Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

pastewatch

1201

ppiankov/pastewatch

Skill Claude Code

Sensitive data scanner — deterministic detection and obfuscation for text content.

not rated 5 today A SkillSpector: warn 16 tokens original MIT

aiguard

1202

zscaler/zguard-ai-integrations

Skill Claude Code

Scan prompts, AI responses, and code for security threats using Zscaler AI Guard. Supports 19 prompt detectors and 21 response detectors including: prompt injection, toxicity, DLP, PII, PII DeepScan, personal data, secrets, malicious URLs, code, gibberish, invisible text, brand risk, competition, language, legal…

not rated 5 11d ago A 230 tokens original MIT

cortex-secrets

1203

davideuler/cortex-auth

Skill Claude CodeCodex

How to autonomously obtain secrets and API keys from a Cortex Auth server and launch projects with those secrets injected as environment variables — without any human intervention to configure keys. Use this skill whenever you need to: Run a project that requires API keys (OpenAI, Anthropic, SMTP, database passwords…

not rated 5 4mo ago B 161 tokens

raigo-owasp-llm

1205

PericuloLimited/raigo

Skill Claude CodeCodex

RAIGO × OWASP LLM Top 10 — official OWASP LLM Application Security Top 10 (2025) enforcement rules for Hermes agents. Covers all 10 OWASP LLM risks: prompt injection, insecure output handling, training data poisoning, model denial of service, supply chain vulnerabilities, sensitive information disclosure, insecure…

not rated 5 5mo ago C 120 tokens

npm-safe-scan

1206

nisconder/npm-safe

Skill Claude CodeCodex needs its repo

Automatically scan any npm package for supply-chain security risks BEFORE the user installs it. Trigger this skill whenever the user asks to install, add, or upgrade an npm package or dependency (e.g. "npm install X", "install X", "add X as a dependency", "yarn add X", "pnpm add X", "upgrade X"), or wants to…

not rated 5 9d ago A 128 tokens original Apache-2.0

dev-qa

1207

songoao25/dsh-virtual-product-team

Skill Claude CodeCodex

A development and quality process for building software, testing it, and checking it for security problems. It separates implementation, quality assurance, and security review while coordinating their handoffs.

not rated 5 +1 8d ago A 50 tokens original MIT

ssojet/skills

Skill Claude CodeCodex

Implement "Sign in with SSO" in native Android/Kotlin applications using SSOJet OIDC with AppAuth.

not rated 5 6mo ago A 32 tokens

OutlineDriven/odin-gemini-cli-extension

Skill Claude Code

Install a Claude-Code PreToolUse hook that blocks destructive git commands (push variants including force-push, hard reset, force clean, branch -D, checkout/restore overwrites) before Bash runs them. Use when the user wants git safety rails, force-push prevention, or repository-wipe protection.

not rated 5 2mo ago B 71 tokens original Apache-2.0

piranha

1210

Falcon-Forge/PiRanha

Skill Claude CodeCodex

Autonomous agentic bug bounty hunting framework v2.0. BugHunter orchestrator with state-machine-driven phases, credential vault, auth flow automation, intelligent skill routing, Burp MCP bridge, parallel agent execution, LLM/AI target track, configurable severity profiles, and live dashboard. USE WHEN bug bounty…

not rated 5 2mo ago D 107 tokens original MIT

supply-chain-sentinel

1211

aajj68/supply-chain-sentinel

Skill Claude CodeCodex

Security scanner for supply chain attacks, malicious dependencies, prompt injection, and suspicious code patterns. Use this skill whenever the user asks to audit a project, scan for malicious packages, check dependencies for threats, look for prompt injection, detect typosquatting, review supply chain security, or…

not rated 5 5mo ago B 159 tokens original MIT

MG-Cafe/agentic-coder-shield

Skill Claude Code

Security-hardened agentic coding assistant with 3 defense layers — input scanning, tool boundaries, and output scanning via Model Armor.

not rated 5 5mo ago C 33 tokens

security

1215

olucasevangelista/security-skill

Skill Claude CodeCodex

Secure web and desktop application development. Use when writing authentication, authorization, API endpoints, form handling, database queries, file uploads, Electron apps, Tauri apps, IPC handlers, cryptography, secrets management, security headers, input validation, or when reviewing code for vulnerabilities. Covers…

not rated 5 5mo ago A 87 tokens

Veritas Acta Verify

1216

VeritasActa/verify

Skill Claude CodeCodex

Signs every Claude Code tool call with an offline-verifiable Ed25519 receipt. Lets you audit exactly what Claude did and when, without trusting any server.

not rated 5 changed 2d ago A 37 tokens

obfuscation-bypass

1218

punishell/SKILLS

Skill Claude CodeCodex

Use this skill when the user wants to encode or obfuscate a prompt to evade content filters, use Base64, Hex, Leetspeak, Caesar cipher, Unicode encoding, Zero-Width characters, Variant Selector, Sneaky Bits, JSON wrapping, Synonym Substitution, Pig Latin translation, Chinese language bypass, Code Comment Smuggling…

not rated 5 5mo ago A 130 tokens

security-skill

1219

justinnoh/security-skill

Skill Claude CodeCodex

A software security review based on South Korea’s KISA 2021 security weakness guide. It checks 69 design and implementation categories and labels each one as passed, vulnerable, needing review, or not applicable.

not rated 5 2mo ago A 0 tokens original MIT

audit

1220

robertknight/skills

Skill Claude CodeCodex

Quickly audit the current project for obvious malicious or untrustworthy behavior so the user can decide whether it is safe to run, build, or install. This is a triage pass, not a full security review — aim for a dozen targeted checks, not an exhaustive audit.

not rated 5 4mo ago A 0 tokens

tailscale-acl

1221

enuno/tailscale-acl

Cursor rule Cursor

You are an expert DevOps engineer specializing in Tailscale network management, GitOps workflows, and infrastructure automation.

not rated 5 9mo ago A 460 tokens original Apache-2.0

kali-lab

1222

andrescaicedom/tribuia-taller-seguridad

MCP server Claude Code

One of 2 in .mcp.json

MCP server "kali-lab" as configured in andrescaicedom/tribuia-taller-seguridad. Runs /workspace/docker/operator/tools/mcp-kali.py with python3. Needs 1 environment variable to run.

not rated 5 4mo ago A tokens not measured

dmaynor/dmaynor-skills-marketplace

Skill Claude CodeCodex

Determine whether a kernelcache-contained macOS kext changed semantically across releases despite relocation noise or unreliable bundle versions. Use for extraction, invariant comparison, masked ARM64 instruction comparison, and per-function review. Validate the method against the target OS build.

not rated 5 changed 2d ago A 66 tokens

bb-local-toolkit

1224

x-cookie/cbughunter-k2

Skill Claude CodeCodex

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload…

not rated 5 3mo ago A ✓ AI review 372 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: