Skills

All Skills

secrets

Skills tagged with #secrets

@Tyox-all
MCP

Io.Github.Tyox All/Mund

AI security scanner - secrets, PII, prompt injection, and exfiltration detection.

mcpgithubai
Tyox-all/Weave_Protocol
19d ago
0
@mujez

argocd-helm

ArgoCD and Helm expert skill. Use when deploying applications with ArgoCD, creating or reviewing Helm charts, designing GitOps workflows, managing ApplicationSets, multi-cluster deployments, progressive delivery with Argo Rollouts, troubleshooting sync issues, secrets management (SOPS, External Secrets Operator), and Kubernetes manifest management. Covers ArgoCD 3.x and Helm 3.x best practices.

mujez/claude-skills+5 more
19d ago
450
@Aguantar
MCP

Io.Github.Aguantar/Vibescan Mcp Server

MCP server for VibeScan — scan projects for leaked secrets and security issues

mcpgithub
Aguantar/vibescan-mcp-server
19d ago
0
@efij

Security guardrails for Claude Code, MCP tools, and Claude cowork workflows. Local-first modular YARA-style guard packs for secrets, exfiltration, prompt injection, MCP abuse, and risky agent actions.

Inspect the current Secure Claude Code posture, enabled protections, and recent audit events.

efij/secure-claude-code
18d ago
1000
@behrensd
MCP

mcpwall

iptables for MCP — blocks dangerous tool calls, scans for secrets, logs everything.

mcpgithub
behrensd/mcp-firewall
19d ago
0
@joelhooks

secret-management

Portable credential management for AI agents using age encryption, session-scoped leases, auto-rotation, and killswitch. Use this skill when agents need secure, time-bounded access to API keys, tokens, or credentials without direct exposure to plaintext secrets.

joelhooks/agent-secrets
18d ago
620
@alirezarezvani

secret-scanner

Detect exposed secrets, API keys, credentials, and tokens in code. Use before commits, on file saves, or when security is mentioned. Prevents accidental secret exposure. Triggers on file changes, git commits, security checks, .env file modifications.

alirezarezvani/claude-code-tresor+1 more
19d ago
6160
@nikivdev

env

Manage environment variables and secrets with flow (always use Flow env store)

nikivdev/flow+2 more
19d ago
21.2K0
@flytohub
MCP

Flyto Core

Secure execution engine for AI agents. 300+ modules, SSRF protection, secrets proxy.

mcpgithubai
flytohub/flyto-core
19d ago
0
@faberlens

1password-hardened

Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.

faberlens/hardened-skills+75 more
19d ago
60
@duriantaco
MCP

Skylos

Dead code, security, secrets detection and code quality for Python, TypeScript, Go.

mcpgithubpythontypescript
duriantaco/skylos
19d ago
0
@VouchlyAI
MCP

Io.Github.VouchlyAI/Pincer

Secure grip for your agent's secrets - security-hardened MCP gateway with proxy token architecture

mcpgithubai
VouchlyAI/Pincer-MCP
19d ago
0
@vkh-cr

project-workflows

Official Festapp workflows. How to run tests, manage secrets, sync translations, and commit changes safely.

vkh-cr/festapp
18d ago
340
@juanisidoro
MCP

Securecode

Secrets vault for Claude Code with audit logs, access rules, and AES-256 encryption.

mcpgithub
juanisidoro/securecode-mcp
19d ago
0
@24braids

terrashark

Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps. Use when generating, reviewing, refactoring, or migrating IaC and when building delivery/testing pipelines.

24braids/terrashark
19d ago
0
@rsdouglas
MCP

Janee

Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.

mcpgithubapiai
rsdouglas/janee
19d ago
0
@Kasempiternal

cyberconan

Security Audit Swarm — Full repo security scan (SAST, SCA, secrets, config). Adaptive orchestration: subagents for small repos, Agent Teams for large. Pure Claude analysis.

Kasempiternal/Claude-Agent-System+10 more
18d ago
130
@cloudflare

cloudflare-browser

Control headless Chrome via Cloudflare Browser Rendering CDP WebSocket. Use for screenshots, page navigation, scraping, and video capture when browser automation is needed in a Cloudflare Workers environment. Requires CDP_SECRET env var and cdpUrl configured in browser.profiles.

cloudflare/moltworker
18d ago
9.6K0
@incogbyte

Decompile Android APK, XAPK, AAB, DEX, JAR, and AAR files using jadx

Decompile Android APK, XAPK, AAB, DEX, JAR, and AAR files using jadx or Fernflower/Vineflower. Reverse engineer Android apps, extract HTTP API endpoints (Retrofit, OkHttp, Volley, GraphQL, WebSocket), trace call flows from UI to network layer, analyze security patterns (cert pinning, exposed secrets), and perform dynamic analysis with Frida (adaptive bypass generation, crash analysis, runtime hooking). Use when the user wants to decompile, analyze, or reverse engineer Android packages, find API endpoints, follow call flows, audit app security, or bypass runtime protections.

incogbyte/android-reverse-engineering-claude-skill
18d ago
140
@Aakashbhardwaj27
MCP

AI Scanner

Scan codebases for LLM/AI SDK usage, exposed API tokens, and hardcoded secrets.

mcpgithubapiaillm
Aakashbhardwaj27/ai-scanner-mcp
19d ago
0
@sparkvibe-io
MCP

Io.Github.Sparkvibe Io/GuardianShield

AI security layer: code scanning, PII detection, prompt injection, secrets, CVEs

mcpgithubai
sparkvibe-io/GuardianShield
19d ago
0
@getaegis
MCP

Aegis

Credential isolation for AI agents. Inject secrets at the network boundary.

mcpgithubai
getaegis/aegis
19d ago
0
@eigent-ai

skill-security-auditor

Security auditing for code, configs, and infrastructure. Use when the user wants to audit or improve security: scan for vulnerabilities (SQL injection, XSS, command injection, path traversal), detect hardcoded secrets and credentials, review auth and authorization, check dependencies for known CVEs, audit config files for insecure defaults, or generate security reports. Trigger on "security audit", "vulnerability scan", "code review for security", "find secrets", "check for vulnerabilities", "OWASP", "CVE", or questions about code security.

eigent-ai/eigent
18d ago
13.0K0
@edmundmiller

agenix-secrets

Create, edit, and wire up agenix-encrypted secrets in this dotfiles repo. Use when adding API keys, tokens, credentials, passwords, or any sensitive values to NixOS host configs. Trigger phrases: "add a secret", "encrypt with agenix", "new age secret", "hide this value", "agenix secret".

edmundmiller/dotfiles+21 more
18d ago
480
@VoidChecksum

omniwire

Control your entire server mesh from chat. Execute commands, transfer files, manage Docker, sync configs, and monitor all your nodes — VPS, Raspberry Pi, laptop, desktop — through one unified interface. 30 MCP tools. Works on any architecture (x64, ARM, Apple Silicon). SSH2 with compression, encrypted config sync, 1Password secrets backend. Just say what you need and your agent runs it across every machine.

infrastructuremeshsshdevopsserversvps
VoidChecksum/omniwire
18d ago
60
@utkusen

Hardcoded Secrets in Public Code Detection

You are performing a focused security assessment to find hardcoded sensitive data that is exposed in publicly accessible code. This skill uses a three-phase approach with subagents: **recon** (find all potential secret candidates), **batched verify** (confirm each is a real secret in publicly reacha

utkusen/sast-skills+12 more
18d ago
5290
@The-17

AgentSecrets — Zero-Knowledge Secrets Infrastructure

AgentSecrets is a complete secrets management system where you — the AI agent — are the operator.

The-17/agentsecrets
18d ago
630
@NousResearch

1password

Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in, and reading/injecting secrets for commands.

NousResearch/hermes-agent+116 more
10d ago
9.4K0
@botiverse

agent-vault

Read and write config files without ever seeing secret values. Secrets are stored in an encrypted local vault. You see `<agent-vault:key-name>` placeholders; the real values are written to disk transparently.

botiverse/agent-vault
19d ago
3380