24,943 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Backend security review and secure-by-default coding for Django and DRF, on an OWASP Top 10:2025, API Security Top 10:2023, and ASVS 5.0 foundation. Apply when backend code is written or reviewed and touches authentication, sessions, cookies, JWT, OAuth2/OIDC, API keys, password hashing, permissions, access control…
Single-CVE applicability triage that evaluates whether a CVE actually applies to the user's environment by reasoning about discriminating conditions against a skill-maintained environment profile; triggers when a user asks whether they are affected by a CVE, whether a CVE applies to them, or wants to assess a CVE…
Artifact-driven, plugin-based multi-agent SAST pipeline for web and mobile app repositories. Web agents cover the OWASP Top 10; mobile agents cover the OWASP Mobile Top 10 (2024, M1-M10). Both share global validation/PoC/reporting agents. Run /vantage:scan-web or /vantage:scan-mobile to scan, then /vantage:fix-issue…
★not rated 4 1mo agoA
tokens not measured
originalMIT
Git branch for your cloud. Understand AWS risk, prove fixes, and ship safer changes. Runs locally from the @emfirge/mcp npm package. Needs 2 environment variables to run.
First-in-the-world AI governance and compliance discipline for AI Governance Officers, Compliance Leads, Risk Managers, DPOs, Legal Counsel, CISOs, and AI and ML and LLM engineers and architects. Operationalizes ISO/IEC 42001:2023 (AI Management System clauses 4 to 10, roughly 38 Annex A controls across 9 objectives…
Clerk authentication integration for Astro/Next.js. Use when implementing authentication, handling Clerk middleware, testing with Playwright, or debugging auth issues. Trigger phrases include "Clerk auth", "sign in", "authentication", "middleware", "E2E testing with Clerk".
Runs real security scanners over code, full git history, dependencies, IaC and Supabase/Firebase row-level security, then verifies every finding against source before reporting.
★not rated 4 1mo agoA
tokens not measured
originalMIT
Finds and ranks open-source packages worth auditing for passive CVE/VulDB research. Use when the user asks for vulnerability research targets, CVE hunting candidates, packages to audit, projects to fuzz, or /omv-find. Supports npm, Python, Go, Rust, Java, Ruby, PHP, C#, Swift, Dart, Elixir, Perl, R, and Lua, with…
Code-quality gate and coding guardrail for AI coding agents. Always invoke when you finish editing and prepare to hand control back, even if the user did not explicitly ask. Trigger on commit, push, PR, or quality questions like any slop, is this clean, review my changes, score my code, any duplicates, or is this…
Use when querying or changing Drata/GRC data through the drata CLI, including compliance status, frameworks, certificates, Trust Center documents, controls, monitoring tests, evidence, risks, vendors, policies, personnel compliance, and background-check questions. Prefer versionless CLI commands, JSON output…
AI API key & subscription manager. Out-of-band key entry, OS-keychain storage, and a PreToolUse hook that injects real keys into commands so the model only ever sees placeholders.
★not rated 4
changed 9d agoA
tokens not measured
originalMIT
Stop shipping vulnerabilities. 156 automated security checks for Claude Code. Blocks exposed API keys, disabled Supabase RLS, missing rate limiting, open CORS, and 150+ more before they reach your codebase.
★not rated 4 5mo agoA
tokens not measured
originalMIT
Policy enforcement, PII detection, and audit trails for Claude Code. Govern tool execution, scan outputs for sensitive data, and maintain compliance-grade records of every action.
★not rated 4
changed 5d agoA
tokens not measured
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: