24,943 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Production readiness review for applications incorporating AI / ML — covering classical ML models, generative models, LLM-powered applications, RAG systems, and agentic workflows. Checks AI system inventory, EU AI Act classification, training data governance, model supply chain, evaluation harness, prompt injection…
Security-focused prompts and Claude Code skills for Infrastructure as Code review. Includes a comprehensive IaC security review skill with compliance mapping to CIS, NIST 800-53, NIST 800-171, PCI-DSS, SOC 2, HIPAA, GDPR, and ISO 27001.
★not rated 2 6mo agoA
tokens not measured
originalMIT
Scan AI agent skills, plugins, and MCP servers for malicious code BEFORE installation — catches prompt injection, credential theft, data exfiltration, and backdoors. Skills and the static MCP source scan use NVIDIA SkillSpector (static patterns + taint tracking + YARA + live OSV.dev CVE lookup + LLM semantic analysis…
Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.
★not rated 2 todayA
tokens not measured
CC-BY-SA-4.0
Use when the user asks about NIST SP 800-53 Rev. 5 from an engineering perspective — selecting baselines, tailoring controls, modeling control inheritance from cloud providers and shared services, emitting OSCAL artifacts, or implementing controls in IaC and code rather than running them as a documentation exercise.…
Cryptographic best practices for secure system design. Use when: choosing encryption algorithms, implementing password hashing, selecting key lengths, using secure random number generation, implementing digital signatures, designing TLS deployments, key management, or avoiding common cryptographic pitfalls.
This skill should be used when the user asks to configure or troubleshoot AAA (Authentication / Authorization / Accounting) on Huawei S / CE / USG series devices — including 802.1X, MAC authentication, Portal authentication, RADIUS, HWTACACS (TACACS+), local authentication, authentication profiles, free-rule, NAC…
Reverse engineering of compiled, packed, virtualized, or obfuscated targets for authorized CTF challenges. Use when the task is to understand, decompile, disassemble, or unpack an unknown executable across ELF, PE, Mach-O, APK, WASM, firmware, bytecode, or custom-VM targets.
Set up the development environment for the project. Use when starting work on the project, when dependencies are out of sync, or to fix environment setup failures.
A read-only security audit for DeepSeek Harness extensions, settings, dependencies, and runtime exposure. It looks for risks such as exposed secrets, unsafe file mounts, data leaving the system, persistence, and malware indicators.
Create or validate a pwnote engagement import/export JSON file. Use when the user wants to generate, edit, or verify a pwnote engagement file for data transfer between pwnote instances. The file bundles an entire pentest engagement — metadata, notebook documents, code/host/credential blocks, findings with…
Intelligent Agent-Skill dependency butler: discover, security-audit, and install Agent Skills into your project. Scans tech stack, plans a vetted combination, audits each skill, and installs per-agent.
★not rated 2 3mo agoA
tokens not measured
originalMIT
Fail-fast quality gate (Typecheck → Lint → Test → Security Audit) that runs before any task is declared done or code is committed. Auto-detects Node.js and Python projects.
★not rated 2 3mo agoA
tokens not measured
originalMIT
Battle-hardened senior engineer who reviews plans and code before they cause a 3 AM incident. Stress-tests architecture, catches data-pipeline fragility, flags security gaps, and calls out missing error handling, then signs off with a severity summary and grudging approval if earned. Use when reviewing new or existing…
Discovers a web app's user flows, drives a real Chromium browser through them with a live local dashboard, flags functional/content/visual/console bugs, and runs a read-only security audit on local source. Identify-only, never fixes.
Keep finished deliverables limited to what their intended users need. Use when demo instructions, mock details, implementation rationale, temporary shortcuts, or superseded requirements might leak into user-facing pages, reports, exports, documentation, APIs, or CLI output. Do not use for general UX or code-quality…
Review application changes for evidence-based security vulnerabilities and hardening opportunities across authentication, authorization, input handling, APIs, dependencies, and data protection.
Sonomos Canary — persistent PII leak counter for Claude Code. 38 checksum-validated regex detectors (plus your own via rules.d) and Claude self-scan catch sensitive data you expose to AI, Canary Tokens give a CERTAIN alarm the instant a planted decoy secret reaches Claude, and Canary Wrapped turns your exposure…
★not rated 2 12d agoA
tokens not measured
originalMIT
Deep, architecture-aware vulnerability discovery for Claude Code — finds what static scanners miss.
★not rated 2 5mo agoA
tokens not measured
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: