1 skill · 60 tokens together

Comprehensive production readiness audit — 75+ checks across 9 pillars: security & supply chain, visual QA, code quality, testing, error handling & observability, build, performance, accessibility (WCAG 2.2), and AI/LLM safety. Like having a senior engineer + QA tester do a final review before deploy.

not rated 5 2mo ago A tokens not measured original MIT

srs-domain-recon

1186

MrCl0wnLab/Skill-SimpleReconSubdomain

Skill Claude CodeCodex

Coleta o máximo de informação (recon/OSINT) sobre um ou mais domínios usando a ferramenta local SimpleReconSubdomain, entregando a saída em JSON por domínio. Use SEMPRE que o usuário quiser investigar um domínio do ponto de vista de segurança — mesmo que diga só "investiga o domínio X" ou cole uma lista de domínios.…

not rated 5 2mo ago A 227 tokens

safe-ai-skill

1188

solanabr/safe-ai-skill

Plugin Claude Code

Bundles 4 hooks

Security firewall + supply-chain verifier for Solana AI dev — gates transactions/deploys/secrets and verifies skills/MCPs.

not rated 5 2mo ago A tokens not measured original MIT

grow-agent

1189

TyrusRC/praetor

Agent Claude Code

Session orchestrator for one domain. Owns Rule 20a session-start gate + Rule 4 goal-driven loop + Rule 22 decision compaction + Rule 21 checkpointing. Promotes confirmed cross-target patterns into KB/skill proposals. On-demand only.

not rated 5 changed today A 56 tokens original Apache-2.0

trust-issues

1190

howshannon/trust-issues

Plugin Claude Code

Bundles 1 skill · 160 tokens together

Adversarial, attacker-minded security review of untrusted code before you install it. A read-only scanner plus a five-persona reasoning pass, ending in a GO / GO-WITH-MITIGATIONS / NO-GO verdict.

not rated 5 1mo ago A tokens not measured original MIT

web-security-reviewer

1191

goingli0324/web-security-reviewer

Skill Claude CodeCodex

A defensive review of web application code for security weaknesses, data-leak risks, performance risks, and code-quality problems. It covers Google Apps Script, browser code, and server APIs written in languages such as Node, Python, or PHP.

not rated 5 1mo ago A 441 tokens original MIT

audit

1192

danygiguere/audit-skills

Skill Claude CodeCodex

Full security, correctness, and operability audit of code. Use when reviewing a diff, endpoint, or feature for vulnerabilities or bugs without a specific topic in mind — security review, audit, code review for safety, "check this for issues".

not rated 5 2mo ago A 51 tokens original MIT

blackbox-htb

1194

allsmog/blackbox-claude-plugin

Plugin Claude Code

Bundles 17 skills, 11 commands, 9 agents · 2,590 tokens together

Black-box and grey-box penetration testing plugin for HackTheBox machine challenges. Provides automated reconnaissance, enumeration, exploitation guidance, and privilege escalation for Linux, Windows, and Active Directory environments.

not rated 5 6mo ago A tokens not measured original MIT

bughunt-suite

1195

robzilla1738/roberts-skills

Plugin Claude Code

Bundles 3 skills, 4 commands · 418 tokens together

Offensive hotspot-driven hunt workflow for bugs, pain points, and inefficiencies — 13 analysis lenses, a zero-dependency toolkit (deterministic hotspots, structured findings, fingerprinted dedupe, baseline diffing, SARIF/HTML/markdown reports, CI exit codes), enforceable verification and coverage in CI, a fast…

not rated 5 3mo ago A tokens not measured original MIT

ai-act-incidents

1196

Peaky8linders/eu-ai-act-scanner

Command Claude Code

Show real-world and research-demonstrated security incidents that map to a scanner dimension, EU AI Act article, or threat category. Surfaces OWASP LLM/ASI, NIST AI RMF, and MITRE ATLAS cross-references alongside published mitigations.

not rated 5 6d ago A 59 tokens original Apache-2.0

skill-guardian

1197

0xtresser/skill-guardian

Skill Claude CodeCodex

Pre-installation security gate for agent skills. This skill should be used when the user or agent attempts to install any skill — including requests like "install X", "add X skill", "help me set up the X skill", "npx skills add", or when the agent autonomously decides to install a skill. Also triggers on skill cleanup…

not rated 5 6mo ago B 125 tokens original MIT

osmedeus-expert

1198

osmedeus/osmedeus-skills

Skill Claude CodeCodex

Expert guide for the Osmedeus security automation workflow engine. Use when: (1) writing or editing YAML workflows (modules and flows), (2) running osmedeus CLI commands (scan, workflow management, installation, server), (3) configuring steps, runners, triggers, or template variables, (4) debugging workflow execution…

not rated 5 5mo ago A 113 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: