Security plugins
Installable bundles that ship commands, skills, agents and MCP config together.
66 of 340 entries
agent-skills
★ 78,448Production-grade engineering skills for AI coding agents — covering the full software development lifecycle from spec to ship.
addyosmaniupdated 16d agoMITconnect-apps
★ 67,771Manage auth and connect to 500+ apps using Composio. Perform real actions from Claude Code - send emails, create issues, post messages, and more.
ComposioHQupdated 2mo agoruflo-loop-workers
★ 64,474Cache-aware /loop workers and CronCreate background automation — wraps 5 hooks_worker-* MCP tools (list/dispatch/status/detect/cancel) and exposes 12 background worker triggers (ultralearn, optimize, consolidate, predict, audit, map, preload, deepdive, document, refactor, benchmark, testgaps)
ruvnetupdated 14d agoMITruflo-federation
★ 64,474Cross-installation agent federation with zero-trust security, peer discovery, consensus-based task routing, and per-call budget circuit breaker (ADR-097)
ruvnetupdated 14d agoMITruflo-security-audit
★ 64,474Security review, dependency scanning, policy gates, and CVE monitoring
ruvnetupdated 14d agoMITruflo-aidefence
★ 64,474AI safety scanning, PII detection, prompt injection defense, and adaptive threat learning
ruvnetupdated 14d agoMITruflo-workflows
★ 64,474Workflow automation across two surfaces: the 10 workflow_* MCP tools (create/run/execute/status/list/pause/resume/cancel/delete/template) with full state-machine lifecycle (created → running ↔ paused → completed/cancelled), and native Claude Code Workflow JS orchestration (.claude/workflows/*.js — agent/parallel/pipeline/phase fan-out). Includes GAIA benchmark component for Princeton HAL leaderboard submissions.
ruvnetupdated 14d agoMITagentic-bundle-aas-security-engineer
★ 43,285Editorial "AAS Security Engineer" bundle for Claude Code from Agentic Awesome Skills.
sickn33updated 14d agoMITagentic-bundle-skill-author
★ 43,285Editorial "Skill Author" bundle for Claude Code from Agentic Awesome Skills.
sickn33updated 14d agoMITagentic-bundle-security-developer
★ 43,285Editorial "Security Developer" bundle for Claude Code from Agentic Awesome Skills.
sickn33updated 14d agoMITagentic-bundle-security-engineer
★ 43,285Editorial "Security Engineer" bundle for Claude Code from Agentic Awesome Skills.
sickn33updated 14d agoMITpr-review
★ 39,867Complete PR review workflow with security, testing, and docs
luongnv89updated 18d agoMITsecurity-compliance
★ 37,927SOC2, HIPAA, and GDPR compliance validation, secrets scanning, compliance checklists, and regulatory documentation
wshobsonupdated 14d agoMITcomprehensive-review
★ 37,927Multi-perspective code analysis covering architecture, security, and best practices
wshobsonupdated 14d agoMITsecurity-scanning
★ 37,927SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and automated security hardening
wshobsonupdated 14d agoMITaccessibility-compliance
★ 37,927WCAG accessibility auditing, compliance validation, UI testing for screen readers, keyboard navigation, and inclusive design
wshobsonupdated 14d agoMITdependency-management
★ 37,927Dependency auditing, version management, and security vulnerability scanning
wshobsonupdated 14d agoMITreverse-engineering
★ 37,927Binary reverse engineering, malware analysis, firmware security, and software protection research for authorized security research, CTF competitions, and defensive security
wshobsonupdated 14d agoMITkubernetes-operations
★ 37,927Kubernetes manifest generation, networking configuration, security policies, observability setup, GitOps workflows, and auto-scaling
wshobsonupdated 14d agoMITseo-analysis-monitoring
★ 37,927Content freshness analysis, cannibalization detection, and authority building for SEO
wshobsonupdated 14d agoMITfull-stack-orchestration
★ 37,927End-to-end feature orchestration with testing, security, performance, and deployment
wshobsonupdated 14d agoMITsigned-audit-trails
★ 37,927Teaching skill: signed audit trails for Claude Code tool calls. Cookbook-style walkthrough of Cedar-gated tool calls with Ed25519 receipts, offline verification, and CI/CD integration. Pairs with the protect-mcp plugin.
wshobsonupdated 14d agoMITseo-content-creation
★ 37,927SEO content writing, planning, and quality auditing with E-E-A-T optimization
wshobsonupdated 14d agoMITdeveloper-essentials
★ 37,927Essential developer skills including Git workflows, SQL optimization, error handling, code review, E2E testing, authentication, debugging, and monorepo management
wshobsonupdated 14d agoMITbackend-api-security
★ 37,927API security hardening, authentication implementation, authorization patterns, rate limiting, and input validation
wshobsonupdated 14d agoMITfrontend-mobile-security
★ 37,927XSS prevention, CSRF protection, content security policies, mobile app security, and secure storage patterns
wshobsonupdated 14d agoMITsecurity-guidance
★ 32,159Security review for Claude-generated code. Pattern-based warnings on edits, LLM-powered diff review on Stop, and an agentic commit reviewer that catches injection, XSS, SSRF, hardcoded secrets, and 25+ other vulnerability classes.
anthropicsupdated 14d agomcp-server-dev
★ 32,159Skills for designing and building MCP servers that work seamlessly with Claude — guides you through deployment models (remote HTTP, MCPB, local), tool design patterns, auth, and interactive MCP apps.
anthropicsupdated 14d agoApache-2.0claude-md-management
★ 32,159Tools to maintain and improve CLAUDE.md files - audit quality, capture session learnings, and keep project memory current.
anthropicsupdated 14d agoApache-2.0cybersecurity-skills
★ 25,606817 cybersecurity skills covering web security, pentesting, DFIR, threat intelligence, cloud security, malware analysis, and more.
mukul975updated 1mo agoApache-2.0business-operations-skills
★ 22,6126 BizOps skills + 1 orchestrator: process-mapper (BPMN + bottleneck + cycle-time), vendor-management (SLA + risk + scorecard), capacity-planner (Erlang-C queueing math for ops teams), internal-comms (ADKAR + Kotter 8-step change comms), knowledge-ops (SOP + runbook authoring with 5W2H validation, context: fork), procurement-optimizer (UNSPSC-aligned spend categorization + supplier consolidation). Orchestrator skill uses context: fork to route inquiries to the right sub-skill via Matt Pocock grill discipline. 18 stdlib-only Python tools, 24+ reference docs each citing ≥7 authoritative sources, asset templates per skill. Distinct from business-growth (external sales) and c-level-advisor (strategic).
alirezarezvaniupdated 15d agoMITbehuman
★ 22,612Self-Mirror consciousness loop for human-like AI responses. Adds inner dialogue (Self → Mirror → Conscious Response) to make AI output feel authentic, not robotic. Zero dependencies — pure prompt technique.
alirezarezvaniupdated 15d agoMITcompliance-team-iso42001
★ 22,612ISO/IEC 42001:2023 AI Management System (AIMS) specialist for compliance teams: AIMS gap analyzer (Clauses 4-10 coverage scoring + remediation priority), AI risk register builder (Annex A 38 controls + risk-to-treatment map per ISO 23894), AIMS audit scheduler (Clause 9.2 internal audit cadence + 12-month plan + auditor independence checks). 4 in-depth references: ISO 42001 Clauses 4-10 walkthrough, Annex A controls A.1-A.10, AIMS implementation maturity model, cross-framework mapping (42001 ↔ EU AI Act ↔ NIST AI RMF ↔ ISO 23894). Stdlib-only. Standalone-installable; also bundled in ra-qm-skills. Built for compliance officers running internal AIMS audits, not for executive AI strategy decisions (see chief-ai-officer-advisor for those).
alirezarezvaniupdated 15d agoMITengineering-advanced-skills
★ 22,61237 advanced engineering skills: agent designer, agent workflow designer, RAG architect, database designer + schema designer + SQL assistant, migration architect, observability designer, dependency auditor, changelog generator (with semantic version bumper and hotfix/rollback procedures), API design reviewer, API test suite builder, CI/CD pipeline builder, MCP server builder, skill security auditor, skill tester, performance profiler, focused-fix, browser-automation, full-page-screenshot, git-worktree-manager, monorepo-navigator, codebase-onboarding, interview-system-designer, runbook-generator, spec-driven-workflow, secrets-vault-manager, env-secrets-manager, pr-review-expert, self-eval, tc-tracker (task context tracker with lifecycle and handoff format), feature-flags-architect, kubernetes-operator, chaos-engineering, ship-gate (pre-production 8-category audit with deploy-intent intercept), slo-architect (SLO designer, error-budget calculator with multi-window burn-rate alerts, SLO reviewer per Google SRE Workbook), and tech-debt-tracker. Agent skill and plugin for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw.
alirezarezvaniupdated 15d agoMITdeep-research
★ 22,612Disciplined, multi-source meta-research for high-stakes questions — the heavyweight alternative to the fast research router. Runs a 9-phase pipeline (reframe into falsifiable hypotheses → genre/blocks → plan → capability discovery → parallel sub-agent fan-out → score & triangulate → synthesize + adversarial pass → verify → refresh targets), triangulates every thesis against >=3 independent, differently-typed sources, saves each source to its own file with verbatim quotes, and never fabricates a citation. Output is an auditable, reusable folder with a delta-update refresh protocol. Use when a wrong answer is expensive: strategy, comparing N options, hypothesis validation, mapping a field.
alirezarezvaniupdated 15d agoMITa11y-audit
★ 22,612WCAG 2.2 accessibility audit and fix skill for React, Next.js, Vue, Angular, Svelte, and HTML. Static scanner detecting 20+ violation types, contrast checker with suggest mode, framework-specific fix patterns, CI-friendly exit codes.
alirezarezvaniupdated 15d agoMITuniversal-scraping-architect
★ 22,612A universal scraping skill with intelligent routing, token budget tracking, and quota awareness. Supports Firecrawl and local Python extraction (firecrawl, pandas, requests, beautifulsoup4). Free-tier compatible, BYOK.
alirezarezvaniupdated 15d agoMITpulse
★ 22,612Multi-source recency research skill. Takes the pulse of any topic across Reddit, Hacker News, the open web, and (optionally) X/Twitter within a configurable recent window (default 30 days). Forcing 2–4 question grill-me intake clarifies topic specificity, angle (trend/sentiment/problems/opportunities/comparison), time window, and platform scope before searching. Phases 1–3 run in parallel per the research-pack convention. Returns a synthesized briefing with citations, engagement metrics, and cross-platform pattern analysis. Source spec: megaprompts/01-pulse-megaprompt.md (PR #657). Implements the Agent Integrity Rules block locked down by PR #657 audit: 1 q/sec per platform, three-count tracking (sent/received/cited), retry-once-after-3s, stop-after-3-consecutive-failures.
alirezarezvaniupdated 15d agoMITcommercial-skills
★ 22,6127 Commercial skills + 1 orchestrator: pricing-strategist (Van Westendorp WTP + packaging + model picker), deal-desk (margin + discount routing + redline scoring), partnerships-architect (5-tier classifier + joint GTM + revshare modeler), channel-economics (cost-to-serve + ROI + channel mix optimizer), commercial-policy (data-backed discount matrix + exception flow + policy linter), rfp-responder (Shipley-method structured RFP/RFI/RFQ response + win-theme + winrate predictor; context: fork for heavy intake), commercial-forecaster (4Q-weighted bookings + cohort NRR/GRR + funnel-confidence with mandatory assumption disclosure). Orchestrator skill uses context: fork. 21 stdlib-only Python tools, 28+ reference docs. Distinct from business-growth (sales execution), c-level-advisor/cro-advisor (strategic CRO), finance (close-and-report).
alirezarezvaniupdated 15d agoMITgrill-me
★ 22,612Relentless plan-and-design interrogator. Walks the decision tree of a plan one branch at a time, asking forcing questions sequentially with recommended answers. Explores codebase to resolve answers where possible. Enhanced from Matt Pocock's MIT-licensed grill-me skill (https://github.com/mattpocock/skills) with: (1) stdlib Python tools (decision-tree extractor, question generator, session-state tracker), (2) 3 reference docs citing 5+ authoritative sources each (forcing-question patterns, decision-tree completeness, when to stop grilling), (3) cs-grill-master persona agent + /cs:grill-me slash command. Matt's relentless one-at-a-time interview discipline preserved verbatim per MIT. Use when user wants to stress-test a plan, get grilled on their design, or says "grill me".
alirezarezvaniupdated 15d agoMITcaveman
★ 22,612Ultra-compressed communication mode. Cuts token usage ~75% by dropping filler, articles, and pleasantries while keeping full technical accuracy. Enhanced from Matt Pocock's MIT-licensed caveman skill (https://github.com/mattpocock/skills) with: (1) stdlib Python tools (text compressor, token-savings estimator, caveman-style linter), (2) 3 reference docs citing 5+ authoritative sources each (compression principles, technical communication patterns, when caveman backfires), (3) cs-caveman-mode persona agent + /cs:caveman slash command. Matt's voice and persistence rules preserved verbatim per MIT. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman.
alirezarezvaniupdated 15d agoMIThelm-chart-builder
★ 22,612Helm chart development agent skill and plugin for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw — chart scaffolding, values design, template patterns, dependency management, security hardening, and chart testing.
alirezarezvaniupdated 15d agoMITpatent
★ 22,612Patent prior-art and landscape intelligence skill — not generic patent help. Commits to one of five sub-use-cases via forcing intake (novelty search / freedom-to-operate / competitive landscape / acquisition diligence / litigation prior-art) before any search runs. Searches Google Patents, Espacenet, USPTO, and optionally Lens.org for citation-graph signals. Output is an editable Word document (.docx) with verdict, ranked closest art (claim-text extracted), CPC-class-aware landscape, family-resolved hits, geographic coverage, FTO flags where applicable, strategy recommendations, and full audit log. Triggers: 'prior art search for [invention]', 'patent search on [topic]', 'freedom to operate analysis', 'FTO for [product]', 'patent landscape for [field]', 'is [invention] novel', 'patents on [topic]', 'competitive patent analysis', 'prior art for litigation', 'patent diligence on [company]'. Produces search signal, not legal advice — always recommends consulting a patent attorney before filing or licensing decisions. Trademark, copyright, and trade-secret questions are out of scope.
alirezarezvaniupdated 15d agoMITcollab-proof
★ 22,612Assisted retrospective: after a session, calibrates what Claude contributed vs what the developer drove. LLM-assessed 4-frame analysis, zero dependencies.
alirezarezvaniupdated 15d agoMITsecurity-guidance
★ 22,612PreToolUse security reminder hook for Claude Code. Catches 12 common security anti-patterns in Edit/Write/MultiEdit operations BEFORE they happen — command injection (exec, os.system, subprocess shell=True), XSS (innerHTML, dangerouslySetInnerHTML, document.write), SQL injection (f-string queries, .format), unsafe deserialization (pickle, yaml.unsafe_load), code injection (eval, new Function), and GitHub Actions workflow injection. Session-state caching prevents duplicate warnings; 30-day auto-cleanup of stale state files. Disable per-session with ENABLE_SECURITY_REMINDER=0. Ported from David Dworken's MIT-licensed plugin at github.com/alirezarezvani/aeo-box.
alirezarezvaniupdated 15d agoMITaeo
★ 22,612Answer Engine Optimization (AEO) skill — optimize content to be cited by AI language models (ChatGPT, Perplexity, Claude, Gemini, Mistral) as authoritative sources. Distinct from SEO (which optimizes for search rankings), AEO optimizes for citation in LLM-generated responses. Ships 3 stdlib Python tools (aeo_audit.py for E-E-A-T + structure scoring, aeo_optimizer.py for content rewriting in conservative/balanced/aggressive modes, citation_tracker.py for local-first citation ledger), 3 references citing 7+ authoritative sources each (E-E-A-T methodology, per-LLM citation patterns, AEO-vs-SEO strategy), and industry-aware thresholds for 8 industries (saas/healthcare/finance/legal/ecommerce/b2b/media/education) with stricter YMYL calibration. Triggers — 'AEO audit', 'optimize for ChatGPT', 'get cited by Perplexity', 'E-E-A-T audit', 'LLM citation strategy', 'answer engine optimization'.
alirezarezvaniupdated 15d agoMITapple-hig-expert
★ 22,612Master Apple's Human Interface Guidelines (HIG) with focus on 2026 Liquid Glass aesthetics. Design and audit iOS, macOS, and visionOS apps for full compliance and premium feel. Includes hig_checker Python tool for tap targets, contrast, and accessibility validation. Reference docs cover visual design, platform specifics (iOS/macOS/visionOS), and accessibility best practices.
alirezarezvaniupdated 15d agoMITchief-data-officer-advisor
★ 22,612Chief Data Officer advisory: AI training data audit (origin x class x use-case matrix with GDPR Art. 6 + EU AI Act citations -> GO/MITIGATE/NO-GO per source), data product strategy picker (warehouse vs lakehouse vs mesh + 6-layer build-vs-buy + 12-month sequencing), data asset valuator (strategic value 0-10 + M&A multiplier with carve-out penalties + 3 ranked productization paths). 4 references answering one decision each: training rights, data product strategy, customer-data-as-asset, data team org evolution. Stdlib-only. Standalone-installable; also bundled in c-level-skills. Strategic only - does not duplicate engineering data skills.
alirezarezvaniupdated 15d agoMITfeature-flags-architect
★ 22,612End-to-end feature-flag discipline: classify, ship, ramp, retire. Detects stale flags as debt, generates phased rollout plans (ring/linear/log/cohort), and audits every flag for a documented kill switch. 3 stdlib Python tools, 4 references on flag taxonomy + provider trade-offs (LaunchDarkly/GrowthBook/Statsig/Unleash/Flipt/DIY) + rollout strategies + lifecycle. /flag-cleanup slash command. Cross-tool compatible.
alirezarezvaniupdated 15d agoMITyoutube-full
★ 22,612YouTube transcripts, video search, channel browsing, playlist extraction, and new-upload monitoring via TranscriptAPI. Covers all YouTube data workflows: transcript extraction with timestamps, in-channel search, and content monitoring. BYOK — 100 free credits included.
alirezarezvaniupdated 15d agoMITdata-quality-auditor
★ 22,612Audit datasets for completeness, consistency, accuracy, and validity. 3 stdlib-only Python tools: data profiler with DQS scoring, missing value analyzer with MCAR/MAR/MNAR classification, and multi-method outlier detector.
alirezarezvaniupdated 15d agoMITkubernetes-operator
★ 22,612End-to-end Kubernetes Operator discipline: CRD design, reconcile-loop patterns, and OperatorHub Capability Levels. Ships CRD validator, reconcile-loop linter, and capability auditor (3 stdlib Python tools), 4 references on the operator pattern + CRD design + reconcile patterns + framework comparison (controller-runtime/kubebuilder/operator-sdk/metacontroller/KOPF), CRD + Go controller skeletons, and /operator-audit slash command. NOT a generic k8s skill — specifically the Operator pattern.
alirezarezvaniupdated 15d agoMITemail
★ 22,612Email triage system — paired skills (inbox-setup + inbox-triage) for personalized recurring email triage. inbox-setup runs once via interactive interview to build a knowledge base of 7 files (taxonomy, patterns, evaluation-framework, rate-card, blocklist, tracker, triage-log/) in ${WORKSPACE}/Email/. inbox-triage runs on recurring cadence (1-3x daily) or on demand: classifies recent emails, researches new senders, generates recommendations, drafts replies (NEVER sends), delivers a report, and updates the KB with learnings. The two skills share a strict file contract — PR #657's cross-skill consistency audit verified the 7 KB filenames align verbatim between the two megaprompts. Source specs: megaprompts/06-inbox-setup-megaprompt.md + megaprompts/07-inbox-triage-megaprompt.md.
alirezarezvaniupdated 15d agoMITgrill-with-docs
★ 22,612Docs-anchored grilling session — interrogates a plan against the project's existing language (CONTEXT.md) and recorded decisions (docs/adr/), updating those files inline as terminology and decisions crystallise. Derived from Matt Pocock's MIT-licensed grill-with-docs skill (https://github.com/mattpocock/skills) with: (1) 3 stdlib Python tools (CONTEXT.md linter, ADR scanner, glossary-to-code consistency check), (2) 3 reference docs each citing 7+ authoritative sources on ubiquitous language, ADR practice, and CONTEXT.md as a living artifact, (3) cs-grill-with-docs persona agent + /cs:grill-with-docs slash command. Matt's interview discipline + domain-awareness rules + ADR-when-3-criteria-are-met gate preserved verbatim per MIT.
alirezarezvaniupdated 15d agoMITcode-tour
★ 22,612Create CodeTour .tour files — persona-targeted, step-by-step walkthroughs that link to real files and line numbers. Supports 10 developer personas (vibecoder, new joiner, architect, security reviewer, etc.), all CodeTour step types, and SMIG description formula.
alirezarezvaniupdated 15d agoMIThandoff
★ 22,612Compact the current conversation into a handoff document for another agent to pick up. Save to a user-configured location (OS temp, home folder, or per-project .handoff/), redact secrets before write, suggest skills for the next session, and auto-load the latest handoff on the next SessionStart. First-run setup asks where to save so the project folder never gets cluttered. Use when the user says 'hand this off', 'handoff doc', 'summarize this for a new session', 'compact this conversation', 'I'm ending this session', or any variation signaling intent to pass work to a fresh agent.
alirezarezvaniupdated 15d agoMITchief-ai-officer-advisor
★ 22,612Chief AI Officer advisory: model build-vs-buy calculator (API vs fine-tune vs build with 3-year TCO across 6 paths + breakeven balancing economics with practical feasibility), AI risk classifier (EU AI Act tier with 7 Article citations + US state patchwork: NYC LL 144, CO AI Act, IL HB 53, CA SB 1001, IL BIPA + industry overlays for FDA AI/ML, CFPB Circular 2023-03, NYDFS Reg 23, NAIC, ECOA, Fed SR 11-7), AI cost economics (API vs self-hosted breakeven with 2026 pricing across A100/H100, utilization reality, hidden costs). 4 in-depth references each citing 5+ authoritative sources. Stdlib-only. Standalone-installable; also bundled in c-level-skills. Strategic only - does not duplicate engineering AI/ML skills.
alirezarezvaniupdated 15d agoMITgoogle-workspace-cli
★ 22,612Google Workspace administration via the gws CLI (github.com/googleworkspace/cli, install: npm i -g @googleworkspace/cli). Authenticate and automate Gmail, Drive, Sheets, Calendar, Docs, Chat, and Tasks. 5 Python tools, 3 reference guides, a local catalog of 43 recipe command templates, and 10 persona bundles. Verify generated commands against gws --help.
alirezarezvaniupdated 15d agoMITterraform-patterns
★ 22,612Terraform infrastructure-as-code agent skill and plugin for module design patterns, state management strategies, provider configuration, security hardening, and CI/CD plan/apply workflows. Covers mono-repo vs multi-repo, workspaces, policy-as-code, and drift detection.
alirezarezvaniupdated 15d agoMITwrite-a-skill
★ 22,612Skill-author skill: create new agent skills with proper structure, progressive disclosure, and bundled resources. Enhanced from Matt Pocock's MIT-licensed write-a-skill (https://github.com/mattpocock/skills) with: (1) stdlib Python validation tools (description validator, structure validator, review-checklist runner), (2) 3 reference docs citing 5+ authoritative sources each (progressive disclosure principles, description design patterns, quality gates), (3) cs-skill-author persona agent + /cs:write-a-skill slash command. Matt's voice and 3-phase workflow (Gather → Draft → Review) preserved verbatim per his MIT license. Use when user wants to create, write, build, or author a new agent skill.
alirezarezvaniupdated 15d agoMIT