otr-protocol
2065yb48666-ctrl/OTR-Protocol-by-orbexa
MCP server Claude CodeCodexCursor +2
Merchant trust verification for AI agents. One call = trust score, badge, and purchase safety. Runs locally from the @otr-protocol/mcp-server npm package.
24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.
yb48666-ctrl/OTR-Protocol-by-orbexa
MCP server Claude CodeCodexCursor +2
Merchant trust verification for AI agents. One call = trust score, badge, and purchase safety. Runs locally from the @otr-protocol/mcp-server npm package.
MCP server Claude CodeCodexCursor +2
Ed25519-signed receipts for every AI agent action. Local-first, verifiable, no server required. Runs locally from the @agent-receipts/mcp-server npm package.
MCP server Claude CodeCodexCursor +2
MCP server "armor" as configured in studiomeyer-io/mcp-armor. Runs in Docker (ghcr.io/studiomeyer-io/mcp-armor:0.7.0).
BeBraveBeKind/mcpskills-server
MCP server Claude CodeCodexCursor +2
Trust scoring for MCP servers, AI skills & npm packages — 15 signals + safety scanning. Runs locally from the @mcpskillsio/server npm package. Needs 1 environment variable to run.
MCP server Claude CodeCodexCursor +2
Polish phone number lookup: who called, spam and scam checks, UKE DNO registry, CERT phishing stats. Remote server at numertel.pl.
MCP server Claude CodeCodexCursor +2
Loads signed ALTWEB context capsules — refuses unsigned, tampered, or untrusted by default. Runs locally from the altweb-context npm package. Needs 1 environment variable to run.
Cursor rule Cursor
Vibe Guard - always-on security guardrails for AI-generated code.
Skill Claude Code
Lightweight AI security guard that intercepts risky install/download commands (npm, npx, pip, cargo, git clone) to block known malicious packages and scan for suspicious code. Invoke ONLY when user runs install/download/clone commands.
Skill Claude CodeCodex
Routes all platform API calls through AgentValet's credential proxy. Your raw API keys and OAuth tokens are never exposed to this agent — AgentValet injects the correct credential per platform call.
Skill Claude CodeCodex
LLM-ready web fetching — extracts clean markdown and metadata from URLs with prompt injection defense.
MCP server Claude CodeCodexCursor +2
Security toolkit for FastAPI-based MCP servers — pre-flight audit + runtime prompt-injection guardrail. Runs locally from the mcp-rampart Python package.
Skill Claude CodeCodex
Run Bumblebee supply-chain inventory and exposure scans on the local machine. Use this skill whenever the user wants to check developer endpoints for compromised npm/PyPI/Go/RubyGems/Composer packages, audit installed editor or browser extensions, inspect MCP host configs, or perform supply-chain incident response on…
MCP server Claude CodeCodexCursor +2
MCP server for Australian PII detection and sanitisation — TFN, Medicare, ABN, ACN, BSB, bank account, drivers licence, passport, Centrelink CRN, and address recognisers with checksum validation, compliance audit logging, built on Presidio. Runs locally from the mcp-pii-guard-au Python package.
ashray/claude-permissions-wizard
Skill Claude CodeCodex
Interactive wizard to configure Claude Code permission rules. Sets up granular allow/ask permissions so you can work without --dangerously-skip-permissions while keeping safety nets for destructive commands. Use when user says "configure permissions", "set up permissions", "permission settings", or "stop asking me for…
Plugin Claude Code
Bundles 3 skills · 369 tokens together
Operator skills for Forseti, the web UI and admin console for the Ory Kratos + Hydra identity stack: guided setup (with or without Docker), goal-driven reconfiguration (login providers, Linux/POSIX login, downstream OAuth clients), and a best-practice security audit of an existing deployment.
Plugin Claude Code
Bundles 1 skill · 126 tokens together
Verifies in compiled machine code that secret zeroization survived dead-store elimination and that constant-time logic did not regain secret-dependent branches. Ships a Ghidra headless inventory script. Use when auditing a binary, shared object, or firmware image against a source-level guarantee.
Plugin Claude Code
Bundles 14 skills, 2 commands, 1 agent, 2 hooks, 2 MCP servers · 2,659 tokens together
Agent-building practices from Anthropic's engineering blog, packaged as installable Claude Code skills, MCP servers, and safety hooks for tool-gating and prompt-injection screening. Covers the gaps no existing skill pack fills.
Skill Claude CodeCodex
Search hashes through 25 billion leaked passwords using the Weakpass API (no API key required).
Skill Claude CodeCodex
Command: /cicada Audit your backend and mobile apps for vulnerabilities — and optionally fix them — without deploying or breaking anything.
markus-smile/ios-app-agentic-engineering
Skill Claude CodeCodex
End-to-end agentic engineering for iPhone apps, from idea to a secure App Store release through 8 gated phases. Use when someone wants to build, plan, or ship an iPhone/iOS app — especially a non-programmer ("vibe coder") asking to create an app, pick a tech stack (SwiftUI, React Native, Flutter), choose a backend…
Skill Claude CodeCodex
A Chinese-language guide for explaining the hidden roles and trust relationships in technical systems. It clarifies who owns tokens, keys, certificates, and endpoints, who checks them, and what each party proves.
Skill Codex
Act as a senior GitHub platform architect, open-source maintainer, DevSecOps engineer, and repository governance specialist. Produce repository systems that are understandable, maintainable, secure by default, automation-friendly, and practical for real teams.
Plugin Claude Code
Critique-led architecture views and a security/privacy/compliance/cost audit for Claude Code, grounded in real code and git history.
codepros100-dev/claude-windows-health-check
Skill Claude Code
Comprehensive Windows system health check, diagnostics, and remediation.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: