Security
7,261 rows, by stacks then stars
772 of these skill files have been read, by 666 distinct authors, and what they tell an agent counted. What Security authors agree on, and what they forbid
KN0WBOT/clavis-mcp/io.github.KN0WBOT/clavis MCP server
0★ repoEncrypted credential vault for AI agents — auto OAuth refresh, rate limiting, audit logging.
Kurok1/mcp-server-mysql/io.github.Kurok1/mcp-server-mysql MCP server
0★ repoSecurity-first MySQL MCP server: AST-validated SQL (fail-closed), default-deny whitelist, audit.
NeuraLegion/mcp/io.github.NeuraLegion/mcp MCP server
no license0★ repoAI-powered application security testing — scan APIs, discover endpoints, and find vulnerabilities.
RobotFleet-HQ/security-orchestra/io.github.RobotFleet-HQ/security-orchestra MCP server
no license0★ repoMulti-agent MCP platform for data centers and critical power.
Siddharth-coder13/secure_schema_mcp/io.github.Siddharth-coder13/secure-schema MCP server
0★ repoRead-only MCP server for exposing database schema metadata without row data.
Tyox-all/Weave_Protocol/io.github.Tyox-all/mund MCP server
0★ repoScan for prompt injection, secrets, PII, and vet MCP servers before installation
Varpost/Scout/io.github.Varpost/scout MCP server
no license0★ repoDeterministic, zero-token security scanner your AI agent calls to find and re-verify issues.
apilocker/apilocker/io.github.apilocker/apilocker MCP server
0★ repoEncrypted credential vault: LLM, service & OAuth keys. 21-tool MCP server for your AI agent.
bch1212/agentvault/io.github.bch1212/agentvault MCP server
0★ repoCredential vault for AI agents — Fernet-encrypted keys, per-agent budgets, audit logs.
ciinkwia/lithium-vault-mcp/io.github.ciinkwia/lithium-vault-mcp MCP server
0★ repoPrimary-source lithium & battery-metals mining data (AISC, reserves, filings) via x402.
denial-web/agent-immune/io.github.denial-web/agent-immune MCP server
0★ repoAI agent security: prompt injection detection, semantic memory, output scanning, prompt hardening
dewtech-technologies/tubemind-secure-mcp/io.github.dewtech-technologies/tubemind-secure-mcp MCP server
0★ repoSecure MCP server for YouTube intelligence — 18 tools, OAuth2, OWASP Top 10 controls.
dewtech-technologies/obsidian-mcp-secure/io.github.dewtech-technologies/obsidian-mcp-secure MCP server
no license0★ repoSecure MCP server for Obsidian with OWASP Top 10 controls and full audit logging.
eason4kim-rocket/purify-feeds-mcp/io.github.eason4kim-rocket/purify-feeds-mcp MCP server
0★ repoQuery CISA KEV / EPSS vulnerability feeds with full per-record provenance and auditable versions
ericm1018/skillfm-byok-vault-mcp/io.github.ericm1018/skillfm-byok-vault-api-key-provider-usage MCP server
0★ repoBYOK vault, provider API key guidance, usage visibility, and SkillFM Beacon checks for MCP agents.
fino-oss/contract-scanner-mcp/io.github.fino-oss/contract-scanner MCP server
no license0★ repoScans Base L2 smart contracts for security risks. Risk score 0-100, detects backdoors & proxies.
frogeye-ai/mcp/io.github.frogeye-ai/mcp MCP server
no license0★ repoZero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
mastrophot/near-mcp-contract-security/io.github.mastrophot/contract-security-scanner MCP server
0★ repoMCP smart contract scanner with NEAR-focused security context.
SBOMApp - SBOM Generator & Vulnerability Scanner
mcpsbom/sbomapp-mcp-server/io.github.mcpsbom/sbom-mcp MCP server
no license0★ repoGenerate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
mdfifty50-boop/agent-security-mcp/io.github.mdfifty50-boop/agent-security MCP server
no license0★ repoSecurity scanning and threat detection for AI agents
mdfifty50-boop/secure-vault-mcp/io.github.mdfifty50-boop/secure-vault MCP server
no license0★ repoEncrypted secrets and credential management for agents
middleBrick/mcp-server/io.github.middleBrick/mcp-server MCP server
0★ repoScan APIs for OWASP Top 10, LLM, and GraphQL security vulnerabilities.
RelayShield Security Intelligence
relayshield/relayshield-mcp/io.github.nzdsf2-gif/relayshield-mcp MCP server
no license0★ repoBreach, SIM swap, infostealer, domain lookalikes, MCP registry risk, prompt-injection detection.
onetrueclaude-creator/hebbian-vault/io.github.onetrueclaude-creator/hebbian-vault MCP server
0★ repoUsage-adaptive Obsidian vault search: Hebbian + PageRank + BM25 hybrid ranking.
onetrueclaude-creator/vault-health-mcp/io.github.onetrueclaude-creator/vault-health-mcp MCP server
0★ repoObsidian vault structural health: broken links, orphans, missing frontmatter, safe auto-repair.
pipeworx-io/mcp-owasp/io.github.pipeworx-io/owasp MCP server
0★ repoOWASP MCP — keyless.
pipeworx-io/mcp-security-feeds/io.github.pipeworx-io/security-feeds MCP server
0★ repoSecurity Feeds MCP.
AgentSecurityLens MCP Security Trust Check
professor2k8/agent-security-lens/io.github.professor2k8/agent-security-lens MCP server
no license0★ repoMCP security trust-check for agents before installing MCPs, Skills or tools.
secureprivacy/secure-privacy-mcp/io.github.secureprivacy/secure-privacy-mcp MCP server
no license0★ repoAn MCP server that automatically integrate GDPR-compliant cookie consent banners into websites
selflabbs/security-intel-mcp/io.github.selflabbs/security-intel-mcp MCP server
0★ repoCVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Google Workspace Admin Security-Audit MCP
shigechika/gwsadm-mcp/io.github.shigechika/gwsadm-mcp MCP server
0★ repoMCP server for Google Workspace security auditing — login audit, external sharing, daily brief
AgentGuard — security checks for AI agents
shuaicongxiaomai/agentguard/io.github.shuaicongxiaomai/agentguard MCP server
0★ repoSecret, CVE and dependency-vulnerability scanning for AI agents (free, OSV.dev).
srotzin/hive-mcp-vault/io.github.srotzin/hive-mcp-vault MCP server
0★ repoA2A ZK wallet recovery — guardian swarm, no seed phrase, HiveLaw enforcement
weiseer/cve-cache-mcp/io.github.weiseer/cve-cache MCP server
no license0★ repoRecent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go).
wyre-technology/abnormal-mcp/io.github.wyre-technology/abnormal-mcp MCP server
0★ repoMCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.
romans-repos/elsas-verify/it.elsas/security-intel MCP server
0★ repoDaily Ed25519-signed security intelligence for AI-agent stacks; CVEs & advisories, paid via x402.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/007 Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
zebbern/claude-code-guide/skills/active-directory-attacks Skill
4,568★ repoClaude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks go from beginner to power user!
SnailSploit/Claude-Red/Skills/ai/offensive-ai-security Skill
2,895★ repoclaude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/plugins/cis-controls/skills/cis-controls Skill
814★ repoClaude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO 27701, DORA, CSRD, India's DPDPA, CMMC 2.0, NIST AI Risk, SWIFT, Australia's ISM, EU NIS2, CCPA/CPRA, and others. Benchmark 97% (with skills) vs 81% (without skills).
Eyadkelleh/awesome-skills-security/skills/security-fuzzing Skill
no license353★ repoSecurity testing toolkit for AI Agent: curated SecLists wordlists, injection payloads, and expert agents for authorized pentesting, CTFs, and bug bounties
Masriyan/Claude-Code-CyberSecurity-Skill/skills/02-vulnerability-scanner Skill
303★ repoA comprehensive collection of 15 Claude Code Skills for cybersecurity professionals ,covering offensive security, defensive operations, reverse engineering, threat hunting, CSOC automation, and more
kklimuk/docx-cli/.claude/skills/security-review Skill
178★ repoCLI for AI agents (Claude, Codex) to read, edit, and comment on .docx files with full format fidelity.
wiz-sec-public/SITF/.claude/skills/red-team-flow Skill
no license177★ repoA comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.
alexgreensh/repo-forensics/plugins/repo-forensics/skills/repo-forensics Skill
no license153★ repoOffline security scanner for AI-agent repos, skills, plugins, and MCP servers.
iammm0/secbot/skills/base/nmap-usage Skill
no license74★ repoAuthorized security testing workspace. v2 TypeScript terminal product on release; v1 Python on pypi-release; Go branch is demo only.
genli-ai/market-research-skills/skills/local-vault Skill
59★ repoTurn Claude into a disciplined research analyst — verify facts against primary sources, brief any topic, draft flagship reports. Standalone or chained; runs across LLM terminals. | 把 Claude 变成讲纪律的研究分析师:核实事实、主题简报、旗舰研报,引用一手来源、绝不造数;可单用或串联,跨 LLM 终端。
ComeOnOliver/skillshub/skills/0xlayerghost/solidity-agent-kit/defi-security Skill
59★ repo🧠 The right skill, one API call. AI agent skills registry with token-efficient skill resolution. 5,000+ skills from 500+ top repos.
tody-agent/codymaster/.agent/skills/xss-html-injection Skill
no license49★ repoVibe Coding Framework - Full SaaS Development Team from A-Z with Brain, Self Improvement, Auto Development
UnitOneAI/SecuritySkills/roles/cloud-security-engineer Skill
49★ repoOpen-source security skills for AI coding agents. Grounded in OWASP, NIST, MITRE ATT&CK, CIS. Works with Claude Code, Gemini CLI, Cursor, Codex CLI, OpenClaw, Kiro.
Zulut30/Wordpress-skills/.cursor/skills/wordpress-plugin-dev Skill
42★ repoProfessional Agent Skill for building, auditing, testing, and releasing modern WordPress plugins with Codex, Cursor, and Claude Code.
servosity/msp-skills/io.github.Servosity/abnormal-mcp MCP server
no license24★ repoAbnormal Security email threats, cases, and reporting in your terminal and your AI agents.
Orizon-eu/claude-code-pentest/attack-path-architect Skill
22★ repo6 Claude Code skills that automate the entire pentest lifecycle. From recon to exploit chains to bug bounty reports — just give it a domain. 43 scripts, zero dependencies, pure Python.
scholarly360/owasp-top10-web-skills/skills/broken-access-control Skill
20★ repoAgent Skills for OWASP Top 10 Application Security Risks (https://owasp.org/Top10/2025/)
alpha-omega-security/threat-model/skills/threat-model-backtest Skill
18★ repoAgent skill for producing threat models for open-source projects
ShieldNet-360/secure-vibe/dist/agent-skills/.agents/skills/auth-security Skill
15★ repoSecureVibe — prevention-first security for AI-written code. Signed SKILL.md knowledge that makes AI coding assistants write secure code at generation time, plus a deterministic CI gate. Offline · keyless · Ed25519-signed. By ShieldNet360.
Postman-Devrel/agent-skills/skills/postman Skill
15★ repoPostman Agent Skills for AI coding agents. Sync collections, generate code, run tests, create mocks, publish docs, audit security, and analyze API readiness.
kdr/overcast/skills/overcast-attack-surface Skill
12★ repoVideo OSINT agent: senses + OSINT reach for any agent.
runkids/my-skills/devops/docker-expert Skill
no license12★ repoMy AI agent skills — managed with skillshare
harnessprotocol/harness-kit/plugins/dependabot-sweep/skills/dependabot-sweep Skill
9★ repoYour plugins, skills, MCP servers, hooks, conventions, and governance packaged into a single config