Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

secure-code-auditor

1345

n-shadloo/secure-code-auditor

Cursor rule Cursor

Backend security review and secure-by-default coding for Django and DRF, on an OWASP Top 10:2025, API Security Top 10:2023, and ASVS 5.0 foundation. Apply when backend code is written or reviewed and touches authentication, sessions, cookies, JWT, OAuth2/OIDC, API keys, password hashing, permissions, access control…

not rated 4 9d ago A 244 tokens original MIT

should-i-care

1346

moltenbit/should-i-care

Skill Claude CodeCodex

Single-CVE applicability triage that evaluates whether a CVE actually applies to the user's environment by reasoning about discriminating conditions against a skill-maintained environment profile; triggers when a user asks whether they are affected by a CVE, whether a CVE applies to them, or wants to assess a CVE…

not rated 4 3mo ago A 69 tokens original MIT

symfony-security

1347

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Symfony / PHP webapp security review — Security Component (firewalls, voters, accesscontrol, role hierarchies), Doctrine ORM injection patterns (raw DQL, QueryBuilder, expr()), Twig auto-escape and |raw, CSRF + session, PHP-specific RCE classes (unserialize, include/require, system/exec, eval, type juggling)…

not rated 4 3mo ago A 116 tokens

mcp-tenant-isolation

1348

subodhkc/mcp-tenant-isolation

MCP server Claude CodeCodexCursor +2

Static analysis scanner for MCP server code and multi-tenant SaaS applications. Runs locally from the mcp-tenant-isolation npm package.

not rated 4 12d ago A tokens not measured original MIT

vantage

1349

tinoimammp/vantage-security-agent

Plugin Claude Code

Bundles 1 skill, 6 commands · 384 tokens together

Artifact-driven, plugin-based multi-agent SAST pipeline for web and mobile app repositories. Web agents cover the OWASP Top 10; mobile agents cover the OWASP Mobile Top 10 (2024, M1-M10). Both share global validation/PoC/reporting agents. Run /vantage:scan-web or /vantage:scan-mobile to scan, then /vantage:fix-issue…

not rated 4 1mo ago A tokens not measured original MIT

zap-mcp

1350

pierre3/dotnet-zap-mcp

MCP server Claude CodeCodexCursor +2

MCP server "zap-mcp" as configured in pierre3/dotnet-zap-mcp. Launched with dotnet-zap-mcp. Needs 2 environment variables to run.

not rated 4 5mo ago A tokens not measured original MIT

ai-appsec

1351

subodhkc/ai-appsec

MCP server Claude CodeCodexCursor +2

Evidence-backed AppSec for AI applications and agents. Powered by HAIEC. Runs locally from the ai-appsec npm package.

not rated 4 23d ago A tokens not measured original MIT

emfirge

1352

theanshsonkar/emfirge

MCP server Claude CodeCodexCursor +2

Git branch for your cloud. Understand AWS risk, prove fixes, and ship safer changes. Runs locally from the @emfirge/mcp npm package. Needs 2 environment variables to run.

not rated 4 1mo ago A tokens not measured

ctf-crypto

1353

MateoBogo/CLEAVE

Skill Claude Code

Cryptography CTF attacks: RSA, AES, ECC, PRNG, hash length-extension, padding oracles, lattice/LWE/CVP, HNP, Coppersmith, Pollard, Wiener, ZKP/Circom/halo2, post-quantum KEM. Dispatch on prime shape, oracle type, or scheme artefact.

not rated 4 3mo ago A 0 tokens

supreme-ai-governance

1354

davccavalcante/supreme-coding-guidelines-skill.ah

Cursor rule Cursor

First-in-the-world AI governance and compliance discipline for AI Governance Officers, Compliance Leads, Risk Managers, DPOs, Legal Counsel, CISOs, and AI and ML and LLM engineers and architects. Operationalizes ISO/IEC 42001:2023 (AI Management System clauses 4 to 10, roughly 38 Annex A controls across 9 objectives…

not rated 4 2mo ago A 244 tokens

clerk

1355

wrsmith108/clerk-claude-skill

Skill Claude CodeCodex

Clerk authentication integration for Astro/Next.js. Use when implementing authentication, handling Clerk middleware, testing with Playwright, or debugging auth issues. Trigger phrases include "Clerk auth", "sign in", "authentication", "middleware", "E2E testing with Clerk".

not rated 4 8mo ago A 58 tokens original MIT

akirtok/preflight-security-audit

Plugin Claude Code

Bundles 1 skill, 1 command, 6 agents · 979 tokens together

Comprehensive 360 pre-ship audit: 61 checks across security, reliability, performance, AI/LLM, privacy/compliance, and launch readiness — including live-database, serverless/edge, GraphQL, client-side, and modern-attack (Trojan Source) checks. Reports a 0–100 security score with severity-ranked findings and proposes…

not rated 4 1mo ago A tokens not measured original MIT

security-audit

1357

cdmx-in/security-review

Plugin Claude Code

Bundles 1 skill · 106 tokens together

Runs real security scanners over code, full git history, dependencies, IaC and Supabase/Firebase row-level security, then verifies every finding against source before reporting.

not rated 4 1mo ago A tokens not measured original MIT

omv-find

1358

bx33661/oh-my-vul

Skill Claude CodeCodex

Finds and ranks open-source packages worth auditing for passive CVE/VulDB research. Use when the user asks for vulnerability research targets, CVE hunting candidates, packages to audit, projects to fuzz, or /omv-find. Supports npm, Python, Go, Rust, Java, Ruby, PHP, C#, Swift, Dart, Elixir, Perl, R, and Lua, with…

not rated 4 24d ago A 122 tokens original MIT

owndiff

1360

owndiff/own-your-diff

Plugin Claude Code

Bundles 2 skills · 184 tokens together

Local ownership gate and multiple choice question approval skill for AI-assisted code diffs.

not rated 4 1mo ago A tokens not measured original MIT

token-antiflash

1361

0xlayerghost/solidity-agent-kit

Skill Claude CodeCodex

When this skill is triggered, DO NOT directly implement all strategies. Follow this workflow.

not rated 4 1mo ago A 91 tokens original MIT

indykite-skills

1362

indykite/skills

Plugin Claude Code

Bundles 23 skills · 3,661 tokens together

IndyKite skills for coding agents — Agent Gateway deployment, MCP server calls, KBAC authorization policy authoring and lifecycle, AuthZEN decisions and search (single evaluation, batch evaluations, action / resource / subject search), Capture API ingests and deletes (nodes, relationships, properties, property…

not rated 4 6d ago A tokens not measured original Apache-2.0

aislop

1363

scanaislop/skills

Skill Claude CodeCodex

Code-quality gate and coding guardrail for AI coding agents. Always invoke when you finish editing and prepare to hand control back, even if the user did not explicitly ask. Trigger on commit, push, PR, or quality questions like any slop, is this clean, review my changes, score my code, any duplicates, or is this…

not rated 4 14d ago B 99 tokens original MIT

drata-cli-workflow

1365

ethanolivertroy/drata-cli

Skill Claude CodeCodex

Use when querying or changing Drata/GRC data through the drata CLI, including compliance status, frameworks, certificates, Trust Center documents, controls, monitoring tests, evidence, risks, vendors, policies, personnel compliance, and background-check questions. Prefer versionless CLI commands, JSON output…

not rated 4 4mo ago A 83 tokens original MIT

stm

1366

matterhornso/subscribetome

Plugin Claude Code

Bundles 5 commands, 4 hooks · 70 tokens together

AI API key & subscription manager. Out-of-band key entry, OS-keychain storage, and a PreToolUse hook that injects real keys into commands so the model only ever sees placeholders.

not rated 4 changed 9d ago A tokens not measured original MIT

vibecheck

1367

Wishmakingfairy/vibecheck

Plugin Claude Code

Bundles 4 skills, 1 agent, 1 hook · 239 tokens together

Stop shipping vulnerabilities. 156 automated security checks for Claude Code. Blocks exposed API keys, disabled Supabase RLS, missing rate limiting, open CORS, and 150+ more before they reach your codebase.

not rated 4 5mo ago A tokens not measured original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: