24,943 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
This document serves as the authoritative registry for all skills in the dex-market-manipulation-detector harness. It documents how skills are registered, resolved, executed, and validated, including input/output JSON schemas for runtime validation and automatic documentation generation.
Lord skill for governing AI coding agents at runtime — gateway interception, agent/flow/model allowlisting, and MCP-server-as-securable. The control layer between an agent's decision and its real-world action.
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies.
Offline reconstruction and security audit of agent execution traces from JSON, JSONL, or pasted logs. Use when Codex needs to review user input, model planning, tool calls, tool results, approvals, and final answers for prompt injection, unauthorized tools, secret exposure, missing approval, repeated-call loops, or…
A setup tool for running an agent skill inside an OpenSandbox isolation environment. It examines the skill and creates the files needed to build and use a Docker-based sandbox.
Analyze JSON Web Tokens (JWTs) for common security vulnerabilities including algorithm confusion attacks (RS256 to HS256), none algorithm bypass, weak secret brute-forcing, and claim manipulation. Practice in isolated lab environments to understand authentication bypass and privilege escalation via token forgery.
OpenCore framework best practices - bootstrap, controllers, imports, security, events, adapters, validation, runtime constraints. Use this skill when writing, reviewing, refactoring, or explaining code built with @open-core/framework and related OpenCore adapters. Trigger on any question about OpenCore, CitizenFX…
AI-powered security review for code changes via the /stride-security-review:security-review slash command. Two scan modes (diff / --full), seven framework rule packs (Android/Kotlin, Django/Python, Express/Node.js, iOS/Swift, Phoenix/Elixir, Rails/Ruby, React/Next.js) covering the full mobile + web + Node ecosystem…
★not rated 5 22d agoA
tokens not measured
originalMIT
Intelligent code security scanner with hybrid local-cloud detection. Fingerprints packages, runs static behavioral analysis, and consults cloud threat intelligence (enabled by default, can be disabled) for confidence scoring.
A security-audit topic for unsafe deserialization. Deserialization turns stored or received data back into program objects, and unsafe handling can create security risks.
Bash permission management for Claude Code: auto-approve compound commands, sync project permissions to global settings, and analyze permission logs to discover missing allow rules.
QA artifact generator — point it at a PR or give freeform instructions. Navigates the UI, captures screenshots, and stitches a GIF. Fully configurable auth and artifact storage via /.sentinel/config.json.
Authentication & authorization for appium-mcp when hosted over SSE / HTTP Stream. Bearer API keys + OAuth JWT, scope-based authorization, per-caller session ownership — built entirely on the appium-mcp Plugin API (no core changes). Runs locally from the @appclaw/appium-mcp-auth npm package.
★not rated 5 1mo agoA
tokens not measured
originalApache-2.0
Detects data exfiltration, lateral movement, and crypto-mining anomalies from ExamplePay observability signals (logs, metrics, traces). Returns a structured ThreatSignal with a confidence score (0.0–1.0).
MCP server for signed machine-action records, offline tool-surface checks, and SSX360 USB signer support. Runs locally from the matrixscroll Python package.
★not rated 5 21d agoA
tokens not measured
originalApache-2.0
Network scanning MCP server wrapping nmap. Provides 14 purpose-built tools for host discovery, port scanning (SYN/TCP/UDP), service & OS detection, NSE script execution, and vulnerability scanning. Returns structured JSON output. Includes scope enforcement (CIDR allowlist), audit logging, and scan persistence. Use…
★not rated 5 6mo agoA83 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: