Security

29,964 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

author-saf-technique

193

secure-agentic-framework/saf-mcp

Skill Claude CodeCodex

Research, author, rewrite, validate, and prepare exactly one SAF-MCP technique and its evidence packet. Use for new or existing SAF technique work that requires source-or-omit traceability, an exclusion ledger, current breach and vulnerability research, tested detection, framework reconciliation, publication-rights…

not rated 361 +1 2d ago A 69 tokens

kesekit

194

cdppcorp/KESE-KIT

Plugin Claude Code

Bundles 8 skills · 1,025 tokens together

Security vulnerability assessment (EN/KO). CII infrastructure (560+), AI Security, Robot Security (IEC 62443), Space Security (satellite/GSaaS/supply chain, CMMC/NIS2), Secure Coding (JS/Python/Pseudo Code, 46 CWE). Use /kesekit-start, /kesekit-start-ko, /kesekit-check, /kesekit-fix, /kesekit-guide etc.

not rated 356 4mo ago A tokens not measured original MIT

emisar AGENTS.md

195

AndrewDryga/emisar

Instructions file CodexOpenCode

AGENTS.md instructions for AndrewDryga/emisar, covering emisar — how we work (canonical agent manual), ⟢ boot — read this when you start, or lose context, the creed — how we build (every project), the repository command surface and the .agent/ working state (per project).

not rated 354 +2 changed today A 10,341 tokens

hypnguyen1209/offensive-claude

Instructions file

Instructions for hypnguyen1209/offensive-claude, covering security research & offensive operations config, behavior, skills available, agents available and engagement workflow — cyber kill chain.

not rated 354 +3 18d ago A 4,127 tokens original MIT

DragonJAR/Android-Pentesting-Skill

Skill Claude CodeCodex

Comprehensive Android APK security audit with static analysis, dynamic instrumentation, source-to-sink tracing, IPC/component abuse analysis, and CVSS 4.0 reporting. Covers decompilation, manifest analysis, deep links and intent injection, secrets detection, crypto analysis, Frida/Objection integration, and APK…

not rated 354 +5 2mo ago A 154 tokens original Apache-2.0

ghtkn

198

suzuki-shunsuke/ghtkn

Skill Claude CodeCodex

Read ghtkn's documentation with ghtkn docs list and ghtkn docs show before answering. ghtkn is a CLI that creates short-lived (8h) GitHub user access tokens from GitHub Apps. Use for any question about ghtkn, GHTKN environment variables, ghtkn get / exec / auth / agent / revoke, the ghtkn git credential helper, or…

not rated 354 +28 today A 146 tokens original MIT

wa-review

199

YoshiiRyo1/document-templates-for-aws

Skill Claude CodeCodex

This skill should be used when the user asks to "review architecture", "Well-Architected review", "check bestpractices", "security assessment",or "cost optimization analysis".

not rated 352 +5 6mo ago A 41 tokens original Unlicense

owasp-security

200

agamm/claude-code-owasp

Skill Claude CodeCodex

Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, LLM Top 10 (2025), and Agentic AI security (2026).

not rated 353 +4 1mo ago A 62 tokens original MIT

secureclaw

201

adversa-ai/secureclaw

Skill Claude CodeCodex

Security hardening toolkit for OpenClaw. Run audits, apply fixes, scan skills, monitor costs and memory integrity.

not rated 347 +2 4mo ago A 28 tokens

zkbugs AGENTS.md

202

zksecurity/zkbugs

Instructions file CodexOpenCode

Instructions for zksecurity/zkbugs, covering repository guidelines, project structure & module organization, build, test, and development commands, coding style & naming conventions and testing guidelines.

not rated 345 16d ago A 997 tokens original MIT

threat-modeling

203

fr33d3m0n/threat-modeling

Skill Claude CodeCodex

Threat model, security audit, find vulnerabilities, check security of my app, risk assessment, penetration test prep, analyze attack surface, what could an attacker exploit. Use this skill whenever a user wants holistic security analysis of a codebase, application, or project. MUST be invoked instead of analyzing…

not rated 341 +4 3mo ago A 178 tokens original BSD-3-Clause

cryptex-oss CLAUDE.md

204

m4xx101/cryptex-oss

Instructions file

Instructions for m4xx101/cryptex-oss, covering contributor + ai-assistant guide, what this repo is, commands, primary (sveltekit app) and python cli (cryptex-cli).

not rated 338 +2 2mo ago A 3,329 tokens original MIT

oracle/netsuite-suitecloud-sdk

Skill Claude CodeCodex ✓ vendor

Comprehensive NetSuite SDF best practices based on the SAFE Guide (12 principles + appendices). Generates Object XML for all 14 script types, enforces governance limits, security patterns, and defensive coding. Includes N/cache, N/query, concurrency limits, OAuth 2.0 guidance, legacy TBA guardrails, CustomTool runtime…

not rated 336 +3 yesterday A 104 tokens UPL-1.0

security-review

207

zhukunpenglinyutong/ai-max

Skill Claude CodeCodex

A security checklist for code that handles login permissions, user input, uploaded files, passwords, API keys, payments, or other sensitive data.

not rated 336 6mo ago A 42 tokens original MIT

prismor CLAUDE.md

208

PrismorSec/prismor

Instructions file

Claude Code instructions for PrismorSec/prismor, covering prismor security — claude.md, prismor runtime protection, cloaking (secret prevention) and working in this repo.

not rated 338 today A 359 tokens original Apache-2.0

mcpproxy-go CLAUDE.md

209

smart-mcp-proxy/mcpproxy-go

Instructions file

Claude Code instructions for smart-mcp-proxy/mcpproxy-go, covering claude.md, autonomous operation constraints, must-do (defaults & assumptions), must-nots and escalation triggers (stop conditions).

not rated 335 +8 changed yesterday A 3,558 tokens original MIT

flounder AGENTS.md

210

adshao/flounder

Instructions file CodexOpenCode

AGENTS.md instructions for adshao/flounder, covering agents.md, project defaults, thin-layer agentic mode, map → dig deep coverage and operating the deep audit.

not rated 330 +1 yesterday A 6,358 tokens AGPL-3.0

codeguard-security

211

cosai-oasis/project-codeguard

Plugin Claude Code

Bundles 4 skills · 207 tokens together

Security code review skill based on Project CodeGuard's comprehensive security rules. Helps AI coding agents write secure code and prevent common vulnerabilities.

not rated 329 +3 yesterday A tokens not measured

ksafe

212

ioannisa/KSafe

Plugin Claude Code

Bundles 1 skill · 251 tokens together

Agent skill for the KSafe Kotlin Multiplatform encrypted persistence library — setup, usage patterns, anti-patterns, and debugging.

not rated 328 +1 today A tokens not measured original Apache-2.0

ghidra-rpc

213

cellebrite-labs/ghidra-rpc

Skill Claude CodeCodex

Reverse engineering assistant powered by Ghidra. Use for binary analysis, decompilation, vulnerability research, auditing compiled code, renaming symbols, annotating disassembly, cross-references, or any RE task - even without explicit mention of Ghidra.

not rated 322 +6 29d ago A 58 tokens

DorkAgent CLAUDE.md

214

yee-yore/DorkAgent

Instructions file

Instructions for yee-yore/DorkAgent, covering claude.md, project overview, commands, running the tool and interactive mode (menu-driven interface).

not rated 319 +2 11d ago A 1,888 tokens original MIT

badchars/darknet-mcp-server

Instructions file

Claude Code instructions for badchars/darknet-mcp-server, covering darknet-mcp — dark web intelligence mcp server, architecture, key rules, providers (16) and commands.

not rated 317 +1 3d ago A 336 tokens original MIT

terrashark

216

LukasNiessen/terrashark

Skill Claude CodeCodex

Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps. Use when generating, reviewing, refactoring, or migrating IaC and when building delivery/testing pipelines.

not rated 316 +2 19d ago A 56 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: