Security for AI agents
100 security-reviewed security listings, skills, MCP servers, and toolkits you can install into Claude Code, Cursor, and other agents with one command.
Access Control
Detect missing or incorrect access control — missing modifiers, wrong role checks, privileged function exposure, public initializers, and role-escalation paths. Activate on any function that mutates state, transfers funds, mints tokens, sets admin parameters, upgrades implementations, or pauses/unpauses.
Threat Model Security Review
Run a dependency-free, threat-model-led application security review of a repository, scoped component, code diff, or supplied vulnerability claim. Use when auditing source code, authentication, authorization, input handling, filesystem or network access, sensitive data paths, trust boundaries, or security regressions. Produces evidence-backed attack paths, explicit validation status, coverage gap…
Handoff
Escribe el handoff de un ciclo de trabajo en el vault, verificando el estado contra git antes de afirmarlo. Usar al cerrar una sesion larga, antes de compactar, cuando el usuario dice handoff, /handoff, escribi el handoff, donde quedamos, antes de irme, cerra el ciclo, o cuando un hilo se vuelve demasiado largo para retomarlo de memoria. No usar para resumir una conversacion corta ni para escribi…
Security Audit
Security review and hardening workflow — root-cause analysis of vulnerabilities, authentication and authorization checks, least privilege, input handling, secret hygiene, and security regression tests. Use when reviewing code for security, fixing a vulnerability, hardening a feature, or handling auth, permissions, secrets, or untrusted input. For a quick automated pass on pending changes, the bui…
Secret Lint
Automated secret scanning using secretlint to prevent credential leaks.
Security Guardian
Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité. OWASP Top 10, authentification, autorisation, cryptographie, gestion de secrets. Utiliser pour audits sécurité, reviews de code sensible, conception de features sécurisées, ou résolution de failles.
Splunk Identity Saml Readiness Advisor
Research current public Splunk sources and use optional existing-auth read-only stack evidence to diagnose SAML, LDAP, roles, capabilities, group mappings, login failures, and access readiness without changing identity configuration or handling credentials.
Redteam Open Redirect Detail Pack
Domain routing and boundary guidance for authorized open redirect testing, including parameter redirects, meta or JavaScript redirects, and OAuth redirect_uri abuse. Use when a task belongs to the open redirect domain and needs scope, evidence, pivot, or exit criteria.
Web Pentest
Web应用渗透测试 — 针对Web应用的完整渗透流程,含技术栈识别、目录枚举、认证测试、输入验证、逻辑漏洞
Cve Triage
CVE lookup and triage — map discovered services/versions to known CVEs via the cve_lookup tool, score by CVSS/exploitability, and prioritize what to verify first.
Redteam Auth Detail Pack
Domain routing and boundary guidance for authorized authentication, authorization, and session security testing, including password policy, JWT/token, OAuth, and MFA bypass issues. Use when a task belongs to the auth testing domain and needs scope, evidence, pivot, or exit criteria.
Redteam Recon Intake
Recon intake skill for first contact with a bare domain, URL, or IP address. Use to build an initial recon_profile and provide factual inputs for CVE lookup and attack-path routing.
Hackerone
HackerOne 赏金项目 scope-guard 流程 — 读取 program scope,强制 scope 与 program rules,再逐个把 in-scope asset 交给 pentest-flow
Redteam Cve Validation
CVE validation domain card. Use after CVE lookup has produced applicable or candidate CVEs and red-team mode needs scoped evidence to decide whether to continue, pivot, or report.
Redteam Logic Detail Pack
Domain routing and boundary guidance for authorized business logic vulnerability testing, including race conditions, flow bypass, price tampering, permission logic errors, and bulk operation abuse. Use when a task belongs to the logic testing domain and needs scope, evidence, pivot, or exit criteria.
Pentest Tools
渗透工具速查 — 编码解码、反向Shell、红队工具、漏洞利用、密码攻击、内网工具、凭据窃取、提权、隧道代理、系统命令、信息收集、域渗透、Web工具、Windows工具
Redteam File Detail Pack
Domain routing and boundary guidance for authorized file operation vulnerability testing, including path traversal, arbitrary file read/write/upload, and LFI/RFI. Use when a task belongs to the file vulnerability domain and needs scope, evidence, pivot, or exit criteria.
Redteam Cve Lookup
CVE lookup and applicability assessment domain card. Use after reconnaissance has identified products, versions, services, or fingerprints and red-team mode needs evidence-based CVE matching before deeper testing.
Redteam Web Detail Pack
Routing and boundary guidance for authorized general web application security testing. Use as a web testing router when the attack surface should be dispatched to more specific web vulnerability skills.
Redteam Cors Miscfg Detail Pack
Domain routing and boundary guidance for authorized CORS misconfiguration testing, including reflected origins, null origins, subdomain trust, and credential exposure. Use when a task belongs to the CORS testing domain and needs scope, evidence, pivot, or exit criteria.
SquidC5
Security-first AI-native C5 teamserver (Command · Control · Cognitive · Collaborative · Coordination) for authorized red team & pentest. Built by SquidSec.
MCPwner
Model Context Protocol server for autonomous vulnerability discovery
Ai Smart Contract Auditor
AuditSentry — AI-powered smart contract security auditor for Claude Code. Automated vulnerability detection, exploit PoCs, mainnet-fork simulation, and professional audit reports for Solidity & Vyper across all EVM chains.
Sallyport
A Mac vault that runs authenticated actions for AI agents over MCP. The agent gets the operation, never the key: no command reveals a stored credential, and there is no export route.
Murmur
Murmur — encrypted agent-to-agent messaging bus for AI coding agents. MCP-native, E2E encrypted (XChaCha20-Poly1305), NATS transport with optional JetStream durability, cross-host and cross-org federation + A2A interop. Connect Claude Code, Codex and friends across machines.
Career Pivot Planner
Plan your career pivot step by step — map transferable skills, translate experience to a new industry, write transition narratives, and identify bridge credentials
Pattern Vault
Extract, index, and retrieve reusable code patterns from any repository. Your personal pattern library, queryable by Agents or by you.
Uc Mcp Proxy
An MCP Proxy built to use any Databricks MCP server in local coding agents with OAuth.
Eo Project Init
eo-skills 在当前仓库的总入口:生成 .eo-project.json、初始化项目管理侧(roadmap/log/backlog)和代码侧最小骨架(eo-doc/),按需建 vault 软链和 agent 配置注入。触发:启动项目 / 初始化项目 / 新建项目 / /eo-project-init。
Apollo Operator
The four ways to run Apollo headless and how to choose: MCP (typed tools, results always through context), the apollo CLI binary (disk output, common filters), REST authenticated with the CLI's own OAuth token (full MCP filter surface WITH disk output, no API key), and REST with an API key. Includes measured context costs, credit costs per lane, verified command recipes, and the kill switch for s…
Security
Secret detection and credential scanning using gitleaks. Use when scanning repositories for leaked secrets, API keys, passwords, tokens, or implementing pre-commit security checks.
Domain Dns Configurator
Use when planning DNS records, nameservers, A/AAAA/CNAME/TXT/MX, SPF/DKIM/DMARC, CDN, propagation, and rollback. Dry-run only; do not change production DNS or store provider credentials without explicit approval.
Admin Ui Orchestrator
Use when a project needs admin/CMS/back-office UI architecture: roles, permissions, content workflows, AI assistant boundaries, audit logs, destructive-action confirmations, and builder handoff. Planning only; do not perform production admin actions or expose secrets.
Audit Security
Scan the codebase for code-level security vulnerabilities including hardcoded secrets, injection risks, missing auth checks, and insecure patterns, then produce a prioritized remediation plan.
Connect It
Self-hosted connector gateway — hold your SaaS credentials once, and hand your agents a single MCP endpoint.
Yandex Direct Mcp
MCP server for Yandex Direct API: campaigns, ads, keywords, bids, reports. Click.ru proxy or direct OAuth with sandbox. Docs in Russian.
Security Auditor
Comprehensive security audit for VibeCoding sites. Triggers on "security check", "is my site secure", "API key exposed", "vulnerability", "security audit", "hacked", "password", "SSL", "HTTPS", "security headers", "XSS", "CSRF", "secrets", "data breach", ".env file", "privacy policy", "GDPR", "cookie consent". Scans for exposed API keys, dependency vulnerabilities, missing security headers, HTTPS…
Stackchan Cloud Mcp
Cloud MCP gateway that connects a StackChan desk robot to claude.ai — OAuth 2.1 bridge, reflex daemon, pixel avatar toolkit, and the field notes from making it work
Cpe Skills
Comprehensive CPE (Common Platform Enumeration) toolkit — SKILLS, Go SDK, CLI & MCP integration for parsing, matching, generation, storage and NVD integration. ≥91% coverage, 108 platform binaries.
Prep Planner
Builds and updates interview prep weekly plans from profile schedule and vault status. Use when the user asks what to do today/tonight, replans the week, adjusts for work/weekend availability, catches up after slipping, or mentions THIS_WEEK / schedule / daily plan / time budget.
Datalad Credentials
>
Hermes Gateway Doctor
Use when Hermes messaging gateway failures must be diagnosed across process state, adapters, credential posture, logs, delivery evidence, polling conflicts, and service persistence without automatic repair.
Hermes Profile Audit
Use when a Hermes profile must be audited for role clarity, authority boundaries, configuration fit, skills, memory posture, credential scope, handoffs, and recurring operational failures.
Hermes Stack Doctor
Use when a top-level, read-only Hermes health audit is needed across installation, updates, gateways, cron, profiles, skills, repositories, credential posture, persistence, and cost signals.
Exocortex Mcp
Remote MCP server for an exocortex vault — query your compiled knowledge and capture to its inbox from claude.ai, the Claude app, or any MCP client
Mcp Secret Sentinel
MCP server that scans code for exposed secrets - API keys, tokens, private keys and high-entropy strings - with placeholder-aware allowlisting and redacted reports
Godig
🔌 CLI & MCP server for pkg.go.dev
Vault Gardener
Recurring maintenance pass for a second-brain vault — link hygiene, naming, metadata/tags, Inbox filing, dedupe, learnings-index sync, index-note freshness. Run daily as a scheduled agent (or weekly by hand). Keeps recall precise as the vault grows; without gardening, a knowledge vault decays into a junk drawer with a search bar. Use when asked to "garden the vault", "clean up the vault", or as t…
Pacioli
Least-privilege governance for ERPNext — the credential floor + a governed agent front door, MCP · A2A, one spine. No debit without a credit: PLAN · CONSENT · PROVE · UNDO.
Pwnote Cve Research
Use whenever the user is doing vulnerability research aimed at a CVE/advisory — tracking a responsible disclosure timeline, drafting a vendor notification, requesting a CVE ID from MITRE or a CNA, writing a public security advisory, or mapping a finding to a CWE. Trigger on "CVE", "CNA", "MITRE", "advisory", "responsible disclosure", "vendor notification", "embargo", or "disclosure timeline", eve…
Pwnote Engagement File
Create or validate a pwnote engagement import/export JSON file. Use when the user wants to generate, edit, or verify a pwnote engagement file for data transfer between pwnote instances. The file bundles an entire pentest engagement — metadata, notebook documents, code/host/credential blocks, findings with CVSS/cwe/cve, attack-path boards, and activity history. Also use when the user asks how to s…
Pwnote Offsec Web300
Use whenever the user is working on Offsec's WEB-300 course/OSWE — whitebox source code review methodology, exploit chain documentation, PoC scripting, or OSWE exam report writing. Trigger on "OSWE", "WEB-300", "whitebox", "source code review" in a pentest context, or "exploit chain", even without the word "skill".
Pruna Api
Use before any Pruna or Replicate HTTP call — credentials, upload/poll/download, parallel batches, and agent safety.
Websearch Search
Run the lit-review orchestrator keyless agent-driven web search channel that uses WebSearch and WebFetch outputs normalized through websearch_ingest.py. Use when the user invokes the web search channel, asks for Stage 4d open-web literature discovery, or needs a Claude Code web-search fallback without SearchAPI, Gemini, or Undermind credentials.
Freesearch Search
Run the lit-review orchestrator free index search channel against keyless OpenAlex, Crossref, and Semantic Scholar keyword-search endpoints. Use when the user invokes the free search channel, asks for keyless scholarly index search, or needs Stage 4e fallback discovery without SearchAPI, Gemini, or Undermind credentials.
Setup Agent Team
Create a bounded manual execution packet for large AI-agent team workflows, or refuse/downgrade when the task should stay single-agent. Use when work is multi-domain, parallelizable, and context-heavy enough to need role selection, context packets, ownership boundaries, handoffs, budgets, verification, package-execution policy, and external-system credential policy before launching workers.
Personal Thought Vault
本地优先的个人思想库与个人生命操作系统。仅在用户明确提到“个人思想库”,或明确要求依据自己的历史原话、原则、案例与复盘来分析、收集、判同、照镜子、决策复盘、思想织网或辩论时使用。按人生根问题组织思想,严格区分用户证据、AI解释与外部来源。
Security Audit Lite
Perform a practical security review focused on auth, secrets, insecure defaults, injection risks, trust boundaries, privilege escalation, token handling, and sensitive data exposure. Use when a user asks for a lightweight security audit, AppSec review, or auth or secret-handling review.
Pledgeguard
Rust-native secret scanner with MCP server, AST refinement, and WASM plugins
Lokalite
Local-first secrets manager for macOS. Encrypted vault, menu bar app, CLI, and an MCP server that loads secrets into your coding agent's shell instead of the chat. No cloud, no account, no subscription.
Agent Rock
>
Rock Quick
>
Rock Deep
>
Rock Deps
>
Rock Diff
>
Public Code Review
Review the current diff or a specified set of files as public open-source code before publishing or merging. Use to check code quality, public-repository safety (secrets and private data), documentation trustworthiness, provenance, onboarding, and maintainability. Reports grouped findings; does not fix them unless asked.
Release Deploy
Prepare a public open-source project for release and deploy it to a detected target. Use at a release or submission boundary to verify setup, docs, secrets, tests, lint, build, and licenses, then follow the target-specific deployment path. Runs expensive checks sequentially. Never publishes, tags, commits, pushes, or deploys without explicit user intent.
Pentquiver
Fast cross-platform TUI/CLI/API/MCP command library and cheat-sheet launcher for pentesters - 2,800+ security commands, argument templates, hexagonal architecture.
Novu Manage Subscribers
Create, update, search, and delete subscribers in Novu. Manage topics for group-based notification targeting. Set subscriber credentials for push and chat channels. Use when managing notification recipients, creating subscriber records, organizing subscribers into topics, or configuring channel-specific credentials.
Infostealer Malware Detector
Detects and removes infostealer malware (credential stealers, data exfiltrators) via full-system file search, cryptographic hashing, and public threat-intelligence cross-checks (VirusTotal, MalwareBazaar). Primary method is always custom hash-based detection. Windows Defender (or any platform-native AV) is allowed **only when necessary** (e.g. inconclusive hashes or deep remediation) and **must n…
Rapprise
Rust MCP server and CLI for Apprise notification fan-out across dozens of delivery backends, with stdio/HTTP transports, auth, and plugin packaging.
Pentester
Skills of a penetration tester for finding exploitable vulnerabilities (API, authentication, multi-tenant isolation) before an attacker does. Trigger this skill for penetration testing, offensive security audits, or vulnerability exploitation within an authorized engagement.
Red Team
Red Team skills for simulating full, realistic attacks (beyond a simple technical pentest) including social engineering and persistence, to test the organization's overall resilience. Trigger this skill for advanced, multi-vector attack simulation exercises within a strictly authorized scope.
Purple Team
Purple Team skills for bridging offense (Red Team) and defense (Blue Team), turning every offensive test into a measurable defensive improvement. Trigger this skill to coordinate a joint red/blue exercise, improve detection rules after a pentest, or measure defensive coverage.
Capture
Drop a small, worth-keeping fact, decision, or preference into the vault's inbox in under 15 seconds — no schema, no index ceremony.
Write A Plan
Direct agent to create a plan and store it in the vault with an attached task.
Retrospect
Periodically review recent vault work — edits, the activity log, and feedback — and propose durable refinements: corrections to promote into SCHEMA.md, knowledge to capture, conventions to add or prune.
Pickup Task
Direct agent to execute a tracked task/plan from the vault, updating its status before and after the work.
Agsync
Agsync is a repo-native control plane for managing skills, MCP servers, secrets, and agent configs across AI clients like Claude Code and Cursor.
Icm Architect
Design any process, idea, problem, or body of knowledge into an ICM (Interpretable Context Methodology) workspace — folder structure as agent architecture — or restructure an existing folder, repo, or vault into one. Use when the user wants to (1) turn a recurring workflow into an agent-runnable folder pipeline, (2) organize scattered notes, files, or knowledge into a library one AI agent can wal…
Pip Boy
War. War never changes. But your dev tooling should. — Personal Vault-Tec approved Claude Code plugin marketplace.
Tool Review Gate
Review a proposed skill, plugin, MCP server, CLI, package, API, connector, application, or service before installation or use. Use when a new capability may execute code, access files or accounts, receive project data, require secrets, cost money, change configuration, or create external effects. Present a decision-ready approval card and wait for explicit, scoped user approval.
Autocommit
Operate the local auto-commit daemon for this vault. Use when the user wants to start, stop, restart, inspect, debug, or verify the auto-commit system, or asks about background git automation in this workspace.
Wordpress Content Manager
WordPress content management via REST API for managing posts. Requires Node.js and WordPress REST API credentials.
Nextjs Module
Structures a Next.js 16 App Router frontend feature as layered modules (lib/api typed fetchers, query-keys, TanStack Query hooks, React 19 pages) fed by one shared fetch client that sends the auth cookie with credentials include, attaches the tenant header, and normalizes errors. Use when scaffolding a new frontend feature or module, building a fetch/apiClient wrapper, wiring cookie-JWT calls to…
Incident Response
Runs the response when something is live-broken or a secret is exposed — report first, contain the blast radius, fix the root cause through a reviewed change, then a blameless post-mortem that hardens the lesson into a standing rule. Use when a production endpoint is down or misbehaving, a key/token/credential may have leaked, an account or session looks compromised, a bad deploy is degrading use…
Security Review
Audits a diff for this stack's top risks — tenant isolation on every business queryset (fail-closed, no client-supplied tenant id trusted), RBAC on every custom endpoint and @action, PII leakage in list endpoints/logs/exports, file-upload validation (content-type, size, extension, private storage), and secrets not committed. Use when reviewing a Django/DRF change before merge, auditing a new View…
Load Context
Use at the start of /research and other workflow recipes to establish vault grounding. Loads vault bootstrap (profile.md), checks inbox, and pre-warms project context if a topic anchor is implied. Repo/git detection lands with /plan and /implement.
Capture To Vault
Use during /research, /scope (or any recipe) to write or update a vault note via dossier-mcp. Agent drafts slug + frontmatter + body + citations, writes the note, and surfaces what was captured so the user can redirect afterward. Supports create (new note) and update (refine existing note) modes.
Dispatch Exploration
Use during /research (or any recipe) to send 1-3 research queries in parallel — vault or web targets — and aggregate compressed findings. Routes each query to vault-researcher or web-researcher based on target. Hosts the cross-verify consent gate so any inline-research caller (/research, /design, /decompose) inherits source-bias mitigation without duplicating logic.
Mcp Auth Wrapper
🔐 Turn your stdio MCP server into a multi-user OAuth-authenticated remote MCP server
Factory Security Engineer
Use to threat-model a feature, audit AI-generated code, design sensitive-data handling, or review auth/authz boundaries. Carries the factory's security conventions — KMS encryption at rest, BAA verification for PHI, safe URL redirects, admin-client bypass guardrails, in-memory rate-limiter caveats, read-only-by-default for AI-generated code, mandatory review queue, request tracing, audit logging…
Binary Credential Format Boundary
Audit and repair readers for fixed-length binary credentials and their text encodings without mutating raw bytes. Use when code loads Ed25519/X25519 keys, nonces, digests, MAC keys, signatures, tokens, or other opaque bytes from files or environment values; when `.strip()`, decoding, newline handling, or format auto-detection occurs before length/type validation; or when cryptographic tests fail…
Public Artifact Runtime Smoke Gate
Verify Python packages, CLIs, MCP servers, and Agent plugins through the exact installed artifact and real runtime contract. Use when source tests pass but a published release may omit modules, expose broken entry points, depend on local paths, fail without optional credentials, or behave differently after public installation.
Vault Ask
Asks questions and gets synthesized answers grounded in vault history with source citations. Use when: (1) /vault-ask <question> to reason over vault knowledge, (2) user wants to know what their notes say about a topic, (3) user wants cross-project pattern analysis.
Emerge
Surface unnamed patterns across vault notes. Use when: (1) /emerge for last 30 days, (2) /emerge 14d for custom window, (3) /emerge this week.
System Recon
Collect a bounded, read-only system inventory for troubleshooting while identifying privilege gaps and avoiding secrets or invasive enumeration.
Publish Ready
Prepare a repository for public release by removing development residue and dead paths, consolidating documentation, tightening generated-sounding prose, checking for secrets and local-machine references, and proving that surviving quickstarts and checks work. Use before open-sourcing, sharing, handing off, demonstrating, or releasing a project.
Quota Footer
Use when a reply should end with a concise Codex quota footer such as “额度:周 11%” or “额度:5h 29%|周 21%”. Reads local Codex OAuth auth.json, queries ChatGPT WHAM usage, and formats only the windows returned by the service unless details are requested.
Codex Backup Recovery
Create, validate, inspect, and restore a secret-free allowlisted backup of Codex, Claude Code, and shared Agent skills, memories, rules, commands, and automations. Use when a user wants a daily Agent workspace backup, a new-Mac migration rehearsal, disaster-recovery verification, or an audit of exactly what an Agent backup contains. Do not use as a full-disk backup or to copy credentials and logi…