Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

public-release-prep

2113

S24DeFi/global-lib-skills

Plugin Claude Code

Bundles 1 skill · 151 tokens together

Audit a private git repo's full history (every branch, tag, and PR ref) for secrets and PII before making it public, then carry out the cleanup.

not rated 1 4d ago A tokens not measured original MIT

kage

2114

skshadan/kage

Plugin Claude Code

Bundles 3 skills, 1 command, 18 agents · 940 tokens together

Local pentest sandbox for black-box, greybox, and white-box security audits inside a per-engagement Kali Docker container.

not rated 1 2mo ago A tokens not measured

spill-scrub

2115

joshuafuller/claude-spill-scrub

Plugin Claude Code

Bundles 1 skill · 102 tokens together

Find and scrub credentials that leaked into Claude Code's own local logs. Scan is read-only, scrub is gated, and every run ends on a rotation checklist.

not rated 1 18d ago A tokens not measured original MIT

dependency-auditor

2116

nariatrip191/my-claude-skills

Skill Claude CodeCodex

The Dependency Auditor is a comprehensive toolkit for analyzing, auditing, and managing dependencies across multi-language software projects. This skill provides deep visibility into your project's dependency ecosystem, enabling teams to identify vulnerabilities, ensure license compliance, optimize dependency trees…

not rated 1 yesterday A 7 tokens

threat-model

2118

evgenii-studitskikh/Claude-Code-SaaS-Studio

Skill Claude Code

Produce a STRIDE-lite threat model for the SaaS app: enumerate assets, trust boundaries, and entry points, then name the top threat and mitigation for each STRIDE category, focused on multi-tenant SaaS.

not rated 1 3mo ago A 48 tokens original MIT

pentester

2119

jonase47/ccpr

Agent Claude Code

Use this agent when you need to actively test applications, APIs, infrastructure, or code for exploitable vulnerabilities. This agent thinks like an attacker and finds entry points before real attackers do. It complements the security-master agent through practical attack simulation. This agent should be used…

not rated 1 changed yesterday A 471 tokens original MIT

shush

2120

rjkaes/shush

Plugin Claude Code

Bundles 1 hook

Context-aware safety guard for Claude Code tool calls.

not rated 1 3mo ago A tokens not measured original Apache-2.0

aegis

2122

Erkan3034/aegis

Skill Claude CodeCodex

Production-grade red-team security audit skill for AI coding assistants. Audits codebases for OWASP Top 10 vulnerabilities, auth flaws, IDOR, XSS, SSRF, JWT misuse, Supabase policies, and provides drop-in secure code replacements with zero exfiltration risk.

not rated 1 1mo ago A 61 tokens original MIT

virtualsms

2123

virtualsms-io/cursor-rules-sms-verification

Cursor rule Cursor

Real-SIM SMS verification, number rentals, matching-country proxies and cloud browser sessions for AI agents via VirtualSMS MCP. Apply when the user asks for a phone number, SMS code, OTP, account verification (WhatsApp, Telegram, Tinder, Discord, Google, etc.), two-factor auth flow, number rental, proxy, or anything…

not rated 1 1mo ago A 0 tokens original MIT

curl-exfil-demo

2124

SuperMarioYL/capsule

Skill Claude CodeCodex needs its repo

A deliberately malicious demo Skill that tries to exfiltrate secrets over the network and read /.ssh/idrsa. Used to show Capsule blocking the calls at the call site.

not rated 1 5d ago D 40 tokens original Apache-2.0

apollyon

2125

thedatakey/apollyon

Plugin Claude Code

Bundles 1 skill, 5 agents · 170 tokens together

Evidence-first source security scan workflow for human-written and AI-generated code.

not rated 1 changed 2d ago A tokens not measured original MIT

ubuntu-server-audit-eu

2126

bugroo/ubuntu-server-audit-eu

Skill Claude CodeCodex

Use when performing strict read-only SSH inspections of Ubuntu/Linux servers for security review, EU cybersecurity compliance evidence, server readiness, operational disorder, waste, drift, CIS-style hardening gaps, runtime visibility, identity/access, network exposure, backups, observability, and unknowns. Requires…

not rated 1 3mo ago A 86 tokens original MIT

bootstrap-sdd-tdd

2127

kxdds/sdd-tdd

Skill Claude CodeCodex

Use when a project needs the OpenSpec + Superpowers sdd-tdd (spec-to-plan-to-TDD) workflow checked, installed, and configured -- or cleanly removed -- in any coding agent (Codex, Claude Code, Cursor, Antigravity, OpenCode, Gemini CLI, Copilot CLI, or others).

not rated 1 2mo ago A 72 tokens original MIT

settings

2128

alex-lamport/kaora-memory

Settings file Claude Code

One of 3 in settings.json

Agent settings declaring 2 hook events (PreToolUse, PostToolUse).

not rated 1 3mo ago A tokens not measured original MIT

sonar-manage-findings

2129

Nick2bad4u/SonarCloud-Skill

Skill Codex

Use this skill whenever the user needs SonarCloud or SonarQube issue and hotspot triage, measures, gates, profiles, settings, tags, or safe mutations with environment-variable tokens.

not rated 1 10d ago A 46 tokens original Unlicense

vapt

2130

bhuvangupta/vapt-claude

Skill Claude Code

Full-spectrum web application Vulnerability Assessment and Penetration Testing (VAPT). Automates reconnaissance, scanning, injection testing, authentication analysis, and report generation. Supports --mode pro (terse) and --mode dev (educational). Enforces authorization gate before any active testing.

not rated 1 5mo ago A 60 tokens original MIT

drmhse/authos_skill

Skill Codex

Secure backend APIs with AuthOS-issued JWTs and the AuthOS Node server adapter. Use when building an API that must verify AuthOS bearer tokens, enforce JWT claims, add Express middleware, validate JWKS keys, or create a backend-owned session after a browser OAuth callback.

not rated 1 3mo ago A 62 tokens original MIT

C31-plan

2133

ChianW/C31

Skill Claude CodeCodex

Turn requirements into validated, executable plans. C31-brainstorm defines WHAT; C31-plan defines HOW — with coverage gates, wave analysis, and threat modeling.

not rated 1 18d ago A 34 tokens original MIT

web3-audit

2134

guib1/red-team-docker

Skill Claude CodeCodex

Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for…

not rated 1 5mo ago A 103 tokens

vector

2135

pharosone/vector-plugin

Plugin Claude Code

Bundles 4 skills, 1 MCP server · 267 tokens together

Red-team scanning for LLM agents — integrate Vector in your repo, harden against findings, generate agent profiles.

not rated 1 3mo ago A tokens not measured original MIT

smartbw-mcp

2136

ocoj/smartbw-mcp

Skill Claude CodeCodex

An MCP connection to Vaultwarden or Bitwarden, which are password managers for storing credentials and other secure fields.

not rated 1 2d ago A 59 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: