A community-driven registry for the Claude Code ecosystem. Not affiliated with Anthropic.
27 packages found
Open-source cybersecurity analysis agent for Claude Code. Scans projects for vulnerabilities across all OWASP 2025 Top 1
Configuration governance for Claude Code. Bootstrap, audit, sync, and evolve .claude/ across projects.
CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code. 67+ commands, 35 techniques, no API keys
Claude Code configs for the expert Solana builder. CLAUDE.md, agents, commands, hooks, rules, skills and settings across
AI-powered cybersecurity code review skill for Claude Code. 8 specialist agents, OWASP 2025, CWE Top 25, MITRE ATT&CK, 1
Stop AI agents from doing things you didn't ask for.
Security-focused skills with CodeQL and Semgrep static analysis
AI/ML security — prompt injection defense, model hardening, data poisoning prevention
Security-focused code review — threat modeling, vulnerability assessment, compliance
Security-first code review — OWASP Top 10, injection prevention, auth hardening
Cloud security posture — IAM, network isolation, encryption, compliance
Reference implementation of all 13 hook events with security enhancements
Scan and secure code with Semgrep static analysis — official Semgrep
Security hooks with SSRF protection, MCP compression, and OpenTelemetry tracing
Expert guidance for ffuf web fuzzing during penetration testing and security recon
Audit skills for malicious code — injection, exfiltration, supply chain risks
Penetration testing guidance — OWASP, vulnerability scanning, exploit analysis
Comprehensive paid advertising audit & optimization skill for Claude Code. 250+ checks across Google, Meta, YouTube, Lin
15 cybersecurity skills covering offensive, defensive, and reverse engineering
实战 SRC / 众测 / Bug bounty 漏洞挖掘 Claude Code skill — 19 个攻击类 playbook、305 个结构化 payload、263 个 WAF/EDR 绕过、2887 份 HackerOne 真实
Blocks dangerous git and shell commands from being executed by AI coding agents
ISO 27001 compliance — ISMS setup, risk assessment, control implementation
.env management, leak detection, secret rotation workflows
Multi-language dependency scanner — license compliance, upgrade planner
Red team exercises — adversarial thinking, attack simulation, defense gaps
Protects sensitive files, credentials, and shell commands from unintended AI access via hooks
Copy-paste hooks: block dangerous commands, protect secrets, auto-stage git, Slack alerts