Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

workflow-code-review

1585

mllt992/vibe-coding-rules

Skill Claude Code

A code-review workflow that reads code without running it and checks technical correctness, coding standards, maintainability, and code-level security. It is triggered by requests to review code or after certain development workflows.

not rated 3 4mo ago A 133 tokens

vibe-security-audit

1586

ohong/agent-skills

Skill Claude CodeCodex

Audit and fix security vulnerabilities in "vibe-coded" apps — projects built fast with AI assistance, especially on Supabase, Firebase, or other BaaS backends. Trigger when building, reviewing, debugging, or deploying a web app with a BaaS backend, or when code touches databases, API keys, authentication, environment…

not rated 3 13d ago A 131 tokens original MIT

intercept

1587

hijacksecurity/claude-plugins

Plugin Claude Code

Bundles 7 skills, 6 commands, 1 MCP server · 835 tokens together

Intercept security for Claude Code — deep AI security scans that supplement your scanners and write findings back to the Intercept platform as your system of record. Targets what rules-based scanners can't reach: container image contents, cloud/infra posture, and cross-file/interprocedural logic.

not rated 3 2mo ago A tokens not measured

genai-governance

1588

djimit/overheid-plugins

Skill Claude Code

Helpt bij het implementeren van technische governance-controls voor generatieve AI-systemen bij de Nederlandse overheid, conform de EU AI Act (hoog-risico), AVG en BIO2. Biedt model cards (Annex IV), conformiteitsbeoordeling (Art. 43), audit trails (Art. 12), menselijk toezicht (Art. 14), besluitregistratie, model…

not rated 3 +1 1mo ago A 292 tokens EUPL-1.2

burpsuite

1590

nguyenthdat/burp-mcp

Skill Claude CodeCodex

Operate an already configured burp-mcp server for authorized web application security testing, penetration testing, vulnerability assessment, and Burp Suite automation: inspect Proxy HTTP/WebSocket history, scope, and site map; craft and replay requests in Repeater; run bounded parallel fuzzing, race condition jobs…

not rated 3 changed 6d ago A 168 tokens original MIT

steganography-mcp

1591

badchars/steganography-mcp

MCP server Claude CodeCodexCursor +2

Steganography analysis MCP server — 128 tools, 17 categories. Image steganalysis, JPEG/F5/JSteg detection, audio steganography, video stego, GIF palette analysis, network covert channels, MP3 stego, spread spectrum, BPCS, archive stego, QR code analysis. Runs locally from the steganography-mcp npm package.

not rated 3 6d ago A tokens not measured original MIT

plugin-cms-toolkit

1593

smithdak/plugin-cms-toolkit

Plugin Claude Code

Bundles 8 skills, 1 agent · 564 tokens together

Claude Code plugin for Sitecore, Umbraco, and Optimizely CMS development — scaffolding, content modeling, accessibility scanning, security audits, best practices, and code generation.

not rated 3 3mo ago A tokens not measured

x402-before-you-pay

1594

seancrecord/scvd-general-store-repo

Cursor rule Cursor

Before paying an x402 endpoint, read its 402 terms and run scvd.store's free preflight and dry run; decide with every reason named.

not rated 3 today A 0 tokens original MIT

security

1596

Luxvil/ai-coding-rules

Cursor rule

Cursor rule "security" from Luxvil/ai-coding-rules, covering windsurf rules - security, 🔴 non-negotiable, authentication & authorization, session management and api security.

not rated 3 today A 158 tokens original MIT

sanction

1597

ericlovold/sanction

Plugin Cursor

Bundles 4 skills · 188 tokens together

Independent authorization plane for AI agents — approve, escalate, or deny spend, tools, credentials, and provisioning. Wires the hosted wallet MCP; the host must ask before acting.

not rated 3 +1 today A tokens not measured

cve-to-cme

1598

stuwrtlttle/cme

Skill Claude CodeCodex

Map CVE IDs or OSIDB flaw IDs to applicable CME controls. Use when the user provides a CVE ID or flaw identifier and asks about mitigations.

not rated 3 3d ago A 39 tokens

network-scanner-mcp

1600

marc-shade/network-scanner-mcp

MCP server Claude CodeCodexCursor +2

MCP server "network-scanner-mcp" as configured in marc-shade/network-scanner-mcp. Runs locally from the network-scanner-mcp Python package.

not rated 2 6mo ago A tokens not measured

vrchat-mcp

1601

BASIC-BIT/vrchat-mcp

Skill Claude CodeCodex

Use when operating VRChat MCP tools, especially auth, privacy-sensitive results, writes, stale cache, or resolving names to IDs.

not rated 2 yesterday A 31 tokens original MIT

enigmagent-mcp

1602

Agnuxo1/enigmagent-mcp

MCP server Claude CodeCodexCursor +2

Local AES-256-GCM vault for AI agents. Secrets stay local, LLMs never see real API keys. Runs locally from the enigmagent-mcp npm package. Needs 2 environment variables to run.

not rated 2 4mo ago A tokens not measured original MIT

secure-host-mcp

1603

Razewang/secure-host-mcp

MCP server Claude CodeCodexCursor +2

Cross-platform remote terminal MCP server with OAuth, jobs, tunnels, and auditing. Runs locally from the secure-host-mcp npm package.

not rated 2 1mo ago A tokens not measured original MIT

presidio-v/presidio-hardened-x402-mcp

MCP server Claude CodeCodexCursor +2

MCP server exposing presidio-hardened-x402 pre-payment PII screening, policy, and replay-guard tools to autonomous agents. Runs locally from the presidio-hardened-x402-mcp Python package.

not rated 2 yesterday A tokens not measured original MIT

guard-x402-payments

1605

razel369/intentfence

Skill Codex

Guard an autonomous agent's x402 payment with the live IntentFence service before it signs. Use when an agent receives a PAYMENT-REQUIRED challenge, is about to pay an x402 endpoint, needs to enforce a USDC price ceiling or payee allowlist, or needs signed evidence that an exact Base USDC quote was checked. Also use…

not rated 2 1mo ago A 89 tokens original Apache-2.0

scanner

1606

RoscoNL/intodns-mcp-server

MCP server Claude CodeCodexCursor +2

DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools. Runs locally from the intodns-mcp npm package.

not rated 2 6d ago A tokens not measured original MIT

neura-openclaw-core

1607

neurarelay/relay-action-card

Skill Claude CodeCodex

Use when an OpenClaw-style or local autonomous computer-use agent needs a single Neura Relay preflight workflow for messages, file changes, browser submits, shell commands, package or publisher changes, workflow state, memory writes, or data exports before execution.

not rated 2 20d ago A 58 tokens original MIT

mcp-gateway-scan

1608

willianpinho/mcp-gateway-scan

MCP server Claude CodeCodexCursor +2

Read-only MCP/agent-gateway readiness scanner — scores a repo across 7 security dimensions. Runs locally from the mcp-gateway-scan npm package.

not rated 2 2mo ago A tokens not measured original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: