Search
Security · Model Context Protocol · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT. | NVIDIA/ | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 2 | A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK. | vulnersCom/ | 376 | — | ~2.3k | Automated safety check: Pass | MIT | 11 days ago |
| 3 | Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service. | wuyoscar/ | 641 | — | ~1.4k | Automated safety check: Pass | Unknown | today |
| 4 | Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities. | context-labs/ | 1.1k | 2 repos | ~3k | Automated safety check: Pass | MIT | 4 days ago |
| 5 | Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 188 | — | ~2.5k | Automated safety check: Notes | Unknown | 12 days ago |
| 6 | Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and… | activepieces/ | 25k | — | ~2.9k | Automated safety check: Pass | Unknown | today |
| 7 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 424 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 8 | Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. | PrefectHQ/ | 28k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 9 | 9.Rsigma Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. | timescale/ | 162 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 10 | Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in… | samugit83/ | 3k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 11 | Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity. | activepieces/ | 25k | — | ~3.6k | Automated safety check: Pass | Unknown | today |
| 12 | Installs, tunes and enforces Sponsio contracts that block unsafe tool calls in LLM agents, covering setup, auditing, observe mode and flipping to enforce. | SponsioLabs/ | 454 | — | ~12k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 13 | A skill your agent uses when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string… | kernullist/ | 162 | — | ~3.7k | Automated safety check: Pass | MIT | 3 mo ago |
| 14 | 14.Burp Scan Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs. | six2dez/ | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | yesterday |
| 15 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 16 | Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers. | CyberStrategyInstitute/ | 146 | — | ~1.2k | Automated safety check: Pass | Unknown | today |
| 17 | 按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's… | jnMetaCode/ | 140 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 11 days ago |
| 18 | Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision. | pegasi-ai/ | 392 | — | ~1.4k | Automated safety check: Warn | Apache-2.0 | 4 mo ago |
| 19 | Add or retrofit Tenuo authorization for AI-agent tools and effects. | tenuo-ai/ | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 20 | Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2… | provos/ | 612 | — | ~5.7k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 21 | 用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF… | index-login/ | 144 | — | ~3k | Automated safety check: Pass | MIT | 9 days ago |
| 22 | Automate low-impact web vulnerability verification through Burp MCP. | langbyyi/ | 135 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 23 | A skill your agent uses when a user provides a TikTok profile or account link and asks for account analysis, competitor research, content or commerce performance, operational-logic research… | aronhy/ | 167 | — | ~492 | Automated safety check: Pass | MIT | 2 mo ago |
| 24 | A skill your agent uses when working with the DecompilerServer MCP server to inspect, search, decompile, analyze, or compare .NET assemblies, especially foreign code such as Unity/RimWorld… | pardeike/ | 106 | — | ~1.5k | Automated safety check: Pass | MIT | 8 days ago |
| 25 | Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry. | samugit83/ | 3k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 26 | Debug and emulate specific code fragments or functions using the Unicorn engine. | index-login/ | 144 | — | ~1.9k | Automated safety check: Pass | MIT | 9 days ago |
| 27 | Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. | hardw00t/ | 104 | — | ~2.2k | Automated safety check: Pass | No licence | 5 mo ago |
| 28 | Runs trace-mcp security, quality-gate and antipattern checks before a commit or pull request, and builds a symbol-level diff for the PR description. | nikolai-vysotskyi/ | 188 | — | ~565 | Automated safety check: Pass | MIT | today |
| 29 | Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token. | samugit83/ | 3k | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 30 | Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows. | hashgraph-online/ | 827 | — | ~605 | Automated safety check: Pass | Apache-2.0 | today |
| 31 | Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP. | Encod3d-Sec/ | 329 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 32 | 32.Earl A skill your agent uses when you need to call an API, run a database query, or execute a shell command via Earl. | mathematic-inc/ | 113 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 33 | SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. | secondsky/ | 462 | — | ~5.9k | Automated safety check: Warn | GPL-3.0 | 4 days ago |
| 34 | Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure. | CyberStrategyInstitute/ | 146 | — | ~2.7k | Automated safety check: Pass | Unknown | today |
| 35 | 35.Keel A skill your agent uses for ANY new software project from idea to release — websites, WordPress/WooCommerce plugins, MCP servers, web apps, components, or libraries. | joseconti/ | 190 | — | ~11k | Automated safety check: Warn | GPL-3.0-or-later | 2 mo ago |
| 36 | 36.Add A Rule Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation… | guardana/ | 130 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 37 | Remediate security vulnerabilities found by Grype or pnpm audit. | stacklok/ | 170 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | today |
| 38 | Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other. | index-login/ | 144 | — | ~1.9k | Automated safety check: Pass | MIT | 9 days ago |
| 39 | Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority. | tenuo-ai/ | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 40 | Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. | affaan-m/ | 276k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | 4 days ago |
| 41 | Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed. | FlorianBruniaux/ | 6.1k | — | ~680 | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 42 | The Priority Board's three-layer score model (rules BASE, REVIEW by the built-in AI or an MCP agent, a person's DECISION) and who may write which layer. | samugit83/ | 3k | — | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 43 | Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. | iflytek/ | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | today |
| 44 | Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. | getknit/ | 132 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 5 days ago |
| 45 | 45.Auto Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions. | guardana/ | 130 | — | ~788 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 46 | Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs… | aws/ | 102 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 47 | OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation | jnMetaCode/ | 140 | — | ~644 | Automated safety check: Warn | Apache-2.0 | 11 days ago |
| 48 | Changing or adding a project setting / default value in RedAmon. | samugit83/ | 3k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |