Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

stride-threat-model

1729

taimurijlal/Claude-Code-Security

Skill Claude CodeCodex

Creates a STRIDE threat model of the current project with ASCII diagrams and outputs a threat.md file. Use when analyzing system security, designing architectures, or identifying threats in applications.

not rated 2 5mo ago A 39 tokens

amg-check-key-vault

1730

Azure/amg-skills

Skill Claude Code ✓ vendor

Fleet-wide Azure Key Vault health check — pulse check for availability, API latency, throttling (429s), auth failures (401/403), and vault saturation across all vaults, then deep-dives into the top 7 most interesting vaults with metrics and resource logs. Tracks known issues across sessions via persistent report. On…

not rated 2 4mo ago A 87 tokens MIT-0

pii-check

1731

clewisdev/skills

Skill Claude CodeCodex

Audit a repo for PII leakage, secrets, and sensitive data before commits or publishing. Runs gitleaks if available, scans git history, checks working tree for known and novel patterns, and optionally wires up a pre-commit hook. Use before making a private repo public, after importing external data into a project, or…

not rated 2 3mo ago A 77 tokens original MIT

pentest-core

1733

thapr0digy/skills

Plugin Claude Code

Bundles 7 skills, 3 agents · 462 tokens together

Core infrastructure for offensive security engagements. Manages engagement configuration, scope validation, remote execution, evidence organization, and Plextrac-compatible finding export.

not rated 2 13d ago A tokens not measured original MIT

handrail

1734

svyatov/handrail

Plugin Claude Code

Bundles 2 skills, 1 hook · 139 tokens together

Declare an agent guardrail once, in one neutral format, and enforce it through every harness's native hooks.

not rated 2 6d ago A tokens not measured original MIT

ask-user-gate

1735

neurocod/llm-loop

Plugin Claude Code

Bundles 1 hook

Refuse shell commands that would stop the session on a permission prompt, and name the replacement for each one.

not rated 2 changed 9d ago A tokens not measured original MIT

check

1736

7xmohamed/Kata

Skill Claude Code

Reviews code diffs after implementation, auto-fixes safe issues, and runs specialist security and architecture reviewers on large diffs. Also triages issues and PRs when the user mentions them. Not for exploring ideas or debugging.

not rated 2 3mo ago A 47 tokens original MIT

vibeship

1737

vibeforge1111/vibeship-plugin

Plugin Claude Code

Bundles 5 commands, 3 MCP servers · 66 tokens together

AI-powered development with persistent memory, specialist skills, and security scanning. Build products faster with an AI that remembers your project.

not rated 2 8mo ago A tokens not measured original Apache-2.0

code-audit

1738

Variant-Systems/skills

Skill Claude CodeCodex

Run a comprehensive code audit on any codebase. Analyzes security vulnerabilities, hardcoded secrets, dependency CVEs, test coverage, code structure, and AI-generated code patterns. Generates CODEAUDITREPORT.md with findings, severity ratings, and remediation guidance. Intelligently selects and orchestrates the best…

not rated 2 5mo ago A 134 tokens

r2rka1/skills

Skill Claude Code

Scans files changed in the current branch for security vulnerabilities including OWASP Top 10, hardcoded secrets, injection flaws, and insecure patterns. Use when the user wants a security audit, vulnerability check, or security review of their changes.

not rated 2 26d ago A 54 tokens

the-inspector

1740

davekindl/skills

Skill Claude CodeCodex

Product readiness auditor that crawls any codebase, maps what exists, identifies gaps, incomplete code, vulnerabilities, and dead ends, then produces a prioritized remediation plan. Trigger this skill when the user says 'inspect this project', 'audit my code', 'what's broken', 'product readiness check', 'MVP audit'…

not rated 2 1mo ago A 200 tokens original MIT

mesh-security

1741

hackIDLE/skills

Skill Claude CodeCodex

Analyze Istio, Consul, and Linkerd service mesh configurations for security vulnerabilities with NIST 800-53 control mappings. Use when users need to audit mesh security, identify misconfigurations, check mTLS settings, review ACL policies, or prepare for FedRAMP assessments. Triggers on keywords like "mesh config"…

not rated 2 2mo ago A 95 tokens copy · 100% MIT

soroban-auditor

1742

cosminmarian53/skills

Skill Claude CodeCodex needs its repo

Security audit orchestration for Soroban/Stellar Rust smart contracts. Use when user asks to "audit this codebase", "run soroban auditor", or "check for security vulnerabilities". Utilizes AST squeezing, pre-computed guard/state/integration/divergence/invariant/unsafe maps, parallel agent spawning, a verification…

not rated 2 4mo ago A 91 tokens original MIT

auth-implementation

1743

sattva2020/skills

Skill Claude Code

Implement authentication and authorization in web applications. Use when adding login, signup, sessions, JWT tokens, OAuth, SSO, API key auth, role-based access control (RBAC), permissions, protected routes, middleware guards, password hashing, MFA/2FA, refresh token rotation, CSRF protection, or integrating auth…

not rated 2 1mo ago A 136 tokens

csw

1744

ltrainsb1/claude-csw-plugin

Plugin Claude Code

Bundles 4 skills · 0 tokens together

Query Cisco Secure Workload (CSW/Tetration) API: environment reports, policy analysis, scopes, filters, connectors, workload inventory, plus guided workflows (lifecycle, investigate, onboard, upgrade, audit, triage, incident) with a per-call approval gate for any write action, focused operator reports (posture, drift.

not rated 2 2mo ago A tokens not measured

gli-gsf-security

1745

mvolkov83/skills

Plugin Claude Code

Bundles 1 skill, 2 commands · 27 tokens together

Security-engineering rules for an interactive gaming platform under the GLI Gaming Security Framework (GLI-GSF-1) — the deep security-controls layer beneath GLI-19's technical-security appendix, owning the infrastructure and network security territory (DNS, firewalls, remote access, hardening, segmentation, IDS/IPS…

not rated 2 1mo ago A tokens not measured

security-audit

1746

kleberbernardo/claude-code-skills

Skill Claude Code

Auditoria e correção de segurança nível enterprise — AppSec, Cloud Security, DevSecOps, Infra Security. Detecta e corrige riscos do básico ao avançado, incluindo vibe coding e código gerado por IA.

not rated 2 3mo ago A 49 tokens

cncoder/serverless-litellm

Skill Claude CodeCodex

Harden ALB-backed services (LiteLLM, generic APIs) behind CloudFront + WAF. Creates CloudFront distribution with secret origin header, WAF Web ACL with path whitelist, and locks down ALB Security Group to CloudFront-only. Use when deploying any internet-facing ALB service that should not be directly accessible.

not rated 2 1mo ago A 73 tokens original MIT

compliance-catalog

1748

oscal-compass/agentic-agile-authoring

Skill Claude Code

Convert a compliance-document PDF (law, regulation, industry standard) into a validated OSCAL Catalog JSON. Use when the user wants to turn a compliance PDF into an OSCAL Catalog, ingest a new framework into the OSCAL ecosystem, or regenerate a catalog from a revised PDF while keeping control IDs stable.

not rated 2 4d ago A 66 tokens original Apache-2.0

security-audit

1749

Surya8991/AgentMaster

Skill Claude CodeCodex

Security auditing skill for web applications and codebases. Scans for OWASP Top 10, dependency vulnerabilities, secrets exposure, XSS/CSRF/injection flaws, auth weaknesses, and misconfigurations. Use when task involves security scan, vulnerability assessment, pen test review, threat modeling, or hardening a codebase.

not rated 2 changed 3d ago A 70 tokens original MIT

bounty-safe-harbor

1750

kkkkjack/claude-omni

Skill Claude CodeCodex

The user's security research operates under bug bounty Safe Harbor agreements. Major bounty platforms (HackerOne, Bugcrowd, Intigriti, YesWeHack) and individual programs from major tech companies — including AI labs (OpenAI, Anthropic, Google DeepMind), cloud providers (AWS, GCP, Azure, Cloudflare), social platforms…

not rated 2 4mo ago A 226 tokens original MIT

catpilot-security-core

1751

catpilotai/catpilot-ai-guardrails

Skill Claude CodeCodex needs its repo

Catpilot's universal AI-coding-agent security baseline. Always-on guardrails across nine components: cloud CLI mutations, database state changes, local CLI destruction, Docker container builds, hardcoded secrets, secrets management, supply-chain integrity, PII / test-data hygiene, and language-agnostic secure-coding…

not rated 2 yesterday A ✓ AI review 110 tokens original MIT

secure-deployment

1752

imarios/skilltree

Skill Claude CodeCodex

Secure deployment practices for production systems.

not rated 2 today A 10 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: