Search
Security · Model Context Protocol
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure. | CyberStrategyInstitute/ | 147 | — | ~2.7k | Automated safety check: Pass | Unknown | yesterday |
| 50 | 50.Auto Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions. | guardana/ | 259 | — | ~945 | Automated safety check: Pass | Apache-2.0 | today |
| 51 | 51.Keel A skill your agent uses for ANY new software project from idea to release — websites, WordPress/WooCommerce plugins, MCP servers, web apps, components, or libraries. | joseconti/ | 190 | — | ~11k | Automated safety check: Warn | GPL-3.0-or-later | 2 mo ago |
| 52 | Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other. | index-login/ | 158 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 53 | Remediate security vulnerabilities found by Grype or pnpm audit. | stacklok/ | 171 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 54 | Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority. | tenuo-ai/ | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 55 | Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. | affaan-m/ | 277k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | today |
| 56 | Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed. | FlorianBruniaux/ | 6.1k | — | ~680 | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 57 | The Priority Board's three-layer score model (rules BASE, REVIEW by the built-in AI or an MCP agent, a person's DECISION) and who may write which layer. | samugit83/ | 3k | — | ~1.7k | Automated safety check: Pass | MIT | 2 days ago |
| 58 | Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 59 | Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. | iflytek/ | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 60 | 60.Docs Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass… | guardana/ | 259 | — | ~967 | Automated safety check: Pass | Apache-2.0 | today |
| 61 | Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. | getknit/ | 133 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | yesterday |
| 62 | Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs… | aws/ | 103 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 63 | OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation | jnMetaCode/ | 140 | — | ~644 | Automated safety check: Warn | Apache-2.0 | 12 days ago |
| 64 | Changing or adding a project setting / default value in RedAmon. | samugit83/ | 3k | — | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 65 | 65.Enrich Ioc Enrich an IOC (IP, domain, hash, URL) with threat intelligence. | dandye/ | 127 | — | ~702 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 66 | Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. | OWASP/ | 188 | — | ~542 | Automated safety check: Pass | CC-BY-4.0 | 15 days ago |
| 67 | Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys. | nanocoai/ | 31k | — | ~856 | Automated safety check: Pass | MIT | today |
| 68 | Hunt for the failure this project exists to prevent — code that compiles, types, tests green, and quietly reports "all clear" about something it never examined. | guardana/ | 259 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 69 | Turn a captured HTTP request/response into a bounded, redacted evidence pack with a stable request-ref using the mantishttpaudit MCP server, instead of pasting raw traffic into a finding | deonmenezes/ | 503 | — | ~455 | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 70 | 70.Vuln Hunter Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation. | dariushoule/ | 209 | — | ~3.9k | Automated safety check: Notes | MIT | 7 mo ago |
| 71 | 71.Gate Run this project's verification — the full local CI mirror (ruff, mypy, import contract, pytest with PostgreSQL, coverage floors, dogfood, generated docs and site, the isolated example suites, the… | guardana/ | 259 | — | ~757 | Automated safety check: Pass | Apache-2.0 | today |
| 72 | 72.Webcrypt MCP Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography. | putervision/ | 50 | — | ~847 | Automated safety check: Pass | MIT | 7 days ago |
| 73 | 73.Threat Model MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness. | ruvnet/ | 696 | — | ~637 | Automated safety check: Notes | MIT | yesterday |
| 74 | 74.Secure Agent Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules. | mathematic-inc/ | 113 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 75 | Reference vocabulary for interpreting vulnerability findings — detector-vs-impact distinction, severity anchoring on demonstrated evidence, the eleven-item interpretation rubric, delegation… | provos/ | 612 | — | ~6.3k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 76 | 减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。 | index-login/ | 158 | — | ~242 | Automated safety check: Pass | MIT | yesterday |
| 77 | 77.Plan Turn a development task into one work file in .work/ — goal, decisions, lanes with exact files and verification, done-criteria. | guardana/ | 259 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 78 | AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。 | affaan-m/ | 277k | 2 repos | ~796 | Automated safety check: Pass | MIT | today |
| 79 | Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates. | awarexone/ | 5.3k | — | ~1.9k | Automated safety check: Warn | MIT | yesterday |
| 80 | Use astgrepscan, sourcesinkscan, and smtcheckreachability (mantisprogramanalysis MCP server) to move a candidate toward a proven-reachable finding | deonmenezes/ | 503 | — | ~551 | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 81 | 81.Refactor Behaviour-preserving restructuring and cleanup — splitting an oversized module, removing dead code, finished scripts, flags or documents, consolidating duplicates, tightening comments. | guardana/ | 259 | — | ~786 | Automated safety check: Pass | Apache-2.0 | today |
| 82 | Black-box security audit of a DEPLOYED AI agent (not the MCP server behind it) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR… | awarexone/ | 5.3k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 83 | For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the… | lyonzin/ | 292 | — | ~2.3k | Automated safety check: Pass | MIT | yesterday |
| 84 | Security review: (1) vet an untrusted SKILL.md or .mcp.json BEFORE installing it — the injection/exfiltration scanner; CRITICAL blocks the install; (2) audit code on an untrusted-input path (a… | redhat-et/ | 2.4k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 85 | 85.Site Check Check the landing page and the generated documentation site (site/, guardana.dev) in a real browser — confirm a page renders after a docs change, review it at phone width, read the console and… | guardana/ | 259 | — | ~679 | Automated safety check: Pass | Apache-2.0 | today |
| 86 | 86.Bumblebee Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs. | sickn33/ | 47k | 1 repo | ~2.5k | Automated safety check: Notes | MIT | 2 days ago |
| 87 | Threat-model and find vulnerabilities, with practical remediation. | antonbabenko/ | 170 | — | ~1.1k | Automated safety check: Pass | MIT | 2 days ago |
| 88 | What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result | deonmenezes/ | 503 | — | ~376 | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 89 | 89.Ida Reverse Reverse engineer binaries with IDA Pro: decompilation, disassembly, data-flow tracking, cross-references, and IDA MCP automation for deep static analysis of PE/ELF/Mach-O targets. | sickn33/ | 47k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 90 | 90.JS Reverse Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output. | sickn33/ | 47k | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 2 days ago |
| 91 | Authorized OSINT and cyber threat intelligence: enriching IOCs, campaigns, impersonation, scams, and threat-actor profiles from public sources with defined boundaries. | sickn33/ | 47k | 1 repo | ~1.1k | Automated safety check: Pass | MIT | 2 days ago |
| 92 | Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. | wshobson/ | 40k | — | ~2.1k | Automated safety check: Pass | MIT | 6 days ago |
| 93 | Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. | wshobson/ | 40k | — | ~2.5k | Automated safety check: Pass | MIT | 6 days ago |
| 94 | Review Maple security across authentication, account isolation, local persistence, Tauri IPC and capabilities, OAuth and deep links, the Local OpenAI Proxy, Agent Mode tools and permissions, MCP… | MaplePrivacyLabs/ | 102 | — | ~7.1k | Automated safety check: Pass | MIT | yesterday |
| 95 | Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP… | trilwu/ | 157 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 96 | 96.Codeql Audit Build a CodeQL database and run dataflow-backed query-suite analysis via the mantiscodeql MCP server | deonmenezes/ | 503 | — | ~325 | Automated safety check: Pass | Apache-2.0 | 7 days ago |