Best Security tools
2231 tools in the Security category across every type.
Skills
entra-app-registration
Guide Microsoft Entra ID app registration, OAuth 2.0 flows, and MSAL integration in your coding agent.
azure-compliance
Run Azure compliance and security audits with azqr plus Key Vault expiration checks
azure-rbac
Find the least-privilege Azure RBAC role, then generate CLI commands and Bicep code to assign it.
openclaw-secure-linux-cloud
Secure self-hosted OpenClaw on Linux cloud servers with conservative defaults: loopback binding, SSH tunneling, token auth, and minimal tool permissions.
entra-agent-id
Provision OAuth 2.0-capable identities for AI agents with per-instance audit trails via Microsoft Entra and Microsoft Graph.
firebase-auth-basics
Set up Firebase Authentication for user sign-in, management, and secure data access.
git-guardrails-claude-code
Block dangerous git commands (push, reset, clean) in Claude Code before execution.
convex-setup-auth
Set up secure authentication in Convex with user management and access control.
better-auth-best-practices
Configure Better Auth server and client with database adapters, sessions, plugins, and environment variables for TypeScript authentication.
firebase-security-rules-auditor
Audit Firestore security rules for vulnerabilities and compliance with security best practices.
audit-website
Audit websites for SEO, performance, security, and 22+ issue categories with 240+ rules using squirrelscan CLI.
golang-security
Security best practices and vulnerability prevention for Go code—injection, crypto, secrets, and authentication.
email-and-password-best-practices
Configure email verification, password reset flows, policies, and hashing for Better Auth email/password authentication.
firestore-security-rules-auditor
Audit Firestore security rules for vulnerabilities and compliance with security best practices.
two-factor-authentication-best-practices
Configure TOTP, OTP, backup codes, and trusted devices for 2FA sign-in flows with Better Auth.
skill-vetter
Security-first vetting checklist for OpenClaw skills before installation.
clerk-setup
Set up Clerk authentication in any project using official quickstarts and CLI automation.
better-auth-security-best-practices
Agent skill from better-auth/skills.
persona-it-admin
Administer Google Workspace security and configuration as an IT administrator.
gws-modelarmor
Filter user-generated content for safety using Google Model Armor templates.
gws-modelarmor-create-template
Create Google Model Armor templates to protect AI models from jailbreak and safety attacks.
gws-modelarmor-sanitize-prompt
Sanitize user prompts through Google Model Armor templates for safety compliance.
gws-modelarmor-sanitize-response
Sanitize model responses through Google Model Armor templates for outbound safety.
security-requirement-extraction
Transform threat models into actionable security requirements and test cases.
clerk
Clerk authentication router that directs you to the right skill for your auth task.
best-practices
Apply modern web development best practices for security, compatibility, and code quality.
insforge-integrations
Wire external auth providers (Clerk, Auth0, WorkOS, Kinde, Stytch, Better Auth) or OKX x402 payment into InsForge.
solidity-security
Master smart contract security best practices and prevent common Solidity vulnerabilities.
sql-code-review
Comprehensive SQL code review for security, performance, and maintainability across MySQL, PostgreSQL, SQL Server, and Oracle.
k8s-security-policies
Implement NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards for production Kubernetes security.
gdpr-data-handling
Implement GDPR-compliant data handling with consent management and data subject rights.
security-review
Security checklist and patterns for authentication, input validation, secrets, and sensitive features.
auth-implementation-patterns
Master JWT, OAuth2, session management, and RBAC patterns for secure, scalable authentication systems.
secrets-management
Secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, and native platform solutions.
azure-role-selector
Find the least-privilege Azure role for any permission requirement and apply it.
agent-governance
Governance, safety, and trust controls for AI agent systems with tool access.
wcag-audit-patterns
Conduct WCAG 2.2 accessibility audits with automated testing, manual verification, and remediation guidance.
security-review
Confidence-based security code review that flags only exploitable vulnerabilities, not theoretical noise.
emblem-ai-agent-wallet
Give your coding agent a review-first, multi-chain crypto wallet via EmblemVault/EmblemAI.
emblem-ai
Add wallet, email, and social login with wallet-enabled user accounts and an embeddable AI chat assistant in one integration.
memory-safety-patterns
Cross-language RAII, ownership, and smart pointer patterns for memory-safe Rust, C++, and C code.
protocol-reverse-engineering
Capture, analyze, and document network protocols for security research and debugging.
verified-agent-identity
Decentralized identity for agents: link to humans, verify ownership, and generate authentication proofs on Billions Network.
memory-forensics
Acquire and analyze memory dumps using Volatility to detect malware, extract artifacts, and investigate incidents.
stride-analysis-patterns
Apply STRIDE methodology to systematically identify threats across authentication, integrity, confidentiality, availability, and authorization.
threat-mitigation-mapping
Map threats to security controls and mitigations for effective defense planning.
attack-tree-construction
Visualize attack scenarios and defense gaps with systematic threat path mapping.
wallet
Multi-chain wallet for EVM and Solana: check balances, send tokens, sign data, and manage policies.
api-security-best-practices
Implement secure API design patterns: authentication, authorization, input validation, rate limiting, and vulnerability protection.
anti-reversing-techniques
Identify and bypass anti-reversing protections in authorized security analysis and malware research.
sast-configuration
Configure SAST tools (Semgrep, SonarQube, CodeQL) for automated vulnerability detection in CI/CD pipelines.
pci-compliance
Implement PCI DSS compliance for secure payment card handling and processing.
mtls-configuration
Configure mutual TLS for zero-trust service-to-service communication with certificate management.
linkerd-patterns
Lightweight, security-first service mesh patterns for Kubernetes with automatic mTLS and traffic control.
google-cloud-recipe-auth
Expert guidance on authenticating and authorizing to Google Cloud services, APIs, and identities.
security-and-hardening
Hardens code against vulnerabilities in user input, authentication, data storage, and external integrations.
google-cloud-waf-security
Security guidance for Google Cloud workloads based on the Well-Architected Framework
code-review
Review code changes for security, performance, and correctness issues before merging.
django-security
Django security best practices, authentication, authorization, and deployment hardening.
springboot-security
Spring Security best practices for authentication, authorization, validation, CSRF, secrets, headers, and rate limiting in Java Spring Boot.
MCP Servers
600+ tools for JavaScript analysis, security auditing, browser automation, and reverse engineering in a single MCP server.
LLM Sandbox
Securely run LLM-generated code in isolated containers across 7 languages and 3 backends.
SafeDep Vet MCP
Real-time malicious package detection and software supply chain security for AI agents and IDEs.
com.decionis/mcp
Fail-closed policy gate for AI agent actions with local evaluation and pre-tool authorization hooks.
HOL Guard
Local-first antivirus for AI agents that detects secrets, prompt injection, unsafe commands, and supply-chain risks.
Brazilian KYC/KYB via MCP: face auth + liveness, document OCR, and onboarding orchestration.
Brazilian KYC/KYB platform with biometrics, OCR, ICP-Brasil e-signature, and onboarding for AI agents.
Fraud prevention and order risk scoring for Brazilian e-commerce, via MCP.
Identity verification, liveness checks, and AML screening for AI agents via Jumio's KYX platform.
Order risk scoring, device intel, and fraud lists for Konduto via MCP.
Real-time fraud scoring and chargeback feedback for Brazilian e-commerce orders via MCP.
Run Onfido identity verification and KYC checks — applicants, documents, checks, workflows — from your AI agent.
MCP access to Persona's identity verification and KYC API — inquiries, accounts, and reports.
Brazilian identity + KYC verification: CPF/CNPJ lookup, OCR, face matching, liveness detection, PEP/watchlist screening.
squirrelscan
Website QA tool for coding agents: audit SEO, performance, security, accessibility with 273 rules and exact fixes over MCP.
AI-powered security analysis and automation through CrowdStrike Falcon platform integration
AI-powered threat hunting & incident response for Elasticsearch/OpenSearch with 139 MCP tools and 6,060 detection rules.
Parse-DMARC MCP Server
Auto-fetch and visualize DMARC email authentication reports in a lightweight dashboard.
Reversecore MCP
AI-powered reverse engineering and malware analysis via MCP with 120 tools for static/dynamic analysis, forensics, and SAST.
io.github.bx33661/wireshark-mcp
AI-powered packet analysis with tshark—security audits, threat detection, and network deep-dives in plain English.
Encrypted shared workspaces for AI agents—one link, read-write access, server cannot see content
io.github.BurtTheCoder/virustotal
Query VirusTotal API for comprehensive security analysis of files, URLs, IPs, and domains.
io.github.jnMetaCode/shellward
AI agent security middleware: 7 MCP tools for prompt injection detection, PII scanning, command safety, and data exfiltration blocking.
Security scanner for AI agents: blocks prompt injection, detects fake packages, audits MCP servers, and scans code vulnerabilities.
Deterministic security scanning with no model or API key, plus governed coding tasks for humans and AI agents.
Auth0 MCP Server
Manage Auth0 applications, APIs, actions, and logs using natural language through Claude, Cursor, or Windsurf.
AES-256-GCM encrypted secrets for Next.js with no external vault required.
three.ws Provenance
Append-only, signed, on-chain-verifiable agent action log for auditing AI agent behavior.
com.pulsemcp/onepassword
Access and manage 1Password credentials and secrets directly from your AI agent via the CLI.
Security-hardened NotebookLM MCP with post-quantum encryption, Gemini Deep Research, and 17 security layers for enterprise compliance.
cloud-audit
AWS security scanner that finds attack chains, IAM escalation paths, and prioritized fixes.
MCP ZAP Server
Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.
ZettelForge
Agentic memory for cyber threat intelligence. STIX graphs, actor aliasing, offline RAG, Sigma/YARA.
Server security audit (413 checks), hardening, and fleet management across 4 cloud providers.
io.snyk/mcp
Easily find and fix security issues in your applications leveraging Snyk platform capabilities.
ProofFlow
Audit infrastructure for AI coding agents with evidence-backed review and policy gates.
MCP Server for OSCAL
AI agent tools for Open Security Controls Assessment Language (OSCAL)
Manage Zscaler Zero Trust Exchange via 400+ tools — ZPA, ZIA, ZDX, ZCC, ZTW, ZMS, EASM, and more.
CodeInspectus
Local-first MCP security scanner and CLI for AI-generated applications.
io.github.mythos-agent/mythos-agent
Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.
io.github.Antmanbuilds/ari-mcp
Fair-price checks, leaderboards, and Ed25519 receipt verification for x402/MPP services.
io.github.Antmanbuilds/ari-mcp-py
Python MCP server: fair-price checks, leaderboards, Ed25519 receipt verification for x402/MPP.
Signet MCP Tools
MCP server exposing Signet cryptographic signing, verification, and content hash tools over stdio.
Solana Security Standard
Scan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.
AI agent identity, permissions, trust scores, and tamper-evident audit trails via Vorim AI
AI agent identity, permissions, trust scores, and tamper-evident audit trails via Vorim AI
OAuth 2.0 for AI agents — scoped delegation tokens, audit trails, and revocation.
Guardrailed FHIR access for AI agents: PHI redaction, audit trail, step-up auth, tenant isolation
io.github.rsdouglas/janee
Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.
agent-bom
Security scanner and graph for agentic infrastructure — agents, MCP, runtime, and blast radius.
ContrastAPI
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
AI safety middleware — detects self-harm and criminal intent in LLM prompts.
Intent-bound action authorization for AI agents: policy, human approval, and a signed audit trail.
io.github.gnt-ai/gnt
Git-native policy layer for AI agents: check_action verdicts against rules approved via PR.
Sign and verify W3C Verifiable Credentials so AI agents can cryptographically authorize actions.
Abnormal Security MCP
Abnormal Security email threats, cases, and reporting in your terminal and your AI agents.
Action1 MCP
Every Action1 endpoint, plus fleet-wide patch and vulnerability views across all your organizations.
Blumira MCP
Cross-account Blumira findings, detections, and agents in one offline-searchable store.
CrowdStrike MCP
Every CrowdStrike Falcon MSP operation, plus a Flight-Control-aware local store that answers
Huntress MCP
Every Huntress endpoint, plus a local SQLite mirror that delivers fleet-wide incident, coverage
Plugins
security-guidance
Pattern-based and LLM-powered security review for Claude-generated code with agentic commit analysis.
backend-api-security
Harden APIs with authentication, authorization, rate limiting, and input validation.
block-no-verify
Prevents AI agents from bypassing git hooks with --no-verify and similar flags
frontend-mobile-security
XSS prevention, CSRF protection, and mobile app security patterns for frontend applications
protect-mcp
Cedar policy enforcement with cryptographic receipts for every Claude Code tool call.
reverse-engineering
Binary reverse engineering and malware analysis tools for authorized security research
review-agent-governance
Require human approval before AI agents post PR reviews, comments, merges, or CI config changes.
security-compliance
Validate SOC2, HIPAA, and GDPR compliance with automated secrets scanning and regulatory checklists.
security-scanning
SAST analysis, dependency scanning, and container security in one plugin
signed-audit-trails
Cedar-gated tool calls with Ed25519 receipts and offline verification for Claude Code.
claude-security
Deep vulnerability scanning and automated patching for your code, verified by agent consensus before reporting.
security-guidance
Pattern-based and LLM-powered security review for Claude-generated code with agentic commit analysis.
aws-agents-for-devsecops
AWS DevOps and Security agents for incident investigation, code review, vulnerability scanning, and penetration testing.
audit
Perform security audits on your codebase to identify vulnerabilities and risks.
Implement GDPR compliance, data privacy engineering, and privacy-by-design for enterprise B2B applications.
Comprehensive B2B security assessments and enterprise compliance validation for SaaS platforms.
Review legal documents and ensure regulatory compliance for app development.
sonarqube
Enforce code quality and security standards with SonarQube's 7,500+ issue types and secrets scanning in your agent coding loop.
zscaler
Manage Zscaler cloud security platform policies, access, and incidents across ZPA, ZIA, ZDX, and more.
auth0
Unified Auth0 authentication setup for any framework with auto-detected guides for login, MFA, Organizations, and more.
workos
WorkOS integration skills for authentication, SSO, directory sync, and access control.
Build cybersecurity applications on CrowdStrike Falcon Foundry with UI, workflows, and API integration skills.
crowdsec
Operational and API skills for CrowdSec engine, bouncers, WAF, and Console cloud management.
stackhawk-hawkscan
Run DAST security scans and transform findings into prioritized fix tasks for your codebase.
stackhawk-api
Query StackHawk platform API for security findings, posture reporting, and app management.
aikido
Scan code for vulnerabilities, secrets, and IaC issues using Aikido Security.
duende-skills
OAuth/OIDC, IdentityServer, and ASP.NET Core identity architecture skills for Claude Code
Semgrep Guardian
Scan agent-generated code for security vulnerabilities with Semgrep
Author, deploy, and execute CrowdStrike Falcon Fusion workflows with live action discovery and schema validation.
JFrog
Connect Claude Code to JFrog to manage, secure, and govern your software supply chain.
sonatype-guide
Scan dependencies for vulnerabilities and get security recommendations from Sonatype intelligence.
vanta-mcp-plugin
Connect Claude Code to Vanta for security and compliance management
nightvision
Find exploitable vulnerabilities in web applications and REST APIs with NightVision DAST scanning.
Catch API security issues during development with automated audit, scan, and remediation.
Agents
Expert backend security coding for input validation, authentication, API security, and vulnerability prevention.
Security auditor for code and architecture review during feature development.
Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.
Expert backend security coder for input validation, authentication, API security, and vulnerability prevention.
firmware-analyst
Expert firmware extraction, analysis, and vulnerability research for embedded systems and IoT devices.
frontend-security-coder
Expert in secure frontend coding: XSS prevention, CSP configuration, and client-side vulnerability fixes.
Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.
malware-analyst
Expert malware analyst for defensive research, threat intelligence, and incident response
mobile-security-coder
Expert in secure mobile coding: input validation, WebView security, and mobile-specific vulnerability fixes.
policy-enforcer
Cedar policy author and reviewer for Claude Code tool authorization rules.
receipt-verifier
Verify Ed25519-signed receipts, detect tampering, and audit hash-chained audit trails.
reverse-engineer
Expert binary analysis and reverse engineering for authorized security research, CTF challenges, and malware defense.
review-policy-author
Cedar policy expert for gating AI agent review actions (comments, merges, CI edits) behind human approval.
Expert security auditor for DevSecOps, vulnerability assessment, and compliance framework implementation.
Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.
team-reviewer
Focused code reviewer for one quality dimension (security, performance, architecture, testing, accessibility) with structured findings.
threat-modeling-expert
Identify and prioritize security threats using STRIDE, PASTA, and attack trees before they become vulnerabilities.
Rules
27 architecture rules for Next.js 15 + Supabase: prevent auth bypasses, RLS gaps, and runtime crashes.
security devsecops ssdls appsec
Secure coding, secrets management, dependency hygiene, and SSDLC practices across multiple languages.
Secure Solana wallet architecture with MEV defense, transaction safety checks, and isolated signer subprocesses.