Leaderboard
Scored on public signals; components with none are listed as Unranked · Formula
Component
Domain
Vertical
| Rank | Score | Component | Description | Evidence | Last commit | Install |
|---|---|---|---|---|---|---|
| 201 | Unranked | depsguard-mcpmcp · other | AI-powered dependency vulnerability and breaking change analyzer that scans dependencies, identifies vulnerabilities via OSV.dev, and uses AI to… | No signals yet | No one-command install · Source | |
| 202 | Unranked | csoai-org-cybersecurity-ai-mcpmcp · other | AI-powered cybersecurity analysis and threat detection tools. | No signals yet | No one-command install · Source | |
| 203 | Unranked | solidity-auditor-mcpmcp · other | Audits Ethereum/Solidity smart contracts using the Cysic Minimax model, providing automated vulnerability detection, gas optimization suggestions, and… | No signals yet | No one-command install · Source | |
| 204 | Unranked | genconfigenvservermcp · other | Generates security config files from environment variables and remote Firebase configuration. | No signals yet | No one-command install · Source | |
| 205 | Unranked | atlas-pipelinemcp · other | AI development pipeline providing code analysis, refactoring, security scanning, and optimization tools. | No signals yet | No one-command install · Source | |
| 206 | Unranked | neogeweb3-code-health-suitemcp · other | Python code quality analysis with 28 tools covering complexity scoring, dead code detection, security scanning, and clone detection. | No signals yet | No one-command install · Source | |
| 207 | Unranked | estonian-cybersecurity-mcpmcp · other | Query Estonian cybersecurity data -- regulations, decisions, and requirements from RIA/CERT-EE -- directly from any MCP-compatible client. | No signals yet | No one-command install · Source | |
| 208 | Unranked | detection-forge-detection-lookupsmcp · other | Security detection lookups for LOLBAS, GTFOBins, and process parent-child relationship analysis. | No signals yet | No one-command install · Source | |
| 209 | Unranked | john-the-ripper-mcpmcp · other | Enables AI assistants to perform password security auditing using John the Ripper on a remote Kali system via SSH, supporting cracking, hash… | No signals yet | No one-command install · Source | |
| 210 | Unranked | frogeyemcp · other | Zero-config security scanner for AI-generated apps with 25K+ vulnerability patterns. | No signals yet | No one-command install · Source | |
| 211 | Unranked | daedalus-smbmapmcp · other | Exposes SMB share enumeration and file operations via the smbmap security tool. | No signals yet | No one-command install · Source | |
| 212 | Unranked | http-security-headers-mcpmcp · other | Analyze and score HTTP security headers (CSP, HSTS, CORS, cookies) with actionable fix recommendations for web applications. | No signals yet | No one-command install · Source | |
| 213 | Unranked | narkytypey-bug-bounty-toolsmcp · other | Provides bug bounty hunting tools including subdomain enumeration, vulnerability scanning, and recon automation. | No signals yet | No one-command install · Source | |
| 214 | Unranked | neveresleep-vibe-checkmcp · other | Scans projects and files for security vulnerabilities including secrets, injections, and unsafe configurations. | No signals yet | No one-command install · Source | |
| 215 | Unranked | mcp-goatmcp · other | A deliberately vulnerable MCP application for learning MCP security through hands-on exercises covering OWASP MCP Top 10 categories. | No signals yet | No one-command install · Source | |
| 216 | Unranked | gh-mintmas-oracle42-intelligencemcp · other | AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT. | No signals yet | No one-command install · Source | |
| 217 | Unranked | contract-scanner-mcpmcp · other | Scans Base L2 smart contracts for security risks including proxy patterns, risky functions, and verification status. | No signals yet | No one-command install · Source | |
| 218 | Unranked | pwnbridgemcp · other | Enables AI assistants to execute security testing tools on a Kali Linux machine over SSH, including reconnaissance, web app scanning, and… | No signals yet | No one-command install · Source | |
| 219 | Unranked | gh-egoughnour-code-firewallmcp · other | Structural similarity-based code filter that blocks malicious patterns before execution. | No signals yet | No one-command install · Source | |
| 220 | Unranked | mcp-hydramcp · other | A lightweight, extensible cybersecurity toolkit that connects AI assistants to security tools through MCP, enabling AI-assisted security research… | No signals yet | No one-command install · Source | |
| 221 | Unranked | hwp-metadata-mcpmcp · other | Enables extraction of metadata from HWP and HWPX files (Korean word processor formats) without requiring HWP installation. Supports document info… | No signals yet | No one-command install · Source | |
| 222 | Unranked | cybersim-promcp · other | Cybersecurity training, simulation, and incident response platform | No signals yet | No one-command install · Source | |
| 223 | Unranked | ai-image-analysis-mcpmcp · other | Provides AI-powered image analysis using Google Gemini 2.0 Flash, with support for multiple access methods and robust security features. | No signals yet | No one-command install · Source | |
| 224 | Unranked | active-directory-attacksskill · other | This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound… | No signals yet | No commit datelisted | armory install active-directory-attacks --cli claude |
| 225 | Unranked | angular-securityrules · other | angular rule: apply when working on angular and you need Angular Security. | No signals yet | No commit datelisted | armory install angular-security --cli claude |
| 226 | Unranked | ansvar-systems-uk-standardsmcp · other | Provides access to 328 UK cybersecurity controls across 28 frameworks including Cyber Essentials, NCSC CAF, and NHS DSPT. | No signals yet | No commit datelisted | No one-command install · Source |
| 227 | Unranked | arkts-securityrules · other | arkts rule: apply when working on arkts and you need HarmonyOS / ArkTS Security. | No signals yet | No commit datelisted | armory install arkts-security --cli claude |
| 228 | Unranked | best-practicesskill · other | Apply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit"… | No signals yet | No commit datelisted | armory install best-practices --cli claude |
| 229 | Unranked | bright-securitymcp · other | Integrates with Bright Security DAST platform for application security scanning and vulnerability discovery. | No signals yet | No commit datelisted | No one-command install · Source |
| 230 | Unranked | burp-suite-web-application-testingskill · other | This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web… | No signals yet | No commit datelisted | armory install burp-suite-web-application-testing --cli claude |
| 231 | Unranked | byteraymcp · other | Provides AI-augmented binary vulnerability analysis with tools for taint tracing, zero-day hunting, and reverse code engineering. | No signals yet | No commit datelisted | No one-command install · Source |
| 232 | Unranked | check-fileworkflow · other | Perform comprehensive analysis of $ARGUMENTS to identify code quality issues, security vulnerabilities, and optimization opportunities. | No signals yet | No commit datelisted | armory install check-file --cli claude |
| 233 | Unranked | code-review-checklistskill · other | Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability | No signals yet | No commit datelisted | armory install code-review-checklist --cli claude |
| 234 | Unranked | cpp-securityrules · other | cpp rule: apply when working on cpp and you need C++ Security. | No signals yet | No commit datelisted | armory install cpp-security --cli claude |
| 235 | Unranked | csharp-securityrules · other | csharp rule: apply when working on csharp and you need C# Security. | No signals yet | No commit datelisted | armory install csharp-security --cli claude |
| 236 | Unranked | dangerous-command-blocker-2hook · other | Dangerous Command Blocker Hook Multi-level security system for blocking dangerous shell commands | No signals yet | No commit datelisted | armory install dangerous-command-blocker-2 --cli claude |
| 237 | Unranked | dart-securityrules · other | dart rule: apply when working on dart and you need Dart/Flutter Security. | No signals yet | No commit datelisted | armory install dart-security --cli claude |
| 238 | Unranked | deps-audit-3workflow · other | Dependency Audit and Security Analysis | No signals yet | No commit datelisted | armory install deps-audit-3 --cli claude |
| 239 | Unranked | digidenone-synapse-auditmcp · other | Detects security vulnerabilities in code and syncs findings with SynapseAudit platform. | No signals yet | No commit datelisted | No one-command install · Source |
| 240 | Unranked | eip-mcpmcp · other | Real-time CVE, exploit, and vulnerability intelligence with 350K+ CVEs and 115K+ proof-of-concept exploits. | No signals yet | No commit datelisted | No one-command install · Source |
| 241 | Unranked | endor-labs-securitymcp · other | Integrates with Endor Labs security platform to provide real-time vulnerability detection, dependency scanning, and security analysis directly in… | No signals yet | No commit datelisted | No one-command install · Source |
| 242 | Unranked | env-file-protectionhook · other | Prevent writing to .env files using the if condition for lightweight filtering. Blocks any Write tool call targeting .env* files, protecting secrets… | No signals yet | No commit datelisted | armory install env-file-protection --cli claude |
| 243 | Unranked | equinixmcp · other | Hundreds of network, communication, security, and cloud providers - all from a single location | No signals yet | No commit datelisted | No one-command install · Source |
| 244 | Unranked | ethical-hacking-methodologyskill · other | This skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance"… | No signals yet | No commit datelisted | armory install ethical-hacking-methodology --cli claude |
| 245 | Unranked | evidiq-lineagemcp · other | Deterministic supply-chain provenance, SBOM/AI-BOM generation, and dependency risk analysis for npm and PyPI packages, with 14 security rules and… | No signals yet | No commit datelisted | No one-command install · Source |
| 246 | Unranked | file-protectionhook · other | Protect critical files from accidental modification. Prevents editing of important system files, configuration files, and production code. | No signals yet | No commit datelisted | armory install file-protection --cli claude |
| 247 | Unranked | find-bugsskill · other | Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or… | No signals yet | No commit datelisted | armory install find-bugs --cli claude |
| 248 | Unranked | flutter-dart-code-reviewskill · other | Library-agnostic Flutter/Dart code review checklist covering widget best practices, state management patterns (BLoC, Riverpod, Provider, GetX, MobX… | No signals yet | No commit datelisted | armory install flutter-dart-code-review --cli claude |
| 249 | Unranked | fsharp-securityrules · other | fsharp rule: apply when working on fsharp and you need F# Security. | No signals yet | No commit datelisted | armory install fsharp-security --cli claude |
| 250 | Unranked | gh-bountyyfi-watchdogmcp · other | Security proxy that detects and blocks 40+ classes of attacks on connections. | No signals yet | No commit datelisted | No one-command install · Source |
| 251 | Unranked | golang-securityrules · other | golang rule: apply when working on golang and you need Go Security. | No signals yet | No commit datelisted | armory install golang-security --cli claude |
| 252 | Unranked | google-cloud-waf-securityskill · other | Generates security-focused guidance for Google Cloud workloads based on the Google Cloud Well-Architected Framework (WAF). Use to evaluate a workload… | No signals yet | No commit datelisted | armory install google-cloud-waf-security --cli claude |
| 253 | Unranked | gws-alertcenterworkflow · other | Google Workspace Alert Center: Manage Workspace security alerts. | No signals yet | No commit datelisted | armory install gws-alertcenter --cli claude |
| 254 | Unranked | homelab-network-readinessskill · other | Readiness checklist for homelab VLAN segmentation, local DNS filtering, and WireGuard-style remote access before changing router, firewall, DHCP, or… | No signals yet | No commit datelisted | armory install homelab-network-readiness --cli claude |
| 255 | Unranked | java-securityrules · other | java rule: apply when working on java and you need Java Security. | No signals yet | No commit datelisted | armory install java-security --cli claude |
| 256 | Unranked | kaspersky-threat-intelligencemcp · other | Integrates with Kaspersky's threat intelligence platform to provide conversational access to commercial threat feeds, STIX object analysis, and URL… | No signals yet | No commit datelisted | No one-command install · Source |
| 257 | Unranked | kotlin-securityrules · other | kotlin rule: apply when working on kotlin and you need Kotlin Security. | No signals yet | No commit datelisted | armory install kotlin-security --cli claude |
| 258 | Unranked | laravel-expertskill · other | Senior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security… | No signals yet | No commit datelisted | armory install laravel-expert --cli claude |
| 259 | Unranked | malwarepatrolmcp · other | Cybersecurity threat intelligence for querying threat actors, IoCs, and CVEs. | No signals yet | No commit datelisted | No one-command install · Source |
| 260 | Unranked | mcp-gateway-lasso-securitymcp · other | Listed on mcp.so; Armory has only its name so far. | No signals yet | No commit datelisted | No one-command install · Source |
| 261 | Unranked | mcp-pentestmcp · other | Listed on mcp.so; Armory has only its name so far. | No signals yet | No commit datelisted | No one-command install · Source |
| 262 | Unranked | metasploit-frameworkskill · other | This skill should be used when the user asks to "use Metasploit for penetration testing", "exploit vulnerabilities with msfconsole", "create payloads… | No signals yet | No commit datelisted | armory install metasploit-framework --cli claude |
| 263 | Unranked | mobb-dev-mobb-vibe-shield-mcpmcp · other | [Mobb Vibe Shield](https://vibe.mobb.ai/) identifies and remediates vulnerabilities in both human and AI-written code, ensuring your applications… | No signals yet | No commit datelisted | No one-command install · Source |
| 264 | Unranked | mobsfmcp · other | Integrates with MobSF (Mobile Security Framework) to provide automated mobile application security analysis including file upload, vulnerability… | No signals yet | No commit datelisted | No one-command install · Source |
| 265 | Unranked | olyport-usda-foodmcp · other | SNAP participation, food insecurity indicators, and agricultural statistics from USDA. | No signals yet | No commit datelisted | No one-command install · Source |
| 266 | Unranked | penetration-testworkflow · other | Perform penetration testing and vulnerability assessment on application | No signals yet | No commit datelisted | armory install penetration-test --cli claude |
| 267 | Unranked | pentest-checklistskill · other | This skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration… | No signals yet | No commit datelisted | armory install pentest-checklist --cli claude |
| 268 | Unranked | pentest-commandsskill · other | This skill should be used when the user asks to "run pentest commands", "scan with nmap", "use metasploit exploits", "crack passwords with hydra or… | No signals yet | No commit datelisted | armory install pentest-commands --cli claude |
| 269 | Unranked | perl-securityrules · other | perl rule: apply when working on perl and you need Perl Security. | No signals yet | No commit datelisted | armory install perl-security --cli claude |
| 270 | Unranked | php-securityrules · other | php rule: apply when working on php and you need PHP Security. | No signals yet | No commit datelisted | armory install php-security --cli claude |
| 271 | Unranked | python-securityrules · other | python rule: apply when working on python and you need Python Security. | No signals yet | No commit datelisted | armory install python-security --cli claude |
| 272 | Unranked | quarkus-verificationskill · other | "Verification loop for Quarkus projects: build, static analysis, tests with coverage, security scans, native compilation, and diff review before… | No signals yet | No commit datelisted | armory install quarkus-verification --cli claude |
| 273 | Unranked | recipe-triage-security-alertsworkflow · other | List and review Google Workspace security alerts from Alert Center. | No signals yet | No commit datelisted | armory install recipe-triage-security-alerts --cli claude |
| 274 | Unranked | red-team-tools-and-methodologyskill · other | This skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS… | No signals yet | No commit datelisted | armory install red-team-tools-and-methodology --cli claude |
| 275 | Unranked | ruby-securityrules · other | ruby rule: apply when working on ruby and you need Ruby Security. | No signals yet | No commit datelisted | armory install ruby-security --cli claude |
| 276 | Unranked | rust-securityrules · other | rust rule: apply when working on rust and you need Rust Security. | No signals yet | No commit datelisted | armory install rust-security --cli claude |
| 277 | Unranked | sast-configurationskill · other | Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple… | No signals yet | No commit datelisted | armory install sast-configuration --cli claude |
| 278 | Unranked | security-auditworkflow · other | Perform comprehensive security assessment and vulnerability analysis | No signals yet | No commit datelisted | armory install security-audit --cli claude |
| 279 | Unranked | security-best-practicesskill · other | Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests… | No signals yet | No commit datelisted | armory install security-best-practices --cli claude |
| 280 | Unranked | security-hardeningworkflow · other | Harden application security configuration with comprehensive security controls | No signals yet | No commit datelisted | armory install security-hardening --cli claude |
| 281 | Unranked | security-scannerhook · other | Scan code for security vulnerabilities and secrets after modifications. Uses multiple security tools to detect potential issues. | No signals yet | No commit datelisted | armory install security-scanner --cli claude |
| 282 | Unranked | security-scanning-toolsskill · other | This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security"… | No signals yet | No commit datelisted | armory install security-scanning-tools --cli claude |
| 283 | Unranked | securitycopilotmcpservermcp · other | Listed on mcp.so; Armory has only its name so far. | No signals yet | No commit datelisted | No one-command install · Source |
| 284 | Unranked | senior-secopsskill · other | Comprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security… | No signals yet | No commit datelisted | armory install senior-secops --cli claude |
| 285 | Unranked | shell-wrapper-guard-2hook · other | shell-wrapper-guard.sh — Detect destructive commands hidden in shell wrappers | No signals yet | No commit datelisted | armory install shell-wrapper-guard-2 --cli claude |
| 286 | Unranked | springboot-verificationskill · other | "Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR." | No signals yet | No commit datelisted | armory install springboot-verification --cli claude |
| 287 | Unranked | swift-securityrules · other | swift rule: apply when working on swift and you need Swift Security. | No signals yet | No commit datelisted | armory install swift-security --cli claude |
| 288 | Unranked | tenable-mcpmcp · other | Exposes Tenable security operations as MCP tools for AI-powered security workflows, enabling asset, vulnerability, scan, plugin, and tag management… | No signals yet | No commit datelisted | No one-command install · Source |
| 289 | Unranked | typescript-securityrules · other | typescript rule: apply when working on typescript and you need TypeScript/JavaScript Security. | No signals yet | No commit datelisted | armory install typescript-security --cli claude |
| 290 | Unranked | vulnerability-scannerskill · other | Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization. | No signals yet | No commit datelisted | armory install vulnerability-scanner --cli claude |
| 291 | Unranked | web-doctormcp · other | Enables live website health checks including TLS, HTTPS, and security headers, returning an A-F grade with specific fixes. | No signals yet | No commit datelisted | No one-command install · Source |
| 292 | Unranked | web-securityrules · other | web rule: apply when working on web and you need Web Security Rules. | No signals yet | No commit datelisted | armory install web-security --cli claude |
| 293 | Unranked | wordpress-penetration-testingskill · other | This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes… | No signals yet | No commit datelisted | armory install wordpress-penetration-testing --cli claude |
| 294 | Unranked | zephexmcp · other | Hosted MCP gateway with 10 tools for code analysis, architecture review, package auditing, and security scanning. | No signals yet | No commit datelisted | No one-command install · Source |
| 295 | Unranked | zh-securityrules · other | zh rule: apply when working on zh and you need 安全指南. | No signals yet | No commit datelisted | armory install zh-security --cli claude |
Score colour shows how many signals stand behind it, never how good it is: amber, three or more; dimmer amber, two; grey, one. The Evidence column names them.
Stars, forks and last commit are as GitHub reported them when Armory last read each repository: for most, or later. A repository may have changed since.