Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

dradis-core

2090

dradis/dradis-claude

Plugin Claude Code

Bundles 3 skills · 0 tokens together

Dradis Framework skills for Claude Code — core skills for your Dradis instance.

not rated 1 18d ago A tokens not measured GPL-2.0

code-sandbox-mcp

2091

feifeigood/code-sandbox-mcp

MCP server Claude CodeCodexCursor +2

MCP server for E2B code sandbox - Execute code and commands in secure E2B sandboxes. Runs locally from the code-sandbox-mcp Python package.

not rated 1 8mo ago A tokens not measured

mcp-1password

2092

kefapps/onepassword-mcp-codex

MCP server Claude CodeCodexCursor +2

Neutral MCP server for 1Password desktop app integrations with opaque-by-default secret handling. Runs locally from the mcp-1password npm package.

not rated 1 1mo ago A tokens not measured

security-claude

2093

rahozosman/security-claude

Skill Claude CodeCodex

Skill "security-claude" from rahozosman/security-claude, covering security architecture & threat modeling intelligence, how this skill is organized (progressive disclosure), 1. pick a mode, 2. core method (applies to every mode) and 3. doing a focused review.

not rated 1 14d ago A 0 tokens original MIT

arcjet-cli

2094

arcjet/arcjet-plugin

Cursor rule Cursor

When to use the Arcjet CLI vs the MCP server, plus the zero-install npx invocation pattern and agent-friendly flags.

not rated 1 9d ago A 0 tokens original Apache-2.0

captchasonic

2095

Captcha-Sonic/Agent-skills

Plugin Claude Code

Bundles 4 skills, 1 MCP server · 218 tokens together

Solve any CAPTCHA with AI — reCAPTCHA, Cloudflare Turnstile, Geetest, AWS WAF, TikTok, OCR and more. MCP server + Claude skills for captcha solving.

not rated 1 3mo ago A tokens not measured original MIT

git-pkgs

2096

git-pkgs/skills

Plugin Claude Code

Bundles 14 skills · 695 tokens together

Dependency and repository management skills powered by git-pkgs, brief, forge, pin, and capcheck. Track dependency history, scan for vulnerabilities, evaluate packages, generate SBOMs, work across git forges, and more.

not rated 1 24d ago A tokens not measured original MIT

grounding-guard

2097

sanjeewamadhuranga/grounding-guard

Plugin Claude Code

Bundles 2 skills, 2 hooks · 79 tokens together

Hook-enforced ground-truth verification for Claude Code. Catches fabricated package names, unpublished versions, unresolvable imports, and nonexistent git SHAs before they land in your codebase — and feeds the correction back to Claude so it fixes itself in-loop.

not rated 1 2mo ago A tokens not measured original MIT

repo-doctor

2098

BekbolotM/repo-doctor

Plugin Claude Code

Bundles 1 command, 6 agents · 199 tokens together

Full health checkup for any repository: Health Score 0-100, findings across 5 dimensions (security, code quality, testing, production readiness, docs), a prioritized fix plan, and one-command fixes with /audit fix N.

not rated 1 1mo ago A tokens not measured original MIT

sll

2101

MohamedEmbarak/SLL

Plugin Claude Code

Bundles 2 hooks

Three hooks, no agents. A stated test result must reproduce, a fabricated import never reaches disk, and every command's real output is recorded. Active in every project the moment it is installed.

not rated 1 27d ago A tokens not measured original MIT

news

2102

mfeo/claude-news-plugin

Skill Claude Code

A skill that collects recent news from RSS feeds about hackers, artificial intelligence, security, and technology, then categorises and summarises it in Traditional Chinese. RSS is a format websites use to publish updates.

not rated 1 3mo ago A 47 tokens

trustshell

2103

William2333ZZ/trustshell

Plugin Claude Code

Bundles 12 skills, 2 commands, 1 agent · 932 tokens together

AI agent security for Claude Code — read the code, break the running agent, prove it (exploit-validated). Commands: /static-scan, /red-team. Subagent: agent-red-teamer. Skills: RT-1..RT-9.

not rated 1 1mo ago A tokens not measured original MIT

oswe

2104

Laucked-Security/claude-oswe

Plugin Claude Code

Bundles 1 skill, 2 agents · 137 tokens together

Deep white-box OSWE-style web app security audit via /oswe:audit (PHP, Node.js, Python, Java, .NET) — Markdown + visual HTML reports. By Laucked Security.

not rated 1 10d ago A tokens not measured original MIT

email-leak-notice

2105

didvc/claude-email-leak-notice

Plugin Claude Code

Bundles 1 hook

Claude Code injects your account email into session context, where an agent may reuse it as a legitimate value and commit it. This warns once per session when a personal address appears in a tool payload. Never blocks.

not rated 1 1mo ago A tokens not measured original MIT

auto-cc

2106

SSHdotCodes/auto-cc

Plugin Claude Code

Bundles 1 hook

Automatic tool-call review for Claude Code. A local encoder scores every proposed tool call before it runs, approving safe work and blocking dangerous calls with an explanation the agent can act on.

not rated 1 1mo ago A tokens not measured original Apache-2.0

keyward

2108

albemiglio/keyward

Plugin Claude Code

Bundles 1 skill, 4 commands, 1 hook · 151 tokens together

Auto-detects API keys and secrets in your prompts, saves them to chmod-600 files in /.claude/secrets/, blocks the original prompt, and re-submits a sanitized version via OS-level paste automation. Cross-platform (macOS, Linux, Windows). Zero-friction secret hygiene for Claude Code.

not rated 1 1mo ago A tokens not measured original MIT

protocol

2109

ReviewToolkits/cpython-security-toolkit

Command Claude Code

Protocol validation coverage analysis. Checks whether security-sensitive values in CPython's HTTP, cookie, WSGI, and URL handling modules are validated consistently across all code paths — including update methods, operator overloads, unpickling, and template substitution paths.

not rated 1 4d ago A 0 tokens

cloud-infra

2111

makigjuro/cloudstack-ai-plugins

Plugin Claude Code

Bundles 7 skills, 1 agent · 339 tokens together

Terraform + Helm infrastructure scaffolding, linting, and review — module scaffolding, chart templates, validation pipelines, security scanning (trivy), and infrastructure-specific code review.

not rated 1 2mo ago A tokens not measured original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: