Search
Security · Model Context Protocol
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT. | NVIDIA/ | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 2 | A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK. | vulnersCom/ | 376 | — | ~2.3k | Automated safety check: Pass | MIT | 11 days ago |
| 3 | Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK. | kubeshark/ | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 4 | Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service. | wuyoscar/ | 641 | — | ~1.4k | Automated safety check: Pass | Unknown | today |
| 5 | Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities. | context-labs/ | 1.1k | 2 repos | ~3k | Automated safety check: Pass | MIT | 4 days ago |
| 6 | Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 188 | — | ~2.5k | Automated safety check: Notes | Unknown | 12 days ago |
| 7 | Run HOL Guard scanner and guard operations via uv run hol-guard. | hashgraph-online/ | 827 | — | ~542 | Automated safety check: Pass | Apache-2.0 | today |
| 8 | Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and… | activepieces/ | 25k | — | ~2.9k | Automated safety check: Pass | Unknown | today |
| 9 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 424 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 10 | Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. | PrefectHQ/ | 28k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 11 | 11.Rsigma Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. | timescale/ | 162 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 12 | Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in… | samugit83/ | 3k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 13 | Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity. | activepieces/ | 25k | — | ~3.6k | Automated safety check: Pass | Unknown | today |
| 14 | Installs, tunes and enforces Sponsio contracts that block unsafe tool calls in LLM agents, covering setup, auditing, observe mode and flipping to enforce. | SponsioLabs/ | 454 | — | ~12k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 15 | A skill your agent uses when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string… | kernullist/ | 162 | — | ~3.7k | Automated safety check: Pass | MIT | 3 mo ago |
| 16 | 16.Solodit Search Solodit for similar smart contract security findings. | marchev/ | 159 | — | ~832 | Automated safety check: Pass | MIT | 5 mo ago |
| 17 | 17.Burp Scan Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs. | six2dez/ | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | yesterday |
| 18 | 18.Setup Install or initialize HOL Guard local runtime protection for Claude Code. | hashgraph-online/ | 827 | — | ~443 | Automated safety check: Pass | Apache-2.0 | today |
| 19 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 20 | Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. | ktnyt/ | 675 | — | ~565 | Automated safety check: Pass | MIT | 7 mo ago |
| 21 | Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers. | CyberStrategyInstitute/ | 146 | — | ~1.2k | Automated safety check: Pass | Unknown | today |
| 22 | 按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's… | jnMetaCode/ | 140 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 23 | 23.Sail Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. | pillar-labs/ | 113 | — | ~5.1k | Automated safety check: Pass | Unknown | 3 mo ago |
| 24 | Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision. | pegasi-ai/ | 392 | — | ~1.4k | Automated safety check: Warn | Apache-2.0 | 4 mo ago |
| 25 | Add or retrofit Tenuo authorization for AI-agent tools and effects. | tenuo-ai/ | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 26 | Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2… | provos/ | 612 | — | ~5.7k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 27 | Deep web-research methodology for the interceptor browser surface — investigate a topic the way researchers, intelligence analysts, investigative journalists, private investigators, and OSINT… | Hacker-Valley-Media/ | 519 | — | ~3.8k | Automated safety check: Pass | Unknown | 7 days ago |
| 28 | 用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF… | index-login/ | 144 | — | ~3k | Automated safety check: Pass | MIT | 9 days ago |
| 29 | Automate low-impact web vulnerability verification through Burp MCP. | langbyyi/ | 135 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 30 | A skill your agent uses when a user provides a TikTok profile or account link and asks for account analysis, competitor research, content or commerce performance, operational-logic research… | aronhy/ | 167 | — | ~492 | Automated safety check: Pass | MIT | 2 mo ago |
| 31 | A skill your agent uses when working with the DecompilerServer MCP server to inspect, search, decompile, analyze, or compare .NET assemblies, especially foreign code such as Unity/RimWorld… | pardeike/ | 106 | — | ~1.5k | Automated safety check: Pass | MIT | 8 days ago |
| 32 | 32.Status Check HOL Guard local protection status for Claude Code without changing configuration. | hashgraph-online/ | 827 | — | ~231 | Automated safety check: Pass | Apache-2.0 | today |
| 33 | Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry. | samugit83/ | 3k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 34 | 34.Ship Commit and push a finished change the way this repo requires — explicit paths, one commit per logical change, no attribution, the five documentation places answered, the site checks before a push (a… | guardana/ | 130 | — | ~838 | Automated safety check: Notes | Apache-2.0 | yesterday |
| 35 | Debug and emulate specific code fragments or functions using the Unicorn engine. | index-login/ | 144 | — | ~1.9k | Automated safety check: Pass | MIT | 9 days ago |
| 36 | Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. | hardw00t/ | 104 | — | ~2.2k | Automated safety check: Pass | No licence | 5 mo ago |
| 37 | Runs trace-mcp security, quality-gate and antipattern checks before a commit or pull request, and builds a symbol-level diff for the PR description. | nikolai-vysotskyi/ | 188 | — | ~565 | Automated safety check: Pass | MIT | today |
| 38 | 38.Deobf String Decrypt and recover obfuscated strings from binaries by analyzing encryption patterns and generating decryption scripts | P4nda0s/ | 140 | — | ~876 | Automated safety check: Pass | No licence | 4 mo ago |
| 39 | Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence. | zhaoxuya520/ | 40k | 1 repo | ~1k | Automated safety check: Pass | MIT | 17 days ago |
| 40 | 40.Mod Any Game Mod a PC game the user owns, taking an idea to working in the real game and recorded. | rehan-remade/ | 5.8k | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 41 | Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token. | samugit83/ | 3k | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 42 | Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows. | hashgraph-online/ | 827 | — | ~605 | Automated safety check: Pass | Apache-2.0 | today |
| 43 | Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP. | Encod3d-Sec/ | 329 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 44 | 44.Earl A skill your agent uses when you need to call an API, run a database query, or execute a shell command via Earl. | mathematic-inc/ | 113 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 45 | SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. | secondsky/ | 462 | — | ~5.9k | Automated safety check: Warn | GPL-3.0 | 4 days ago |
| 46 | Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure. | CyberStrategyInstitute/ | 146 | — | ~2.7k | Automated safety check: Pass | Unknown | today |
| 47 | 47.Keel A skill your agent uses for ANY new software project from idea to release — websites, WordPress/WooCommerce plugins, MCP servers, web apps, components, or libraries. | joseconti/ | 190 | — | ~11k | Automated safety check: Warn | GPL-3.0-or-later | 2 mo ago |
| 48 | 48.Add A Rule Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation… | guardana/ | 130 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |