AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in

Security for AI agents

100 security-reviewed security listings, skills, MCP servers, and toolkits you can install into Claude Code, Cursor, and other agents with one command.

100+ results
Self-run
SKILL MIT 1mo ago

Access Control

Detect missing or incorrect access control — missing modifiers, wrong role checks, privileged function exposure, public initializers, and role-escalation paths. Activate on any function that mutates state, transfers funds, mints tokens, sets admin parameters, upgrades implementations, or pauses/unpauses.

Local-only
1
66
Free
Self-run
SKILL MIT yesterday

Threat Model Security Review

Run a dependency-free, threat-model-led application security review of a repository, scoped component, code diff, or supplied vulnerability claim. Use when auditing source code, authentication, authorization, input handling, filesystem or network access, sensitive data paths, trust boundaries, or security regressions. Produces evidence-backed attack paths, explicit validation status, coverage gap…

Local-only
0
0
Free
Self-run
SKILL MIT yesterday

Handoff

Escribe el handoff de un ciclo de trabajo en el vault, verificando el estado contra git antes de afirmarlo. Usar al cerrar una sesion larga, antes de compactar, cuando el usuario dice handoff, /handoff, escribi el handoff, donde quedamos, antes de irme, cerra el ciclo, o cuando un hilo se vuelve demasiado largo para retomarlo de memoria. No usar para resumir una conversacion corta ni para escribi…

Local-only
0
3
Free
Self-run
SKILL MIT 2d ago

Security Audit

Security review and hardening workflow — root-cause analysis of vulnerabilities, authentication and authorization checks, least privilege, input handling, secret hygiene, and security regression tests. Use when reviewing code for security, fixing a vulnerability, hardening a feature, or handling auth, permissions, secrets, or untrusted input. For a quick automated pass on pending changes, the bui…

Local-only
0
3
Free
Self-run
SKILL MIT 2d ago

Secret Lint

Automated secret scanning using secretlint to prevent credential leaks.

Local-only
0
0
Free
Self-run
SKILL MIT 8mo ago

Security Guardian

Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité. OWASP Top 10, authentification, autorisation, cryptographie, gestion de secrets. Utiliser pour audits sécurité, reviews de code sensible, conception de features sécurisées, ou résolution de failles.

Local-only
0
0
Free
Self-run
SKILL Apache-2.0 yesterday

Splunk Identity Saml Readiness Advisor

Research current public Splunk sources and use optional existing-auth read-only stack evidence to diagnose SAML, LDAP, roles, capabilities, group mappings, login failures, and access readiness without changing identity configuration or handling credentials.

Local-only
0
2
Free
Self-run
SKILL MIT yesterday

Redteam Open Redirect Detail Pack

Domain routing and boundary guidance for authorized open redirect testing, including parameter redirects, meta or JavaScript redirects, and OAuth redirect_uri abuse. Use when a task belongs to the open redirect domain and needs scope, evidence, pivot, or exit criteria.

Local-only
0
3
Free
Self-run
SKILL MIT yesterday

Web Pentest

Web应用渗透测试 — 针对Web应用的完整渗透流程,含技术栈识别、目录枚举、认证测试、输入验证、逻辑漏洞

env
0
3
Free
Self-run
SKILL MIT yesterday

Cve Triage

CVE lookup and triage — map discovered services/versions to known CVEs via the cve_lookup tool, score by CVSS/exploitability, and prioritize what to verify first.

Local-only
0
3
Free
Self-run
SKILL MIT yesterday

Redteam Auth Detail Pack

Domain routing and boundary guidance for authorized authentication, authorization, and session security testing, including password policy, JWT/token, OAuth, and MFA bypass issues. Use when a task belongs to the auth testing domain and needs scope, evidence, pivot, or exit criteria.

Local-only
0
3
Free
Self-run
SKILL MIT yesterday

Redteam Recon Intake

Recon intake skill for first contact with a bare domain, URL, or IP address. Use to build an initial recon_profile and provide factual inputs for CVE lookup and attack-path routing.

Local-only
0
3
Free
Self-run
SKILL MIT yesterday

Hackerone

HackerOne 赏金项目 scope-guard 流程 — 读取 program scope,强制 scope 与 program rules,再逐个把 in-scope asset 交给 pentest-flow

Local-only
0
3
Free
Self-run
SKILL MIT yesterday

Redteam Cve Validation

CVE validation domain card. Use after CVE lookup has produced applicable or candidate CVEs and red-team mode needs scoped evidence to decide whether to continue, pivot, or report.

Local-only
0
3
Free
Self-run
SKILL MIT yesterday

Redteam Logic Detail Pack

Domain routing and boundary guidance for authorized business logic vulnerability testing, including race conditions, flow bypass, price tampering, permission logic errors, and bulk operation abuse. Use when a task belongs to the logic testing domain and needs scope, evidence, pivot, or exit criteria.

Local-only
0
3
Free
Self-run
SKILL MIT yesterday

Pentest Tools

渗透工具速查 — 编码解码、反向Shell、红队工具、漏洞利用、密码攻击、内网工具、凭据窃取、提权、隧道代理、系统命令、信息收集、域渗透、Web工具、Windows工具

Local-only
0
3
Free
Self-run
SKILL MIT yesterday

Redteam File Detail Pack

Domain routing and boundary guidance for authorized file operation vulnerability testing, including path traversal, arbitrary file read/write/upload, and LFI/RFI. Use when a task belongs to the file vulnerability domain and needs scope, evidence, pivot, or exit criteria.

Local-only
0
3
Free
Self-run
SKILL MIT yesterday

Redteam Cve Lookup

CVE lookup and applicability assessment domain card. Use after reconnaissance has identified products, versions, services, or fingerprints and red-team mode needs evidence-based CVE matching before deeper testing.

net
0
3
Free
Self-run
SKILL MIT yesterday

Redteam Web Detail Pack

Routing and boundary guidance for authorized general web application security testing. Use as a web testing router when the attack surface should be dispatched to more specific web vulnerability skills.

Local-only
0
3
Free
Self-run
SKILL MIT yesterday

Redteam Cors Miscfg Detail Pack

Domain routing and boundary guidance for authorized CORS misconfiguration testing, including reflected origins, null origins, subdomain trust, and credential exposure. Use when a task belongs to the CORS testing domain and needs scope, evidence, pivot, or exit criteria.

Local-only
0
3
Free
Self-run
MCP MIT 8d ago

SquidC5

Security-first AI-native C5 teamserver (Command · Control · Cognitive · Collaborative · Coordination) for authorized red team & pentest. Built by SquidSec.

netenv
0
3
Free
Self-run
MCP Apache-2.0 3d ago

MCPwner

Model Context Protocol server for autonomous vulnerability discovery

netenv
0
3
Free
Self-run
MCP MIT yesterday

Ai Smart Contract Auditor

AuditSentry — AI-powered smart contract security auditor for Claude Code. Automated vulnerability detection, exploit PoCs, mainnet-fork simulation, and professional audit reports for Solidity & Vyper across all EVM chains.

Local-only
0
3
Free
Self-run
MCP Apache-2.0 24d ago

Sallyport

A Mac vault that runs authenticated actions for AI agents over MCP. The agent gets the operation, never the key: no command reveals a stored credential, and there is no export route.

netenv
0
3
Free
Self-run
MCP MIT 9d ago

Murmur

Murmur — encrypted agent-to-agent messaging bus for AI coding agents. MCP-native, E2E encrypted (XChaCha20-Poly1305), NATS transport with optional JetStream durability, cross-host and cross-org federation + A2A interop. Connect Claude Code, Codex and friends across machines.

net
0
14
Free
Self-run
SKILL MIT 4mo ago

Career Pivot Planner

Plan your career pivot step by step — map transferable skills, translate experience to a new industry, write transition narratives, and identify bridge credentials

Local-only
0
15
Free
Self-run
MCP Apache-2.0 10d ago

Pattern Vault

Extract, index, and retrieve reusable code patterns from any repository. Your personal pattern library, queryable by Agents or by you.

Local-only
0
14
Free
Self-run
MCP MIT 11d ago

Uc Mcp Proxy

An MCP Proxy built to use any Databricks MCP server in local coding agents with OAuth.

Local-only
0
13
Free
Self-run
SKILL MIT 1mo ago

Eo Project Init

eo-skills 在当前仓库的总入口:生成 .eo-project.json、初始化项目管理侧(roadmap/log/backlog)和代码侧最小骨架(eo-doc/),按需建 vault 软链和 agent 配置注入。触发:启动项目 / 初始化项目 / 新建项目 / /eo-project-init。

Local-only
0
13
Free
Self-run
SKILL MIT 14d ago

Apollo Operator

The four ways to run Apollo headless and how to choose: MCP (typed tools, results always through context), the apollo CLI binary (disk output, common filters), REST authenticated with the CLI's own OAuth token (full MCP filter surface WITH disk output, no API key), and REST with an API key. Includes measured context costs, credit costs per lane, verified command recipes, and the kill switch for s…

netfs
0
18
Free
Self-run
SKILL MIT 12d ago

Security

Secret detection and credential scanning using gitleaks. Use when scanning repositories for leaked secrets, API keys, passwords, tokens, or implementing pre-commit security checks.

env
0
20
Free
Self-run
SKILL Apache-2.0 1mo ago

Domain Dns Configurator

Use when planning DNS records, nameservers, A/AAAA/CNAME/TXT/MX, SPF/DKIM/DMARC, CDN, propagation, and rollback. Dry-run only; do not change production DNS or store provider credentials without explicit approval.

Local-only
0
20
Free
Self-run
SKILL Apache-2.0 1mo ago

Admin Ui Orchestrator

Use when a project needs admin/CMS/back-office UI architecture: roles, permissions, content workflows, AI assistant boundaries, audit logs, destructive-action confirmations, and builder handoff. Planning only; do not perform production admin actions or expose secrets.

Local-only
0
17
Free
Self-run
SKILL MIT 15d ago

Audit Security

Scan the codebase for code-level security vulnerabilities including hardcoded secrets, injection risks, missing auth checks, and insecure patterns, then produce a prioritized remediation plan.

shellenv
0
21
Free
Self-run
MCP MIT 14d ago

Connect It

Self-hosted connector gateway — hold your SaaS credentials once, and hand your agents a single MCP endpoint.

env
0
16
Free
Self-run
MCP Apache-2.0 15d ago

Yandex Direct Mcp

MCP server for Yandex Direct API: campaigns, ads, keywords, bids, reports. Click.ru proxy or direct OAuth with sandbox. Docs in Russian.

netenv
0
19
Free
Self-run
SKILL MIT 3mo ago

Security Auditor

Comprehensive security audit for VibeCoding sites. Triggers on "security check", "is my site secure", "API key exposed", "vulnerability", "security audit", "hacked", "password", "SSL", "HTTPS", "security headers", "XSS", "CSRF", "secrets", "data breach", ".env file", "privacy policy", "GDPR", "cookie consent". Scans for exposed API keys, dependency vulnerabilities, missing security headers, HTTPS…

env
0
19
Free
Self-run
MCP MIT 16d ago

Stackchan Cloud Mcp

Cloud MCP gateway that connects a StackChan desk robot to claude.ai — OAuth 2.1 bridge, reflex daemon, pixel avatar toolkit, and the field notes from making it work

net
0
18
Free
Self-run
MCP MIT 1mo ago

Cpe Skills

Comprehensive CPE (Common Platform Enumeration) toolkit — SKILLS, Go SDK, CLI & MCP integration for parsing, matching, generation, storage and NVD integration. ≥91% coverage, 108 platform binaries.

Local-only
0
25
Free
Self-run
SKILL MIT 18d ago

Prep Planner

Builds and updates interview prep weekly plans from profile schedule and vault status. Use when the user asks what to do today/tonight, replans the week, adjusts for work/weekend availability, catches up after slipping, or mentions THIS_WEEK / schedule / daily plan / time budget.

Local-only
0
24
Free
Self-run
SKILL MIT 19d ago

Datalad Credentials

>

Local-only
0
19
Free
Self-run
SKILL Apache-2.0 18d ago

Hermes Gateway Doctor

Use when Hermes messaging gateway failures must be diagnosed across process state, adapters, credential posture, logs, delivery evidence, polling conflicts, and service persistence without automatic repair.

Local-only
0
27
Free
Self-run
SKILL Apache-2.0 18d ago

Hermes Profile Audit

Use when a Hermes profile must be audited for role clarity, authority boundaries, configuration fit, skills, memory posture, credential scope, handoffs, and recurring operational failures.

Local-only
0
21
Free
Self-run
SKILL Apache-2.0 18d ago

Hermes Stack Doctor

Use when a top-level, read-only Hermes health audit is needed across installation, updates, gateways, cron, profiles, skills, repositories, credential posture, persistence, and cost signals.

Local-only
0
16
Free
Self-run
MCP MIT 19d ago

Exocortex Mcp

Remote MCP server for an exocortex vault — query your compiled knowledge and capture to its inbox from claude.ai, the Claude app, or any MCP client

netenv
0
32
Free
Self-run
MCP MIT 19d ago

Mcp Secret Sentinel

MCP server that scans code for exposed secrets - API keys, tokens, private keys and high-entropy strings - with placeholder-aware allowlisting and redacted reports

env
0
23
Free
Self-run
MCP MIT 1mo ago

Godig

🔌 CLI & MCP server for pkg.go.dev

Local-only
0
28
Free
Self-run
SKILL MIT 21d ago

Vault Gardener

Recurring maintenance pass for a second-brain vault — link hygiene, naming, metadata/tags, Inbox filing, dedupe, learnings-index sync, index-note freshness. Run daily as a scheduled agent (or weekly by hand). Keeps recall precise as the vault grows; without gardening, a knowledge vault decays into a junk drawer with a search bar. Use when asked to "garden the vault", "clean up the vault", or as t…

Local-only
0
27
Free
Self-run
MCP Apache-2.0 20d ago

Pacioli

Least-privilege governance for ERPNext — the credential floor + a governed agent front door, MCP · A2A, one spine. No debit without a credit: PLAN · CONSENT · PROVE · UNDO.

Local-only
0
28
Free
Self-run
SKILL MIT 21d ago

Pwnote Cve Research

Use whenever the user is doing vulnerability research aimed at a CVE/advisory — tracking a responsible disclosure timeline, drafting a vendor notification, requesting a CVE ID from MITRE or a CNA, writing a public security advisory, or mapping a finding to a CWE. Trigger on "CVE", "CNA", "MITRE", "advisory", "responsible disclosure", "vendor notification", "embargo", or "disclosure timeline", eve…

Local-only
0
18
Free
Self-run
SKILL MIT 21d ago

Pwnote Engagement File

Create or validate a pwnote engagement import/export JSON file. Use when the user wants to generate, edit, or verify a pwnote engagement file for data transfer between pwnote instances. The file bundles an entire pentest engagement — metadata, notebook documents, code/host/credential blocks, findings with CVSS/cwe/cve, attack-path boards, and activity history. Also use when the user asks how to s…

Local-only
0
25
Free
Self-run
SKILL MIT 21d ago

Pwnote Offsec Web300

Use whenever the user is working on Offsec's WEB-300 course/OSWE — whitebox source code review methodology, exploit chain documentation, PoC scripting, or OSWE exam report writing. Trigger on "OSWE", "WEB-300", "whitebox", "source code review" in a pentest context, or "exploit chain", even without the word "skill".

Local-only
0
28
Free
Self-run
SKILL Apache-2.0 20d ago

Pruna Api

Use before any Pruna or Replicate HTTP call — credentials, upload/poll/download, parallel batches, and agent safety.

Local-only
0
15
Free
Self-run
SKILL MIT 21d ago

Websearch Search

Run the lit-review orchestrator keyless agent-driven web search channel that uses WebSearch and WebFetch outputs normalized through websearch_ingest.py. Use when the user invokes the web search channel, asks for Stage 4d open-web literature discovery, or needs a Claude Code web-search fallback without SearchAPI, Gemini, or Undermind credentials.

shell
0
20
Free
Self-run
SKILL MIT 21d ago

Freesearch Search

Run the lit-review orchestrator free index search channel against keyless OpenAlex, Crossref, and Semantic Scholar keyword-search endpoints. Use when the user invokes the free search channel, asks for keyless scholarly index search, or needs Stage 4e fallback discovery without SearchAPI, Gemini, or Undermind credentials.

shell
0
19
Free
Self-run
SKILL MIT 24d ago

Setup Agent Team

Create a bounded manual execution packet for large AI-agent team workflows, or refuse/downgrade when the task should stay single-agent. Use when work is multi-domain, parallelizable, and context-heavy enough to need role selection, context packets, ownership boundaries, handoffs, budgets, verification, package-execution policy, and external-system credential policy before launching workers.

Local-only
0
29
Free
Self-run
SKILL Apache-2.0 21d ago

Personal Thought Vault

本地优先的个人思想库与个人生命操作系统。仅在用户明确提到“个人思想库”,或明确要求依据自己的历史原话、原则、案例与复盘来分析、收集、判同、照镜子、决策复盘、思想织网或辩论时使用。按人生根问题组织思想,严格区分用户证据、AI解释与外部来源。

Local-only
0
27
Free
Self-run
SKILL Apache-2.0 21d ago

Security Audit Lite

Perform a practical security review focused on auth, secrets, insecure defaults, injection risks, trust boundaries, privilege escalation, token handling, and sensitive data exposure. Use when a user asks for a lightweight security audit, AppSec review, or auth or secret-handling review.

Local-only
0
22
Free
Self-run
MCP MIT 23d ago

Pledgeguard

Rust-native secret scanner with MCP server, AST refinement, and WASM plugins

netenv
0
26
Free
Self-run
MCP MIT 21d ago

Lokalite

Local-first secrets manager for macOS. Encrypted vault, menu bar app, CLI, and an MCP server that loads secrets into your coding agent's shell instead of the chat. No cloud, no account, no subscription.

shellenv
0
21
Free
Self-run
SKILL MIT 5mo ago

Agent Rock

>

Local-only
0
14
Free
Self-run
SKILL MIT 5mo ago

Rock Quick

>

Local-only
0
13
Free
Self-run
SKILL MIT 5mo ago

Rock Deep

>

Local-only
0
12
Free
Self-run
SKILL MIT 5mo ago

Rock Deps

>

Local-only
0
14
Free
Self-run
SKILL MIT 5mo ago

Rock Diff

>

Local-only
0
13
Free
Self-run
SKILL MIT 21d ago

Public Code Review

Review the current diff or a specified set of files as public open-source code before publishing or merging. Use to check code quality, public-repository safety (secrets and private data), documentation trustworthiness, provenance, onboarding, and maintainability. Reports grouped findings; does not fix them unless asked.

Local-only
0
16
Free
Self-run
SKILL MIT 21d ago

Release Deploy

Prepare a public open-source project for release and deploy it to a detected target. Use at a release or submission boundary to verify setup, docs, secrets, tests, lint, build, and licenses, then follow the target-specific deployment path. Runs expensive checks sequentially. Never publishes, tags, commits, pushes, or deploys without explicit user intent.

env
0
13
Free
Self-run
MCP MIT 29d ago

Pentquiver

Fast cross-platform TUI/CLI/API/MCP command library and cheat-sheet launcher for pentesters - 2,800+ security commands, argument templates, hexagonal architecture.

net
0
29
Free
Self-run
SKILL MIT 24d ago

Novu Manage Subscribers

Create, update, search, and delete subscribers in Novu. Manage topics for group-based notification targeting. Set subscriber credentials for push and chat channels. Use when managing notification recipients, creating subscriber records, organizing subscribers into topics, or configuring channel-specific credentials.

env
0
28
Free
Self-run
SKILL MIT 1mo ago

Infostealer Malware Detector

Detects and removes infostealer malware (credential stealers, data exfiltrators) via full-system file search, cryptographic hashing, and public threat-intelligence cross-checks (VirusTotal, MalwareBazaar). Primary method is always custom hash-based detection. Windows Defender (or any platform-native AV) is allowed **only when necessary** (e.g. inconclusive hashes or deep remediation) and **must n…

netfs
0
29
Free
Self-run
MCP MIT 23d ago

Rapprise

Rust MCP server and CLI for Apprise notification fan-out across dozens of delivery backends, with stdio/HTTP transports, auth, and plugin packaging.

netenv
0
31
Free
Self-run
SKILL MIT 25d ago

Pentester

Skills of a penetration tester for finding exploitable vulnerabilities (API, authentication, multi-tenant isolation) before an attacker does. Trigger this skill for penetration testing, offensive security audits, or vulnerability exploitation within an authorized engagement.

Local-only
0
18
Free
Self-run
SKILL MIT 25d ago

Red Team

Red Team skills for simulating full, realistic attacks (beyond a simple technical pentest) including social engineering and persistence, to test the organization's overall resilience. Trigger this skill for advanced, multi-vector attack simulation exercises within a strictly authorized scope.

Local-only
0
27
Free
Self-run
SKILL MIT 25d ago

Purple Team

Purple Team skills for bridging offense (Red Team) and defense (Blue Team), turning every offensive test into a measurable defensive improvement. Trigger this skill to coordinate a joint red/blue exercise, improve detection rules after a pentest, or measure defensive coverage.

Local-only
0
26
Free
Self-run
SKILL MIT 23d ago

Capture

Drop a small, worth-keeping fact, decision, or preference into the vault's inbox in under 15 seconds — no schema, no index ceremony.

Local-only
0
25
Free
Self-run
SKILL MIT 23d ago

Write A Plan

Direct agent to create a plan and store it in the vault with an attached task.

Local-only
0
24
Free
Self-run
SKILL MIT 23d ago

Retrospect

Periodically review recent vault work — edits, the activity log, and feedback — and propose durable refinements: corrections to promote into SCHEMA.md, knowledge to capture, conventions to add or prune.

Local-only
0
30
Free
Self-run
SKILL MIT 23d ago

Pickup Task

Direct agent to execute a tracked task/plan from the vault, updating its status before and after the work.

Local-only
0
26
Free
Self-run
MCP MIT 1mo ago

Agsync

Agsync is a repo-native control plane for managing skills, MCP servers, secrets, and agent configs across AI clients like Claude Code and Cursor.

Local-only
0
20
Free
Self-run
SKILL MIT 23d ago

Icm Architect

Design any process, idea, problem, or body of knowledge into an ICM (Interpretable Context Methodology) workspace — folder structure as agent architecture — or restructure an existing folder, repo, or vault into one. Use when the user wants to (1) turn a recurring workflow into an agent-runnable folder pipeline, (2) organize scattered notes, files, or knowledge into a library one AI agent can wal…

Local-only
0
12
Free
Self-run
MCP MIT 1mo ago

Pip Boy

War. War never changes. But your dev tooling should. — Personal Vault-Tec approved Claude Code plugin marketplace.

Local-only
0
19
Free
Self-run
SKILL MIT 27d ago

Tool Review Gate

Review a proposed skill, plugin, MCP server, CLI, package, API, connector, application, or service before installation or use. Use when a new capability may execute code, access files or accounts, receive project data, require secrets, cost money, change configuration, or create external effects. Present a decision-ready approval card and wait for explicit, scoped user approval.

Local-only
0
19
Free
Self-run
SKILL MIT 28d ago

Autocommit

Operate the local auto-commit daemon for this vault. Use when the user wants to start, stop, restart, inspect, debug, or verify the auto-commit system, or asks about background git automation in this workspace.

Local-only
0
23
Free
Self-run
SKILL MIT 29d ago

Wordpress Content Manager

WordPress content management via REST API for managing posts. Requires Node.js and WordPress REST API credentials.

Local-only
0
23
Free
Self-run
SKILL MIT 26d ago

Nextjs Module

Structures a Next.js 16 App Router frontend feature as layered modules (lib/api typed fetchers, query-keys, TanStack Query hooks, React 19 pages) fed by one shared fetch client that sends the auth cookie with credentials include, attaches the tenant header, and normalizes errors. Use when scaffolding a new frontend feature or module, building a fetch/apiClient wrapper, wiring cookie-JWT calls to…

env
0
25
Free
Self-run
SKILL MIT 26d ago

Incident Response

Runs the response when something is live-broken or a secret is exposed — report first, contain the blast radius, fix the root cause through a reviewed change, then a blameless post-mortem that hardens the lesson into a standing rule. Use when a production endpoint is down or misbehaving, a key/token/credential may have leaked, an account or session looks compromised, a bad deploy is degrading use…

Local-only
0
23
Free
Self-run
SKILL MIT 26d ago

Security Review

Audits a diff for this stack's top risks — tenant isolation on every business queryset (fail-closed, no client-supplied tenant id trusted), RBAC on every custom endpoint and @action, PII leakage in list endpoints/logs/exports, file-upload validation (content-type, size, extension, private storage), and secrets not committed. Use when reviewing a Django/DRF change before merge, auditing a new View…

netenv
0
25
Free
Self-run
SKILL MIT 1mo ago

Load Context

Use at the start of /research and other workflow recipes to establish vault grounding. Loads vault bootstrap (profile.md), checks inbox, and pre-warms project context if a topic anchor is implied. Repo/git detection lands with /plan and /implement.

Local-only
0
31
Free
Self-run
SKILL MIT 1mo ago

Capture To Vault

Use during /research, /scope (or any recipe) to write or update a vault note via dossier-mcp. Agent drafts slug + frontmatter + body + citations, writes the note, and surfaces what was captured so the user can redirect afterward. Supports create (new note) and update (refine existing note) modes.

Local-only
0
20
Free
Self-run
SKILL MIT 1mo ago

Dispatch Exploration

Use during /research (or any recipe) to send 1-3 research queries in parallel — vault or web targets — and aggregate compressed findings. Routes each query to vault-researcher or web-researcher based on target. Hosts the cross-verify consent gate so any inline-research caller (/research, /design, /decompose) inherits source-bias mitigation without duplicating logic.

Local-only
0
19
Free
Self-run
MCP MIT 1mo ago

Mcp Auth Wrapper

🔐 Turn your stdio MCP server into a multi-user OAuth-authenticated remote MCP server

shell
0
21
Free
Self-run
SKILL MIT 26d ago

Factory Security Engineer

Use to threat-model a feature, audit AI-generated code, design sensitive-data handling, or review auth/authz boundaries. Carries the factory's security conventions — KMS encryption at rest, BAA verification for PHI, safe URL redirects, admin-client bypass guardrails, in-memory rate-limiter caveats, read-only-by-default for AI-generated code, mandatory review queue, request tracing, audit logging…

env
0
29
Free
Self-run
SKILL Apache-2.0 26d ago

Binary Credential Format Boundary

Audit and repair readers for fixed-length binary credentials and their text encodings without mutating raw bytes. Use when code loads Ed25519/X25519 keys, nonces, digests, MAC keys, signatures, tokens, or other opaque bytes from files or environment values; when `.strip()`, decoding, newline handling, or format auto-detection occurs before length/type validation; or when cryptographic tests fail…

Local-only
0
5
Free
Self-run
SKILL Apache-2.0 26d ago

Public Artifact Runtime Smoke Gate

Verify Python packages, CLIs, MCP servers, and Agent plugins through the exact installed artifact and real runtime contract. Use when source tests pass but a published release may omit modules, expose broken entry points, depend on local paths, fail without optional credentials, or behave differently after public installation.

shell
0
10
Free
Self-run
SKILL MIT 1mo ago

Vault Ask

Asks questions and gets synthesized answers grounded in vault history with source citations. Use when: (1) /vault-ask <question> to reason over vault knowledge, (2) user wants to know what their notes say about a topic, (3) user wants cross-project pattern analysis.

fs
0
22
Free
Self-run
SKILL MIT 1mo ago

Emerge

Surface unnamed patterns across vault notes. Use when: (1) /emerge for last 30 days, (2) /emerge 14d for custom window, (3) /emerge this week.

Local-only
0
22
Free
Self-run
SKILL MIT 1mo ago

System Recon

Collect a bounded, read-only system inventory for troubleshooting while identifying privilege gaps and avoiding secrets or invasive enumeration.

Local-only
0
17
Free
Self-run
SKILL MIT 1mo ago

Publish Ready

Prepare a repository for public release by removing development residue and dead paths, consolidating documentation, tightening generated-sounding prose, checking for secrets and local-machine references, and proving that surviving quickstarts and checks work. Use before open-sourcing, sharing, handing off, demonstrating, or releasing a project.

Local-only
0
21
Free
Self-run
SKILL MIT 26d ago

Quota Footer

Use when a reply should end with a concise Codex quota footer such as “额度:周 11%” or “额度:5h 29%|周 21%”. Reads local Codex OAuth auth.json, queries ChatGPT WHAM usage, and formats only the windows returned by the service unless details are requested.

Local-only
0
14
Free
Self-run
SKILL MIT 26d ago

Codex Backup Recovery

Create, validate, inspect, and restore a secret-free allowlisted backup of Codex, Claude Code, and shared Agent skills, memories, rules, commands, and automations. Use when a user wants a daily Agent workspace backup, a new-Mac migration rehearsal, disaster-recovery verification, or an audit of exactly what an Agent backup contains. Do not use as a full-disk backup or to copy credentials and logi…

Local-only
0
19
Free