Search
Security · MCP servers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Design or change REA investigation tools, CLI/MCP contracts, provider capabilities, and Evidence semantics. | morluto/ | 80k | — | ~239 | Automated safety check: Pass | MIT | today |
| 2 | Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities. | context-labs/ | 1.1k | 2 repos | ~3k | Automated safety check: Pass | MIT | 6 days ago |
| 3 | Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 190 | — | ~2.5k | Automated safety check: Notes | Unknown | 14 days ago |
| 4 | Run HOL Guard scanner and guard operations via uv run hol-guard. | hashgraph-online/ | 845 | — | ~542 | Automated safety check: Pass | Apache-2.0 | today |
| 5 | 5.Rsigma Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. | timescale/ | 166 | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 6 | Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. | PrefectHQ/ | 28k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 7 | Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT. | responsibleai/ | 330 | — | ~11k | Automated safety check: Notes | MIT | 3 days ago |
| 8 | Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in… | samugit83/ | 3k | — | ~1.3k | Automated safety check: Pass | MIT | 2 days ago |
| 9 | Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs. | six2dez/ | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | 2 days ago |
| 10 | Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. | ktnyt/ | 675 | — | ~565 | Automated safety check: Pass | MIT | 7 mo ago |
| 11 | Add or retrofit Tenuo authorization for AI-agent tools and effects. | tenuo-ai/ | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 12 | Automate low-impact web vulnerability verification through Burp MCP. | langbyyi/ | 129 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 13 | A skill your agent uses when working with the DecompilerServer MCP server to inspect, search, decompile, analyze, or compare .NET assemblies, especially foreign code such as Unity/RimWorld… | pardeike/ | 108 | — | ~1.5k | Automated safety check: Pass | MIT | 10 days ago |
| 14 | 14.Docs Update project documentation when features are added or changed. | boostsecurityio/ | 523 | — | ~336 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 15 | Run Mira environment risk collection. An agent skill from vw2x/Mira. | vw2x/ | 105 | — | ~793 | Automated safety check: Pass | GPL-3.0 | 6 days ago |
| 16 | Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token. | samugit83/ | 3k | — | ~1.8k | Automated safety check: Pass | MIT | 2 days ago |
| 17 | SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. | secondsky/ | 462 | — | ~5.9k | Automated safety check: Warn | GPL-3.0 | 6 days ago |
| 18 | 18.Keel A skill your agent uses for ANY new software project from idea to release — websites, WordPress/WooCommerce plugins, MCP servers, web apps, components, or libraries. | joseconti/ | 190 | — | ~11k | Automated safety check: Warn | GPL-3.0-or-later | 2 mo ago |
| 19 | Remediate security vulnerabilities found by Grype or pnpm audit. | stacklok/ | 171 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 20 | Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. | affaan-m/ | 277k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | today |
| 21 | The Priority Board's three-layer score model (rules BASE, REVIEW by the built-in AI or an MCP agent, a person's DECISION) and who may write which layer. | samugit83/ | 3k | — | ~1.7k | Automated safety check: Pass | MIT | 2 days ago |
| 22 | Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. | iflytek/ | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 23 | Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | 3 days ago |
| 24 | 24.Webcrypt MCP Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography. | putervision/ | 50 | — | ~847 | Automated safety check: Pass | MIT | 8 days ago |
| 25 | Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk. | seb1n/ | 206 | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 26 | Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates. | awarexone/ | 5.3k | — | ~1.9k | Automated safety check: Warn | MIT | 2 days ago |
| 27 | Security review: (1) vet an untrusted SKILL.md or .mcp.json BEFORE installing it — the injection/exfiltration scanner; CRITICAL blocks the install; (2) audit code on an untrusted-input path (a… | redhat-et/ | 2.4k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 28 | 28.Ida Reverse Reverse engineer binaries with IDA Pro: decompilation, disassembly, data-flow tracking, cross-references, and IDA MCP automation for deep static analysis of PE/ELF/Mach-O targets. | sickn33/ | 47k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 29 | Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. | wshobson/ | 40k | — | ~2.1k | Automated safety check: Pass | MIT | 6 days ago |
| 30 | Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP… | trilwu/ | 157 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 31 | Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Pass | CC0-1.0 | 2 days ago |
| 32 | 32.Sapui5 This skill should be used when developing SAP UI5 applications, including creating freestyle apps, Fiori Elements apps, custom controls, testing, data binding, OData integration, routing, and… | secondsky/ | 462 | — | ~4.1k | Automated safety check: Pass | GPL-3.0 | 6 days ago |
| 33 | Audit MCP (Model Context Protocol) server configurations for security issues. | github/ | 40k | — | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 34 | Security review of MCP (Model Context Protocol) server implementations and configurations. | OWASP/ | 188 | — | ~574 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 35 | Review the implementation source code of MCP (Model Context Protocol) servers, clients, and tool handlers against a security baseline — authentication, sessions, rate limiting, input-schema… | github/ | 40k | — | ~5.2k | Automated safety check: Pass | MIT | 2 days ago |
| 36 | 36.Aif Set up agent context for a project. An agent skill from unxed/f4. | unxed/ | 243 | — | ~8.4k | Automated safety check: Pass | BSD-3-Clause | yesterday |
| 37 | A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. | SCStelz/ | 249 | — | ~13k | Automated safety check: Pass | MIT | 3 days ago |
| 38 | Find decision-makers at a specific company using Apollo, Crustdata, Fiber, and PDL people search via Gooseworks MCP. | gooseworks-ai/ | 1.2k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | 2 days ago |
| 39 | 39.Polygraph Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills. | BankrBot/ | 1.2k | — | ~3.4k | Automated safety check: Pass | No licence | yesterday |
| 40 | 40.Hunt Burp Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)… | Encod3d-Sec/ | 329 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 41 | 41.Hunt MCP MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. | Encod3d-Sec/ | 329 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 42 | Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth… | cyanheads/ | 158 | — | ~6.4k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 43 | Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 44 | 44.Checkpoint Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations. | automateyournetwork/ | 676 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 45 | Audit MCP (Model Context Protocol) server configurations for security issues. | boshi-xixixi/ | 276 | — | ~2.2k | Automated safety check: Pass | MIT | 5 mo ago |
| 46 | Read-only audit of MCP definition language across an existing surface — tools, resources, prompts, server instructions. | cyanheads/ | 158 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 47 | MCP gateway security patterns, token management, request validation, and audit logging for MCP communications | Hack23/ | 239 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 48 | Manage Google Security Operations (SecOps) SOAR cases throughout their lifecycle. | google/ | 21k | — | ~3.2k | Automated safety check: Warn | Apache-2.0 | yesterday |