Search
Security · Model Context Protocol · For devops and sre engineers
- Security (remove filter)
- Model Context Protocol (remove filter)
- For devops and sre engineers (remove filter)
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK. | kubeshark/ | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 2 | Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 188 | — | ~2.5k | Automated safety check: Notes | Unknown | 12 days ago |
| 3 | Run HOL Guard scanner and guard operations via uv run hol-guard. | hashgraph-online/ | 827 | — | ~542 | Automated safety check: Pass | Apache-2.0 | today |
| 4 | 4.Setup Install or initialize HOL Guard local runtime protection for Claude Code. | hashgraph-online/ | 827 | — | ~443 | Automated safety check: Pass | Apache-2.0 | today |
| 5 | Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. | ktnyt/ | 675 | — | ~565 | Automated safety check: Pass | MIT | 7 mo ago |
| 6 | 6.Status Check HOL Guard local protection status for Claude Code without changing configuration. | hashgraph-online/ | 827 | — | ~231 | Automated safety check: Pass | Apache-2.0 | today |
| 7 | 7.Ship Commit and push a finished change the way this repo requires — explicit paths, one commit per logical change, no attribution, the five documentation places answered, the site checks before a push (a… | guardana/ | 130 | — | ~838 | Automated safety check: Notes | Apache-2.0 | yesterday |
| 8 | Decrypt and recover obfuscated strings from binaries by analyzing encryption patterns and generating decryption scripts | P4nda0s/ | 140 | — | ~876 | Automated safety check: Pass | No licence | 4 mo ago |
| 9 | Mod a PC game the user owns, taking an idea to working in the real game and recorded. | rehan-remade/ | 5.8k | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 10 | Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. | iflytek/ | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | today |
| 12 | Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. | getknit/ | 132 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 5 days ago |
| 13 | Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs… | aws/ | 102 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 14 | OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation | jnMetaCode/ | 140 | — | ~644 | Automated safety check: Warn | Apache-2.0 | 11 days ago |
| 15 | Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. | OWASP/ | 187 | — | ~542 | Automated safety check: Pass | CC-BY-4.0 | 14 days ago |
| 16 | 16.Webcrypt MCP Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography. | putervision/ | 114 | — | ~847 | Automated safety check: Pass | MIT | 6 days ago |
| 17 | 17.Vuln Hunter Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation. | dariushoule/ | 209 | — | ~3.9k | Automated safety check: Notes | MIT | 7 mo ago |
| 18 | Hunt for the failure this project exists to prevent — code that compiles, types, tests green, and quietly reports "all clear" about something it never examined. | guardana/ | 130 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 19 | Use astgrepscan, sourcesinkscan, and smtcheckreachability (mantisprogramanalysis MCP server) to move a candidate toward a proven-reachable finding | deonmenezes/ | 504 | — | ~551 | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 20 | 20.Plan Turn a development task into one work file in .work/ — goal, decisions, lanes with exact files and verification, done-criteria. | guardana/ | 130 | — | ~1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 21 | For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the… | lyonzin/ | 292 | — | ~2.3k | Automated safety check: Pass | MIT | 5 days ago |
| 22 | Security review: (1) vet an untrusted SKILL.md or .mcp.json BEFORE installing it — the injection/exfiltration scanner; CRITICAL blocks the install; (2) audit code on an untrusted-input path (a… | redhat-et/ | 2.4k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | today |
| 23 | Threat-model and find vulnerabilities, with practical remediation. | antonbabenko/ | 170 | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 24 | What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result | deonmenezes/ | 504 | — | ~376 | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 25 | 25.Ida Reverse Reverse engineer binaries with IDA Pro: decompilation, disassembly, data-flow tracking, cross-references, and IDA MCP automation for deep static analysis of PE/ELF/Mach-O targets. | sickn33/ | 47k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | today |
| 26 | Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. | wshobson/ | 40k | — | ~2.5k | Automated safety check: Pass | MIT | 5 days ago |
| 27 | 27.Codeql Audit Build a CodeQL database and run dataflow-backed query-suite analysis via the mantiscodeql MCP server | deonmenezes/ | 504 | — | ~325 | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 28 | Run Azure compliance and security audits with azqr plus Key Vault expiration checks. | microsoft/ | 255 | 2 repos | ~997 | Automated safety check: Pass | MIT | today |
| 29 | Run osv-scanner via the mantisosvscanner MCP server for SCA (vulnerable dependency) findings | deonmenezes/ | 504 | — | ~298 | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 30 | 30.Stack Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally… | guardana/ | 130 | — | ~568 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 31 | Run full security scans on the codebase using Ruflo security tools. | ruvnet/ | 74k | — | ~298 | Automated safety check: Pass | MIT | today |
| 32 | 32.Safety Scan Scan inputs for prompt injection, unsafe content, and adversarial attacks using AIDefence. | ruvnet/ | 74k | — | ~409 | Automated safety check: Notes | MIT | today |
| 33 | Create OPA governance policies for Harness via MCP. An agent skill from harness/harness-skills. | harness/ | 115 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 34 | 34.Cpg Analysis Deep code property graph analysis with Joern CPG (AST+CFG+PDG) and CodeQL for control flow, data flow, taint analysis, and security auditing | alinaqi/ | 707 | — | ~2k | Automated safety check: Pass | MIT | 15 days ago |
| 35 | ANALYSIS SKILL — Azure compliance and security auditing: best practices, Key Vault expiration monitoring, resource validation. | jonathan-vella/ | 217 | — | ~1.6k | Automated safety check: Pass | MIT | yesterday |
| 36 | 36.Secrets Scan Run trufflehog via the mantistrufflehog MCP server and handle secret findings without ever exposing the raw secret | deonmenezes/ | 504 | — | ~347 | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 37 | Enterprise-review-grade threat model from harness threat-model <path. | ruvnet/ | 74k | — | ~363 | Automated safety check: Notes | MIT | today |
| 38 | 38.Pivot On Ioc Explore GTI relationships for an IOC to discover related entities. | dandye/ | 127 | — | ~690 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | 39.Hunt MCP MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. | Encod3d-Sec/ | 329 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 40 | 40.Wiki Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status. | Encod3d-Sec/ | 329 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 41 | Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth… | cyanheads/ | 156 | — | ~6.4k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 42 | 42.Work Entry point for any development task in this repo — feature, bugfix, refactor, cleanup, a new command, target or evaluator, a collector change. | guardana/ | 130 | — | ~968 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 43 | Read-only audit of MCP definition language across an existing surface — tools, resources, prompts, server instructions. | cyanheads/ | 156 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 44 | MCP gateway security patterns, token management, request validation, and audit logging for MCP communications | Hack23/ | 239 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | today |
| 45 | 45.Spring AI Diagnose and operate Spring AI projects with version-aware Maven or Gradle checks for ChatClient, advisors, retrieval, conversation memory, tool/MCP boundaries, streaming, configuration, and… | magnus919/ | 116 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 46 | A skill your agent uses when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue. | openshift-eng/ | 120 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 47 | MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file… | LeoYeAI/ | 2.2k | — | ~969 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 48 | AWS security service suitability, coverage and cost recommendations: WAF/origin overlap, AWS Network Firewall inspection coverage and policy review, VPC endpoint, Transit Gateway/Cloud WAN… | aws/ | 2.8k | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | today |