Security AI Agent Skills
AI agent skills for application security. Vulnerability scanning, secure coding patterns, authentication, and audit workflows.
202 listings
MCP-Dandan - MCP Security Framework
MCP-Dandan is an integrated monitoring service that observes MCP (Model Context Protocol) communications and detects security threats in real time. It features a modern desktop UI built with Electron for easy monitoring and management. Currently, MCP-Dandan is listed in well-known MCP-related open-source collections and can be found in the following repositories: - Awesome MCP Servers β Security -
Stride Analysis Patterns
Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
MCP AI SOC Sher
A powerful AI-driven Security Operations Center (SOC) Text2SQL framework based MCP Server (Local and Remote) for converting natural language Prompts to SQL queries dynamically, with integrated security threat analysis and monitoring. - Text2SQL Conversion: Convert natural language queries to optimized SQL - Multiple Interfaces: Support for STDIO, SSE, and REST API - Security Threat Analysis: Built
Apple MCP Servers
A collection of Model Context Protocol (MCP) servers that provide AI assistants with access to native Apple applications on macOS. - macOS (uses AppleScript and macOS-specific APIs) - Node.js 18+ (22+ for Apple Messages) - Full Disk Access granted to your terminal app (System Settings > Privacy & Security > Full Disk Access) β required for reading the Messages database - The associated Apple app m
Solidity Foundry
You are an expert in Solidity and smart contract security.
WSB Analyst MCP Server
A Model Context Protocol (MCP) server that provides real-time WallStreetBets data for analysis with Claude or other LLM clients. - Fetch WallStreetBets Posts: Filter posts by score, comment count, and content type - Detailed Post Analysis: Extract comments, links, and metadata from posts - External Link Collection: Gather links being shared in WSB discussions - Analysis Templates: Ready-to-use pro
Xcode MCP Server
An MCP (Model Context Protocol) server providing comprehensive Xcode integration for AI assistants. This server enables AI agents to interact with Xcode projects, manage iOS simulators, and perform various Xcode-related tasks with enhanced error handling and support for multiple project types. - Set active projects and get detailed project information - Create new Xcode projects from templates (iO
Security Bluebook Builder
Build security Blue Books for sensitive apps
File Uploads
Expert at handling file uploads and cloud storage. Covers S3, Cloudflare R2, presigned URLs, multipart uploads, and image optimization. Knows how to handle large files without blocking. Use when: file upload, S3, R2, presigned URL, multipart.
EntraID MCP Server (Microsoft Graph FastMCP)
This project provides a modular, resource-oriented FastMCP server for interacting with Microsoft Graph API. It is designed for extensibility, maintainability, and security, supporting advanced queries for users, sign-in logs, MFA status, and privileged users. - Modular Resource Structure: - Each resource (users, sign-in logs, MFA, etc.) is implemented in its own module under src/msgraphmcpserver/r
Biothings MCP
MCP (Model Context Protocol) server for Biothings.io This server implements the Model Context Protocol (MCP) for BioThings, providing a standardized interface for accessing and manipulating biomedical data. MCP enables AI assistants and agents to access specialized biomedical knowledge through structured interfaces to authoritative data sources. Supported BioThings data sources include: - mygene.i
DNStwist MCP Server
A Model Context Protocol (MCP) server for dnstwist, a powerful DNS fuzzing tool that helps detect typosquatting, phishing, and corporate espionage. This server provides tools for analyzing domain permutations and identifying potentially malicious domains. It is designed to integrate seamlessly with MCP-compatible applications like Claude Desktop. This tool is designed for legitimate security resea
Agent Security Scanner MCP
Security scanner for AI coding agents, MCP servers, prompts, and AI-suggested packages. Run it before Claude Code, Cursor, Windsurf, Cline, OpenCode, or another agent trusts new code, tools, prompts, or dependencies. Scan any repo and get an A-F agent security grade: Install the scanner into your AI coding client: Replace claude-code with cursor, claude-desktop, windsurf, cline, kilo-code, opencod
MCP Server - VMS Integration
A Model Context Protocol (MCP) server designed to connect to a CCTV recording program (VMS) to retrieve recorded and live video streams. It also provides tools to control the VMS software, such as showing live or playback dialogs for specific channels at specified times. - Retrieve video channel information, including connection and recording status. - Fetch recording dates and times for specific
MCP Cybersec Watchdog
A portable, single-binary system auditing tool for Linux. Like Lynis but faster and smarter. No configuration needed. No dependencies. Just run. - π Security: Firewall, SSH hardening, SSL/TLS, fail2ban, SUID binaries, open ports - π Services: Systemd services, web servers, databases, Docker - π» Resources: CPU, RAM, disk usage, top processes - πΎ Storage: SMART health, inode usage, filesystem er
MCP Jira Server fo Claude Code
A comprehensive Model Context Protocol (MCP) server for Jira integration with Claude Code. This server provides complete Jira functionality including issue management, sprint operations, comments, attachments, and batch processing. β οΈ Security Note: Never commit your API tokens! All credentials should be in .env files or environment variables. - create-issue - Create issues with full field support
Es Module Node.js Guidelines
Follow best practices, lean towards agile methodologies
Elasticsearch/OpenSearch MCP Server
MCP Official Registry A Model Context Protocol (MCP) server implementation that provides Elasticsearch and OpenSearch interaction. This server enables searching documents, analyzing indices, and managing cluster through a set of tools. - generalapirequest: Perform a general HTTP API request. Use this tool for any Elasticsearch/OpenSearch API that does not have a dedicated tool. - listindices: List
Safe Local Python Executor
An MCP server (stdio transport) that wraps Hugging Face's LocalPythonExecutor (from the smolagents framework). It is a custom Python runtime that provides basic isolation/security when running Python code generated by LLMs locally. It does not require Docker or VM. This package allows to expose the Python executor via MCP (Model Context Protocol) as a tool for LLM apps like Claude Desktop, Cursor
Seerr MCP Server
- π 99% fewer API calls for batch operations (150-300 β 1) - β‘ 88% token reduction with compact response formats - π― Batch Dedupe Mode - Check 50-100 titles in one operation - π Smart Caching - 70-85% API call reduction - π‘οΈ Safety Features - Multi-season confirmation, validation - π¦ 4 Powerful Tools - Consolidated from 8 for clarity - π€ Automated Security Scanning - Dependabot for dependenc
Starknet MCP Server
A comprehensive Model Context Protocol (MCP) server for the Starknet blockchain. This server provides AI agents with the ability to interact with Starknet networks, query blockchain data, manage wallets, and interact with smart contracts. - Supported Networks - Prerequisites - Installation - Server Configuration - API Reference - Resources - Usage with AI Assistants - Security Considerations - Pro
Varlock Skill for Claude Code
Secure environment variable management with Varlock. Use when handling secrets, API keys, credentials, or any sensitive configuration. Ensures secrets are never exposed in terminals, logs, traces, or Claude's context. Trigger phrases include "environment variables", "secrets", ".env", "API key", "credentials", "sensitive", "Varlock".
Dependency Management Deps Audit
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
Security Requirement Extraction
Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.