Security

25,251 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

opencti-mcp

2282

blauwers/opencti-mcp-server

MCP server Claude CodeCodexCursor +2

MCP server exposing the OpenCTI threat-intelligence platform to AI assistants. Runs locally from the opencti-mcp Python package.

not rated 1 1mo ago A tokens not measured

guardrails

2283

ExpertVagabond/guardrails-mcp-server

MCP server Claude CodeCodexCursor +2

AI Agent Guardrails MCP server - security layer. Runs locally from the guardrails-mcp-server npm package.

not rated 1 6d ago A tokens not measured original MIT

contract-scanner

2285

lordbasilaiassistant-sudo/mcp-servers

MCP server Claude CodeCodexCursor +2

One of 4 in server.json

Smart contract security scanner — vulnerabilities, risk scores, and calldata decoding. Runs locally from the @thryx/contract-scanner-mcp-server npm package. Needs 4 environment variables to run.

not rated 1 5mo ago A tokens not measured

n8n-mcp-community

2286

drzamarian/n8n-mcp-community

MCP server Claude CodeCodexCursor +2

A security-focused MCP server for self-hosted n8n Community Edition. Runs locally from the n8n-mcp-community npm package. Needs 4 environment variables to run.

not rated 1 4d ago A tokens not measured original MIT

apex-psi-mcp

2289

kawal393/apex-psi-mcp-server

MCP server Claude CodeCodexCursor +2

Cryptographic truth infrastructure for AI agents: seal, verify, anchor, cite, audit. Runs locally from the apex-psi-mcp npm package. Needs 2 environment variables to run.

not rated 1 1mo ago A tokens not measured

402sentinel-mcp

2290

kaditang/402sentinel-mcp

MCP server Claude CodeCodexCursor +2

MCP tools for x402 payment safety — vet the counterparty (risk score, allow/review/block, spending policy) AND vet the payment itself (buyer-side firewall: routing/drain/injection). Thin client for 402sentinel.com. Runs locally from the @kaditang/402sentinel-mcp npm package. Needs 2 environment variables to run.

not rated 1 7d ago A tokens not measured

MojoAuth/skills

Skill Claude CodeCodex

Implement passwordless authentication in native Android/Kotlin applications using MojoAuth OIDC with AppAuth.

not rated 1 6mo ago A 27 tokens

setup-semgrep-plugin

2292

semgrep/cursor-plugin

Skill Claude CodeCodex

Set up the Semgrep plugin by installing Semgrep, authenticating, and verifying compatibility.

not rated 1 1mo ago A 22 tokens

shugo

2293

aritraghosh01/shugo

MCP server Claude CodeCodexCursor +2

Minimal MCP guardrails proxy — policy-first, human approvals, hash-chained audit log. Runs locally from the shugo Python package.

not rated 1 1mo ago A tokens not measured original MIT

team-qa

2294

huuanh20/awesome-ai-agent-skills

Skill Claude Code

QA/QC agent. Reads ALL pipeline artifacts (BA + TechLead + PM + BE + FE + Tester) and produces quality-report.md, compliance-check.md, and sign-off.md. Declares Gate 3: Release Sign-off (advisory only — operator has final authority). Part of the Virtual Team Skill pipeline.

not rated 1 1mo ago A 70 tokens original MIT

mcp-marketing-site

2295

deeppath-ai/mcp-marketing-site

MCP server Claude CodeCodexCursor +2

This is a Crawler Security Guard based on the Model Context Protocol (MCP). Runs locally from the mcp-marketing-site npm package.

not rated 1 1y ago A tokens not measured original MIT

5g-ddos-mcp

2296

core-ncsrd/5g-ddos-mcp

MCP server Claude CodeCodexCursor +2

MCP server for 5G DDoS detection using the NCSRD-DS-5GDDoS dataset. Runs locally from the 5g-ddos-mcp Python package.

not rated 1 3mo ago A tokens not measured original MIT

timwukp/aws-security-posture-advisor-mcp

MCP server Claude CodeCodexCursor +2

MCP server "awslabs.aws-security-posture-advisor" as configured in timwukp/aws-security-posture-advisor-mcp. Runs locally from the awslabs.aws-security-posture-advisor Python package.

not rated 1 4mo ago A tokens not measured original Apache-2.0

tshark-mcp

2298

niusulong/TShark2MCP

MCP server Claude CodeCodexCursor +2

MCP server for using TShark to analyze network packets. Runs locally from the tshark-mcp Python package.

not rated 1 1mo ago A tokens not measured copy · 100% MIT

outris-identity-mcp

2299

outris-dev-org/outris-identity-mcp

MCP server Claude CodeCodexCursor +2

MCP server "outris-identity-mcp", hosted remotely at mcp-server.outris.com, as configured in outris-dev-org/outris-identity-mcp.

not rated 1 2mo ago A tokens not measured original MIT

mcp-demo-enforcer

2300

danduh/mcp-security

Skill Claude CodeCodex

Forces the model to always use the mcp-security demo MCP server tools instead of native capabilities. Use this skill whenever the user is working in the mcp-security project and asks to read files, count lines, write files, check npm packages, inspect npm config, verify registry, or do any file/npm operation. This…

not rated 1 2mo ago A 119 tokens

agentscore-mcp

2301

tmishra-sp/agentscore-mcp

MCP server Claude CodeCodexCursor +2

Trust scoring for AI agents. Investigate, verify, and compare agent trustworthiness through MCP. Runs locally from the agentscore-mcp npm package.

not rated 1 4mo ago A tokens not measured original MIT

pentquiver

2302

edglz/pentquiver

MCP server Claude CodeCodexCursor +2

A cross-platform TUI/CLI/API/MCP command library for authorized security testing. Runs locally from the pentquiver Python package.

not rated 1 2mo ago A tokens not measured original MIT

mcp-api-pentest

2303

josenieto/mcp-api-pentest

MCP server Claude CodeCodexCursor +2

MCP server for autonomous API logic penetration testing — OWASP API Top 10 / BOLA-IDOR detection via LLM-driven analysis. Runs locally from the mcp-api-pentest Python package.

not rated 1 1mo ago A tokens not measured original MIT

promptwall

2304

vtino17/promptwall

MCP server Claude CodeCodexCursor +2

LLM prompt injection firewall with session tracking, explainability and multilingual detection. Runs locally from the promptwall Python package.

not rated 1 28d ago A tokens not measured original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: