PluginBench
Category

Best Security tools

3119 tools in the Security category across every type.

Skills

ENentra-app-registration logo

entra-app-registration

Official
microsoft/azure-skills

Guide Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

610k installsAudited
AZazure-compliance logo

azure-compliance

Official
microsoft/azure-skills

Run Azure compliance and security audits with azqr and Key Vault expiration checks.

610k installsAudited
AZazure-rbac logo

azure-rbac

Official
microsoft/azure-skills

Find the least-privilege Azure RBAC role, then generate CLI commands and Bicep code to assign it.

493k installs
GIgit-guardrails-claude-code logo

git-guardrails-claude-code

mattpocock/skills

Block dangerous git commands (push, reset, clean) in Claude Code before execution.

414k installs
ENentra-agent-id logo

entra-agent-id

Official
microsoft/azure-skills

Provision OAuth 2.0 identities for AI agents with per-instance audit trails via Microsoft Entra and Microsoft Graph.

332k installs
FIfirebase-auth-basics logo

firebase-auth-basics

Official
firebase/agent-skills

Set up Firebase Authentication for user sign-in, management, and secure data access.

161k installsAudited
FIfirebase-security-rules-auditor logo

firebase-security-rules-auditor

Official
firebase/agent-skills

Audit Firebase security rules for vulnerabilities, privilege escalation, and compliance gaps.

125k installsAudited
BEbetter-auth-best-practices logo

better-auth-best-practices

Official
better-auth/skills

Configure Better Auth server and client with database adapters, sessions, plugins, and OAuth.

116k installs
COconvex-setup-auth logo

convex-setup-auth

get-convex/agent-skills

Set up secure authentication in Convex with user management and access control.

94k installsAudited
MUmulti-account-isolation logo

multi-account-isolation

antibrow/anti-detect-browser-skills

Verify browser profile isolation: timezone, WebRTC, canvas hash, cookies, and personas are not shared across accounts.

75k installs
AUaudit-website logo

audit-website

squirrelscan/skills

Audit websites against 260+ rules (SEO, performance, security, accessibility) and drive fixes to code until scores improve.

72k installs
BRbrowser-fingerprint-audit logo

browser-fingerprint-audit

liarjsdev/liarjs-skills

Audit browser fingerprints for internal contradictions and spoofing indicators.

71k installsAudited
FIfingerprint-failure-triage logo

fingerprint-failure-triage

liarjsdev/liarjs-skills

Attribute fingerprint check failures to their source component for targeted remediation.

71k installsAudited
TUturnstile-spin logo

turnstile-spin

cloudflare/skills

Set up, repair, or migrate Cloudflare Turnstile bot verification end-to-end in your frontend and backend.

70k installsAudited
CLcloudflare-one logo

cloudflare-one

cloudflare/skills

Design, configure, and troubleshoot Cloudflare One Zero Trust and SASE deployments.

68k installsAudited
INinvestigate-without-getting-made logo

investigate-without-getting-made

useosint/skills

OPSEC framework for covert investigation—control attribution surface, build aged personas, avoid detection.

58k installs
WHwhat-leaked-about-you logo

what-leaked-about-you

useosint/skills

Check which services an identity used by searching data-breach databases for email, username, phone, or name.

58k installs
CLclerk-setup logo

clerk-setup

Official
clerk/skills

Set up Clerk authentication in any project with the Clerk CLI and official framework quickstarts.

50k installs
SEsecurity-and-hardening logo

security-and-hardening

addyosmani/agent-skills

Audit and harden code against OWASP Top Ten vulnerabilities, injection, XSS, broken auth, and supply-chain risks.

48k installs
INinsforge-integrations logo

insforge-integrations

insforge/insforge-skills

Wire external auth providers and x402 payment facilitators into InsForge for JWT-based RLS and onchain billing.

45k installs
GOgolang-security logo

golang-security

samber/cc-skills-golang

Security best practices and vulnerability prevention for Go: injection, cryptography, secrets, threat modeling, and SAST tooling.

41k installsAudited
BEbetter-auth-security-best-practices logo

better-auth-security-best-practices

Official
better-auth/skills

Secure Better Auth deployments with rate limiting, CSRF protection, session hardening, and audit logging.

39k installsAudited
EMemail-and-password-best-practices logo

email-and-password-best-practices

Official
better-auth/skills

Configure email verification, password reset flows, and security policies for Better Auth email/password authentication.

38k installs
TWtwo-factor-authentication-best-practices logo

two-factor-authentication-best-practices

Official
better-auth/skills

Configure TOTP, OTP, backup codes, and trusted devices for 2FA with Better Auth.

32k installs
PE

persona-it-admin

googleworkspace/cli

Administer Google Workspace security and configuration as an IT administrator.

29k installsAudited
GW

gws-modelarmor

googleworkspace/cli

Filter user-generated content for safety using Google Model Armor templates.

29k installsAudited
GW

gws-modelarmor-create-template

googleworkspace/cli

Create Google Model Armor templates to protect AI models from jailbreak and safety attacks.

29k installsAudited
CLclerk logo

clerk

Official
clerk/skills

Router skill that directs to specialized Clerk authentication sub-skills based on your task.

28k installsAudited
GW

gws-modelarmor-sanitize-prompt

googleworkspace/cli

Sanitize user prompts through Google Model Armor templates for safety compliance.

28k installsAudited
GW

gws-modelarmor-sanitize-response

googleworkspace/cli

Sanitize model responses through Google Model Armor templates for outbound safety.

28k installs
COconvex-authz logo

convex-authz

get-convex/agent-skills

Audit and harden Convex app authorization: detect identity spoofing, missing ownership checks, PII leaks, and unsafe parent writes.

27k installsAudited
COconvex-reviewer logo

convex-reviewer

get-convex/agent-skills

Security, auth, and performance reviewer for Convex functions—catch anti-patterns before shipping.

27k installsAudited
BEbest-practices logo

best-practices

addyosmani/web-quality-skills

Apply modern web development best practices for security, compatibility, and code quality.

26k installs
EXextension-email-verification logo

extension-email-verification

caffeinelabs/skills

Email verification via click-to-verify links for proving email ownership.

23k installsAudited
EXextension-authorization logo

extension-authorization

caffeinelabs/skills

Role-based access control system for apps managing personal or restricted data.

23k installsAudited
EXextension-user-approval logo

extension-user-approval

caffeinelabs/skills

Approval-based user management for Caffeine AI applications.

23k installsAudited
SEsecurity-requirement-extraction logo

security-requirement-extraction

wshobson/agents

Transform threat models into actionable security requirements and test cases.

22k installsAudited
SKskill-vetter logo

skill-vetter

useai-pro/openclaw-skills-security

Security-first vetting checklist for OpenClaw skills before installation.

21k installs
FIfirestore-security-rules-auditor logo

firestore-security-rules-auditor

Official
firebase/agent-skills

Audit Firestore security rules for vulnerabilities and compliance with security best practices.

20k installsAudited
SEsecurity-audit logo

security-audit

cloudflare/security-audit-skill

Security guidance and vulnerability review for codebases, APIs, services, and daemons.

20k installs
SEsecurity-review logo

security-review

Official
getsentry/skills

Systematic security code review identifying HIGH-CONFIDENCE vulnerabilities with OWASP-based analysis.

17k installs
SE

security-review

affaan-m/ecc

Comprehensive security checklist and patterns for authentication, input validation, secrets, and sensitive features.

17k installsAudited
STstride-analysis-patterns logo

stride-analysis-patterns

wshobson/agents

Apply STRIDE methodology to systematically identify threats across authentication, integrity, confidentiality, availability, and authorization.

17k installsAudited
AUauth-implementation-patterns logo

auth-implementation-patterns

wshobson/agents

Master JWT, OAuth2, session management, and RBAC patterns for secure, scalable authentication systems.

17k installsAudited
THthreat-mitigation-mapping logo

threat-mitigation-mapping

wshobson/agents

Map threats to security controls and mitigations for effective defense planning.

16k installsAudited
SOsolidity-security logo

solidity-security

wshobson/agents

Master smart contract security best practices and prevent common Solidity vulnerabilities.

15k installs
ATattack-tree-construction logo

attack-tree-construction

wshobson/agents

Visualize attack scenarios and defense gaps with systematic threat path mapping.

15k installs
GDgdpr-data-handling logo

gdpr-data-handling

wshobson/agents

Implement GDPR-compliant data handling with consent management and data subject rights.

14k installs
K8k8s-security-policies logo

k8s-security-policies

wshobson/agents

Implement NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards for production Kubernetes security.

14k installsAudited
GOgoogle-cloud-recipe-auth logo

google-cloud-recipe-auth

google/skills

Expert guidance on authenticating and authorizing to Google Cloud services, APIs, and identities.

14k installsAudited
CLclerk-swift logo

clerk-swift

Official
clerk/skills

Clerk authentication for native Swift and iOS apps using ClerkKit and ClerkKitUI.

14k installs
SQsql-code-review logo

sql-code-review

Official
github/awesome-copilot

Comprehensive SQL code review for security, performance, and maintainability across MySQL, PostgreSQL, SQL Server, and Oracle.

13k installs
GOgoogle-cloud-waf-security logo

google-cloud-waf-security

google/skills

Security guidance for Google Cloud workloads based on the Well-Architected Framework.

13k installsAudited
SEsecrets-management logo

secrets-management

wshobson/agents

Secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, and platform-native solutions.

12k installs
HUhuawei-cloud-iam-query logo

huawei-cloud-iam-query

huaweicloud/huaweicloud-skills

Query Huawei Cloud IAM resources (users, groups, policies, agencies, credentials, MFA) via read-only Python SDK.

12k installs
WCwcag-audit-patterns logo

wcag-audit-patterns

wshobson/agents

Conduct WCAG 2.2 accessibility audits with automated testing, manual verification, and remediation guidance.

12k installsAudited
PRprotocol-reverse-engineering logo

protocol-reverse-engineering

wshobson/agents

Capture, analyze, and document network protocols for security research and debugging.

12k installs
MEmemory-safety-patterns logo

memory-safety-patterns

wshobson/agents

Cross-language RAII, ownership, and smart pointer patterns for memory-safe Rust, C++, and C code.

11k installsAudited
PEpenetration-testing-with-strix logo

penetration-testing-with-strix

usestrix/strix

Autonomous AI penetration testing that exploits and proves vulnerabilities with proof-of-concept exploits.

11k installs
AGagent-email-inbox logo

agent-email-inbox

Official
resend/resend-skills

Secure email inbox for AI agents with sender validation and sandboxed processing.

11k installs

MCP Servers

600+ tools for JavaScript analysis, security auditing, browser automation, and reverse engineering in a single MCP server.

1.9k
TypeScript
AGPL-3.0
View repository →
LLLLM Sandbox logo

Securely run LLM-generated code in isolated containers across 7 languages and 3 backends.

1.1k
Python
MIT
View repository →

Real-time malicious package detection and software supply chain security for AI agents and IDEs.

1.1k
Go
Apache-2.0
View repository →

Policy-gated SSH access for LLM agents with role-based authorization, approval workflows, and audit logging.

773
TypeScript
MIT
View repository →

Authorize consequential AI agent actions before execution through an independent policy boundary.

589
TypeScript
Apache-2.0
View repository →
HOHOL Guard logo

HOL Guard

Active

Local-first antivirus for AI agents—detect and block secrets, prompt injection, unsafe commands, and supply-chain risks before execution.

453
Python
Apache-2.0
View repository →

DEPRECATED: Latin America commerce API collection with no live endpoint.

267
JavaScript
MIT
View repository →

DEPRECATED: Certta MCP server for Latin American commerce — no longer operational.

267
JavaScript
MIT
View repository →

Fraud prevention and order risk scoring for Brazilian e-commerce, via MCP.

267
JavaScript
MIT
View repository →

Identity verification, liveness checks, and AML screening for AI agents via Jumio's KYX platform.

267
JavaScript
MIT
View repository →

Order risk scoring, device intel, and fraud lists for Konduto via MCP.

267
JavaScript
MIT
View repository →

DEPRECATED: Collection of 110 MCP servers for Latin American commerce, payments, fiscal, logistics, and banking APIs.

267
JavaScript
MIT
View repository →

Run Onfido identity verification and KYC checks — applicants, documents, checks, workflows — from your AI agent.

267
JavaScript
MIT
View repository →

MCP access to Persona's identity verification and KYC API — inquiries, accounts, and reports.

267
JavaScript
MIT
View repository →

DEPRECATED: Unico identity verification MCP server with no active endpoint.

267
JavaScript
MIT
View repository →
SQsquirrelscan logo

Website QA tool for coding agents: audit SEO, performance, security, accessibility with 273 rules and exact fixes over MCP.

254
TypeScript
MIT
View repository →

Append-only, signed, on-chain-verifiable agent action log for auditing AI agent behavior.

218
JavaScript
Apache-2.0
View repository →
NOnode9 logo

node9

Active

Access control for AI agents: allow, hold for approval, or block each tool call

216
TypeScript
Apache-2.0
View repository →

AI-powered security analysis and automation for CrowdStrike Falcon platform

206
Python
MIT
View repository →

AI-powered threat hunting & incident response for Elasticsearch/OpenSearch with 139 MCP tools and 6,060 detection rules.

206
Python
GPL-3.0
View repository →

Auto-fetch and visualize DMARC email authentication reports in a lightweight dashboard.

193
Go
Apache-2.0
View repository →

AI-powered reverse engineering, malware analysis, and security auditing via 120 integrated tools

188
Python
MIT
View repository →

AI-powered packet analysis with tshark—security audits, threat detection, and network deep-dives in plain English.

158
Python
MIT
View repository →

Encrypted shared workspaces for AI agents—one link, read-write access, server cannot see content

155
TypeScript
MIT
View repository →

Query VirusTotal API for comprehensive security analysis of files, URLs, IPs, and domains.

134
TypeScript
MIT
View repository →

AI agent security middleware: 7 MCP tools for prompt injection detection, PII scanning, command safety, and data exfiltration blocking.

129
TypeScript
Apache-2.0
View repository →

Security scanner for AI agents: blocks prompt injection, detects fake packages, audits MCP servers, and scans code vulnerabilities.

120
JavaScript
MIT
View repository →

Deterministic security scanning with offline-verifiable fixes—no API keys, no models required.

112
TypeScript
MIT
View repository →

Manage Auth0 applications, APIs, actions, and logs using natural language through Claude, Cursor, or Windsurf.

111
TypeScript
MIT
View repository →

AES-256-GCM encrypted secrets for Next.js with no external vault required.

109
TypeScript
View repository →

Access and manage 1Password credentials and secrets directly from your AI agent via the CLI.

77
TypeScript
MIT
View repository →

Security-hardened NotebookLM MCP with post-quantum encryption, Gemini Deep Research, and enterprise compliance.

69
TypeScript
MIT
View repository →
CLcloud-audit logo

AWS security scanner that finds attack chains, IAM escalation paths, and prioritized fixes.

69
Python
MIT
View repository →

670+ security tools for CTF, pentest, and DFIR, driven by AI agents through governed execution in a sandbox VM.

65
Python
MIT
View repository →
KEKeibiDrop logo

KeibiDrop

Active

P2P encrypted folder sync between machines—no cloud, only bytes you read move across the network.

61
Go
View repository →

Safe, self-hosted OWASP ZAP operator for AI-guided web security scans with operator control and production guardrails.

59
Java
Apache-2.0
View repository →
ZEZettelForge logo

Agentic memory system for cyber threat intelligence with STIX graphs, actor aliasing, and offline RAG.

58
Python
MIT
View repository →

AI-native server security audit, hardening, and fleet management across 4 cloud providers with 449 checks.

57
TypeScript
Apache-2.0
View repository →
IOio.snyk/mcp logo

Integrate Snyk security scanning directly into AI workflows via MCP.

54
Go
Apache-2.0
View repository →
PRProofFlow logo

ProofFlow

Active

Audit infrastructure for AI coding agents with evidence-backed review and policy gates.

48
Python
MIT
View repository →

AI agent tools for working with NIST's Open Security Controls Assessment Language (OSCAL)

47
Python
Apache-2.0
View repository →

AI-powered management of Zscaler Zero Trust Exchange with 400+ tools across ZPA, ZIA, ZDX, ZCC, and more.

46
Python
MIT
View repository →

Local-first security scanner for AI-generated code—no account, no network egress, MCP-ready.

42
TypeScript
Apache-2.0
View repository →

AI code-review assistant that hunts security issues via hypothesis-driven scanning, variant analysis, and multi-stage verification.

41
TypeScript
MIT
View repository →

Fair-price checks, leaderboards, and Ed25519 receipt verification for x402/MPP services.

40
TypeScript
Apache-2.0
View repository →

Fair-price verification and leaderboard management for x402/MPP micropayment protocol.

40
TypeScript
Apache-2.0
View repository →
SISignet MCP Tools logo

Cryptographic signing and verification for AI agent tool calls — tamper-evident receipts, offline-verifiable.

37
Rust
Apache-2.0
View repository →

Scan Solana/Anchor code against 52 security rules drawn from $514M in real exploits, firing in Claude, Cursor, Windsurf, and CI.

33
JavaScript
MIT
View repository →

Cryptographic identity, scoped permissions, and tamper-evident audit trails for AI agents.

33
JavaScript
MIT
View repository →

Cryptographic identity, scoped permissions, and tamper-evident audit trails for AI agents.

33
JavaScript
MIT
View repository →

OAuth 2.0 for AI agents — scoped delegation tokens, audit trails, and revocation.

31
TypeScript
View repository →

Open-source security layer for AI agents accessing clinical data: PHI redaction, audit trails, step-up auth, and tenant isolation.

30
Python
MIT
View repository →

Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.

30
TypeScript
MIT
View repository →
AGagent-bom logo

agent-bom

Active

Security scanner and control plane for AI agents, MCP servers, and cloud infrastructure—discover vulnerabilities and trace blast radius.

29
Python
Apache-2.0
View repository →
COContrastAPI logo

55 security tools for AI agents: CVE/KEV lookup, vulnerability assessment, threat intelligence, and OSINT—free, no API key.

28
Python
MIT
View repository →

AI safety middleware that detects self-harm and criminal intent in LLM prompts before they reach the model.

28
Python
Apache-2.0
View repository →

Zero-dependency Web Crypto MCP server with AES-256-GCM, RSA-4096, and post-quantum cryptography for AI agents.

28
JavaScript
MIT
View repository →

Intent-bound action authorization for AI agents: policy, human approval, and signed audit trail.

27
Python
Apache-2.0
View repository →
MCmcp-airlock logo

Governance proxy for MCP servers: allowlist, dry-run enforcement, human confirmation, blast-radius limits, and audit trails.

27
Python
MIT
View repository →

Git-native policy layer for AI agents: approve rules via PR, agents check actions before acting.

27
TypeScript
Apache-2.0
View repository →

Plugins

Pattern-based and LLM-powered security review for Claude-generated code with agentic commit analysis.

Claude
149k
View repository →

Harden APIs with authentication, authorization, rate limiting, and input validation.

Claude
Codex
40k
View repository →

Prevent AI agents from bypassing git hooks with --no-verify and similar flags

Claude
Codex
40k
View repository →

XSS prevention, CSRF protection, and mobile app security patterns for frontend applications

Claude
Codex
40k
View repository →
PRprotect-mcp logo

Cryptographic governance for Claude Code with Cedar policies and Ed25519-signed call receipts.

Claude
Codex
40k
View repository →

Binary reverse engineering and malware analysis tools for authorized security research

Claude
Codex
40k
View repository →

Require human approval before AI agents post PR reviews, comments, merges, or CI config changes.

Claude
Codex
40k
View repository →

Validate SOC2, HIPAA, and GDPR compliance with automated secrets scanning and regulatory checklists.

Claude
Codex
40k
View repository →

SAST analysis, dependency scanning, and container security in one plugin

Claude
Codex
40k
View repository →

Cedar-gated tool calls with Ed25519 receipts and offline verification for Claude Code.

Claude
Codex
40k
View repository →

Deep vulnerability scanning of your own code with agent-verified findings and targeted patches.

Claude
37k
View repository →

Pattern-based and LLM-powered security review for Claude-generated code.

Claude
37k
View repository →

Investigate incidents, review code, and execute security testing with AWS DevOps and Security agents.

Claude
Codex
Cursor
2.8k
View repository →
AUaudit logo

audit

Stale

Perform security audits on your codebase to identify vulnerabilities and risks.

Claude
690
View repository →

Implement GDPR compliance, data privacy engineering, and privacy-by-design for enterprise B2B applications.

Claude
690
View repository →

Comprehensive B2B security assessments and enterprise compliance validation for SaaS platforms.

Claude
690
View repository →

Review legal documents and ensure regulatory compliance for app development.

Claude
690
View repository →
SOsonarqube logo

sonarqube

Active

AI-powered code quality and security verification with 7,500+ issue types and secrets scanning.

Claude
Codex
Cursor
108
View repository →
AUauth0 logo

auth0

Active

Unified Auth0 authentication setup guide for any framework and feature.

Claude
Codex
Cursor
52
View repository →
ZSzscaler logo

zscaler

Active

Manage Zscaler cloud security platform policies, connectivity, and incidents across ZPA, ZIA, ZDX, and more.

Claude
Cursor
50
View repository →
WOworkos logo

workos

Active

WorkOS integration skills for authentication, SSO, directory sync, and access control.

Claude
Codex
Cursor
45
View repository →

CrowdStrike Falcon Foundry development skills for building cybersecurity applications on the Falcon platform.

Claude
Codex
28
View repository →
CRcrowdsec logo

crowdsec

Active

Operational and API skills for CrowdSec security engine, bouncers, WAF, and bot detection.

Claude
24
View repository →

Author, deploy, and execute CrowdStrike Falcon Fusion workflows with live action discovery and schema validation.

Claude
Codex
20
View repository →

Run HawkScan DAST security scans and transform findings into prioritized fix tasks for your code.

Claude
Codex
16
View repository →

Query StackHawk platform API for security findings, posture reporting, and app management.

Claude
Codex
16
View repository →
AIaikido logo

aikido

Active

Scan code for vulnerabilities, secrets, and IaC issues using Aikido Security.

Claude
14
View repository →

Scans agent-generated code for security vulnerabilities.

Claude
14
View repository →

OAuth/OIDC, IdentityServer, and ASP.NET Core authentication skills for secure identity architecture

Claude
Codex
9
View repository →
JFJFrog logo

JFrog

Active

Connect Claude Code to JFrog to manage, secure, and govern your software supply chain.

Claude
6
View repository →

Scan dependencies for vulnerabilities and get security recommendations from Sonatype intelligence.

Claude
4
View repository →
VAvanta-mcp-plugin logo

Connect Claude Code to Vanta for security and compliance management

Claude
4
View repository →
HOhol-guard logo

hol-guard

Active

Local pre-execution security controls and scanning for AI agent tools and plugins.

Claude
3
View repository →
NInightvision logo

DAST and API discovery skills for finding vulnerabilities in web applications and REST APIs

Claude
3
View repository →

Catch API security issues during development with automated audit, scan, and remediation.

Claude
1
View repository →

Agents

Expert backend security coding for input validation, authentication, and API security implementation.

sonnet
40k
via wshobson/agents

Audit Active Directory security posture, privilege escalation risks, and authentication hardening.

inherit
25k
via VoltAgent/awesome-claude-code-subagents

Comprehensive Python security expertise for cryptography, secure coding, vulnerability assessment, and compliance.

4.4k
via vijaythecoder/awesome-claude-agents
SEsecurity-auditor logo

Comprehensive security audit agent that identifies vulnerabilities and generates actionable remediation reports.

2.0k
via iannuttall/claude-agents
SEsecurity-auditor logo

Senior security auditor for comprehensive vulnerability assessment, penetration testing, and secure code review across the SDLC.

sonnet
1.7k
via lst97/claude-code-sub-agents

Auth0 implementation expert for identity management, OAuth2/OIDC flows, and secure authentication configuration

claude-sonnet-4-20250514
1.0k
via 0xfurai/claude-code-subagents

Security auditor for code and architecture review during feature development.

sonnet
40k
via wshobson/agents

Build OAuth 2.1, OIDC, SAML, and multi-tenant auth systems that validate every assertion and fail closed by default.

sonnet
25k
via VoltAgent/awesome-claude-code-subagents

Security-aware code review agent that runs automated checks and routes critical issues to specialists.

4.4k
via vijaythecoder/awesome-claude-agents
JWjwt-expert logo

JWT implementation, validation, and security best practices for token-based authentication.

claude-sonnet-4-20250514
1.0k
via 0xfurai/claude-code-subagents

Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.

opus
40k
via wshobson/agents

Regulatory compliance auditor for GDPR, HIPAA, PCI DSS, SOC 2, and ISO frameworks with automated evidence collection.

inherit
25k
via VoltAgent/awesome-claude-code-subagents

Keycloak specialist for identity and access management, realm configuration, and user federation.

claude-sonnet-4-20250514
1.0k
via 0xfurai/claude-code-subagents

Expert backend security coding for input validation, authentication, and API protection.

sonnet
40k
via wshobson/agents

Build secure, compliant payment systems and financial integrations with 100% transaction accuracy and regulatory adherence.

inherit
25k
via VoltAgent/awesome-claude-code-subagents

Expert in OAuth 2.0 and OpenID Connect for secure authentication and authorization implementation.

claude-sonnet-4-20250514
1.0k
via 0xfurai/claude-code-subagents

Expert firmware analyst for embedded systems security, IoT penetration testing, and hardware reverse engineering.

opus
40k
via wshobson/agents

Expert GDPR and CCPA/CPRA compliance guidance for product and engineering teams.

25k
via VoltAgent/awesome-claude-code-subagents

Identify and mitigate OWASP Top 10 web application security risks through expert assessment and remediation.

claude-sonnet-4-20250514
1.0k
via 0xfurai/claude-code-subagents

Expert in secure frontend coding: XSS prevention, CSP, DOM security, and client-side vulnerability fixes.

sonnet
40k
via wshobson/agents

HIPAA compliance guidance for healthcare SaaS vendors and product teams.

25k
via VoltAgent/awesome-claude-code-subagents

Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.

opus
40k
via wshobson/agents

Rapid incident response for security breaches, outages, and operational crises with evidence preservation and recovery coordination.

sonnet
25k
via VoltAgent/awesome-claude-code-subagents

Defensive malware analysis expert for threat intelligence, incident response, and security research.

opus
40k
via wshobson/agents

Design and deploy comprehensive software licensing systems with compliance pipelines, risk mitigation, and IP protection.

inherit
25k
via VoltAgent/awesome-claude-code-subagents

Expert in secure mobile coding: input validation, WebView security, and mobile-specific vulnerability fixes.

sonnet
40k
via wshobson/agents

Authorized penetration testing to identify real vulnerabilities through active exploitation and validation.

inherit
25k
via VoltAgent/awesome-claude-code-subagents

Cedar policy author and reviewer for Claude Code tool authorization rules.

opus
40k
via wshobson/agents

Harden PowerShell automation, remoting, and Windows endpoints against enterprise security baselines and compliance frameworks.

inherit
25k
via VoltAgent/awesome-claude-code-subagents

Verify Ed25519-signed receipts and detect tampering using JCS canonicalization.

sonnet
40k
via wshobson/agents
RIrisk-manager logo

Identify, quantify, and mitigate enterprise risks across financial, operational, regulatory, and strategic domains.

inherit
25k
via VoltAgent/awesome-claude-code-subagents

Expert binary analysis and reverse engineering for security research, CTF, and authorized vulnerability assessment.

opus
40k
via wshobson/agents

Comprehensive security audits, compliance assessments, and risk evaluations across systems and infrastructure.

inherit
25k
via VoltAgent/awesome-claude-code-subagents

Cedar policy expert for gating AI review actions behind human approval

sonnet
40k
via wshobson/agents

Senior security engineer for infrastructure hardening, DevSecOps automation, and compliance-driven security architecture.

inherit
25k
via VoltAgent/awesome-claude-code-subagents

Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.

opus
40k
via wshobson/agents

Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.

opus
40k
via wshobson/agents

Focused code reviewer for one quality dimension (security, performance, architecture, testing, or accessibility) with structured findings.

opus
40k
via wshobson/agents

Expert threat modeling and security architecture review using STRIDE, PASTA, and attack trees

opus
40k
via wshobson/agents

Rules

27 architecture rules for Next.js 15 + Supabase preventing auth, params, and security hallucinations

**/*
41k
via PatrickJS/awesome-cursorrules

Secure coding, secret handling, dependency hygiene, and compliance for DevSecOps and SSDLC.

["**/*.py" +8
41k
via PatrickJS/awesome-cursorrules

Secure Solana wallet architecture with MEV defense, signer isolation, and transaction safety checks.

**/*.{ts +5
41k
via PatrickJS/awesome-cursorrules