Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

agent-identity

1369

agentmessaging/agent-identity

Plugin Claude Code

Bundles 1 skill · 53 tokens together

Authenticate AI agents with auth servers using the Agent Identity (AID) protocol. Ed25519 identity documents, proof of possession, and OAuth 2.0 token exchange.

not rated 4 1mo ago A tokens not measured original MIT

llm-redact

1370

asanderson/llm-redact

Plugin Claude Code

Bundles 10 commands, 1 hook · 181 tokens together

llm-redact proxy control: status, live traffic, sessions, redaction preview, audit verification, and guarded config editing as slash commands.

not rated 5 4d ago A tokens not measured AGPL-3.0

code-reviewer

1371

osouthgate/agent-plus

Skill Claude Code

Reviews code for quality, bugs, security, and best practices. Use when changing code or before merge. Checks security, authentication, and validation; ensures new code follows project rules and conventions.

not rated 4 2mo ago A 42 tokens original MIT

web-security-guard

1372

ayalaphiscan/web-security-guard

Plugin Claude Code

Bundles 6 skills, 2 commands · 1,012 tokens together

Integrated security for websites and apps: hardening, secure authentication (email verification, 2FA, passkeys), payment privacy, attack-defense agent with lockdown, 4-layer Fortress architecture and automated GitHub security workflows. Bilingual skills (English + Italiano). | Sicurezza integrata per siti e app…

not rated 4 3mo ago A tokens not measured original MIT

feedback

1373

ch015/code-pentester

Command Claude Code

A design-stage security review for product requirement documents and other planning documents; a PRD is a document describing what a product should do.

not rated 4 changed 3d ago A 21 tokens original MIT

smart-approval

1374

froggeric/claude-smart-approval

Plugin Claude Code

Bundles 1 hook

AI permission tier for Claude Code Bash commands: deny-list gate plus smart AI evaluation for unknown commands. Requires Claude Code >= 2.0.45, shfmt, jq (brew install shfmt jq).

not rated 4 24d ago A tokens not measured original MIT

metago-security-audit

1375

metago-ai/metagolifeform

Skill Claude CodeCodex

A security review skill based on the OWASP Top 10, a commonly used list of major web-application security risks. It checks code, dependencies, configuration, authentication, and data handling.

not rated 4 11d ago A 75 tokens original MIT

xray-suite

1376

Roshu18/bearstrike-ai

Skill Claude CodeCodex

Playbook for Xray Suite scanner, crawlergo, and headless browser usage with safe request pacing.

not rated 4 5mo ago A 25 tokens original MIT

skillsafe-scanner

1377

adamoutler/joplin-server-vector-memory

Skill Claude CodeCodex

Run the skillsafe scan on the adamoutler/joplin-server-vector-memory package, then operate and improve/complete all issues identified. Use this when asked to scan or fix skillsafe issues.

not rated 4 3mo ago A 45 tokens

review-guard

1378

eclipsesource/review-guard

MCP server Claude CodeCodexCursor +2

Safety boundary for agent written GitHub PR reviews: pending and invisible, submitting is opt-in. Runs locally from the @eclipsesource/review-guard-mcp npm package. Needs 1 environment variable to run.

not rated 4 2d ago A tokens not measured original MIT

mcpvessel

1379

okedeji/mcpvessel

Skill Claude CodeCodex

Cage, run, and audit MCP servers with mcpvessel: install an MCP server into an isolated container, serve it to Claude Code, and watch what it does with the network and the user's secrets. Use this whenever the user mentions mcpvessel by name, or wants to add, install, set up, try, run, or sandbox an MCP server, or…

not rated 4 1mo ago A 152 tokens original Apache-2.0

nsauditor-ai

1380

nsasoft/nsauditor-ai-agent-skill

Skill Claude CodeCodex

Use this skill whenever the user wants network security scanning, auditing, vulnerability assessment, host reconnaissance, or cloud-account security/compliance auditing with NSAuditor AI (via the nsauditor-ai MCP server: scanhost, scancloud, getfindings, probeservice, getvulnerabilities, listplugins). Triggers include…

not rated 4 changed 3d ago B 248 tokens original MIT

code-reviewer

1381

techgangboss/agentstore

Plugin Claude Code

Bundles 1 skill · 70 tokens together

AI-powered code review that analyzes your code for bugs, security issues, and best practices.

not rated 4 7mo ago A tokens not measured original MIT

6jeffr3y/burpsuite-mcp-bridge

Skill Codex

Operate BurpSuite MCP Bridge for professional, authorized web testing. Use when Codex needs to inspect Burp live/history/logger/selection traffic, prioritize one target, retrieve a decisive request/response, intercept and edit a request or response before forwarding, replay one controlled mutation, manage temporary…

not rated 4 5d ago A 92 tokens

enigmagent-vault

1383

Agnuxo1/EnigmAgent

Skill Claude CodeCodex

Use the EnigmAgent encrypted vault to handle credentials, API keys, and private documents without those values ever appearing in your reasoning or output. Placeholders are resolved at execution time.

not rated 4 3mo ago A 42 tokens original MIT

skillsync-mcp

1384

adityasugandhi/skillsync-mcp

Skill Claude CodeCodex

Search, scan, install, and manage Claude Code skills with built-in security scanning. Every installation is gated behind a 60+ pattern threat scan.

not rated 4 6mo ago A 0 tokens original MIT

toolpermit

1385

sunhao123456sun-svg/toolpermit

Skill Codex

Install, configure, operate, and troubleshoot ToolPermit, the local-first permission policy, one-time approval, and redacted audit layer for MCP stdio tool calls. Use when Codex needs to protect or inspect an MCP server, wrap an MCP stdio command, create or review allow/ask/deny policies, manage approvals, replay…

not rated 4 3d ago A 100 tokens original Apache-2.0

savvydfir

1386

kismatkunwar89/SAVVYDFIR-MCP

MCP server Claude CodeCodexCursor +2

MCP server "savvydfir" as configured in kismatkunwar89/SAVVYDFIR-MCP. Runs sift_mcp.server with ./venv/bin/python3. Needs 4 environment variables to run.

not rated 4 3mo ago A tokens not measured original MIT

marq

1387

rhaist/marq

Skill Claude CodeCodex

Skill "marq" from rhaist/marq, covering marq — cyber assistant, start here — scope and domains, how to call a tool, discover tools and long-running scans.

not rated 4 1mo ago A 69 tokens AGPL-3.0

tool-gates

1388

camjac251/tool-gates

Plugin Claude Code

Bundles 2 skills · 460 tokens together

Intelligent permission gate for Claude Code shell, file, search, Skill, and MCP tool surfaces. AST-parses Bash commands, guards file reads/writes, and blocks configured tool invocations. Defers benign asks to CC's resolver so the prompt UI shows the 'Yes, and don't ask again for X' button, while keeping a deny floor…

not rated 4 today A tokens not measured

break-risk-intel

1389

c0urag1/break-risk-intel-skill

Skill Claude CodeCodex

An assistant for analysing intelligence about black- and grey-market abuse, such as fraud, account attacks, and dishonest automation.

not rated 4 3mo ago A 154 tokens

test-kitchen

1390

2389-research/test-kitchen

Plugin Claude Code

Bundles 4 skills · 257 tokens together

Parallel exploration of implementation approaches - run multiple variants simultaneously and let tests determine the winner.

not rated 4 2mo ago A tokens not measured original MIT

archguardian

1391

ysfAskri/archguardian

Cursor rule Cursor

Pre-commit hook and CLI that catches security issues, AI-generated code smells, naming convention violations, code duplication, and architecture layer breaches. Works with TypeScript, JavaScript, Python, Go, Rust, and Java.

not rated 4 6mo ago A 692 tokens original MIT

1password

1392

petejm/1password-skill

Cursor rule Cursor

Interact with 1Password CLI (op) — auth recovery, secret retrieval, SSH agent, git commit signing, shell plugins, service accounts, and troubleshooting. Use this skill when the user mentions 1Password, op CLI, or when you know their environment uses the 1Password SSH agent. Trigger on SSH "Permission denied" errors…

not rated 4 1mo ago B 8,182 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: