Search
Security · Model Context Protocol
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Pass | CC0-1.0 | 2 days ago |
| 98 | 98.Oma Security Scan application source, agent skills, and MCP components; run penetration tests against scoped web test deployments, validate findings, and configure scan gates. | first-fluke/ | 1.3k | — | ~3.9k | Automated safety check: Pass | MIT | yesterday |
| 99 | 99.LLM Security LLM and AI application security testing skill for prompt injection (direct, indirect, multimodal), system-prompt extraction, RAG poisoning, memory poisoning, MCP server injection, skill-file… | hardw00t/ | 105 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 100 | Run Azure compliance and security audits with azqr plus Key Vault expiration checks. | microsoft/ | 255 | 2 repos | ~997 | Automated safety check: Pass | MIT | yesterday |
| 101 | 101.Sapui5 This skill should be used when developing SAP UI5 applications, including creating freestyle apps, Fiori Elements apps, custom controls, testing, data binding, OData integration, routing, and… | secondsky/ | 462 | — | ~4.1k | Automated safety check: Pass | GPL-3.0 | 5 days ago |
| 102 | 102.Work Entry point for any development task in this repo — feature, bugfix, refactor, cleanup, a new command, target or evaluator, a collector change. | guardana/ | 131 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 103 | 103.Evm Audit Flow A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint… | mtarcure/ | 165 | — | ~1.5k | Automated safety check: Pass | MIT | 20 days ago |
| 104 | 104.Hunt LLM AI Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). | elementalsouls/ | 4.8k | — | ~4k | Automated safety check: Warn | MIT | yesterday |
| 105 | Audit MCP (Model Context Protocol) server configurations for security issues. | github/ | 40k | — | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 106 | 106.Architecture Verter codebase architecture: high-level module map, TypeScript packages, plugin system, CSS analysis, MCP server, static analysis types | pikax/ | 113 | — | ~5.6k | Automated safety check: Pass | MIT | yesterday |
| 107 | Run osv-scanner via the mantisosvscanner MCP server for SCA (vulnerable dependency) findings | deonmenezes/ | 503 | — | ~298 | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 108 | Composite Phase-2 audit worker (ADR-150). An agent skill from ruvnet/ruflo. | ruvnet/ | 74k | — | ~720 | Automated safety check: Notes | MIT | yesterday |
| 109 | Weekly supply-chain hygiene scan (Perplexity Bumblebee). An agent skill from Szotasz/marveen. | Szotasz/ | 117 | — | ~2.1k | Automated safety check: Pass | MIT | yesterday |
| 110 | Security review of MCP (Model Context Protocol) server implementations and configurations. | OWASP/ | 188 | — | ~574 | Automated safety check: Pass | CC-BY-4.0 | 15 days ago |
| 111 | 111.Security Scan Run full security scans on the codebase using Ruflo security tools. | ruvnet/ | 74k | — | ~298 | Automated safety check: Pass | MIT | yesterday |
| 112 | 112.Security Review Use before committing changes to auth, workspace scoping, channel webhooks, AI tools/MCP, permission settings, or anything handling untrusted channel content in ChatbotX. | ChatbotXIO/ | 885 | — | ~1.8k | Automated safety check: Notes | Unknown | 2 days ago |
| 113 | 113.Safety Scan Scan inputs for prompt injection, unsafe content, and adversarial attacks using AIDefence. | ruvnet/ | 74k | — | ~409 | Automated safety check: Notes | MIT | yesterday |
| 114 | Review the implementation source code of MCP (Model Context Protocol) servers, clients, and tool handlers against a security baseline — authentication, sessions, rate limiting, input-schema… | github/ | 40k | — | ~5.2k | Automated safety check: Pass | MIT | 2 days ago |
| 115 | A skill your agent uses when an open-source developer tool, package, CLI, agent, or MCP server must be evaluated for legitimacy, supply-chain risk, telemetry, dangerous capabilities, claim accuracy… | asimons81/ | 126 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 116 | 116.Screenshot Burp Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 117 | 117.Create Policy Create OPA governance policies for Harness via MCP. An agent skill from harness/harness-skills. | harness/ | 115 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 118 | AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and… | modu-ai/ | 1.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 119 | 119.Cpg Analysis Deep code property graph analysis with Joern CPG (AST+CFG+PDG) and CodeQL for control flow, data flow, taint analysis, and security auditing | alinaqi/ | 707 | — | ~2k | Automated safety check: Pass | MIT | 17 days ago |
| 120 | 120.Aif Set up agent context for a project. An agent skill from unxed/f4. | unxed/ | 243 | — | ~8.4k | Automated safety check: Pass | BSD-3-Clause | yesterday |
| 121 | 121.Stack Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally… | guardana/ | 131 | — | ~568 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 122 | ANALYSIS SKILL — Azure compliance and security auditing: best practices, Key Vault expiration monitoring, resource validation. | jonathan-vella/ | 217 | — | ~1.6k | Automated safety check: Pass | MIT | yesterday |
| 123 | Find decision-makers at a specific company using Apollo, Crustdata, Fiber, and PDL people search via Gooseworks MCP. | gooseworks-ai/ | 1.2k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | 2 days ago |
| 124 | 124.Secrets Scan Run trufflehog via the mantistrufflehog MCP server and handle secret findings without ever exposing the raw secret | deonmenezes/ | 503 | — | ~347 | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 125 | 125.Polygraph Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills. | BankrBot/ | 1.2k | — | ~3.4k | Automated safety check: Pass | No licence | yesterday |
| 126 | Enterprise-review-grade threat model from harness threat-model {path}. | ruvnet/ | 74k | — | ~363 | Automated safety check: Notes | MIT | yesterday |
| 127 | 127.Pivot On Ioc Explore GTI relationships for an IOC to discover related entities. | dandye/ | 127 | — | ~690 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 128 | 128.Hunt Burp Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)… | Encod3d-Sec/ | 329 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 129 | 129.Hunt MCP MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. | Encod3d-Sec/ | 329 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 130 | 130.Wiki Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status. | Encod3d-Sec/ | 329 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 131 | 131.Security Audit Periodic security sweep of Atlas in four areas (MCP and CLI, the Tauri desktop shell, the web renderer and connectors, the supply chain and CI) that follows untrusted input to what it can reach… | wlsdks/ | 142 | — | ~182 | Automated safety check: Pass | MIT | yesterday |
| 132 | 132.Security Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries… | telagod/ | 244 | — | ~907 | Automated safety check: Pass | MIT | 2 mo ago |
| 133 | A skill your agent uses when closing a patch cycle with rigorous stress LAST on the Railway hub, bensbench x86 fieldbus → MQTTS, CSV/synth59/Creekside/gate 19, B100 Railway-only, light OWASP ZAP… | bbartling/ | 173 | — | ~1.2k | Automated safety check: Pass | Unknown | yesterday |
| 134 | 134.Security Pass Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth… | cyanheads/ | 158 | — | ~6.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 135 | Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 136 | 136.Checkpoint Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations. | automateyournetwork/ | 676 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 137 | 137.Debug Systematic diagnosis of a red test, a rule that fires or stays silent wrongly, a scan or probe whose artifact looks wrong, a collector error, a red CI run or a gate that is green for the wrong reason. | guardana/ | 131 | — | ~933 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 138 | Audit MCP (Model Context Protocol) server configurations for security issues. | boshi-xixixi/ | 276 | — | ~2.2k | Automated safety check: Pass | MIT | 5 mo ago |
| 139 | Read-only audit of MCP definition language across an existing surface — tools, resources, prompts, server instructions. | cyanheads/ | 158 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 140 | 140.Semgrep Triage Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle | deonmenezes/ | 503 | — | ~312 | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 141 | MCP gateway security patterns, token management, request validation, and audit logging for MCP communications | Hack23/ | 239 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 142 | Manage Google Security Operations (SecOps) SOAR cases throughout their lifecycle. | google/ | 21k | — | ~3.2k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 143 | 143.Spring AI Diagnose and operate Spring AI projects with version-aware Maven or Gradle checks for ChatClient, advisors, retrieval, conversation memory, tool/MCP boundaries, streaming, configuration, and… | magnus919/ | 115 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 144 | 144.Security Scan 使用 AgentShield 扫描 Claude Code 配置(.claude/ 目录)中的安全漏洞、配置错误和注入风险。检查 CLAUDE.md、settings.json、MCP 服务端、钩子(Hooks)和智能体(Agents)定义。 | xu-xiang/ | 2k | — | ~723 | Automated safety check: Pass | MIT | 7 mo ago |