24,943 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Complete security hardening of a Linux server based on CIS Benchmarks, NIST 800-123, and ANSSI BP-028. Smart service discovery to avoid disruption. 4 hardening levels (minimal/standard/enhanced/paranoid). Installs open-source security tools, hardens SSH/kernel/firewall/systemd/permissions, runs all scans, generates a…
Drive IDA Pro through the IDA Pro MCP like a senior reverse engineer: don't just narrate decompiler output, transform the database. Use this whenever the user is reverse engineering, analyzing malware, working a crackme or CTF, or doing binary/firmware analysis with IDA Pro over an MCP connection (mrexodia/ida-pro-mcp…
Use when reviewing or writing LLM, RAG, MCP, tool, or agent code for OWASP-aligned security issues; triggered by "owasp my code", "owasp this PR", AI security review, PR review, or changes to AI system code.
Triage security findings from Semgrep Pro and Claude security-code-review using IaC files as deployment context (Terraform, Kubernetes, Docker Compose, CloudFormation, Azure Pipelines). Detects whichever IaC files are present, extracts deployment facts, scores each finding with CVSS 4.0 with per-vector justification…
Fix CISA Known Exploited Vulnerabilities (KEV) if exists in your codebase. Search for vulnerabilities that are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog using Trivy filesystem scanning. If any of these vulnerabilities are found, fix them by the CVE notes.
Comprehensive production readiness audit — 75+ checks across 9 pillars: security & supply chain, visual QA, code quality, testing, error handling & observability, build, performance, accessibility (WCAG 2.2), and AI/LLM safety. Like having a senior engineer + QA tester do a final review before deploy.
★not rated 5 2mo agoA
tokens not measured
originalMIT
Coleta o máximo de informação (recon/OSINT) sobre um ou mais domínios usando a ferramenta local SimpleReconSubdomain, entregando a saída em JSON por domínio. Use SEMPRE que o usuário quiser investigar um domínio do ponto de vista de segurança — mesmo que diga só "investiga o domínio X" ou cole uma lista de domínios.…
Security guardrails for AI-built apps: OWASP/API/LLM/MCP rules applied while building, an /audit skill for full reviews, and a hook that blocks secret commits.
★not rated 5 2mo agoA
tokens not measured
originalMIT
Adversarial, attacker-minded security review of untrusted code before you install it. A read-only scanner plus a five-persona reasoning pass, ending in a GO / GO-WITH-MITIGATIONS / NO-GO verdict.
★not rated 5 1mo agoA
tokens not measured
originalMIT
A defensive review of web application code for security weaknesses, data-leak risks, performance risks, and code-quality problems. It covers Google Apps Script, browser code, and server APIs written in languages such as Node, Python, or PHP.
Full security, correctness, and operability audit of code. Use when reviewing a diff, endpoint, or feature for vulnerabilities or bugs without a specific topic in mind — security review, audit, code review for safety, "check this for issues".
Black-box and grey-box penetration testing plugin for HackTheBox machine challenges. Provides automated reconnaissance, enumeration, exploitation guidance, and privilege escalation for Linux, Windows, and Active Directory environments.
★not rated 5 6mo agoA
tokens not measured
originalMIT
Show real-world and research-demonstrated security incidents that map to a scanner dimension, EU AI Act article, or threat category. Surfaces OWASP LLM/ASI, NIST AI RMF, and MITRE ATLAS cross-references alongside published mitigations.
Pre-installation security gate for agent skills. This skill should be used when the user or agent attempts to install any skill — including requests like "install X", "add X skill", "help me set up the X skill", "npx skills add", or when the agent autonomously decides to install a skill. Also triggers on skill cleanup…
Map Tenable Security Center findings to MITRE ATT&CK techniques and export a VPR-scored ATT&CK Navigator layer.
★not rated 5 2mo agoA
tokens not measured
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: