Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

devops-best-practices

1681

ronalships/claude-devops-skill

Skill Claude CodeCodex

Opinionated production-grade DevOps defaults for Terraform, Kubernetes, CI/CD, Docker, cloud security, observability, cost, and disaster recovery. ALWAYS use when generating, reviewing, or modifying any infrastructure code, Kubernetes manifests (Deployment, Service, StatefulSet, Helm, Kustomize), Terraform (.tf…

not rated 2 3mo ago B 209 tokens original MIT

ai-readiness

1682

Nordic-AI/production-readiness-skills

Skill Claude CodeCodex

Production readiness review for applications incorporating AI / ML — covering classical ML models, generative models, LLM-powered applications, RAG systems, and agentic workflows. Checks AI system inventory, EU AI Act classification, training data governance, model supply chain, evaluation harness, prompt injection…

not rated 2 4mo ago A 160 tokens original Apache-2.0

agent-guard

1685

elliottwaves-20/agent-guard

Skill Codex

Scan AI agent skills, plugins, and MCP servers for malicious code BEFORE installation — catches prompt injection, credential theft, data exfiltration, and backdoors. Skills and the static MCP source scan use NVIDIA SkillSpector (static patterns + taint tracking + YARA + live OSV.dev CVE lookup + LLM semantic analysis…

not rated 2 changed 6d ago C 400 tokens original MIT

entry-point-analyzer

1686

Fodhol/skills

Plugin Claude Code

Bundles 1 skill · 110 tokens together

Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level, and generates structured audit reports.

not rated 2 today A tokens not measured CC-BY-SA-4.0

nist-800-53

1687

grcwarlock/compliance-as-code

Skill Claude Code

Use when the user asks about NIST SP 800-53 Rev. 5 from an engineering perspective — selecting baselines, tailoring controls, modeling control inheritance from cloud providers and shared services, emitting OSCAL artifacts, or implementing controls in IaC and code rather than running them as a documentation exercise.…

not rated 2 4mo ago A 76 tokens original MIT

crypto-best-practices

1688

pedromneto97/custom-skills

Skill Claude Code

Cryptographic best practices for secure system design. Use when: choosing encryption algorithms, implementing password hashing, selecting key lengths, using secure random number generation, implementing digital signatures, designing TLS deployments, key management, or avoiding common cryptographic pitfalls.

not rated 2 2mo ago A 57 tokens original MIT

ihme

1689

lroolle/ihme-cli

Skill Claude CodeCodex

Manage iCloud Hide My Email addresses — list, create, edit, deactivate, export.

not rated 2 changed yesterday B 20 tokens original MIT

aaa-auth-config

1690

nanxiaoyao/network-huawei-skills

Skill Claude CodeCodex

This skill should be used when the user asks to configure or troubleshoot AAA (Authentication / Authorization / Accounting) on Huawei S / CE / USG series devices — including 802.1X, MAC authentication, Portal authentication, RADIUS, HWTACACS (TACACS+), local authentication, authentication profiles, free-rule, NAC…

not rated 2 1mo ago A 165 tokens original MIT

fieldops-ctf-reverse

1691

download4you/n2-fieldops

Skill Codex

Reverse engineering of compiled, packed, virtualized, or obfuscated targets for authorized CTF challenges. Use when the task is to understand, decompile, disassemble, or unpack an unknown executable across ELF, PE, Mach-O, APK, WASM, firmware, bytecode, or custom-VM targets.

not rated 2 24d ago A 71 tokens original MIT

setup-dev-env

1692

yu-iskw/skill-inspector

Skill Claude Code

Set up the development environment for the project. Use when starting work on the project, when dependencies are out of sync, or to fix environment setup failures.

not rated 2 12d ago A 35 tokens original Apache-2.0

dsh-security-audit

1693

yhny1001/dsh-security-audit

Skill Claude CodeCodex

A read-only security audit for DeepSeek Harness extensions, settings, dependencies, and runtime exposure. It looks for risks such as exposed secrets, unsafe file mounts, data leaving the system, persistence, and malware indicators.

not rated 2 25d ago A 67 tokens original MIT

pwnote-engagement-file

1694

Pwnote/skills

Skill Claude CodeCodex

Create or validate a pwnote engagement import/export JSON file. Use when the user wants to generate, edit, or verify a pwnote engagement file for data transfer between pwnote instances. The file bundles an entire pentest engagement — metadata, notebook documents, code/host/credential blocks, findings with…

not rated 2 1mo ago A 113 tokens original MIT

skillforge

1695

yvzhou1111/skillforge

Plugin Claude Code

Bundles 2 skills · 139 tokens together

Intelligent Agent-Skill dependency butler: discover, security-audit, and install Agent Skills into your project. Scans tech stack, plans a vetted combination, audits each skill, and installs per-agent.

not rated 2 3mo ago A tokens not measured original MIT

pre-flight-check

1696

mirekondro/The-Pre-Flight-Check

Plugin Claude Code

Bundles 1 skill · 45 tokens together

Fail-fast quality gate (Typecheck → Lint → Test → Security Audit) that runs before any task is declared done or code is committed. Auto-detects Node.js and Python projects.

not rated 2 3mo ago A tokens not measured original MIT

grouchy-mentor

1697

emekdahl/skills

Skill Claude CodeCodex

Battle-hardened senior engineer who reviews plans and code before they cause a 3 AM incident. Stress-tests architecture, catches data-pipeline fragility, flags security gaps, and calls out missing error handling, then signs off with a severity summary and grudging approval if earned. Use when reviewing new or existing…

not rated 2 2mo ago A 82 tokens original MIT

flow-tester

1698

kushagraagent47/vibe-tester

Plugin Claude Code

Bundles 1 skill · 114 tokens together

Discovers a web app's user flows, drives a real Chromium browser through them with a live local dashboard, flags functional/content/visual/console bugs, and runs a read-only security audit on local source. Identify-only, never fixes.

not rated 2 2mo ago A tokens not measured

user-facing-only

1699

Ljhhhhhh/user-facing-only-skill

Skill Codex

Keep finished deliverables limited to what their intended users need. Use when demo instructions, mock details, implementation rationale, temporary shortcuts, or superseded requirements might leak into user-facing pages, reports, exports, documentation, APIs, or CLI output. Do not use for general UX or code-quality…

not rated 2 13d ago A 64 tokens original MIT

security-review

1700

Arnosdeus/agent-toolkit

Skill Claude CodeCodex

Review application changes for evidence-based security vulnerabilities and hardening opportunities across authentication, authorization, input handling, APIs, dependencies, and data protection.

not rated 2 20d ago A 31 tokens original MIT

canary

1702

sonomoshq/Canary

Plugin Claude Code

Bundles 5 skills, 1 agent, 3 hooks · 208 tokens together

Sonomos Canary — persistent PII leak counter for Claude Code. 38 checksum-validated regex detectors (plus your own via rules.d) and Claude self-scan catch sensitive data you expose to AI, Canary Tokens give a CERTAIN alarm the instant a planted decoy secret reaches Claude, and Canary Wrapped turns your exposure…

not rated 2 12d ago A tokens not measured original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: