24,943 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
A converter for CNNVD XML files, where CNNVD is China’s national database of information-security vulnerabilities. It changes newer XML files into the older format by renaming tags and normalising their structure.
Agent Skills for dependency security including vulnerability scanning, package review, patching, setup and configuration, and secure dependency updates via Socket.dev.
★not rated 2 yesterdayA
tokens not measured
originalMIT
Use when designing, implementing, reviewing, refactoring, or maintaining software in any programming language where security is a requirement. Apply secure-by-design principles, identify vulnerabilities, and recommend industry best practices throughout the software development lifecycle.
Deterministic simulation testing for containerized services. Write Lua scripts to inject chaos (pause, kill, resource deprivation) into Docker containers with reproducible, seeded fault injection. Use when writing chaos experiments, testing service resilience, or debugging distributed systems.
Use when you want to reverse-engineer an active Auth0 tenant into a structured, multi-environment Terraform project for replicating that tenant into new empty tenants. Runs auth0 tf generate, then restructures the flat output into a flat modules/ directory (one foreach block per resource type with typed map…
Perform a "red team" security and risk assessment of the codebase. Use when user says "/redteam", "red team this code", or asks for a security/vulnerability audit.
Systematically identify and classify technical and business risks using the risk-centric PASTA threat modeling framework. Use when the user says "run PASTA", "do PASTA threat modeling", or "identify risks".
Apply Matt Shumer's Gauntlet Loop to ambitious software, game, product-design, writing, research, and creative tasks. Establish a concrete inspectable quality bar, let a lead agent decompose the work, use separate builder and critic agents, inspect the real artifact, and iterate until the work meets the bar or the…
Perform a strict, fail-closed production-readiness review of the exact staged change before initial PR/MR submission or an explicit direct-to-default fast track. Use when asked to prepare changes for submission, inspect every staged file and hunk, discover and run mandatory build, test, security, and performance…
Run runtz DevSecOps security scans (SCA, SAST, host packages, container images, Kubernetes) and read runtz documentation. Use when the user wants to find vulnerable dependencies or packages, scan source code for secrets/weak crypto, audit a container image or Linux host for CVEs, check Kubernetes posture, or asks how…
AgentGuard — security review & secure-by-design for agentic AI (OWASP Agentic 2026 + LLM 2025 + CWE). Use when auditing or designing code that uses LLMs, tool-calling, memory/RAG, MCP or multi-agent.
Enriches Vectra findings with VirusTotal threat intelligence — IOC reputation lookup for IPs, domains, URLs, and file hashes via the VirusTotal v3 API. Ships two paths — a standalone Bash CLI (scripts/vt-lookup.sh) for one-off lookups that needs only curl/jq, and a sourced framework adapter (scripts/virustotal.sh) for…
Expert code reviewer specializing in code quality, security vulnerabilities, and best practices across multiple languages. Masters static analysis, design patterns, and performance optimization with focus on maintainability and technical debt reduction.
Parallel Codex code reviews for Claude Code. N independent agents (diff, security, tests, architecture) review your changes with project-aware context. Includes self-review, anti-pattern detection, and knowledge compounding.
★not rated 2 1mo agoA
tokens not measured
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: