Security
Vulnerability scanning, secrets management, and security tooling. 891 entrées correspondantes dans le registre Forge — affichage des 150 premières.
- microsoft/mcp-for-beginnersThis open-source curriculum introduces the fundamentals of Model Context Protocol (MCP) through real-world, cr
- @azure/mcpAzure MCP Server - Model Context Protocol implementation for Azure
- 0x4m4/hexstrike-aiHexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomousl
- firerpa/lamda The most powerful Android RPA agent framework, next generation mobile automation.
- wgpsec/ENScan_GO一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。支持MCP接入
- snyk/agent-scanSecurity scanner for AI agents, MCP servers and agent skills.
- elementalsouls/Claude-BugHunterA Claude Code skill bundle for bug hunting and external red-team work — 71 skills, 15 slash commands, 681 disc
- cyberagiinc/DevDocsCompletely free, private, UI based Tech Documentation MCP server. Designed for coders and software developers
- stacklok/toolhiveToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.
- @aikidosec/mcpAikido MCP server
- mukul975/cve-mcp-serverProduction-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS sco
- cisco-ai-defense/mcp-scannerScan MCP servers for potential threats & security findings.
- utkusen/sast-skillsCollection of agent skills that turn your AI coder into a SAST scanner
- ghostsecurity/skillsGhost Security's collection of AppSec skills for AI coding agents
- semgrep/skillsA collection of skills for AI coding agents from Semgrep
- cisco-ai-defense/a2a-scannerScan A2A agents for potential threats and security issues
- Houseofmvps/ultraship"ULTRASHIP" Claude Code plugin — 39 skills, 33 tools, 11 agents for ship-ready workflows: planning, review, pe
- AndrewAltimit/template-repoAgent orchestration & security template featuring MCP tool building, agent2agent workflows, mechanistic interp
- claude-skill-security-auditorClaude Code skill for running structured security audits with actionable remediation plans
- claude-pentest-skillsStructured web application penetration testing with OWASP methodology, curated payload references, 6-gate vali
- ModelContextProtocol-Security/modelcontextprotocol-security.ioOfficial website and documentation hub for the Model Context Protocol Security initiative. Provides security g
- flutter-apk-securityReview Flutter Android APK/AAB release artifacts for manifest, permission, cleartext traffic, exported compone
- capiscio/a2a-demosDemo agents showcasing CapiscIO Agent Guard and MCP Guard — trust badges, identity verification, and tool-leve
- ia-security-skillAuditoria de segurança defensiva pré-entrega para projetos Claude Code. Cobre web, mobile (MASVS), cloud/IaC,
- PiQrypt/piqryptAI agent governance layer — sign, monitor and control every agent action. EU AI Act · ANSSI · NIST ready.
- vitonique/a2a-secureEnd-to-end encrypted communication for AI agents. The security layer that Google A2A forgot.
- solidity-security-auditComprehensive Solidity smart contract security auditing and vulnerability analysis skill. Based on methodologi
- QWED-AI/qwed-a2aFail-closed Agent-to-Agent verification, provenance, and attestation infrastructure for AI systems.
- ai.helixar/mcpSecurity tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
- com.arcself/arc-securityScan AI agent skills for 25 attack classes + runtime monitoring. 1,316+ findings.
- com.blackduck/mcp-serverAI-powered security scanning using Black Duck Signal for vulnerability detection.
- com.brightsec/mcpEnables AI agents to access Bright Security tools for app discovery and security testing.
- com.exploit-intel/eip-mcpReal-time CVE, exploit, and vulnerability intelligence for AI assistants (350K+ CVEs, 115K+ PoCs)
- com.olyport/cdc-sviSVI scores and theme breakdowns by county and tract
- com.skillssafe/scannerAI skill security scanner. Detects prompt injection, credential theft, ClawHavoc. Free, no signup.
- io.github.Ansvar-Systems/ot-security-mcpOT security standards: IEC 62443, NIST 800-82/53, MITRE ATT&CK for ICS
- io.github.Compuute/compuute-scan-apiScan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
- io.github.DevInder1/tridentchain-securityLocal supply-chain CVE scanner via OSV/NVD. Scans deps and IDE extensions. No upload.
- io.github.Kloudle/cloud-security-scannerAWS cloud security scanners for AI agents — S3, IAM, EC2, EKS, RDS, CloudTrail, CloudWatch Logs
- io.github.MCPower-Security/mcpower-proxySecurity proxy that automatically wraps MCP servers with real-time monitoring and policy enforcement
- io.github.NeuraLegion/mcpAI-powered application security testing — scan APIs, discover endpoints, and find vulnerabilities.
- io.github.Nomadu27/insaitsRuntime AI-to-AI security monitor. 23 anomaly types, OWASP MCP Top 10 coverage.
- io.github.RobotFleet-HQ/security-orchestraMulti-agent MCP platform for data centers and critical power.
- io.github.Servosity/abnormal-mcpAbnormal Security email threats, cases, and reporting in your terminal and your AI agents.
- io.github.Shrike-Security/shrike-mcpAI agent security scanner — prompt injection detection, SQL injection, PII isolation, threat intel.
- io.github.Tyox-all/mundScan for prompt injection, secrets, PII, and vet MCP servers before installation
- io.github.ako2345/android-security-analyzerMCP server for static security analysis of Android source code
- io.github.ashlrai/phantom-secrets-mcpStop AI coding agents from leaking API keys. Local proxy swaps real secrets for phm_ tokens.
- io.github.cyanheads/pentest-mcp-serverOffline methodology engine for authorized penetration testing, CTF, and security research.
- io.github.dalisecurity/frayWAF security testing: 5,500+ payloads, 25 WAF fingerprints, 21 recon checks, bypass AI
- io.github.diemoeve/mcpampelScan installed MCP servers for security vulnerabilities with 16 detection engines.
- io.github.eltociear/secrets-audit-mcpDetects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps.
- io.github.fino-oss/contract-scannerScans Base L2 smart contracts for security risks. Risk score 0-100, detects backdoors & proxies.
- io.github.frogeye-ai/mcpZero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
- io.github.joepangallo/mcp-server-security-auditScan websites for security vulnerabilities, headers, TLS, and email security.
- io.github.lordbasilaiassistant-sudo/base-security-scanner-mcpMCP server to scan smart contracts on Base for honeypots, rug pulls, and vulnerabilities.
- io.github.mastrophot/contract-security-scannerMCP smart contract scanner with NEAR-focused security context.
- io.github.mcpsbom/sbom-mcpGenerate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
- io.github.mdfifty50-boop/agent-securitySecurity scanning and threat detection for AI agents
- io.github.nzdsf2-gif/relayshield-mcpBreach detection, SIM swap, domain lookalikes, OAuth watchlist, URL scanning. Subscription or PAYG.
- io.github.ormuzdo/agentic-security-shield12-layer security configs for AI coding agents. Autonomous purchase via x402 (USDC on Base).
- io.github.rom-baro/arcwall-securitySecurity scanning for AI coding tools. Detects secrets, threat models, and runs pre-commit checks.
- io.github.sinewaveai/agent-security-scanner-mcpSecurity layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
- io.github.srotzin/hive-mcp-secretsEncrypted secret store and rotation for autonomous agent credentials
- io.github.weiseer/cve-cacheRecent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go).
- io.github.wyre-technology/abnormal-mcpMCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.
- io.github.zw008/vmware-nsx-securityVMware NSX security: DFW policies, security groups, tags, Traceflow, IDPS — 21 MCP tools.
- @vantasdk/vanta-mcp-serverModel Context Protocol server for Vanta's security compliance platform
- @forge-registry/cliVerify, install, and publish MCP servers, A2A agents, and AI skills via the Forge trust registry.
- security-auditPerform a project-wide security and safety audit of the 5thPlanet workspace.
- security-checklistSecurity review methodology using OWASP Top 10 and STRIDE frameworks. Reference material for scanning code cha
- owasp-securityUse when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user
- ci-security-complianceEnforces GitHub Actions security and compliance for this monorepo. Use when adding third-party actions, handli
- rag-securityDetects RAG pipelines that ingest external documents into LLM context without
- security-reviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints,
- offensive-ai-securityclaude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill
- prav-raghu-security-reviewSecurity audit for backend services and API endpoints — authentication gaps, injection risks, hardcoded secret
- security-complianceEstablish comprehensive security scanning and compliance infrastructure from scratch. Use when working with se
- security-pr-reviewerSecurity-focused review of an ACTUAL diff (PR, branch delta, or staged/working changes) — hunts authn/authz ga
- snailsploit-offensive-ai-securityclaude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill
- email-domain-securityRigorous, defensible email-spoofability verdict and SPF supply-chain risk analysis computed from published DNS
- robotics-securitySecurity hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation,
- dynamic-application-security-testingPerform dynamic security testing against running web applications and APIs to discover vulnerabilities through
- seb1n-security-auditPerform a broad, authorized security audit across application, infrastructure, identity, dependencies, and ope
- static-application-security-testingAnalyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated
- docs-security-overviewUse when a prospect, customer, IT/security team, or procurement evaluator asks about Louis's security posture,
- dom-security-hardeningWhen hardening a web application against Cross-Site Scripting (XSS) and injection attacks.
- check-securitySecurity-focused review of a PR — injection, XSS, auth, secrets, dependencies
- automotive-security-systemsExpert skill in alarm focusing on security-systems domain applications. Covers 40 topics across security-syste
- automotive-securityExpert skill in authentication focusing on security domain applications. Covers 198 topics across security dom
- irfad7-security-reviewWhen the user wants a security audit, vulnerability assessment, or security hardening of their codebase. Use w
- pentest-agentModel-driven penetration testing engine. Drive a full black-box pentest (recon → crawl → multi-agent attack →
- ai-securityUse when assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data p
- dependency-cveDependency version fingerprinting and CVE matching. Fastest ROI: identify framework/library versions from JS,
- api-security-best-practicesImplement secure API design patterns including authentication, authorization, input validation, rate limiting,
- backend-security-coderExpert in secure backend coding practices specializing in input
- frontend-security-coderExpert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-sid
- secrets-managementPerforms a structured secrets management review against OWASP Secrets Management Cheat Sheet and NIST SP 800-5
- kunanonj-security-auditorExpert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
- kunanonj-security-reviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints,
- secrets-managerAWS Secrets Manager for secure secret storage and rotation. Use when storing credentials, configuring automati
- jayrha-security-auditorAudits source code against the OWASP Top 10 (2021) and produces concrete, exploitable findings with proof-of-c
- vulnerability-triageTriages and prioritizes security vulnerabilities (CVEs) by combining CVSS base/temporal scores, real-world exp
- enterprise-workspace-security-basicsEstablish baseline administrative and security practices for rolling out Claude in an organization, based on c
- security-review-automationAutomate security review workflows with Claude Code by running ad-hoc checks before commits and adding pull-re
- bigpapicb-security-auditSecurity audit with OWASP top 10 checklist, dependency scanning, secrets detection, input validation, and inje
- security-engineerYou MUST use this for security decisions - threat modeling, vulnerability assessment, auth/authz design, secur
- marine-softdrink524-security-auditorApplication security expert that performs thorough security audits including OWASP Top 10 analysis, dependency
- api-securityAPI security best practices and common vulnerability prevention. Enforces security checks for authentication,
- security-reviewerUse when performing security audits, reviewing code for vulnerabilities, checking auth flows, or validating OW
- security-best-practicesPerform language and framework specific security best-practice reviews and suggest improvements. Use when the
- security-ownership-mapAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensi
- security-threat-modelCreate a repository-grounded AppSec threat model covering assets, trust boundaries, attackers, abuse paths, an
- heidihowilson-security-reviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints,
- gulmezeren2-byte-security-reviewReview a change for injection, authz gaps, secret handling and unsafe deserialisation, with the threat model s
- security-and-hardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external
- aws-security-specialtyAWS security engineering — threat detection (GuardDuty, Security Hub CSPM, Detective, Security Lake), incident
- silvakwan1-security-auditSkill de auditoria de segurança universal. Contém checklist baseado no OWASP Top 10, verificação de secrets ex
- review-securityWhite-box security audit. Blue-teamer and lead red-teamer run in parallel isolation for an independent first p
- reviewing-code-for-securityReviews code changes for security vulnerabilities - injection risks, hardcoded secrets, insecure defaults - an
- gongyuancaiji-owasp-securityComprehensive OWASP-aligned security guidance across six standards - Top 10 (2021) for web apps, ASVS 5.0, MAS
- environment-secretsManage environment variables and secrets. View, set, delete env vars and request secrets from users.
- security-scanScan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and
- mikey1168-offensive-ai-securityOffensive security skills for Claude — drop-in SKILL.md files that turn Claude into a context-aware red team o
- offensive-security-headersSecurity Headers validation methodology. Covers CSP, HSTS, X-Frame-Options, CORS headers, and how missing conf
- wso2-security-scanUse when analyzing security vulnerability reports or advisories for WSO2 IS runtimes or Docker images. Covers
- dev-security-auditorPacotes de instruções, scripts e ferramentas definidos em arquivos markdown (SKILL.md) que estendem o comporta
- dennisyu-security-auditContinuously verify that a website is still the site you published — no injected spam, no rogue admin, no hidd
- security-posture-reviewProduce a current-state security posture review covering IAM, secrets, third parties, and a 0-30 / 30-90 / 90-
- pipeline-securityReviews CI/CD pipeline configurations against SLSA v1.0 build levels and OWASP Top 10 CI/CD Security Risks. Au
- kubernetes-securityHarden a Kubernetes cluster's data plane and control plane. Covers Pod Security Standards (Restricted, Baselin
- network-securityProtects traffic and boundaries through segmentation, default-deny rules, egress control, and TLS everywhere,
- security-scanningAgentShield security audit with 5 scanning categories, 102 static analysis rules, and optional red-team simula
- arjunprabhulal-supply-chain-securityEstablishes trust in what you build and ship — SBOMs, build provenance, dependency pinning and verification, a
- vulnerability-managementFinds, prioritizes, and closes out vulnerabilities across code, dependencies, images, and infrastructure witho
- flutter-security-a11ySecurity and accessibility for a Flutter app — secure storage, secrets, cert pinning, obfuscation; Semantics,
- gh-security-hardeningGoes beyond finding bugs — produces a hardening plan that raises the baseline security posture of a system.
- lovable-securityAudits your Lovable app for the security vulnerabilities that vibe-coded apps almost always ship with.
- security-riskTranslate technical vulnerabilities into a business-impact risk assessment that gets resources approved — not
- m0ksha-tech-offensive-ai-securityclaude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill
- skill-security-scanUse BEFORE installing a third-party Claude Code skill or plugin, or to audit skills you already have. Triggers
- validate-codex-security-with-mythosChatGPT Codex is still immature on security-context reasoning. When Codex makes claims about authentication, a
- security-hardeningApplication security covering input validation, auth, headers, secrets management, and dependency auditing
- researchers-securityResearches malware analysis, CVEs, attribution reports, and hacker community sources. Use when the album subje
- spring-security-jwtUse when an application issues and validates its own first-party JWT access and refresh tokens, including auth
- kklimuk-security-reviewReview code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check f
- security-researchomo/lazycodex: The coding agent for tokenmaxxers;the one and only agent harness for complex codebases. For you
- alibaba-security-center-hardeningHarden Alibaba Cloud security posture via Security Center (threat detection, vulnerability scanning, baseline
- alibaba-waf-security-reviewAssess Alibaba Cloud workload security posture: RAM least-privilege, VPC isolation, KMS/HSM encryption, Cloud
- aws-bedrock-agent-security-governorReview Amazon Bedrock agents, AgentCore, Guardrails, knowledge bases, action groups, memory, MCP/tool integrat
Autres thèmes