Security

29,257 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

security-agent

122

alinaqi/maggy

Agent

Performs security analysis on completed features - OWASP scanning, secrets detection, dependency audit. Blocks on Critical/High.

not rated 705 +1 17d ago A 27 tokens original MIT

code-review

123

juicesharp/rpiv-mono

Skill Claude CodeCodex

Conduct comprehensive code reviews of pending changes, a branch, or a PR using parallel specialist agents that audit the diff, compare against peer code, and verify claims. Use when the user asks to 'review this', wants pending changes, a PR, a branch, or a diff reviewed, or asks for a code review. Produces review…

not rated 736 yesterday A 100 tokens original MIT

arcjet/arcjet-js

Skill Claude CodeCodex

Integrate Arcjet security into a Claude Agent SDK agent using @arcjet/guard — wrap tool() handlers, screen inbound prompts with UserPromptSubmit, and deny unwrapped built-in/MCP tools with PreToolUse. Use when asked to add Arcjet to a Claude Agent SDK or Claude Code agent, rate limit its tools, screen inbound…

not rated 681 5d ago A 92 tokens original Apache-2.0

encode-veris-incident

125

vz-risk/VCDB

Skill Claude CodeCodex

Encode a GitHub issue describing a data breach into a VERIS-schema JSON incident for VCDB. Invoke with a vz-risk/VCDB issue URL (e.g. https://github.com/vz-risk/VCDB/issues/23372) and an optional analyst GitHub handle. Reads the issue and its linked sources, finds an additional independent source via web search, maps…

not rated 669 1mo ago A 106 tokens

ssh-mcp

126

tufantunc/ssh-mcp

MCP server Claude CodeCodexCursor +2

Policy-gated, audited SSH for Linux and Windows hosts: roles, approvals, and an audit log. Runs locally from the ssh-mcp npm package. Needs 4 environment variables to run.

not rated 669 9d ago A tokens not measured original MIT

Cybermes AGENTS.md

127

Zyrexnn/Cybermes

Instructions file CodexOpenCode

Instructions for Zyrexnn/Cybermes, covering 🛡️ cybermes master operational directives (agents.md), 1. 🎯 persona & core mission, 2. ⚡ core operational principles, 3. 📁 strict target-scoped workspace & deliverables and mandatory rules for file creation.

not rated 668 5d ago A 1,549 tokens original Apache-2.0

iron-proxy AGENTS.md

128

paradigmxyz/iron-proxy

Instructions file CodexOpenCode

AGENTS.md instructions for paradigmxyz/iron-proxy, covering agents.md, repo at a glance, go conventions, simplicity and security invariants (do not weaken).

not rated 647 +5 yesterday B 1,429 tokens original Apache-2.0

abuse-hunter

129

nexu-io/harness-engineering-guide

Skill Claude CodeCodex

Detect and investigate bulk registration abuse on SaaS platforms. Given access to a user database (or exported CSV/JSON), run a multi-dimensional anomaly analysis — email domain clustering, registration tempo, UA fingerprinting, session structure, usage patterns, and credit consumption — to produce a scored abuse…

not rated 635 +4 4mo ago A 86 tokens original MIT

alibaba/anolisa

Skill Claude CodeCodex ✓ vendor

A read-only tool for examining security events already saved by agent-sec-cli, a command-line security log. It can connect those events to an agent session, run, or trace.

not rated 618 yesterday A 145 tokens original Apache-2.0

c-safety-reviewer

131

ZacheryGlass/.claude

Agent

Use this agent when C source files (.c, .h) have been created or modified, especially code involving memory allocation, file descriptors, sockets, cryptographic operations, credential handling, or external input parsing. Should be triggered on every code change to C files to catch resource lifecycle bugs and security…

not rated 599 2mo ago A 492 tokens

jndi-map

132

X1r0z/JNDIMap

Skill Claude CodeCodex

Use this skill for JNDIMap, a JNDI injection framework for RMI, LDAP, and LDAPS. It helps run the jar, choose flags and ports, build JNDI URLs for Basic payloads, MemShell injection, BeanFactory bypasses, JDBC RCE, Tomcat XXE, Hessian, LDAP deserialization gadgets, custom scripts, and advanced options such as JShell…

not rated 601 4mo ago A 103 tokens original MIT

ironcurtain CLAUDE.md

133

provos/ironcurtain

Instructions file

Claude Code instructions for provos/ironcurtain, covering claude.md, general workflow, git & worktrees, git workflow and platform considerations.

not rated 600 yesterday A 5,773 tokens original Apache-2.0

multi-agent-roles

134

berabuddies/Semia

Skill Claude CodeCodex

This skill provides a comprehensive framework for designing professional multi-agent systems. It includes standardized role definitions for various AI applications and workflows.

not rated 595 3d ago A 0 tokens original Apache-2.0

emersonfelipesp/netbox-proxbox

Instructions file

Claude Code instructions for emersonfelipesp/netbox-proxbox, covering netbox-proxbox codebase guide, repository destination policy (hard rule), pre-commit checklist, framework stack preference and security and permissions.

not rated 590 changed today A 30,387 tokens original Apache-2.0

chainloop-dev/chainloop

Skill Claude CodeCodex

Reviews vulnerability policy violations for the chainloop project recorded in Chainloop and performs fixes in Dockerfiles or go.mod. Use when asked to fix vulnerabilities, review CVEs, or remediate security issues in chainloop.

not rated 583 2d ago A 48 tokens original Apache-2.0

js-reverse-automation

137

Fausto-404/js-reverse-automation--skill

Skill Claude CodeCodex

A workflow for examining JavaScript in a real browser to find where login data, API requests, form fields, or responses are encrypted or signed. It then produces code and connection documentation for using that logic elsewhere.

not rated 577 +3 1mo ago A 48 tokens original Apache-2.0

elastic-cloud

138

elastic/agent-skills

Plugin Claude Code ✓ vendor

Bundles 2 skills · 151 tokens together

Elastic Cloud skills - project setup, access management, network security, and Serverless project lifecycle.

not rated 568 +1 changed today A tokens not measured original Apache-2.0

security-audit

140

TheDecipherist/claude-code-mastery

Skill Claude CodeCodex

Audit code and dependencies for security vulnerabilities. Use when reviewing PRs, checking dependencies, preparing for deployment, or when user mentions security, vulnerabilities, or audit.

not rated 545 3mo ago A 36 tokens original MIT

cryptography

141

yhy0/CHYing-agent

Skill Claude CodeCodex

Use when facing cryptography challenges involving cipher analysis, key recovery, mathematical attacks, or protocol weaknesses.

not rated 549 +16 4mo ago A 22 tokens original MIT

mcp

142

decionis/agent-safe-pipeline

MCP server Claude CodeCodexCursor +2

Authorize consequential AI agent actions before execution. Runs locally from the @decionis/mcp npm package. Needs 1 environment variable to run.

not rated 533 2d ago A tokens not measured original Apache-2.0

google/mcp-security

Skill Claude CodeCodex ✓ vendor

Helps the user configure the Google SecOps Remote MCP Server for Antigravity. Use this when the user asks to "set up" or "configure" the security tools for Antigravity.

not rated 521 today A 48 tokens original Apache-2.0

remix

144

kentcdodds/kody

Skill Claude CodeCodex

Build and review Remix 3 applications using the remix npm package and subpath imports. Use when working on Remix app structure, routes, controllers, middleware, validation, data access, auth, sessions, file uploads, server setup, UI components, hydration, navigation, or tests.

not rated 525 today A 62 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: