Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

agent-governance-lord

1274

m3taz-ahmed/ai-globals

Skill Claude CodeCodex

Lord skill for governing AI coding agents at runtime — gateway interception, agent/flow/model allowlisting, and MCP-server-as-securable. The control layer between an agent's decision and its real-world action.

not rated 5 changed 6d ago A 49 tokens original MIT

security-dependencies

1275

zsutxz/ClaudeLearning

Command Claude Code

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies.

not rated 5 1mo ago A 0 tokens original MIT

audit-agent-traces

1276

mumuchongchongchong/security-skills

Skill Codex

Offline reconstruction and security audit of agent execution traces from JSON, JSONL, or pasted logs. Use when Codex needs to review user input, model planning, tool calls, tool results, approvals, and final answers for prompt injection, unauthorized tools, secret exposure, missing approval, repeated-call loops, or…

not rated 5 1mo ago A 73 tokens original MIT

withcrux/agentHack-skills

Skill Claude CodeCodex

Analyze JSON Web Tokens (JWTs) for common security vulnerabilities including algorithm confusion attacks (RS256 to HS256), none algorithm bypass, weak secret brute-forcing, and claim manipulation. Practice in isolated lab environments to understand authentication bypass and privilege escalation via token forgery.

not rated 5 5mo ago A 62 tokens

ctf-pwn

1279

dailyyarn/CTF-agent

Skill Claude Code

Provides binary exploitation (pwn) techniques for CTF challenges. Use when exploiting buffer overflows, format strings, heap vulnerabilities (House of Orange, Spirit, Lore, Apple 2, Einherjar, tcache stashing unlink), race conditions, kernel bugs, ROP chains, ret2libc, ret2dlresolve, shellcode, GOT overwrite…

not rated 5 5mo ago A 137 tokens original MIT

newcore-network/opencore-ai-skills

Skill Claude CodeCodex

OpenCore framework best practices - bootstrap, controllers, imports, security, events, adapters, validation, runtime constraints. Use this skill when writing, reviewing, refactoring, or explaining code built with @open-core/framework and related OpenCore adapters. Trigger on any question about OpenCore, CitizenFX…

not rated 5 5mo ago A 107 tokens

grc

1281

nathanimphilipos/synergos-grc

Plugin Claude Code

Bundles 1 skill, 27 commands · 451 tokens together

GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.

not rated 5 6mo ago A tokens not measured original MIT

stride-security-review

1282

cheezy/stride-security-review

Plugin Claude Code

Bundles 1 skill, 1 command, 1 agent · 661 tokens together

AI-powered security review for code changes via the /stride-security-review:security-review slash command. Two scan modes (diff / --full), seven framework rule packs (Android/Kotlin, Django/Python, Express/Node.js, iOS/Swift, Phoenix/Elixir, Rails/Ruby, React/Next.js) covering the full mobile + web + Node ecosystem…

not rated 5 22d ago A tokens not measured original MIT

hacking-buddy-mcp

1283

ManuelBerrueta/hacking-buddy-mcp

MCP server Claude CodeCodexCursor +2

MCP server "hacking-buddy-mcp" as configured in ManuelBerrueta/hacking-buddy-mcp. Runs locally from the hacking-buddy-mcp Python package.

not rated 5 1y ago A tokens not measured original Apache-2.0

malskanner

1284

Octolabo/malskanner

MCP server Claude CodeCodexCursor +2

Scan a repo for hidden prompt-injection payloads before your AI agent trusts it. Runs locally from the malskanner npm package.

not rated 5 1mo ago A tokens not measured original MIT

yidun-skill-sec

1285

yidun/yidun-skill-sec

Skill Claude CodeCodex

Intelligent code security scanner with hybrid local-cloud detection. Fingerprints packages, runs static behavioral analysis, and consults cloud threat intelligence (enabled by default, can be disabled) for confidence scoring.

not rated 5 6mo ago C 46 tokens

jinyimeng01/net-code-audit-skill-master

Skill Claude CodeCodex

A security-audit topic for unsafe deserialization. Deserialization turns stored or received data back into program objects, and unsafe handling can create security risks.

not rated 5 4mo ago A 0 tokens MulanPSL-2.0

bugbounty-mcp-server

1287

akinabudu/bug-bounty-mcp

MCP server Claude CodeCodexCursor +2

MCP server "bugbounty-mcp-server" as configured in akinabudu/bug-bounty-mcp. Runs locally from the bugbounty-mcp-server Python package.

not rated 5 11mo ago A tokens not measured

raze-security

1288

xhulz/raze

MCP server Claude CodeCodexCursor +2

MCP-first smart contract attack engine for AI developer tools. Runs locally from the raze-security npm package.

not rated 5 5mo ago A tokens not measured original MIT

tenable-tie-mcp

1289

knethteo/tenable-identity-exposure-mcp

MCP server Claude CodeCodexCursor +2

MCP server "tenable-tie-mcp" as configured in knethteo/tenable-identity-exposure-mcp. Runs locally from the tenable-tie-mcp Python package.

not rated 5 1mo ago A tokens not measured original MIT

drata-mcp

1290

sderosiaux/drata-mcp

MCP server Claude CodeCodexCursor +2

MCP server "drata-mcp" as configured in sderosiaux/drata-mcp. Runs locally from the drata-mcp Python package.

not rated 5 8mo ago A tokens not measured

sentinel

1292

Nelsonochoam/nelsonochoam-claude-plugins

Plugin Claude Code

Bundles 1 skill · 0 tokens together

QA artifact generator — point it at a PR or give freeform instructions. Navigates the UI, captures screenshots, and stitches a GIF. Fully configurable auth and artifact storage via /.sentinel/config.json.

not rated 5 3mo ago A tokens not measured

appium-mcp-auth

1293

appclawhq/appium-mcp-auth

MCP server Claude CodeCodexCursor +2

Authentication & authorization for appium-mcp when hosted over SSE / HTTP Stream. Bearer API keys + OAuth JWT, scope-based authorization, per-caller session ownership — built entirely on the appium-mcp Plugin API (no core changes). Runs locally from the @appclaw/appium-mcp-auth npm package.

not rated 5 1mo ago A tokens not measured original Apache-2.0

g-greatdevaks/mcp-dev-summit-blr-2026

Skill Claude CodeCodex

Detects data exfiltration, lateral movement, and crypto-mining anomalies from ExamplePay observability signals (logs, metrics, traces). Returns a structured ThreatSignal with a confidence score (0.0–1.0).

not rated 5 1mo ago A 53 tokens original Apache-2.0

matrixscroll

1295

SSX360/matrixscroll

MCP server Claude CodeCodexCursor +2

MCP server for signed machine-action records, offline tool-surface checks, and SSX360 USB signer support. Runs locally from the matrixscroll Python package.

not rated 5 21d ago A tokens not measured original Apache-2.0

nmap-mcp

1296

sbmilburn/nmap-mcp

Skill Claude CodeCodex

Network scanning MCP server wrapping nmap. Provides 14 purpose-built tools for host discovery, port scanning (SYN/TCP/UDP), service & OS detection, NSE script execution, and vulnerability scanning. Returns structured JSON output. Includes scope enforcement (CIDR allowlist), audit logging, and scan persistence. Use…

not rated 5 6mo ago A 83 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: