Install payload
Install payload is broadly covered in current results.
100% (12/12)
108 trusted · 266 review · 10 limited in this set — compare to see which signals differ.
Trust signals across 40 of 384 results
4 trust signals differ in this sample: Review status, Package trust, Source provenance, Submitter
Signals differ on Review status, Package trust, Source provenance — add entries to compare before you install.
Rollout signal scan
Biggest gaps: metadata review. 0 entries have 2+ required gaps.
Install payload
Install payload is broadly covered in current results.
100% (12/12)
Most at-risk entries in this view
/security - Vulnerability Scan Command for Claude Code
No required rollout gaps
Security Guidance Plugin Before Merge
No required rollout gaps
Security-First React Components for Claude
No required rollout gaps
Security Scanner Hook - Hooks
No required rollout gaps
Security Auditor Expert - CLAUDE.md Rules for Claude Code
No required rollout gaps
Adoption queue
42/384 visible results are in hold tier and need mitigation before adoption.
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
skills/agent-evals-regression-gate · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
skills/ai-agent-observability-incident-response · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
skills/ai-business-idea-validation-capability-pack · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
skills/ai-search-ranking-content-cluster-strategy · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
mcp/airtable-mcp-server · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
mcp/asana-mcp-server · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
skills/audio-transcription-summarization · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
mcp/aws-services-mcp-server · trust trusted · confidence 83%
Decision confidence
33/384 results are low-confidence and need review before adoption.
Confident candidate for staged adoption.
74/100
skills/agent-evals-regression-gate · trust trusted
Confident candidate for staged adoption.
74/100
skills/ai-agent-observability-incident-response · trust trusted
Confident candidate for staged adoption.
74/100
skills/ai-business-idea-validation-capability-pack · trust trusted
Confident candidate for staged adoption.
74/100
skills/ai-search-ranking-content-cluster-strategy · trust trusted
Confident candidate for staged adoption.
74/100
mcp/airtable-mcp-server · trust trusted
Confident candidate for staged adoption.
74/100
mcp/asana-mcp-server · trust trusted
Confident candidate for staged adoption.
74/100
skills/audio-transcription-summarization · trust trusted
Confident candidate for staged adoption.
74/100
mcp/aws-services-mcp-server · trust trusted
Freshness distribution
Median age 109 days; 1 fresh of 12 scanned. Re-verify the oldest entries.
Oldest entries in this view
Security Auditor Expert - CLAUDE.md Rules for Claude Code
Not yet verified
/security - Vulnerability Scan Command for Claude Code
Not yet verified
Security Scanner Hook - Hooks
Not yet verified
Security-First React Components for Claude
Not yet verified
/security-audit - Security Scanner Command for Claude Code
Not yet verified
Theme distribution
75% of this view shares the top theme. Leading themes: security, mcp, capability-pack.
105 distinct themes across 24 scanned
Comprehensive security audit with vulnerability detection, threat analysis, and automated remediation recommendations
Install and use the official Claude Code security-guidance plugin before merge: per-edit pattern warnings, end-of-turn and commit git-diff review, and team rollout for command injection, XSS, eval, and dangerous file edits.
Security-first React component architect with XSS prevention, CSP integration, input sanitization, and OWASP Top 10 mitigation patterns
Automated security vulnerability scanning that integrates with development workflow to detect and prevent security issues before deployment.
Configure Claude as a security expert for vulnerability assessment, penetration testing, and security best practices
Deploy 100 specialized sub-agents for comprehensive enterprise-grade security, performance, and optimization audit of production codebase
Expert EVM capability skill for secure contract architecture across Ethereum and Base, including Foundry testing and operational controls.
Build and harden Ethereum smart contracts with Foundry, invariant testing, and battle-tested OpenZeppelin security patterns.
Expert GitHub Actions capability skill for secure workflow architecture, token minimization, supply-chain controls, and CI reliability.
Expert MCP capability skill for secure server authoring, tool schema discipline, authorization boundaries, and prompt-injection risk review.
Secure MCP servers with strict tool boundaries, auth controls, dependency hygiene, and abuse-resistant runtime policies.
Expert n8n capability skill focused on secure production operation, workflow isolation, secret hygiene, and abuse-resistant automation design.
Build applications, analyze traffic, and manage security settings through Cloudflare
Security analysis and vulnerability scanning for dependencies
49 remote MCP security tools for CVE/KEV/CWE/EPSS lookup, composite CVSS+EPSS+KEV+PoC risk scoring, CVSS v3.x vector parsing, domain/IP/IOC enrichment, dependency and web intelligence checks, MITRE ATLAS AI/ML attacks, and MITRE D3FEND defenses. Anonymous tier available; Pro tier uses an API key.
The official Codacy MCP server (@codacy/codacy-mcp) that gives AI assistants access to the Codacy API for code quality, security, and coverage — listing repository and pull-request issues, retrieving file coverage and duplication, searching security (SRM) findings, inspecting analysis tools and patterns, and running local analysis with the Codacy CLI.
Independent community library of 754 cybersecurity Agent Skills mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF for defensive security analysis, incident response, forensics, cloud security, SOC operations, and governed red-team workflows.
Microsoft open-source course for learning AI agents with lessons on agentic frameworks, design patterns, tool use, agentic RAG, trustworthy agents, planning, multi-agent systems, MCP/A2A/NLWeb, memory, browser use, and Microsoft Agent Framework.
Microsoft open-source Model Context Protocol curriculum with hands-on MCP server, client, security, transport, auth, deployment, Azure, VS Code, Inspector, PostgreSQL, and cross-language examples.
WordPress contributor-reviewed Agent Skills for AI coding assistants working on Gutenberg blocks, block themes, plugins, REST APIs, Interactivity API, Abilities API, WP-CLI, Playground, performance, PHPStan, and directory rules.
Expert GitHub Actions security review capability pack applying documented workflow hardening, GITHUB_TOKEN least privilege, secrets handling, and fork PR safety checks from official GitHub Actions security documentation.
Community reusable agent prompt for reviewing new MCP server adoption in Claude Code using official security documentation: trusted providers, permissions configuration, trust verification, and settings checked into source control.
Slash command that reviews a pull request diff for security regressions: authentication and authorization gaps, injection surfaces, secret exposure, unsafe deserialization, and dependency risk introduced by the change.
Expert MCP remote server trust review capability pack for auditing OAuth flows, transport security, tool permissions, data exfiltration risk, and vendor scope before connecting Claude Code to third-party MCP servers.
Official SonarSource MCP server that connects Claude to SonarQube Server or SonarQube Cloud for code quality, security issues, hotspots, measures, quality gates, branches, pull requests, snippets, and system context.
Offensive security MCP framework that connects AI agents to a large toolkit for authorized penetration testing, vulnerability discovery, CTF, OSINT, and security research workflows.
Apache-2.0 CNCF-incubating Kubernetes security platform and CLI for scanning clusters, manifests, Helm charts, Kustomize projects, Git repositories, and container images for misconfigurations, compliance gaps, and vulnerabilities.
Official Snyk Studio MCP Server for connecting Claude Code, Codex CLI, Cursor, Gemini CLI, and other local MCP clients to Snyk Code, Open Source, IaC, container, SBOM, AI-BOM, package-health, authentication, and secure-at-inception workflows.
Source-backed agent that reviews active Claude Code sessions and configuration for security gaps, cross-references the official security guidance, and produces a ranked remediation plan covering permissions, MCP trust, prompt injection, credential handling, and hook safety.
Checklist for reviewing remote MCP servers before team rollout: OAuth scopes, transport security, tool surface, registry provenance, and rollback.