PluginBench
Category

Best Security tools

2231 tools in the Security category across every type.

Skills

EN

entra-app-registration

Official
microsoft/azure-skills

Guide Microsoft Entra ID app registration, OAuth 2.0 flows, and MSAL integration in your coding agent.

419k installsAudited
AZ

azure-compliance

Official
microsoft/azure-skills

Run Azure compliance and security audits with azqr plus Key Vault expiration checks

419k installsAudited
AZ

azure-rbac

Official
microsoft/azure-skills

Find the least-privilege Azure RBAC role, then generate CLI commands and Bicep code to assign it.

419k installs
OP

openclaw-secure-linux-cloud

xixu-me/skills

Secure self-hosted OpenClaw on Linux cloud servers with conservative defaults: loopback binding, SSH tunneling, token auth, and minimal tool permissions.

253k installs
EN

entra-agent-id

Official
microsoft/azure-skills

Provision OAuth 2.0-capable identities for AI agents with per-instance audit trails via Microsoft Entra and Microsoft Graph.

143k installsAudited
FI

firebase-auth-basics

Official
firebase/agent-skills

Set up Firebase Authentication for user sign-in, management, and secure data access.

94k installsAudited
GI

git-guardrails-claude-code

mattpocock/skills

Block dangerous git commands (push, reset, clean) in Claude Code before execution.

84k installs
CO

convex-setup-auth

get-convex/agent-skills

Set up secure authentication in Convex with user management and access control.

76k installsAudited
BE

better-auth-best-practices

Official
better-auth/skills

Configure Better Auth server and client with database adapters, sessions, plugins, and environment variables for TypeScript authentication.

67k installsAudited
FI

firebase-security-rules-auditor

Official
firebase/agent-skills

Audit Firestore security rules for vulnerabilities and compliance with security best practices.

59k installsAudited
AU

audit-website

squirrelscan/skills

Audit websites for SEO, performance, security, and 22+ issue categories with 240+ rules using squirrelscan CLI.

57k installs
GO

golang-security

samber/cc-skills-golang

Security best practices and vulnerability prevention for Go code—injection, crypto, secrets, and authentication.

32k installsAudited
EM

email-and-password-best-practices

Official
better-auth/skills

Configure email verification, password reset flows, policies, and hashing for Better Auth email/password authentication.

23k installs
FI

firestore-security-rules-auditor

Official
firebase/agent-skills

Audit Firestore security rules for vulnerabilities and compliance with security best practices.

20k installsAudited
TW

two-factor-authentication-best-practices

Official
better-auth/skills

Configure TOTP, OTP, backup codes, and trusted devices for 2FA sign-in flows with Better Auth.

20k installs
SK

skill-vetter

useai-pro/openclaw-skills-security

Security-first vetting checklist for OpenClaw skills before installation.

20k installs
CL

clerk-setup

Official
clerk/skills

Set up Clerk authentication in any project using official quickstarts and CLI automation.

18k installs
BE

better-auth-security-best-practices

Official
better-auth/skills

Agent skill from better-auth/skills.

18k installs
PE

persona-it-admin

googleworkspace/cli

Administer Google Workspace security and configuration as an IT administrator.

18k installsAudited
GW

gws-modelarmor

googleworkspace/cli

Filter user-generated content for safety using Google Model Armor templates.

18k installsAudited
GW

gws-modelarmor-create-template

googleworkspace/cli

Create Google Model Armor templates to protect AI models from jailbreak and safety attacks.

17k installsAudited
GW

gws-modelarmor-sanitize-prompt

googleworkspace/cli

Sanitize user prompts through Google Model Armor templates for safety compliance.

17k installsAudited
GW

gws-modelarmor-sanitize-response

googleworkspace/cli

Sanitize model responses through Google Model Armor templates for outbound safety.

17k installs
SE

security-requirement-extraction

wshobson/agents

Transform threat models into actionable security requirements and test cases.

15k installsAudited
CL

clerk

Official
clerk/skills

Clerk authentication router that directs you to the right skill for your auth task.

15k installsAudited
BE

best-practices

addyosmani/web-quality-skills

Apply modern web development best practices for security, compatibility, and code quality.

12k installsAudited
IN

insforge-integrations

insforge/agent-skills

Wire external auth providers (Clerk, Auth0, WorkOS, Kinde, Stytch, Better Auth) or OKX x402 payment into InsForge.

12k installs
SO

solidity-security

wshobson/agents

Master smart contract security best practices and prevent common Solidity vulnerabilities.

12k installs
SQ

sql-code-review

Official
github/awesome-copilot

Comprehensive SQL code review for security, performance, and maintainability across MySQL, PostgreSQL, SQL Server, and Oracle.

12k installs
K8

k8s-security-policies

wshobson/agents

Implement NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards for production Kubernetes security.

11k installsAudited
GD

gdpr-data-handling

wshobson/agents

Implement GDPR-compliant data handling with consent management and data subject rights.

11k installs
SE

security-review

affaan-m/everything-claude-code

Security checklist and patterns for authentication, input validation, secrets, and sensitive features.

11k installs
AU

auth-implementation-patterns

wshobson/agents

Master JWT, OAuth2, session management, and RBAC patterns for secure, scalable authentication systems.

9.7k installsAudited
SE

secrets-management

wshobson/agents

Secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, and native platform solutions.

9.4k installs
AZ

azure-role-selector

Official
github/awesome-copilot

Find the least-privilege Azure role for any permission requirement and apply it.

9.2k installs
AG

agent-governance

Official
github/awesome-copilot

Governance, safety, and trust controls for AI agent systems with tool access.

9.2k installs
WC

wcag-audit-patterns

wshobson/agents

Conduct WCAG 2.2 accessibility audits with automated testing, manual verification, and remediation guidance.

8.9k installsAudited
SE

security-review

Official
getsentry/skills

Confidence-based security code review that flags only exploitable vulnerabilities, not theoretical noise.

8.8k installs
EM

emblem-ai-agent-wallet

emblemcompany/agent-skills

Give your coding agent a review-first, multi-chain crypto wallet via EmblemVault/EmblemAI.

8.8k installs
EM

emblem-ai

emblemcompany/agent-skills

Add wallet, email, and social login with wallet-enabled user accounts and an embeddable AI chat assistant in one integration.

8.7k installs
ME

memory-safety-patterns

wshobson/agents

Cross-language RAII, ownership, and smart pointer patterns for memory-safe Rust, C++, and C code.

8.6k installsAudited
PR

protocol-reverse-engineering

wshobson/agents

Capture, analyze, and document network protocols for security research and debugging.

8.4k installs
VE

verified-agent-identity

billionsnetwork/verified-agent-identity

Decentralized identity for agents: link to humans, verify ownership, and generate authentication proofs on Billions Network.

8.1k installs
ME

memory-forensics

wshobson/agents

Acquire and analyze memory dumps using Volatility to detect malware, extract artifacts, and investigate incidents.

8.1k installs
ST

stride-analysis-patterns

wshobson/agents

Apply STRIDE methodology to systematically identify threats across authentication, integrity, confidentiality, availability, and authorization.

8.0k installsAudited
TH

threat-mitigation-mapping

wshobson/agents

Map threats to security controls and mitigations for effective defense planning.

8.0k installsAudited
AT

attack-tree-construction

wshobson/agents

Visualize attack scenarios and defense gaps with systematic threat path mapping.

7.9k installs
WA

wallet

starchild-ai-agent/official-skills

Multi-chain wallet for EVM and Solana: check balances, send tokens, sign data, and manage policies.

7.9k installs
AP

api-security-best-practices

sickn33/antigravity-awesome-skills

Implement secure API design patterns: authentication, authorization, input validation, rate limiting, and vulnerability protection.

7.7k installs
AN

anti-reversing-techniques

wshobson/agents

Identify and bypass anti-reversing protections in authorized security analysis and malware research.

7.7k installs
SA

sast-configuration

wshobson/agents

Configure SAST tools (Semgrep, SonarQube, CodeQL) for automated vulnerability detection in CI/CD pipelines.

7.7k installsAudited
PC

pci-compliance

wshobson/agents

Implement PCI DSS compliance for secure payment card handling and processing.

7.6k installs
MT

mtls-configuration

wshobson/agents

Configure mutual TLS for zero-trust service-to-service communication with certificate management.

7.4k installs
LI

linkerd-patterns

wshobson/agents

Lightweight, security-first service mesh patterns for Kubernetes with automatic mTLS and traffic control.

7.3k installs
GO

google-cloud-recipe-auth

google/skills

Expert guidance on authenticating and authorizing to Google Cloud services, APIs, and identities.

7.3k installsAudited
SE

security-and-hardening

addyosmani/agent-skills

Hardens code against vulnerabilities in user input, authentication, data storage, and external integrations.

7.0k installs
GO

google-cloud-waf-security

google/skills

Security guidance for Google Cloud workloads based on the Well-Architected Framework

6.6k installsAudited
CO

code-review

Official
anthropics/knowledge-work-plugins

Review code changes for security, performance, and correctness issues before merging.

6.3k installsAudited
DJ

django-security

affaan-m/everything-claude-code

Django security best practices, authentication, authorization, and deployment hardening.

6.3k installs
SP

springboot-security

affaan-m/everything-claude-code

Spring Security best practices for authentication, authorization, validation, CSRF, secrets, headers, and rate limiting in Java Spring Boot.

6.2k installsAudited

MCP Servers

600+ tools for JavaScript analysis, security auditing, browser automation, and reverse engineering in a single MCP server.

1.9k
TypeScript
AGPL-3.0
View repository →

Securely run LLM-generated code in isolated containers across 7 languages and 3 backends.

1.1k
Python
MIT
View repository →

Real-time malicious package detection and software supply chain security for AI agents and IDEs.

1.1k
Go
Apache-2.0
View repository →

Fail-closed policy gate for AI agent actions with local evaluation and pre-tool authorization hooks.

534
TypeScript
Apache-2.0
View repository →

HOL Guard

Active

Local-first antivirus for AI agents that detects secrets, prompt injection, unsafe commands, and supply-chain risks.

453
Python
Apache-2.0
View repository →

Brazilian KYC/KYB via MCP: face auth + liveness, document OCR, and onboarding orchestration.

267
JavaScript
MIT
View repository →

Brazilian KYC/KYB platform with biometrics, OCR, ICP-Brasil e-signature, and onboarding for AI agents.

267
JavaScript
MIT
View repository →

Fraud prevention and order risk scoring for Brazilian e-commerce, via MCP.

267
JavaScript
MIT
View repository →

Identity verification, liveness checks, and AML screening for AI agents via Jumio's KYX platform.

267
JavaScript
MIT
View repository →

Order risk scoring, device intel, and fraud lists for Konduto via MCP.

267
JavaScript
MIT
View repository →

Real-time fraud scoring and chargeback feedback for Brazilian e-commerce orders via MCP.

267
JavaScript
MIT
View repository →

Run Onfido identity verification and KYC checks — applicants, documents, checks, workflows — from your AI agent.

267
JavaScript
MIT
View repository →

MCP access to Persona's identity verification and KYC API — inquiries, accounts, and reports.

267
JavaScript
MIT
View repository →

Brazilian identity + KYC verification: CPF/CNPJ lookup, OCR, face matching, liveness detection, PEP/watchlist screening.

267
JavaScript
MIT
View repository →

Website QA tool for coding agents: audit SEO, performance, security, accessibility with 273 rules and exact fixes over MCP.

254
TypeScript
MIT
View repository →

AI-powered security analysis and automation through CrowdStrike Falcon platform integration

206
Python
MIT
View repository →

AI-powered threat hunting & incident response for Elasticsearch/OpenSearch with 139 MCP tools and 6,060 detection rules.

206
Python
GPL-3.0
View repository →

Auto-fetch and visualize DMARC email authentication reports in a lightweight dashboard.

193
Go
Apache-2.0
View repository →

AI-powered reverse engineering and malware analysis via MCP with 120 tools for static/dynamic analysis, forensics, and SAST.

188
Python
MIT
View repository →

AI-powered packet analysis with tshark—security audits, threat detection, and network deep-dives in plain English.

158
Python
MIT
View repository →

Encrypted shared workspaces for AI agents—one link, read-write access, server cannot see content

155
TypeScript
MIT
View repository →

Query VirusTotal API for comprehensive security analysis of files, URLs, IPs, and domains.

134
TypeScript
MIT
View repository →

AI agent security middleware: 7 MCP tools for prompt injection detection, PII scanning, command safety, and data exfiltration blocking.

129
TypeScript
Apache-2.0
View repository →

Security scanner for AI agents: blocks prompt injection, detects fake packages, audits MCP servers, and scans code vulnerabilities.

120
JavaScript
MIT
View repository →

Deterministic security scanning with no model or API key, plus governed coding tasks for humans and AI agents.

112
TypeScript
MIT
View repository →

Manage Auth0 applications, APIs, actions, and logs using natural language through Claude, Cursor, or Windsurf.

111
TypeScript
MIT
View repository →

AES-256-GCM encrypted secrets for Next.js with no external vault required.

109
TypeScript
View repository →

Append-only, signed, on-chain-verifiable agent action log for auditing AI agent behavior.

98
JavaScript
View repository →

Access and manage 1Password credentials and secrets directly from your AI agent via the CLI.

77
TypeScript
MIT
View repository →

Security-hardened NotebookLM MCP with post-quantum encryption, Gemini Deep Research, and 17 security layers for enterprise compliance.

69
TypeScript
MIT
View repository →

AWS security scanner that finds attack chains, IAM escalation paths, and prioritized fixes.

69
Python
MIT
View repository →

Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.

59
Java
Apache-2.0
View repository →

Agentic memory for cyber threat intelligence. STIX graphs, actor aliasing, offline RAG, Sigma/YARA.

58
Python
MIT
View repository →

Server security audit (413 checks), hardening, and fleet management across 4 cloud providers.

57
TypeScript
Apache-2.0
View repository →

Easily find and fix security issues in your applications leveraging Snyk platform capabilities.

54
Go
Apache-2.0
View repository →

ProofFlow

Active

Audit infrastructure for AI coding agents with evidence-backed review and policy gates.

48
Python
MIT
View repository →

AI agent tools for Open Security Controls Assessment Language (OSCAL)

47
Python
Apache-2.0
View repository →

Manage Zscaler Zero Trust Exchange via 400+ tools — ZPA, ZIA, ZDX, ZCC, ZTW, ZMS, EASM, and more.

46
Python
MIT
View repository →

Local-first MCP security scanner and CLI for AI-generated applications.

42
TypeScript
Apache-2.0
View repository →

Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.

41
TypeScript
MIT
View repository →

Fair-price checks, leaderboards, and Ed25519 receipt verification for x402/MPP services.

40
TypeScript
Apache-2.0
View repository →

Python MCP server: fair-price checks, leaderboards, Ed25519 receipt verification for x402/MPP.

40
TypeScript
Apache-2.0
View repository →

MCP server exposing Signet cryptographic signing, verification, and content hash tools over stdio.

37
Rust
Apache-2.0
View repository →

Scan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.

33
JavaScript
MIT
View repository →

AI agent identity, permissions, trust scores, and tamper-evident audit trails via Vorim AI

33
JavaScript
MIT
View repository →

AI agent identity, permissions, trust scores, and tamper-evident audit trails via Vorim AI

33
JavaScript
MIT
View repository →

OAuth 2.0 for AI agents — scoped delegation tokens, audit trails, and revocation.

31
TypeScript
View repository →

Guardrailed FHIR access for AI agents: PHI redaction, audit trail, step-up auth, tenant isolation

30
Python
MIT
View repository →

Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.

30
TypeScript
MIT
View repository →

agent-bom

Active

Security scanner and graph for agentic infrastructure — agents, MCP, runtime, and blast radius.

29
Python
Apache-2.0
View repository →

55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.

28
Python
MIT
View repository →

AI safety middleware — detects self-harm and criminal intent in LLM prompts.

28
Python
Apache-2.0
View repository →

Intent-bound action authorization for AI agents: policy, human approval, and a signed audit trail.

27
Python
Apache-2.0
View repository →

Git-native policy layer for AI agents: check_action verdicts against rules approved via PR.

27
TypeScript
Apache-2.0
View repository →

Sign and verify W3C Verifiable Credentials so AI agents can cryptographically authorize actions.

27
Python
View repository →

Abnormal Security email threats, cases, and reporting in your terminal and your AI agents.

25
Go
View repository →

Every Action1 endpoint, plus fleet-wide patch and vulnerability views across all your organizations.

25
Go
View repository →

Cross-account Blumira findings, detections, and agents in one offline-searchable store.

25
Go
View repository →

Every CrowdStrike Falcon MSP operation, plus a Flight-Control-aware local store that answers

25
Go
View repository →

Every Huntress endpoint, plus a local SQLite mirror that delivers fleet-wide incident, coverage

25
Go
View repository →

Plugins

Pattern-based and LLM-powered security review for Claude-generated code with agentic commit analysis.

Claude
142k
View repository →

Harden APIs with authentication, authorization, rate limiting, and input validation.

Claude
Codex
39k
View repository →

Prevents AI agents from bypassing git hooks with --no-verify and similar flags

Claude
Codex
39k
View repository →

XSS prevention, CSRF protection, and mobile app security patterns for frontend applications

Claude
Codex
39k
View repository →

Cedar policy enforcement with cryptographic receipts for every Claude Code tool call.

Claude
Codex
39k
View repository →

Binary reverse engineering and malware analysis tools for authorized security research

Claude
Codex
39k
View repository →

Require human approval before AI agents post PR reviews, comments, merges, or CI config changes.

Claude
Codex
39k
View repository →

Validate SOC2, HIPAA, and GDPR compliance with automated secrets scanning and regulatory checklists.

Claude
Codex
39k
View repository →

SAST analysis, dependency scanning, and container security in one plugin

Claude
Codex
39k
View repository →

Cedar-gated tool calls with Ed25519 receipts and offline verification for Claude Code.

Claude
Codex
39k
View repository →

Deep vulnerability scanning and automated patching for your code, verified by agent consensus before reporting.

Claude
34k
View repository →

Pattern-based and LLM-powered security review for Claude-generated code with agentic commit analysis.

Claude
34k
View repository →

AWS DevOps and Security agents for incident investigation, code review, vulnerability scanning, and penetration testing.

Claude
Codex
Cursor
2.4k
View repository →

audit

Stale

Perform security audits on your codebase to identify vulnerabilities and risks.

Claude
688
View repository →

Implement GDPR compliance, data privacy engineering, and privacy-by-design for enterprise B2B applications.

Claude
688
View repository →

Comprehensive B2B security assessments and enterprise compliance validation for SaaS platforms.

Claude
688
View repository →

Review legal documents and ensure regulatory compliance for app development.

Claude
688
View repository →

sonarqube

Active

Enforce code quality and security standards with SonarQube's 7,500+ issue types and secrets scanning in your agent coding loop.

Claude
Codex
Cursor
100
View repository →

zscaler

Active

Manage Zscaler cloud security platform policies, access, and incidents across ZPA, ZIA, ZDX, and more.

Claude
Cursor
46
View repository →

auth0

Active

Unified Auth0 authentication setup for any framework with auto-detected guides for login, MFA, Organizations, and more.

Claude
Codex
Cursor
44
View repository →

workos

Active

WorkOS integration skills for authentication, SSO, directory sync, and access control.

Claude
Codex
Cursor
44
View repository →

Build cybersecurity applications on CrowdStrike Falcon Foundry with UI, workflows, and API integration skills.

Claude
Codex
24
View repository →

crowdsec

Active

Operational and API skills for CrowdSec engine, bouncers, WAF, and Console cloud management.

Claude
23
View repository →

Run DAST security scans and transform findings into prioritized fix tasks for your codebase.

Claude
Codex
15
View repository →

Query StackHawk platform API for security findings, posture reporting, and app management.

Claude
Codex
15
View repository →

aikido

Active

Scan code for vulnerabilities, secrets, and IaC issues using Aikido Security.

Claude
13
View repository →

OAuth/OIDC, IdentityServer, and ASP.NET Core identity architecture skills for Claude Code

Claude
10
View repository →

Scan agent-generated code for security vulnerabilities with Semgrep

Claude
10
View repository →

Author, deploy, and execute CrowdStrike Falcon Fusion workflows with live action discovery and schema validation.

Claude
Codex
6
View repository →

JFrog

Active

Connect Claude Code to JFrog to manage, secure, and govern your software supply chain.

Claude
4
View repository →

sonatype-guide

Maintained

Scan dependencies for vulnerabilities and get security recommendations from Sonatype intelligence.

Claude
4
View repository →

Connect Claude Code to Vanta for security and compliance management

Claude
3
View repository →

Find exploitable vulnerabilities in web applications and REST APIs with NightVision DAST scanning.

Claude
2
View repository →

Catch API security issues during development with automated audit, scan, and remediation.

Claude
1
View repository →

Agents

Expert backend security coding for input validation, authentication, API security, and vulnerability prevention.

sonnet
39k
via wshobson/agents

Security auditor for code and architecture review during feature development.

sonnet
39k
via wshobson/agents

Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.

opus
39k
via wshobson/agents

Expert backend security coder for input validation, authentication, API security, and vulnerability prevention.

sonnet
39k
via wshobson/agents

Expert firmware extraction, analysis, and vulnerability research for embedded systems and IoT devices.

opus
39k
via wshobson/agents

Expert in secure frontend coding: XSS prevention, CSP configuration, and client-side vulnerability fixes.

sonnet
39k
via wshobson/agents

Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.

opus
39k
via wshobson/agents

Expert malware analyst for defensive research, threat intelligence, and incident response

opus
39k
via wshobson/agents

Expert in secure mobile coding: input validation, WebView security, and mobile-specific vulnerability fixes.

sonnet
39k
via wshobson/agents

Cedar policy author and reviewer for Claude Code tool authorization rules.

opus
39k
via wshobson/agents

Verify Ed25519-signed receipts, detect tampering, and audit hash-chained audit trails.

sonnet
39k
via wshobson/agents

Expert binary analysis and reverse engineering for authorized security research, CTF challenges, and malware defense.

opus
39k
via wshobson/agents

Cedar policy expert for gating AI agent review actions (comments, merges, CI edits) behind human approval.

sonnet
39k
via wshobson/agents

Expert security auditor for DevSecOps, vulnerability assessment, and compliance framework implementation.

opus
39k
via wshobson/agents

Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.

opus
39k
via wshobson/agents

Focused code reviewer for one quality dimension (security, performance, architecture, testing, accessibility) with structured findings.

opus
39k
via wshobson/agents

Identify and prioritize security threats using STRIDE, PASTA, and attack trees before they become vulnerabilities.

opus
39k
via wshobson/agents

Rules

27 architecture rules for Next.js 15 + Supabase: prevent auth bypasses, RLS gaps, and runtime crashes.

**/*
41k
via PatrickJS/awesome-cursorrules

Secure coding, secrets management, dependency hygiene, and SSDLC practices across multiple languages.

["**/*.py" +8
41k
via PatrickJS/awesome-cursorrules

Secure Solana wallet architecture with MEV defense, transaction safety checks, and isolated signer subprocesses.

**/*.{ts +5
41k
via PatrickJS/awesome-cursorrules