Skills

All Skills

vulnerability

Skills tagged with #vulnerability

@inkog-io
MCP

Io.Github.Inkog Io/Inkog

Scan AI agents for security vulnerabilities. Audit MCP servers before installation.

mcpgithubai
inkog-io/inkog-mcp
19d ago
0
@postrv

narsil

Use narsil-mcp code intelligence tools effectively. Use when searching code, finding symbols, analyzing call graphs, scanning for security vulnerabilities, exploring dependencies, or performing static analysis on indexed repositories.

postrv/narsil-mcp
19d ago
1230
@thoughtbot

rails-audit-thoughtbot

Perform comprehensive code audits of Ruby on Rails applications based on thoughtbot best practices. Use this skill when the user requests a code audit, code review, quality assessment, or analysis of a Rails application. The skill analyzes the entire codebase focusing on testing practices (RSpec), security vulnerabilities, code design (skinny controllers, domain models, PORO with ActiveModel), Rails conventions, database optimization, and Ruby best practices. Outputs a detailed markdown audit report grouped by category (Testing, Security, Models, Controllers, Code Design, Views) with severity levels (Critical, High, Medium, Low) within each category.

thoughtbot/rails-audit-thoughtbot
19d ago
610
@mcpsbom
MCP

SBOMApp - SBOM Generator & Vulnerability Scanner

Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.

mcpgithub
mcpsbom/sbomapp-mcp-server
19d ago
0
@marchev

solodit

Search Solodit for similar smart contract security findings. Use when reviewing vulnerabilities, comparing to known issues, or researching prior art from real audits.

marchev/claudit
18d ago
1140
@0xiehnnkta

Feynman Auditor

Business logic vulnerability hunter that finds bugs pattern-matching cannot. Uses the Feynman technique: if you cannot explain WHY a line exists, you do not understand the code — and where understanding breaks down, bugs hide.

0xiehnnkta/nemesis-auditor+2 more
19d ago
1820
@vulnersCom
MCP

Io.Github.VulnersCom/Vulners Mcp

MCP server for the Vulners.com API

mcpgithubapi
vulnersCom/vulners-mcp
19d ago
0
@jefflester

api-security

API security best practices and common vulnerability prevention. Enforces security checks for authentication, input validation, SQL injection, XSS, and OWASP Top 10 vulnerabilities. Use when building or modifying APIs.

jefflester/claude-skills-supercharged
19d ago
370
@caido-community

write-check-v2

Write security checks using the CheckDefinitionV2 system. Use when creating new checks, converting V1 checks to V2, or when the user asks to implement a vulnerability scanner check. Covers defineCheckV2, defineRegexCheck, CheckContext API, parameter injection, testing with testCheck/mockTarget, and registration.

caido-community/scanner
18d ago
390
@ofershap
MCP

Npm Plus

npm MCP — search packages, bundle sizes, vulnerabilities, compare downloads.

mcpgithubsearch
ofershap/mcp-server-npm-plus
19d ago
0
@revsmoke
MCP

Promptrejectormcp

Security gateway for AI agents: detects prompt injections, jailbreaks, and common vulnerabilities.

mcpgithubai
revsmoke/promptrejectormcp
19d ago
0
@NeuraLegion
MCP

Bright Security

AI-powered application security testing — scan APIs, discover endpoints, and find vulnerabilities.

mcpgithubapiai
NeuraLegion/mcp
19d ago
0
@mcp-registry
MCP

Zenable

Zenable cleans up sloppy AI code and prevents vulnerabilities with deterministic guardrails

mcpai
19d ago
0
@securityscan-api
MCP

SecurityScan

Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.

mcpgithubapiaillm
securityscan-api/securityscan-api
19d ago
0
@operantlabs
MCP

Operant Mcp

Security testing MCP server for penetration testing, forensics, and vulnerability assessment

mcpgithub
operantlabs/operant-mcp
19d ago
0
@microsoft

fix-dependabot-alerts

Fix Dependabot security alerts by updating vulnerable npm dependencies. Use when the user mentions "dependabot", "security alerts", "vulnerability", "CVE", or wants to update packages with security issues.

microsoft/powerplatform-vscode
18d ago
2570
@huzaifa525

dep-check

Use when the user wants to check dependencies, find outdated packages, or audit for vulnerabilities.

huzaifa525/claude-code-optimizer+7 more
18d ago
70
@joepangallo
MCP

Mcp Server Security Audit

Scan websites for security vulnerabilities, headers, TLS, and email security.

mcpgithubaiweb
joepangallo/agent-audit
19d ago
0
@lordbasilaiassistant-sudo
MCP

Io.Github.Lordbasilaiassistant Sudo/Contract Scanner

Smart contract security scanner — vulnerabilities, risk scores, and calldata decoding

mcpgithubai
lordbasilaiassistant-sudo/mcp-servers+3 more
19d ago
0
@FinishKit
MCP

Io.Github.FinishKit/Mcp

FinishKit MCP: scan GitHub repos for security vulnerabilities, deployment blockers, and quality

mcpgithub
FinishKit/mcp
19d ago
0
@blacktop

ipsw

Apple firmware and binary reverse engineering with the ipsw CLI tool. Use when analyzing iOS/macOS binaries, disassembling functions in dyld_shared_cache, dumping Objective-C headers from private frameworks, downloading IPSWs or kernelcaches, extracting entitlements, analyzing Mach-O files, or researching Apple security. Triggers on requests involving Apple RE, iOS internals, kernel analysis, KEXT extraction, or vulnerability research on Apple platforms.

blacktop/ipsw-skill+1 more
5d ago
430
@dynatrace-oss
MCP

Io.Github.Dynatrace Oss/Dynatrace Mcp

Access Dynatrace observability data: logs, metrics, problems, vulnerabilities via DQL and Davis AI

mcpgithubai
dynatrace-oss/Dynatrace-mcp
19d ago
0
@allsmog

AI/ML Attack Surface

This skill should be used when the user asks about "AI security", "ML pipeline attacks", "prompt injection", "model deserialization", "unsafe model loading", "Jupyter injection", "LLM security", or needs to identify AI/ML-specific vulnerabilities in codebases that use machine learning frameworks.

allsmog/vuln-scout+18 more
18d ago
140
@agamm

owasp-security

Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026).

agamm/claude-code-owasp
18d ago
760
@authgear

dep-audit

Audit and fix dependency vulnerabilities in Go and Node.js packages. Runs govulncheck for Go and npm audit for each package.json directory. Commits fixes directory by directory.

authgear/authgear-server
18d ago
1.5K0
@Oolab-labs

Dependency Security Audit

Scan all project dependencies for known security vulnerabilities.

Oolab-labs/claude-ide-bridge+14 more
18d ago
110
@lordbasilaiassistant-sudo
MCP

Io.Github.Lordbasilaiassistant Sudo/Base Security Scanner Mcp

MCP server to scan smart contracts on Base for honeypots, rug pulls, and vulnerabilities.

mcpgithubai
lordbasilaiassistant-sudo/base-security-scanner-mcp
19d ago
0
@mcp-registry
MCP

Exploit Intelligence Platform — CVE, Vulnerability and Exploit Database

Real-time CVE, exploit, and vulnerability intelligence for AI assistants (350K+ CVEs, 115K+ PoCs)

mcpai
19d ago
0
@mitkox

security-audit-rlm

Run and troubleshoot privacy-preserving, local DSPy RLM security audits for large legacy .NET codebases. Use when asked to scan repositories for vulnerabilities, tune RLM/tool limits, fix truncation/stall issues, or produce actionable markdown/json audit outputs without loading entire codebases into model context.

mitkox/megacode
19d ago
740
@Bajuzjefe
MCP

Io.Github.Bajuzjefe/Aikido Mcp

Security analysis for Aiken smart contracts on Cardano. 75 vulnerability detectors.

mcpgithubai
Bajuzjefe/Aikido-Security-Analysis-Platform
19d ago
0
@zkVerify

Cargo Audit Triage

This skill should be used when the user asks to "run cargo audit", "triage cargo audit", "fix audit vulnerabilities", "update audit.toml", "check cargo audit ignores", "clean up audit ignore list", "review audit.toml", "remove stale audit ignores", or mentions resolving Rust security advisories or RUSTSEC identifiers. Provides a systematic workflow for analyzing each vulnerability, attempting updates, and writing motivated ignore entries when updates are not possible.

zkVerify/zkVerify
19d ago
4780
@baidu-baige

code-analysis

Code review and debugging assistant. Identifies bugs, performance issues, security vulnerabilities, and suggests optimizations.

baidu-baige/LoongFlow+1 more
19d ago
3760
@nevalang

vuln-scan

Run a repository vulnerability audit with lint, tests, and govulncheck. Use this when asked for security scanning or CVE triage in this repo.

nevalang/neva
18d ago
1.1K0
@eigent-ai

skill-security-auditor

Security auditing for code, configs, and infrastructure. Use when the user wants to audit or improve security: scan for vulnerabilities (SQL injection, XSS, command injection, path traversal), detect hardcoded secrets and credentials, review auth and authorization, check dependencies for known CVEs, audit config files for insecure defaults, or generate security reports. Trigger on "security audit", "vulnerability scan", "code review for security", "find secrets", "check for vulnerabilities", "OWASP", "CVE", or questions about code security.

eigent-ai/eigent
18d ago
13.0K0
@digidenone
MCP

Synapse Audit

AI-Powered Security Scanner for LLMs. Detects vulnerabilities and syncs with SynapseAudit.

mcpgithubaillm
digidenone/SynapseAudit
19d ago
0
@cisco-ai-defense

mcp-security-scan

Scans MCP servers, tools, prompts, and resources for security vulnerabilities using YARA rules, LLM analysis, and Cisco AI Defense API. Use this skill when the user wants to check MCP servers for security issues, detect prompt injection, tool poisoning, or analyze MCP configurations for threats.

cisco-ai-defense/mcp-scanner
18d ago
8440
@kousen

Security Code Review

Identify security vulnerabilities and suggest secure coding practices

kousen/claude-code-training+1 more
18d ago
1340
@rmyndharis

security-scanning-security-sast

Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks

rmyndharis/antigravity-skills
19d ago
5230
@SnailSploit

offensive-business-logic

Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.

SnailSploit/Claude-Red+23 more
3d ago
1.2K0
@sjdemartini

bump-transitive-dependency

Bump a transitive dependency to a patched version using pnpm. Use when Dependabot reports a security vulnerability in a transitive dependency and cannot auto-update it, or when the user mentions bumping, upgrading, or patching a transitive dependency.

sjdemartini/mui-tiptap+1 more
18d ago
4550
@fetter-io
MCP

Fetter MCP

Real-time Python package and vulnerability data for AI coding agents.

mcpgithubpythonai
fetter-io/fetter-mcp
19d ago
0
@payloadcms

audit-dependencies

Use when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

payloadcms/payload+3 more
18d ago
41.3K0
@sinewaveai
MCP

Agent Security Scanner Mcp

Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

mcpgithubai
sinewaveai/agent-security-scanner-mcp+2 more
19d ago
0
@mcp-registry
MCP

MCP Fortress

Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

mcpgithub
19d ago
0
@ferdinandobons

Startup Competitors

Deep competitive intelligence that goes beyond surface-level profiles. Produces actionable battle cards, pricing landscape analysis, and strategic vulnerability mapping using real web data.

ferdinandobons/startup-skill+3 more
18d ago
1320