Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

mobsf-mcp

1921

plur1bu5/mobsf-mcp

MCP server Claude CodeCodexCursor +2

MCP server "mobsf-mcp" as configured in plur1bu5/mobsf-mcp. Runs locally from the mobsf-mcp Python package.

not rated 2 1mo ago A tokens not measured original MIT

securedact-enforced

1922

GigantesHJI/securedact-mcp

Plugin Claude Code

Bundles 1 skill · 20 tokens together

Local privacy enforcement for Claude Code. Checks prompts before model processing and blocks or requires review when SecuRedact detects protected information.

not rated 2 3d ago A tokens not measured original Apache-2.0

m2m-sentinel

1923

M2M-Sentinel/m2m-sentinel-sdk

Skill Claude CodeCodex

Deterministic EVM bytecode capability observations, EIP-1967 proxy resolution, gas recommendations, and sourced telemetry for autonomous applications on Base (Chain ID 8453).

not rated 2 +1 6d ago A 42 tokens original MIT

shrike-mcp

1924

Shrike-Security/shrike-mcp

MCP server Claude CodeCodexCursor +2

AI agent security scanner — prompt injection detection, SQL injection, PII isolation, threat intel. Runs locally from the shrike-mcp npm package.

not rated 2 13d ago A tokens not measured original Apache-2.0

inbox-check

1925

live-direct-marketing/ldm-inbox-check-mcp

MCP server Claude CodeCodexCursor +2

Email inbox placement tests across Gmail, Outlook, Yahoo, Mail.ru, Yandex (SPF/DKIM/DMARC). Runs locally from the ldm-inbox-check-mcp npm package. Needs 2 environment variables to run.

not rated 2 4mo ago A tokens not measured original MIT

sheleg-dev

1926

ssheleg/sheleg-dev

Plugin Claude Code

Bundles 7 skills, 1 hook · 1,444 tokens together

The integration layer a product needs once it has users: Stripe subscription billing reconciled into your own database, crypto payments that survive over-payment and duplicate webhooks, ad and conversion tracking under Consent Mode v2, Google sign-in with the account-linking guards, the wider Google auth surface, and…

not rated 2 changed 3d ago A tokens not measured original MIT

agentguards-claude

1927

alelaguard/agentguards-plugins

Plugin Claude Code

Bundles 1 MCP server

LLM security guardrails for Claude Code — jailbreak detection, prompt-injection and web-content scanning, data-exfiltration blocking, and destructive-command authorization. Bundles the AgentGuards MCP server plus enforcing hooks.

not rated 2 14d ago A tokens not measured original MIT

guard-hooks

1928

AndrewDongminYoo/cc-agents-kit

Plugin Claude Code

Bundles 2 hooks

Nine defensive hooks: blocks recursive rm on $HOME, download-and-execute pipelines, secrets-file access, path-less formatter runs, credentials in the staged diff, and the two zsh quoting mistakes that fail silently; warns on stale lockfiles, shellcheck findings, and automatic security-review findings after a commit…

not rated 2 +1 changed today A tokens not measured original Apache-2.0

reverse-skill-router

1929

Asaiuta/reverse-workbench-skill

Skill Codex

Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.

not rated 2 1mo ago A 51 tokens original MIT

mcpkernel-security

1930

piyushptiwari1/mcpkernel

Skill Claude CodeCodex

AI agent security gateway — policy enforcement, taint tracking, tool poisoning detection, DLP chain analysis, and SARIF output for CI/CD.

not rated 2 2mo ago A 34 tokens original Apache-2.0

dfx-agentguard

1931

dockfixlabs/agentguard

MCP server Claude CodeCodexCursor +2

Autonomous security scanner for AI agents. Detects prompt injection, tool abuse, data exfiltration, and OWASP ASI Top 10 vulnerabilities. Runs locally from the dfx-agentguard Python package.

not rated 2 1mo ago A tokens not measured LGPL-3.0

security-recon

1932

ewwhardik/nirikshak

Skill Claude CodeCodex

Use when the user wants a security/exposure check on a domain or website they own or are authorized to test — "audit my site", "what's my attack surface look like", "did anything change on my domain", etc. Drives the nirikshak MCP tools (fullsurfacescan, and the individual checks) and turns raw output into a…

not rated 2 1mo ago A 97 tokens original MIT

jelmervdm/sophos-firewall-mcp

MCP server Claude CodeCodexCursor +2

MCP server "sophos-firewall-mcp-server" as configured in jelmervdm/sophos-firewall-mcp. Runs locally from the sophos-firewall-mcp-server Python package.

not rated 2 +1 20d ago A tokens not measured original Apache-2.0

pseudonym-mcp

1934

woladi/pseudonym-mcp

MCP server Claude CodeCodexCursor +2

Locally pseudonymizes sensitive text before cloud LLM work and restores the tokens afterward. Runs locally from the pseudonym-mcp npm package.

not rated 2 +2 9d ago A tokens not measured original MIT

ai-risk-oracle

1935

InterAILabs/ai-risk-oracle

MCP server Claude CodeCodexCursor +2

Policy gate and signed trust receipts for autonomous agent actions. Remote server at ai-risk-oracle.fly.dev.

not rated 2 2d ago A tokens not measured

sentinel

1936

oaslananka/mcp-suite

MCP server Claude CodeCodexCursor +2

One of 2 in server.json

Zero-trust MCP security proxy with policy enforcement, PII scrubbing, approvals, and audit trails. Runs locally from the @oaslananka/sentinel npm package. Needs 3 environment variables to run.

not rated 2 1mo ago A tokens not measured original Apache-2.0

ssh-mcp-pro

1937

oaslananka/ssh-mcp-pro

Plugin Claude Code

Bundles 3 skills, 1 MCP server · 94 tokens together

SSH MCP Pro plugin for controlled SSH operations, remote host workflows, command execution guardrails, and infrastructure automation.

not rated 2 2d ago A tokens not measured original MIT

npmjs-mcp

1938

YawLabs/npmjs-mcp

MCP server Claude CodeCodexCursor +2

npm registry MCP server — package intelligence, security audits, and dependency analysis for AI assistants. Runs locally from the @yawlabs/npmjs-mcp npm package.

not rated 2 yesterday A tokens not measured original MIT

bi-mcp

1939

whoamiTM/bi-mcp

MCP server Claude CodeCodexCursor +2

MCP server for Blue Iris NVR — exposes read-only tools backed by the Blue Iris JSON API. Runs locally from the bi-mcp Python package.

not rated 2 +1 14d ago A tokens not measured original MIT

fwrule-mcp

1940

AutomateIP/fwrule-mcp

MCP server Claude CodeCodexCursor +2

MCP server "fwrule-mcp" as configured in AutomateIP/fwrule-mcp. Runs locally from the fwrule-mcp Python package.

not rated 2 5mo ago A tokens not measured

spicedb-dev

1942

authzed/authzed-marketplace

Plugin Claude Code

Bundles 7 skills, 15 commands, 3 agents · 691 tokens together

Comprehensive SpiceDB development toolkit for designing permission models, generating schemas, implementing authorization, testing, and migrating from other authorization systems (OpenFGA, Okta FGA, etc.) to SpiceDB.

not rated 2 17d ago A tokens not measured original Apache-2.0

bumper

1943

gnana997/bumper

Plugin Claude Code

Bundles 3 skills · 250 tokens together

bumper security skills: Terraform plan safety gate, dependency vuln/malware triage, and Advisor lookups.

not rated 2 20d ago A tokens not measured original Apache-2.0

sileo-oss/agentflow-community

Skill Claude CodeCodex

Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.

not rated 2 6mo ago A 35 tokens ODbL-1.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: