24,943 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Collect natural-language environment context and generate evidence collection guidance for Mandate 2.2.3 Secure Training and Fine-Tuning. Use when code is insufficient and operational proof is required for final compliance evaluation.
Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.
KENSHO (検証) — industry-grade playbook for offensive Web3 security assessment and responsible disclosure, covering EVM smart contracts / DeFi and Rust/Solana consensus & validator code. Usable by individual researchers, audit teams, and security firms. Invoke when a target is named (project, handle, repo, or website)…
Full-spectrum security audit for any project — SAST, DAST, SCA, secret scanning, IaC security, container hardening, IAM/RBAC review, threat modeling, and API security. Step-by-step investigation with context-gathering questions before scanning. Produces triage findings, autofix patches, and a structured report.
Security auditor for agent skills. Scans SKILL.md files, scripts, hooks, and commands for prompt injection, data exfiltration, destructive operations, obfuscation, and permission overreach. Generates trust scores and hardening recommendations. Use before installing any community skill.
Comprehensive Android app security best practices from official Android documentation. Use when implementing features, reviewing security issues, handling sensitive data, or ensuring compliance with Android security guidelines.
A security-audit guide for Electron desktop applications, which are desktop programs built with web technologies. It focuses on vulnerabilities that ordinary users can trigger through projects, files, links, or other normal actions.
Audit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up…
Read and apply this skill whenever you are helping a user build a non-custodial crypto wallet or wallet-related application and the conversation touches any of the following.
An authorised reverse-engineering workflow for examining local software samples and recovering how they work. Reverse engineering means studying compiled or packaged software, such as an APK, ELF, PE, or firmware image, to infer its logic.
Use before committing to the public CTObot repo to catch company-specific or proprietary content that has drifted into the public files (AGENTS.md, SOUL.md, docs/, skills/, README). The agent reads the diff (or all files) and reasons about whether the content is generic and shareable or specific to our company…
Scans Claude Code skills for security risks before installation. Checks for prompt injection, credential harvesting, exfiltration patterns, hooks, excessive permissions, and settings modification. Supports GitHub URLs, local paths, and bulk scanning. Use when asked to audit, scan, or check a skill for malware or…
Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.
Security scanner using VirusTotal. Use when the user asks to scan a file for malware, check if a downloaded file or script is safe, verify a file hash against threat intelligence, or assess the security of any file. Returns both antivirus engine detections AND AI-powered Code Insight analysis (when available) in a…
Node.js modules handling authenticated RPC commands from clients. The server never decrypts document content — it only processes metadata, access control, and storage operations on encrypted blobs and public keys.
Socratic lenses for software engineering: question batteries that examine your work from security, design, usability, test-quality, and operational-recovery perspectives — plus an orchestrator that surfaces caveats, rabbit holes, and blast radius before you build, and a memory loop that grows new lenses from your real.
★not rated 5 1mo agoA
tokens not measured
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: