Best Security tools
3119 tools in the Security category across every type.
Skills

entra-app-registration
Guide Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

azure-compliance
Run Azure compliance and security audits with azqr and Key Vault expiration checks.

azure-rbac
Find the least-privilege Azure RBAC role, then generate CLI commands and Bicep code to assign it.

git-guardrails-claude-code
Block dangerous git commands (push, reset, clean) in Claude Code before execution.

entra-agent-id
Provision OAuth 2.0 identities for AI agents with per-instance audit trails via Microsoft Entra and Microsoft Graph.

firebase-auth-basics
Set up Firebase Authentication for user sign-in, management, and secure data access.

firebase-security-rules-auditor
Audit Firebase security rules for vulnerabilities, privilege escalation, and compliance gaps.

better-auth-best-practices
Configure Better Auth server and client with database adapters, sessions, plugins, and OAuth.

convex-setup-auth
Set up secure authentication in Convex with user management and access control.

multi-account-isolation
Verify browser profile isolation: timezone, WebRTC, canvas hash, cookies, and personas are not shared across accounts.

audit-website
Audit websites against 260+ rules (SEO, performance, security, accessibility) and drive fixes to code until scores improve.

browser-fingerprint-audit
Audit browser fingerprints for internal contradictions and spoofing indicators.

fingerprint-failure-triage
Attribute fingerprint check failures to their source component for targeted remediation.

turnstile-spin
Set up, repair, or migrate Cloudflare Turnstile bot verification end-to-end in your frontend and backend.

cloudflare-one
Design, configure, and troubleshoot Cloudflare One Zero Trust and SASE deployments.

investigate-without-getting-made
OPSEC framework for covert investigation—control attribution surface, build aged personas, avoid detection.

what-leaked-about-you
Check which services an identity used by searching data-breach databases for email, username, phone, or name.

clerk-setup
Set up Clerk authentication in any project with the Clerk CLI and official framework quickstarts.

security-and-hardening
Audit and harden code against OWASP Top Ten vulnerabilities, injection, XSS, broken auth, and supply-chain risks.

insforge-integrations
Wire external auth providers and x402 payment facilitators into InsForge for JWT-based RLS and onchain billing.

golang-security
Security best practices and vulnerability prevention for Go: injection, cryptography, secrets, threat modeling, and SAST tooling.

better-auth-security-best-practices
Secure Better Auth deployments with rate limiting, CSRF protection, session hardening, and audit logging.

email-and-password-best-practices
Configure email verification, password reset flows, and security policies for Better Auth email/password authentication.

two-factor-authentication-best-practices
Configure TOTP, OTP, backup codes, and trusted devices for 2FA with Better Auth.
persona-it-admin
Administer Google Workspace security and configuration as an IT administrator.
gws-modelarmor
Filter user-generated content for safety using Google Model Armor templates.
gws-modelarmor-create-template
Create Google Model Armor templates to protect AI models from jailbreak and safety attacks.

clerk
Router skill that directs to specialized Clerk authentication sub-skills based on your task.
gws-modelarmor-sanitize-prompt
Sanitize user prompts through Google Model Armor templates for safety compliance.
gws-modelarmor-sanitize-response
Sanitize model responses through Google Model Armor templates for outbound safety.

convex-authz
Audit and harden Convex app authorization: detect identity spoofing, missing ownership checks, PII leaks, and unsafe parent writes.

convex-reviewer
Security, auth, and performance reviewer for Convex functions—catch anti-patterns before shipping.

best-practices
Apply modern web development best practices for security, compatibility, and code quality.

extension-email-verification
Email verification via click-to-verify links for proving email ownership.

extension-authorization
Role-based access control system for apps managing personal or restricted data.

extension-user-approval
Approval-based user management for Caffeine AI applications.

security-requirement-extraction
Transform threat models into actionable security requirements and test cases.

skill-vetter
Security-first vetting checklist for OpenClaw skills before installation.

firestore-security-rules-auditor
Audit Firestore security rules for vulnerabilities and compliance with security best practices.

security-audit
Security guidance and vulnerability review for codebases, APIs, services, and daemons.

security-review
Systematic security code review identifying HIGH-CONFIDENCE vulnerabilities with OWASP-based analysis.
security-review
Comprehensive security checklist and patterns for authentication, input validation, secrets, and sensitive features.

stride-analysis-patterns
Apply STRIDE methodology to systematically identify threats across authentication, integrity, confidentiality, availability, and authorization.

auth-implementation-patterns
Master JWT, OAuth2, session management, and RBAC patterns for secure, scalable authentication systems.

threat-mitigation-mapping
Map threats to security controls and mitigations for effective defense planning.

solidity-security
Master smart contract security best practices and prevent common Solidity vulnerabilities.

attack-tree-construction
Visualize attack scenarios and defense gaps with systematic threat path mapping.

gdpr-data-handling
Implement GDPR-compliant data handling with consent management and data subject rights.

k8s-security-policies
Implement NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards for production Kubernetes security.

google-cloud-recipe-auth
Expert guidance on authenticating and authorizing to Google Cloud services, APIs, and identities.

clerk-swift
Clerk authentication for native Swift and iOS apps using ClerkKit and ClerkKitUI.

sql-code-review
Comprehensive SQL code review for security, performance, and maintainability across MySQL, PostgreSQL, SQL Server, and Oracle.

google-cloud-waf-security
Security guidance for Google Cloud workloads based on the Well-Architected Framework.

secrets-management
Secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, and platform-native solutions.

huawei-cloud-iam-query
Query Huawei Cloud IAM resources (users, groups, policies, agencies, credentials, MFA) via read-only Python SDK.

wcag-audit-patterns
Conduct WCAG 2.2 accessibility audits with automated testing, manual verification, and remediation guidance.

protocol-reverse-engineering
Capture, analyze, and document network protocols for security research and debugging.

memory-safety-patterns
Cross-language RAII, ownership, and smart pointer patterns for memory-safe Rust, C++, and C code.

penetration-testing-with-strix
Autonomous AI penetration testing that exploits and proves vulnerabilities with proof-of-concept exploits.

agent-email-inbox
Secure email inbox for AI agents with sender validation and sandboxed processing.
MCP Servers

600+ tools for JavaScript analysis, security auditing, browser automation, and reverse engineering in a single MCP server.

LLM Sandbox
Securely run LLM-generated code in isolated containers across 7 languages and 3 backends.

SafeDep Vet MCP
Real-time malicious package detection and software supply chain security for AI agents and IDEs.

Policy-gated SSH access for LLM agents with role-based authorization, approval workflows, and audit logging.

com.decionis/mcp
Authorize consequential AI agent actions before execution through an independent policy boundary.

HOL Guard
Local-first antivirus for AI agents—detect and block secrets, prompt injection, unsafe commands, and supply-chain risks before execution.

DEPRECATED: Latin America commerce API collection with no live endpoint.

DEPRECATED: Certta MCP server for Latin American commerce — no longer operational.

Fraud prevention and order risk scoring for Brazilian e-commerce, via MCP.

Identity verification, liveness checks, and AML screening for AI agents via Jumio's KYX platform.

Order risk scoring, device intel, and fraud lists for Konduto via MCP.

DEPRECATED: Collection of 110 MCP servers for Latin American commerce, payments, fiscal, logistics, and banking APIs.

Run Onfido identity verification and KYC checks — applicants, documents, checks, workflows — from your AI agent.

MCP access to Persona's identity verification and KYC API — inquiries, accounts, and reports.

DEPRECATED: Unico identity verification MCP server with no active endpoint.

squirrelscan
Website QA tool for coding agents: audit SEO, performance, security, accessibility with 273 rules and exact fixes over MCP.

three.ws Provenance
Append-only, signed, on-chain-verifiable agent action log for auditing AI agent behavior.

node9
Access control for AI agents: allow, hold for approval, or block each tool call

AI-powered security analysis and automation for CrowdStrike Falcon platform

AI-powered threat hunting & incident response for Elasticsearch/OpenSearch with 139 MCP tools and 6,060 detection rules.

Parse-DMARC MCP Server
Auto-fetch and visualize DMARC email authentication reports in a lightweight dashboard.

Reversecore MCP
AI-powered reverse engineering, malware analysis, and security auditing via 120 integrated tools

io.github.bx33661/wireshark-mcp
AI-powered packet analysis with tshark—security audits, threat detection, and network deep-dives in plain English.

Encrypted shared workspaces for AI agents—one link, read-write access, server cannot see content

io.github.BurtTheCoder/virustotal
Query VirusTotal API for comprehensive security analysis of files, URLs, IPs, and domains.

io.github.jnMetaCode/shellward
AI agent security middleware: 7 MCP tools for prompt injection detection, PII scanning, command safety, and data exfiltration blocking.
Security scanner for AI agents: blocks prompt injection, detects fake packages, audits MCP servers, and scans code vulnerabilities.
Deterministic security scanning with offline-verifiable fixes—no API keys, no models required.

Auth0 MCP Server
Manage Auth0 applications, APIs, actions, and logs using natural language through Claude, Cursor, or Windsurf.

AES-256-GCM encrypted secrets for Next.js with no external vault required.

com.pulsemcp/onepassword
Access and manage 1Password credentials and secrets directly from your AI agent via the CLI.
Security-hardened NotebookLM MCP with post-quantum encryption, Gemini Deep Research, and enterprise compliance.

cloud-audit
AWS security scanner that finds attack chains, IAM escalation paths, and prioritized fixes.

670+ security tools for CTF, pentest, and DFIR, driven by AI agents through governed execution in a sandbox VM.

KeibiDrop
P2P encrypted folder sync between machines—no cloud, only bytes you read move across the network.

MCP ZAP Server
Safe, self-hosted OWASP ZAP operator for AI-guided web security scans with operator control and production guardrails.

ZettelForge
Agentic memory system for cyber threat intelligence with STIX graphs, actor aliasing, and offline RAG.

AI-native server security audit, hardening, and fleet management across 4 cloud providers with 449 checks.

io.snyk/mcp
Integrate Snyk security scanning directly into AI workflows via MCP.

ProofFlow
Audit infrastructure for AI coding agents with evidence-backed review and policy gates.

MCP Server for OSCAL
AI agent tools for working with NIST's Open Security Controls Assessment Language (OSCAL)

AI-powered management of Zscaler Zero Trust Exchange with 400+ tools across ZPA, ZIA, ZDX, ZCC, and more.

CodeInspectus
Local-first security scanner for AI-generated code—no account, no network egress, MCP-ready.

io.github.mythos-agent/mythos-agent
AI code-review assistant that hunts security issues via hypothesis-driven scanning, variant analysis, and multi-stage verification.

io.github.Antmanbuilds/ari-mcp
Fair-price checks, leaderboards, and Ed25519 receipt verification for x402/MPP services.

io.github.Antmanbuilds/ari-mcp-py
Fair-price verification and leaderboard management for x402/MPP micropayment protocol.

Signet MCP Tools
Cryptographic signing and verification for AI agent tool calls — tamper-evident receipts, offline-verifiable.

Solana Security Standard
Scan Solana/Anchor code against 52 security rules drawn from $514M in real exploits, firing in Claude, Cursor, Windsurf, and CI.

Cryptographic identity, scoped permissions, and tamper-evident audit trails for AI agents.
Cryptographic identity, scoped permissions, and tamper-evident audit trails for AI agents.

OAuth 2.0 for AI agents — scoped delegation tokens, audit trails, and revocation.
Open-source security layer for AI agents accessing clinical data: PHI redaction, audit trails, step-up auth, and tenant isolation.

io.github.rsdouglas/janee
Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.

agent-bom
Security scanner and control plane for AI agents, MCP servers, and cloud infrastructure—discover vulnerabilities and trace blast radius.

ContrastAPI
55 security tools for AI agents: CVE/KEV lookup, vulnerability assessment, threat intelligence, and OSINT—free, no API key.
AI safety middleware that detects self-harm and criminal intent in LLM prompts before they reach the model.

WebCrypt MCP Server
Zero-dependency Web Crypto MCP server with AES-256-GCM, RSA-4096, and post-quantum cryptography for AI agents.

Intent-bound action authorization for AI agents: policy, human approval, and signed audit trail.

mcp-airlock
Governance proxy for MCP servers: allowlist, dry-run enforcement, human confirmation, blast-radius limits, and audit trails.

io.github.gnt-ai/gnt
Git-native policy layer for AI agents: approve rules via PR, agents check actions before acting.
Plugins

security-guidance
Pattern-based and LLM-powered security review for Claude-generated code with agentic commit analysis.

backend-api-security
Harden APIs with authentication, authorization, rate limiting, and input validation.

block-no-verify
Prevent AI agents from bypassing git hooks with --no-verify and similar flags

frontend-mobile-security
XSS prevention, CSRF protection, and mobile app security patterns for frontend applications

protect-mcp
Cryptographic governance for Claude Code with Cedar policies and Ed25519-signed call receipts.

reverse-engineering
Binary reverse engineering and malware analysis tools for authorized security research

review-agent-governance
Require human approval before AI agents post PR reviews, comments, merges, or CI config changes.

security-compliance
Validate SOC2, HIPAA, and GDPR compliance with automated secrets scanning and regulatory checklists.

security-scanning
SAST analysis, dependency scanning, and container security in one plugin

signed-audit-trails
Cedar-gated tool calls with Ed25519 receipts and offline verification for Claude Code.

claude-security
Deep vulnerability scanning of your own code with agent-verified findings and targeted patches.

security-guidance
Pattern-based and LLM-powered security review for Claude-generated code.

aws-agents-for-devsecops
Investigate incidents, review code, and execute security testing with AWS DevOps and Security agents.

audit
Perform security audits on your codebase to identify vulnerabilities and risks.

Implement GDPR compliance, data privacy engineering, and privacy-by-design for enterprise B2B applications.

Comprehensive B2B security assessments and enterprise compliance validation for SaaS platforms.

Review legal documents and ensure regulatory compliance for app development.

sonarqube
AI-powered code quality and security verification with 7,500+ issue types and secrets scanning.

auth0
Unified Auth0 authentication setup guide for any framework and feature.

zscaler
Manage Zscaler cloud security platform policies, connectivity, and incidents across ZPA, ZIA, ZDX, and more.

workos
WorkOS integration skills for authentication, SSO, directory sync, and access control.

CrowdStrike Falcon Foundry development skills for building cybersecurity applications on the Falcon platform.

crowdsec
Operational and API skills for CrowdSec security engine, bouncers, WAF, and bot detection.

Author, deploy, and execute CrowdStrike Falcon Fusion workflows with live action discovery and schema validation.

stackhawk-hawkscan
Run HawkScan DAST security scans and transform findings into prioritized fix tasks for your code.

stackhawk-api
Query StackHawk platform API for security findings, posture reporting, and app management.

aikido
Scan code for vulnerabilities, secrets, and IaC issues using Aikido Security.

Semgrep Guardian
Scans agent-generated code for security vulnerabilities.

duende-skills
OAuth/OIDC, IdentityServer, and ASP.NET Core authentication skills for secure identity architecture

JFrog
Connect Claude Code to JFrog to manage, secure, and govern your software supply chain.

sonatype-guide
Scan dependencies for vulnerabilities and get security recommendations from Sonatype intelligence.

vanta-mcp-plugin
Connect Claude Code to Vanta for security and compliance management

hol-guard
Local pre-execution security controls and scanning for AI agent tools and plugins.

nightvision
DAST and API discovery skills for finding vulnerabilities in web applications and REST APIs

Catch API security issues during development with automated audit, scan, and remediation.
Agents
Expert backend security coding for input validation, authentication, and API security implementation.

ad-security-reviewer
Audit Active Directory security posture, privilege escalation risks, and authentication hardening.

Comprehensive Python security expertise for cryptography, secure coding, vulnerability assessment, and compliance.

security-auditor
Comprehensive security audit agent that identifies vulnerabilities and generates actionable remediation reports.

security-auditor
Senior security auditor for comprehensive vulnerability assessment, penetration testing, and secure code review across the SDLC.

auth0-expert
Auth0 implementation expert for identity management, OAuth2/OIDC flows, and secure authentication configuration
Security auditor for code and architecture review during feature development.

Build OAuth 2.1, OIDC, SAML, and multi-tenant auth systems that validate every assertion and fail closed by default.

code-reviewer
Security-aware code review agent that runs automated checks and routes critical issues to specialists.

jwt-expert
JWT implementation, validation, and security best practices for token-based authentication.
Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.

compliance-auditor
Regulatory compliance auditor for GDPR, HIPAA, PCI DSS, SOC 2, and ISO frameworks with automated evidence collection.

keycloak-expert
Keycloak specialist for identity and access management, realm configuration, and user federation.
Expert backend security coding for input validation, authentication, and API protection.

fintech-engineer
Build secure, compliant payment systems and financial integrations with 100% transaction accuracy and regulatory adherence.

oauth-oidc-expert
Expert in OAuth 2.0 and OpenID Connect for secure authentication and authorization implementation.

firmware-analyst
Expert firmware analyst for embedded systems security, IoT penetration testing, and hardware reverse engineering.

gdpr-ccpa-compliance
Expert GDPR and CCPA/CPRA compliance guidance for product and engineering teams.

owasp-top10-expert
Identify and mitigate OWASP Top 10 web application security risks through expert assessment and remediation.

frontend-security-coder
Expert in secure frontend coding: XSS prevention, CSP, DOM security, and client-side vulnerability fixes.

hipaa-compliance
HIPAA compliance guidance for healthcare SaaS vendors and product teams.
Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.

incident-responder
Rapid incident response for security breaches, outages, and operational crises with evidence preservation and recovery coordination.

malware-analyst
Defensive malware analysis expert for threat intelligence, incident response, and security research.

license-engineer
Design and deploy comprehensive software licensing systems with compliance pipelines, risk mitigation, and IP protection.

mobile-security-coder
Expert in secure mobile coding: input validation, WebView security, and mobile-specific vulnerability fixes.

penetration-tester
Authorized penetration testing to identify real vulnerabilities through active exploitation and validation.

policy-enforcer
Cedar policy author and reviewer for Claude Code tool authorization rules.

Harden PowerShell automation, remoting, and Windows endpoints against enterprise security baselines and compliance frameworks.

receipt-verifier
Verify Ed25519-signed receipts and detect tampering using JCS canonicalization.

risk-manager
Identify, quantify, and mitigate enterprise risks across financial, operational, regulatory, and strategic domains.

reverse-engineer
Expert binary analysis and reverse engineering for security research, CTF, and authorized vulnerability assessment.

security-auditor
Comprehensive security audits, compliance assessments, and risk evaluations across systems and infrastructure.

review-policy-author
Cedar policy expert for gating AI review actions behind human approval

security-engineer
Senior security engineer for infrastructure hardening, DevSecOps automation, and compliance-driven security architecture.
Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.
Expert security auditor for DevSecOps, vulnerability assessment, and compliance frameworks.

team-reviewer
Focused code reviewer for one quality dimension (security, performance, architecture, testing, or accessibility) with structured findings.

threat-modeling-expert
Expert threat modeling and security architecture review using STRIDE, PASTA, and attack trees
Rules
27 architecture rules for Next.js 15 + Supabase preventing auth, params, and security hallucinations

security devsecops ssdls appsec
Secure coding, secret handling, dependency hygiene, and compliance for DevSecOps and SSDLC.
Secure Solana wallet architecture with MEV defense, signer isolation, and transaction safety checks.





