Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

deep-security-check

1705

give-jd/deep-security-check

Plugin Claude Code

Bundles 1 skill · 103 tokens together

Defensive, read-only security assessment of a local project (Semgrep + osv-scanner + gitleaks) with a reproducible reliability grade (0-100, A-F).

not rated 2 2mo ago A tokens not measured original MIT

robtex

1706

robtex/skills

Plugin Claude Code

Bundles 6 skills, 1 MCP server · 162 tokens together

DNS, IP intelligence, AS routing, domain reputation, Bitcoin blockchain, Lightning Network, and threat intelligence. 50+ tools for network analysis, crypto investigation, and security research.

not rated 2 2mo ago A tokens not measured

swe-workbench

1707

lugassawan/swe-workbench

Plugin Claude Code

Bundles 60 skills, 25 commands, 22 agents, 4 hooks · 6,768 tokens together

Senior-engineer toolkit: principled design (Clean Arch, DDD, SOLID, TDD, patterns, observability, concurrency), security review, language expertise (Bash, C#, Dart, Go, Java, Kotlin, Python, Ruby, Rust, SQL, Swift, TypeScript), and pragmatic workflows.

not rated 2 changed 6d ago A tokens not measured original MIT

secure-coding

1708

joaovicdev/claude-owasp-10

Plugin Claude Code

Bundles 2 skills, 1 agent · 215 tokens together

OWASP Top 10:2025 rules for writing and reviewing backend/API code in any language, plus /api-secure-report — a full security inventory of every HTTP route in a project.

not rated 2 18d ago A tokens not measured original MIT

terraform-lsp

1709

zircote/terraform-lsp

Plugin Claude Code

Bundles 2 commands · 0 tokens together

Claude Code plugin for Terraform development with terraform-ls LSP integration, 17 automated hooks for security scanning (trivy, checkov), linting (tflint), formatting, and Terragrunt support.

not rated 2 1mo ago A tokens not measured original MIT

runverdict/sf-security-review-toolkit

Plugin Claude Code

Bundles 14 skills, 1 hook · 1,677 tokens together

Skills that prepare an ISV partner for the AppExchange/AgentExchange security review end to end — autonomous multi-agent codebase audit, submission-artifact generation, scan orchestration, test-environment runbooks, and an honest readiness verdict.

not rated 2 1mo ago A tokens not measured original Apache-2.0

document-guard

1711

davidmoneil/aifred-document-guard

Plugin Claude Code

Bundles 1 command, 1 hook · 14 tokens together

Prevents Claude from accidentally damaging important files. Intercepts Edit/Write operations and validates them against configurable protection rules including credential scanning, structural preservation, and semantic checks.

not rated 2 5mo ago A tokens not measured original MIT

audit-plugin

1712

AgenticPawan/FullStack-Pilot

Command Claude Code

Brutal pre-submission audit of a Claude Code plugin marketplace — vulnerabilities, wiring integrity, standards compliance, skill gaps.

not rated 2 1mo ago A 24 tokens original MIT

theseus

1713

kalt-sit/theseus

Skill Claude CodeCodex

Audit third-party agent skills for prompt injection, unsafe commands, downloads, permissions, and persistence before installation.

not rated 2 14d ago A 24 tokens original MIT

fable-audits

1714

diegomarino/fable-audits

Plugin Claude Code

Bundles 8 commands · 177 tokens together

Adversarial audit suite: whole-repo codebase/docs/process/security audits, a diff-scoped change audit, an orchestrator that synthesizes one fixes backlog, and a human-gated fixing agent. Evidence labels, stable finding IDs, acceptance checks.

not rated 2 1mo ago A tokens not measured original MIT

mcpnuke-development

1717

babywyrm/mcpnuke

Cursor rule Cursor

Core mcpnuke development standards and superpowers workflow integration.

not rated 2 5d ago A 1,059 tokens original MIT

delegate

1718

kanoniv/auth-action

Skill Claude Code

Cryptographic delegation for AI agents. Scope-confines what Claude Code can do in this session using Ed25519 delegation tokens. Every action is verified before execution and signed for the audit trail. Use when asked to "delegate", "restrict scope", "authorize", or "sudo mode".

not rated 2 5mo ago A 61 tokens

github

1719

adudley78/mcp-audit

MCP server Claude CodeCodexCursor +2

One of 3 in claude_desktop_config.json

Lets the agent work with GitHub: search code, read and create issues and pull requests, and manage repositories through the GitHub API. Runs locally from the @modelcontextprotocol/server-github npm package. Needs 1 environment variable to run.

not rated 2 today A tokens not measured copy · 89% Apache-2.0

a2amesh

1720

oaslananka/a2amesh

Plugin Claude Code

Bundles 3 skills, 1 MCP server · 93 tokens together

A2A Mesh workflows for endpoint validation, approved task operations, and security-bounded MCP consumption.

not rated 2 today A tokens not measured original Apache-2.0

synapsor-protect

1721

Synapsor/Synapsor-Runner

Command Claude Code

Draft and validate one disabled Synapsor Safe Action for an existing application.

not rated 2 13d ago A 21 tokens original Apache-2.0

securly

1722

BghitCode/Securly

Skill Claude CodeCodex

Apply security guidelines when designing, building, or reviewing AI chatbots, LLM-powered apps, autonomous/tool-using agents, and mobile apps (React Native/Expo, Flutter) — covering agent controls (authorization checks, plan validation, execution limits, audit logging), LLM/prompt security (prompt injection, RAG…

not rated 2 2mo ago A 198 tokens original MIT

govern-codex

1723

KeyArgo/custodian-codex-guard

Skill Claude Code

Govern consequential Codex tool calls with Custodian before execution, including writes, network access, credentials, destructive commands, production changes, and money movement.

not rated 2 22d ago A 36 tokens original Apache-2.0

security-audit

1724

krinalme/ai-security-audit

Skill Claude CodeCodex

Comprehensive security audit for web applications and APIs. Performs a full-stack security review covering authentication, authorization, rate limiting, input validation, secrets management, security headers, cost controls (AI/API spend), email abuse prevention, dependency vulnerabilities, and data exposure risks.…

not rated 2 6mo ago B 172 tokens original MIT

trycatch

1725

GitRavz/TryCatch

Skill Claude CodeCodex

Use when asked to check, audit, or review a web application's security, authentication, permissions, access control, error handling, API/endpoint surface, or database management — including "is my app secure", "check my auth", "review my permissions", "find vulnerabilities", or a pre-launch/pre-handover review.

not rated 2 1mo ago A 68 tokens original MIT

eu-ai-act-compliance

1726

BuilderCed/agent-skills

Skill Claude CodeCodex

Classify AI system risk under EU AI Act (Reg 2024/1689), generate Article 50 disclosures, and design conformity audit trails.

not rated 2 4mo ago A 36 tokens original MIT

agent-security-audit

1727

dacuma-labs/agent-security-audit

Skill Claude CodeCodex

Audits AI agent projects for security risks in prompts, tools, memory, RAG, and permissions. Use when: the user asks to review agent security, harden an agentic system, check for prompt injection risks, audit tool permissions, or secure an AI assistant before deployment. Do NOT use for: projects with no agentic…

not rated 2 5mo ago A 82 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: