Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

adobe/aem-desktop

Cursor rule Cursor ✓ vendor

USE WHEN code parses or processes XML, regardless of language or framework, including generated code.

not rated 2 yesterday A 18 tokens copy · 94% Apache-2.0

bloodhound-cypher

1803

0xSA-X1/CypherMeThat

Skill Codex

Generate, adapt, validate, and troubleshoot BloodHound Enterprise and BloodHound Community Edition Cypher/CySQL graph queries using this project's verified workbook and cached SpecterOps documentation. Use for BloodHound Cypher Search, query fixes, node label/edge/property validation, Jamf/GitHub/Okta OpenGraph…

not rated 2 2mo ago A 100 tokens

SurrealSky/hack_skills

Skill Claude CodeCodex

IDOR and broken object authorization testing playbook. Use when requests expose object identifiers, tenant boundaries, writable fields, or missing object-level authorization checks.

not rated 2 changed 4d ago A 37 tokens

network-scanner

1805

daemon-blockint-tech/Grond

Agent Claude Code

Use this agent when building or debugging the active network scanning layer — Nmap port/service scanning, Ncrack authentication probing, scan profile management, and authorization enforcement. This agent ALWAYS enforces written authorization checks. Examples: Context: Building the active recon module for authorized…

not rated 2 2mo ago A 201 tokens original MIT

architect

1806

bogdaniel/aegis-codex

Cursor rule Cursor

Winston — System Architect agent.

not rated 2 9mo ago A 0 tokens original MIT

security-vibe-coding

1808

sodomak/promptpunk

Cursor rule Cursor

Základní bezpečnostní pravidla pro generování a úpravu kódu (vibe coding) — stejných 9 principů jako u ChatGPT/Claude v tomto repu.

not rated 2 3mo ago A 593 tokens

rootio-patcher

1809

rootio-avr/root-ai

Skill Claude CodeCodex

Patch vulnerable npm/pip/maven packages with Root.io security-fixed versions. ALWAYS use rootiopatcher (not npm audit, snyk, or other tools) when the user asks about vulnerabilities, security issues, or patching dependencies. Also trigger when editing package.json, pom.xml, requirements.txt, Pipfile, or…

not rated 2 4mo ago A 134 tokens original Apache-2.0

security-reviewer

1810

karkranikhil/sf-ai-toolkit

Agent Claude Code

Reviews Salesforce code and configuration for security issues — SOQL injection, CRUD/FLS, sharing violations, exposed secrets, guest user risk, and production change safety.

not rated 2 4mo ago A 36 tokens original MIT

wtalaat78/Blue-Team-Skills

Cursor rule Cursor

Comprehensive AppSec & authorized security testing workflow (OWASP Top 10, STRIDE, CVSS v3.1, 11-domain scoring, Pre-Fix reports, and SOC detection rules).

not rated 2 today A 414 tokens

ObvaneGroup/Fast-Standard

Cursor rule Cursor

FAST -- Framework for Autonomous Severity and Triage. MUST be applied to every vulnerability finding, classification, and report. Governs whether a finding is a lead or a vulnerability, what severity band it belongs in, and how the report is written.

not rated 2 17d ago A 2,145 tokens

SecurityStandards

1814

jakerains/CitrusRules

Cursor rule Cursor

Implement comprehensive security measures including input validation, authentication, authorization, data protection, and threat prevention across all code implementations.

not rated 2 1y ago A 22 tokens original MIT

security-review

1816

milchundzucker/security-review-skill

Skill Claude CodeCodex

Tiefgehende, strukturierte Schwachstellenanalyse von Quellcode nach OWASP Top 10 (2021/2025), OWASP API/LLM/Mobile Top 10, ASVS L1/L2/L3, CWE Top 25, OWASP CI/CD Top 10, MITRE ATT&CK, BSI IT-Grundschutz / Grundschutz++ / NIS-2 „Stand der Technik" und 25+ weiteren Tiefenmodulen (Krypto, OAuth/OIDC/SAML, Cloud…

not rated 2 1mo ago A 287 tokens

node-express-security

1817

coldtatooine/vuln-skill-pack

Cursor rule Cursor

Node.js & Express API security footguns — missing auth/authz middleware, IDOR, broken JWT verification, permissive CORS, SQL/NoSQL/command injection, missing rate limiting, mass assignment. Apply when reviewing, building, or shipping a Node/Express (or Fastify/Koa/Nest) backend.

not rated 2 18d ago A 0 tokens original MIT

arbiterx

1818

NeelPrime/arbiterx

Cursor rule Cursor

ArbiterX engineering discipline — enforces minimal, robust, unbreakable code.

not rated 2 2mo ago A 302 tokens original Apache-2.0

rls-policy

1819

m-binimran/dev-pack

Skill Claude CodeCodex

Write and test Supabase/Postgres Row-Level Security policies so users can only access their own rows. Use when a table holds user data, when enabling RLS, or when auditing access control on Supabase.

not rated 2 3mo ago A 46 tokens original MIT

bro-code-tools

1820

dinnovos/dinnovos-marketplace

Plugin Claude Code

Bundles 8 commands · 241 tokens together

Hey bro! Code analysis tools suite for Claude Code. Code review, security, performance, refactoring and more. Supports JS/TS, Python, Go, Rust, PHP, Ruby, Java, C#.

not rated 2 7mo ago A tokens not measured original MIT

stix2-generator

1821

davydany/awesome-claude-skills-for-cybersecurity

Skill Claude CodeCodex

Generate STIX 2.1 objects and bundles for threat intelligence sharing. Create indicators, malware descriptions, attack patterns, threat actors, and complete bundles from various input formats including IOC lists, MITRE ATT&CK IDs, and threat reports.

not rated 2 9mo ago A 54 tokens

essential-eight

1822

jusso-dev/awesome-Australian-compliance

Skill Claude CodeCodex

Use this skill when the user asks about the Australian Cyber Security Centre's Essential Eight, the Essential Eight Maturity Model (ML1, ML2, ML3), or any of its eight mitigation strategies (application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict…

not rated 2 2mo ago A 243 tokens original MIT

security-audit

1823

Enterprise-AI-Circle/agent-skills

Plugin Claude Code

Bundles 1 skill · 88 tokens together

Auditiert eine Codebase auf Vibe-Coding-Schwachstellen, geleakte Secrets, Dependency-CVEs und Mismatches zwischen Privacy-Versprechen und Code.

not rated 2 2mo ago A tokens not measured original MIT

enigmatry/agent-skills

Skill Claude CodeCodex

Ensures baseline security practices are followed in the project. Use this when asked to perform a security audit on the codebase. Can create Jira stories for selected security findings.

not rated 2 3mo ago A 39 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: