Leaderboard
Scored on public signals; components with none are listed as Unranked · Formula
Component
Domain
Vertical
| Rank | Score | Component | Description | Evidence | Last commit | Install |
|---|---|---|---|---|---|---|
| 3201 | Unranked | sast-configurationskill · other | Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple… | No signals yet | No commit datelisted | armory install sast-configuration --cli claude |
| 3202 | Unranked | scopepilot-mcpmcp · auth | A safe and bounded AI-agent security testing framework that enables authorized web security testing tasks like reconnaissance, attack surface… | No signals yet | No commit datelisted | No one-command install · Source |
| 3203 | Unranked | scriptdocs-mcp-servermcp · back-end | A Model Context Protocol server that provides AI coding agents with real, live, source-cited documentation for npm, PyPI, and Cargo packages… | No signals yet | No commit datelisted | No one-command install · Source |
| 3204 | Unranked | se-security-reviewersubagent · ai-agents | Security-focused code review specialist with OWASP Top 10, Zero Trust, LLM security, and enterprise security standards | No signals yet | No commit datelisted | armory install se-security-reviewer --cli claude |
| 3205 | Unranked | secpipemcp · ai-agents | Enables AI agents to orchestrate security research workflows by connecting to containerized security tools via MCP, allowing automated vulnerability… | No signals yet | No commit datelisted | No one-command install · Source |
| 3206 | Unranked | secret-scanner-2hook · github-vcs | Secret Scanner Hook Detects hardcoded secrets before git commits | No signals yet | No commit datelisted | armory install secret-scanner-2 --cli claude |
| 3207 | Unranked | secrets-managementskill · devops | Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools. | No signals yet | No commit datelisted | armory install secrets-management --cli claude |
| 3208 | Unranked | secrets-scannerworkflow · auth | Scan codebase for exposed secrets, credentials, and sensitive information | No signals yet | No commit datelisted | armory install secrets-scanner --cli claude |
| 3209 | Unranked | secure-mcp-servermcp · auth | Template for deploying a remote MCP server with Cloudflare ZeroTrust Access authentication, supporting OAuth and container-based proxy. | No signals yet | No commit datelisted | No one-command install · Source |
| 3210 | Unranked | security-analyzersubagent · back-end | PROACTIVELY USE this agent when you need to perform comprehensive security analysis on code to identify vulnerabilities, potential attack vectors, and… | No signals yet | No commit datelisted | armory install security-analyzer --cli claude |
| 3211 | Unranked | security-architectsubagent · front-end | PROACTIVELY USE this agent when you need to design comprehensive security frameworks, authentication systems, authorization models, or data protection… | No signals yet | No commit datelisted | armory install security-architect --cli claude |
| 3212 | Unranked | security-auditworkflow · other | Perform comprehensive security assessment and vulnerability analysis | No signals yet | No commit datelisted | armory install security-audit --cli claude |
| 3213 | Unranked | security-audit-2skill · back-end | Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security… | No signals yet | No commit datelisted | armory install security-audit-2 --cli claude |
| 3214 | Unranked | security-auditorsubagent · devops | Use this agent when conducting comprehensive security audits, compliance assessments, or risk evaluations across systems, infrastructure, and… | No signals yet | No commit datelisted | armory install security-auditor --cli claude |
| 3215 | Unranked | security-best-practicesskill · other | Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests… | No signals yet | No commit datelisted | armory install security-best-practices --cli claude |
| 3216 | Unranked | security-bounty-hunterskill · github-vcs | Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports… | No signals yet | No commit datelisted | armory install security-bounty-hunter --cli claude |
| 3217 | Unranked | security-compliance-security-auditorsubagent · auth | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat… | No signals yet | No commit datelisted | armory install security-compliance-security-auditor --cli claude |
| 3218 | Unranked | security-controls-mcp-servermcp · back-end | Enables searching and bidirectional mapping of 1,451 security controls across 262 SCF-mapped frameworks, including ISO 27001, NIST CSF, DORA, and many… | No signals yet | No commit datelisted | No one-command install · Source |
| 3219 | Unranked | security-dependenciesworkflow · ai-agents | Dependency Vulnerability Scanning | No signals yet | No commit datelisted | armory install security-dependencies --cli claude |
| 3220 | Unranked | security-devsecops-ssdls-appsecrules · auth | Cursor rules for secure coding, secret handling, dependency hygiene, authentication, authorization, security testing, and compliance documentation. | No signals yet | No commit datelisted | armory install security-devsecops-ssdls-appsec --cli claude |
| 3221 | Unranked | security-engineersubagent · devops | Use this agent when implementing comprehensive security solutions across infrastructure, building automated security controls into CI/CD pipelines, or… | No signals yet | No commit datelisted | armory install security-engineer --cli claude |
| 3222 | Unranked | security-engineer-2subagent · devops | Use this agent when implementing comprehensive security solutions across infrastructure, building automated security controls into CI/CD pipelines, or… | No signals yet | No commit datelisted | armory install security-engineer-2 --cli claude |
| 3223 | Unranked | security-hardeningworkflow · other | Harden application security configuration with comprehensive security controls | No signals yet | No commit datelisted | armory install security-hardening --cli claude |
| 3224 | Unranked | security-hardening-2workflow · ai-agents | Implement security-first architecture and hardening measures with coordinated agent orchestration: | No signals yet | No commit datelisted | armory install security-hardening-2 --cli claude |
| 3225 | Unranked | security-ownership-mapskill · github-vcs | Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON… | No signals yet | No commit datelisted | armory install security-ownership-map --cli claude |
| 3226 | Unranked | security-paper-search-mcp-servermcp · back-end | Enables searching and retrieving security conference papers from major venues (S&P, USENIX, CCS, NDSS, etc.) using natural language queries through… | No signals yet | No commit datelisted | No one-command install · Source |
| 3227 | Unranked | security-reviewskill · back-end | Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive… | No signals yet | No commit datelisted | armory install security-review --cli claude |
| 3228 | Unranked | security-sastworkflow · ai-agents | Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks | No signals yet | No commit datelisted | armory install security-sast --cli claude |
| 3229 | Unranked | security-scanworkflow · ai-agents | Run AgentShield against agent, hook, MCP, permission, and secret surfaces. | No signals yet | No commit datelisted | armory install security-scan --cli claude |
| 3230 | Unranked | security-scannerhook · other | Scan code for security vulnerabilities and secrets after modifications. Uses multiple security tools to detect potential issues. | No signals yet | No commit datelisted | armory install security-scanner --cli claude |
| 3231 | Unranked | security-scanning-security-auditorsubagent · auth | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat… | No signals yet | No commit datelisted | armory install security-scanning-security-auditor --cli claude |
| 3232 | Unranked | security-scanning-toolsskill · other | This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security"… | No signals yet | No commit datelisted | armory install security-scanning-tools --cli claude |
| 3233 | Unranked | security-threat-modelskill · front-end | Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a… | No signals yet | No commit datelisted | armory install security-threat-model --cli claude |
| 3234 | Unranked | security-vulnerability-mcp-servermcp · back-end | Provides Claude with live access to multiple vulnerability databases (NVD, OSV, GitHub Advisories, Snyk) for querying CVEs, package vulnerabilities… | No signals yet | No commit datelisted | No one-command install · Source |
| 3235 | Unranked | securitycopilotmcpservermcp · other | Listed on mcp.so; Armory has only its name so far. | No signals yet | No commit datelisted | No one-command install · Source |
| 3236 | Unranked | securityscan-api-securityscan-apimcp · ai-agents | Scans AI agent skills and plugins for prompt injection, malware patterns, and OWASP LLM Top 10 vulnerabilities before installation. | No signals yet | No commit datelisted | No one-command install · Source |
| 3237 | Unranked | senior-backendskill · back-end | Comprehensive backend development skill for building scalable backend systems using NodeJS, Express, Go, Python, Postgres, GraphQL, REST APIs… | No signals yet | No commit datelisted | armory install senior-backend --cli claude |
| 3238 | Unranked | senior-code-reviewersubagent · auth | Use this agent when you need comprehensive code review from a senior fullstack developer perspective, including analysis of code quality, architecture… | No signals yet | No commit datelisted | armory install senior-code-reviewer --cli claude |
| 3239 | Unranked | senior-secopsskill · other | Comprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security… | No signals yet | No commit datelisted | armory install senior-secops --cli claude |
| 3240 | Unranked | senior-securityskill · front-end | Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes… | No signals yet | No commit datelisted | armory install senior-security --cli claude |
| 3241 | Unranked | servercard-trustmcp · ai-agents | MCP server-card validation, auth checks, and trust packet generation for agent security. | No signals yet | No commit datelisted | No one-command install · Source |
| 3242 | Unranked | service-mesh-expertsubagent · back-end | Expert service mesh architect specializing in Istio, Linkerd, and cloud-native networking patterns. Masters traffic management, security policies… | No signals yet | No commit datelisted | armory install service-mesh-expert --cli claude |
| 3243 | Unranked | setup-kubernetes-deploymentworkflow · devops | Configure comprehensive Kubernetes deployment with manifests, security, scaling, and production best practices | No signals yet | No commit datelisted | armory install setup-kubernetes-deployment --cli claude |
| 3244 | Unranked | sf-opensearch-logging-mcpmcp · auth | Enables querying ShareFile OpenSearch production logs via MCP with automatic EntraID OAuth authentication. | No signals yet | No commit datelisted | No one-command install · Source |
| 3245 | Unranked | shannon-lite-mcpmcp · ai-agents | MCP server for Shannon Lite security workflows, enabling configuration, scan orchestration, workspace management, and report reading. | No signals yet | No commit datelisted | No one-command install · Source |
| 3246 | Unranked | shell-wrapper-guardhook · database | Detects destructive commands hidden inside shell wrappers (sh -c, bash -c, python3 -c, node -e, perl -e, ruby -e). Complements… | No signals yet | No commit datelisted | armory install shell-wrapper-guard --cli claude |
| 3247 | Unranked | shell-wrapper-guard-2hook · other | shell-wrapper-guard.sh — Detect destructive commands hidden in shell wrappers | No signals yet | No commit datelisted | armory install shell-wrapper-guard-2 --cli claude |
| 3248 | Unranked | shodan-reconnaissance-and-pentestingskill · back-end | This skill should be used when the user asks to "search for exposed devices on the internet," "perform Shodan reconnaissance," "find vulnerable… | No signals yet | No commit datelisted | armory install shodan-reconnaissance-and-pentesting --cli claude |
| 3249 | Unranked | shopee-mcp-servermcp · back-end | Enables AI agents to automate product listing on Shopee via the Shopee Open Platform API, including OAuth2 authentication, product creation, image… | No signals yet | No commit datelisted | No one-command install · Source |
| 3250 | Unranked | skeleton-mcpmcp · back-end | A starter template for building an MCP server with Vault-based secret management and Postgres-backed configuration, featuring tool-level authorization… | No signals yet | No commit datelisted | No one-command install · Source |
| 3251 | Unranked | skyxtools-mcpmcp · back-end | Manual listener MCP server that bridges OpenCode with local security tools via a Flask HTTP service, enabling AI-assisted security operations. | No signals yet | No commit datelisted | No one-command install · Source |
| 3252 | Unranked | slack-expertsubagent · back-end | Use this agent when developing Slack applications, implementing Slack API integrations, or reviewing Slack bot code for security and best practices. | No signals yet | No commit datelisted | armory install slack-expert --cli claude |
| 3253 | Unranked | sleekbeat-keyvault-promcp · back-end | Provides secure encrypted storage and intelligent auto-fill for API keys across development environments through browser extension, CLI tool, and… | No signals yet | No commit datelisted | No one-command install · Source |
| 3254 | Unranked | smartpark-central-mcp-servermcp · back-end | Records approved parking reservations to a secure text file via the Model Context Protocol, with token authentication and input sanitization. | No signals yet | No commit datelisted | No one-command install · Source |
| 3255 | Unranked | smtp-penetration-testingskill · back-end | This skill should be used when the user asks to "perform SMTP penetration testing", "enumerate email users", "test for open mail relays", "grab SMTP… | No signals yet | No commit datelisted | armory install smtp-penetration-testing --cli claude |
| 3256 | Unranked | solidity-sentinelmcp · devops | Enables static security audit of Solidity smart contracts by analyzing source code or deployed bytecode for vulnerabilities, providing risk scores and… | No signals yet | No commit datelisted | No one-command install · Source |
| 3257 | Unranked | springboot-securityskill · auth | Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot… | No signals yet | No commit datelisted | armory install springboot-security --cli claude |
| 3258 | Unranked | springboot-verificationskill · other | "Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR." | No signals yet | No commit datelisted | armory install springboot-verification --cli claude |
| 3259 | Unranked | sql-injection-testingskill · database | This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL… | No signals yet | No commit datelisted | armory install sql-injection-testing --cli claude |
| 3260 | Unranked | sqli-detectormcp · database | Enables AI-assisted security assessments by scanning URLs for SQL injection vulnerabilities using error-based, boolean-based, and time-based detection… | No signals yet | No commit datelisted | No one-command install · Source |
| 3261 | Unranked | sqlmap-database-penetration-testingskill · database | This skill should be used when the user asks to "automate SQL injection testing," "enumerate database structure," "extract database credentials using… | No signals yet | No commit datelisted | armory install sqlmap-database-penetration-testing --cli claude |
| 3262 | Unranked | ssh-penetration-testingskill · auth | This skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH… | No signals yet | No commit datelisted | armory install ssh-penetration-testing --cli claude |
| 3263 | Unranked | stackhawk-security-onboardingsubagent · github-vcs | Automatically set up StackHawk security testing for your repository with generated configuration and GitHub Actions workflow | No signals yet | No commit datelisted | armory install stackhawk-security-onboarding --cli claude |
| 3264 | Unranked | staticapkauditor-mcpmcp · observability | Enables Android APK security auditing through natural language by decompiling APKs with Apktool and running static analysis heuristics for attack… | No signals yet | No commit datelisted | No one-command install · Source |
| 3265 | Unranked | substance-designer-mcpmcp · front-end | A security-focused MCP server for Adobe Substance 3D Designer that reads application state, creates and manipulates nodes, and saves packages, with… | No signals yet | No commit datelisted | No one-command install · Source |
| 3266 | Unranked | supabase-security-auditworkflow · database | Conduct comprehensive Supabase security audit with RLS analysis and vulnerability assessment | No signals yet | No commit datelisted | armory install supabase-security-audit --cli claude |
| 3267 | Unranked | super-rag-mcp-servermcp · search | Enables AI agents to perform offline cybersecurity research and penetration testing by querying a local knowledge base of curated security data, with… | No signals yet | No commit datelisted | No one-command install · Source |
| 3268 | Unranked | supply-chain-securitysubagent · ai-agents | An AI security specialist focused on software supply chain threats: dependency | No signals yet | No commit datelisted | armory install supply-chain-security --cli claude |
| 3269 | Unranked | suprawallmcp · observability | Zero-trust runtime security layer for AI agents with policy enforcement, human approval workflows, and audit logging. | No signals yet | No commit datelisted | No one-command install · Source |
| 3270 | Unranked | swift-securityrules · other | swift rule: apply when working on swift and you need Swift Security. | No signals yet | No commit datelisted | armory install swift-security --cli claude |
| 3271 | Unranked | tdd-workflows-code-reviewersubagent · ai-agents | Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production… | No signals yet | No commit datelisted | armory install tdd-workflows-code-reviewer --cli claude |
| 3272 | Unranked | team-reviewersubagent · ai-agents | Multi-dimensional code reviewer that operates on one assigned review dimension (security, performance, architecture, testing, or accessibility) with… | No signals yet | No commit datelisted | armory install team-reviewer --cli claude |
| 3273 | Unranked | team-spawnworkflow · ai-agents | Spawn an agent team using presets (review, debug, feature, fullstack, research, security, migration) or custom composition | No signals yet | No commit datelisted | armory install team-spawn --cli claude |
| 3274 | Unranked | tenable-mcpmcp · other | Exposes Tenable security operations as MCP tools for AI-powered security workflows, enabling asset, vulnerability, scan, plugin, and tag management… | No signals yet | No commit datelisted | No one-command install · Source |
| 3275 | Unranked | terraformsubagent · devops | Terraform infrastructure specialist with automated HCP Terraform workflows. Leverages Terraform MCP server for registry integration, workspace… | No signals yet | No commit datelisted | armory install terraform --cli claude |
| 3276 | Unranked | test-automatorsubagent · devops | Use this agent when you need to build, implement, or enhance automated test frameworks, create test scripts, or integrate testing into CI/CD… | No signals yet | No commit datelisted | armory install test-automator --cli claude |
| 3277 | Unranked | thornguardmcp · auth | MCP security gateway for auth enforcement, request blocking, data redaction, policy control, and audit logging. | No signals yet | No commit datelisted | No one-command install · Source |
| 3278 | Unranked | threat-modeling-expertskill · front-end | Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security… | No signals yet | No commit datelisted | armory install threat-modeling-expert --cli claude |
| 3279 | Unranked | threat-modeling-expertsubagent · front-end | Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security… | No signals yet | No commit datelisted | armory install threat-modeling-expert --cli claude |
| 3280 | Unranked | tinyfishmcp · auth | TinyFish Web Agent - Web browsing and data extraction via MCP with real-time progress streaming, async tasks, and stealth browser profiles. Requires a… | No signals yet | No commit datelisted | No one-command install · Source |
| 3281 | Unranked | tool-use-threat-intel-enrichment-agentworkflow · ai-agents | Build an agent that autonomously investigates IOCs by querying multiple threat intel sources, cross-referencing findings, mapping to MITRE ATT&CK, and… | No signals yet | No commit datelisted | armory install tool-use-threat-intel-enrichment-agent --cli claude |
| 3282 | Unranked | top-100-web-vulnerabilities-referenceskill · back-end | This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability… | No signals yet | No commit datelisted | armory install top-100-web-vulnerabilities-reference --cli claude |
| 3283 | Unranked | tvcmall-customer-mcpmcp · back-end | A remote MCP server for TVCMall customers to query products, orders, shipping, points, and balance transactions via natural language, with PAT-based… | No signals yet | No commit datelisted | No one-command install · Source |
| 3284 | Unranked | tyox-all-mundmcp · ai-agents | Security scanner for AI agents detecting prompt injection, secrets, PII, dangerous code patterns, and malicious tool descriptions. | No signals yet | No commit datelisted | No one-command install · Source |
| 3285 | Unranked | typescript-reviewersubagent · ai-agents | Expert TypeScript/JavaScript code reviewer specializing in type safety, async correctness, Node/web security, and idiomatic patterns. Use for all… | No signals yet | No commit datelisted | armory install typescript-reviewer --cli claude |
| 3286 | Unranked | typescript-securityrules · other | typescript rule: apply when working on typescript and you need TypeScript/JavaScript Security. | No signals yet | No commit datelisted | armory install typescript-security --cli claude |
| 3287 | Unranked | ugreen-nas-mcp-servermcp · front-end | A secure MCP server designed for Ugreen NAS, enabling AI clients to list and access shared directories over SSE with token authentication and… | No signals yet | No commit datelisted | No one-command install · Source |
| 3288 | Unranked | ui-ux-testersubagent · front-end | Use this agent when you need exhaustive UI and UX functionality testing driven by documented user flows, with browser or desktop interaction tooling… | No signals yet | No commit datelisted | armory install ui-ux-tester --cli claude |
| 3289 | Unranked | unifi-mcp-servermcp · ai-agents | MCP server providing Claude Code with full UniFi network management capabilities -- devices, clients, ports, bandwidth auditing, firewall policies… | No signals yet | No commit datelisted | No one-command install · Source |
| 3290 | Unranked | using-neonskill · back-end | Guides and best practices for working with Neon Serverless Postgres. Covers getting started, local development with Neon, choosing a connection… | No signals yet | No commit datelisted | armory install using-neon --cli claude |
| 3291 | Unranked | validate-branch-name-2hook · auth | ❌ Invalid Git Flow branch name: {branch_name} Git Flow branches must follow these patterns: • feature/<descriptive-name> •… | No signals yet | No commit datelisted | armory install validate-branch-name-2 --cli claude |
| 3292 | Unranked | vercelmcp · auth | Official Vercel integration that provides secure access to deployments, project configuration, and team resources through OAuth authentication for… | No signals yet | No commit datelisted | No one-command install · Source |
| 3293 | Unranked | vercel-edge-functionworkflow · front-end | Generate optimized Vercel Edge Functions with geolocation, authentication, and data transformation | No signals yet | No commit datelisted | armory install vercel-edge-function --cli claude |
| 3294 | Unranked | verrysimatupang99-aegismcp · devops | Defensive security scanning for secrets, dependency vulnerabilities, obfuscation, Docker misconfigurations, and filesystem permission issues. | No signals yet | No commit datelisted | No one-command install · Source |
| 3295 | Unranked | vsa-x-mcpmcp · back-end | MCP server that wraps the VSA X API to enable querying and managing devices, assets, organizations, and rate limits, with centralized configuration… | No signals yet | No commit datelisted | No one-command install · Source |
| 3296 | Unranked | vulnebifymcp · observability | Real-time vulnerability monitoring and threat intelligence for developers | No signals yet | No commit datelisted | No one-command install · Source |
| 3297 | Unranked | vulnerability-scannerskill · other | Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization. | No signals yet | No commit datelisted | armory install vulnerability-scanner --cli claude |
| 3298 | Unranked | wascer-gtm-mcp-servermcp · auth | A remote MCP server for Google Tag Manager that enables AI assistants to manage GTM accounts, containers, tags, triggers, variables, and more via… | No signals yet | No commit datelisted | No one-command install · Source |
| 3299 | Unranked | web-check-mcpmcp · back-end | MCP server that exposes 31 OSINT checks from Lissy93/web-check as tools for website analysis, including SSL, DNS, headers, WHOIS, and security… | No signals yet | No commit datelisted | No one-command install · Source |
| 3300 | Unranked | web-doctormcp · other | Enables live website health checks including TLS, HTTPS, and security headers, returning an A-F grade with specific fixes. | No signals yet | No commit datelisted | No one-command install · Source |
Score colour shows how many signals stand behind it, never how good it is: amber, three or more; dimmer amber, two; grey, one. The Evidence column names them.
Stars, forks and last commit are as GitHub reported them when Armory last read each repository: for most, or later. A repository may have changed since.