Armory
Source

Leaderboard

Scored on public signals; components with none are listed as Unranked · Formula

RankScoreComponentDescriptionEvidenceLast commitInstall
3201Unrankedsast-configurationskill · otherStatic Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple…No signals yetNo commit datelisted armory install sast-configuration --cli claude
3202Unrankedscopepilot-mcpmcp · authA safe and bounded AI-agent security testing framework that enables authorized web security testing tasks like reconnaissance, attack surface…No signals yetNo commit datelisted No one-command install · Source
3203Unrankedscriptdocs-mcp-servermcp · back-endA Model Context Protocol server that provides AI coding agents with real, live, source-cited documentation for npm, PyPI, and Cargo packages…No signals yetNo commit datelisted No one-command install · Source
3204Unrankedse-security-reviewersubagent · ai-agentsSecurity-focused code review specialist with OWASP Top 10, Zero Trust, LLM security, and enterprise security standardsNo signals yetNo commit datelisted armory install se-security-reviewer --cli claude
3205Unrankedsecpipemcp · ai-agentsEnables AI agents to orchestrate security research workflows by connecting to containerized security tools via MCP, allowing automated vulnerability…No signals yetNo commit datelisted No one-command install · Source
3206Unrankedsecret-scanner-2hook · github-vcsSecret Scanner Hook Detects hardcoded secrets before git commitsNo signals yetNo commit datelisted armory install secret-scanner-2 --cli claude
3207Unrankedsecrets-managementskill · devopsSecure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.No signals yetNo commit datelisted armory install secrets-management --cli claude
3208Unrankedsecrets-scannerworkflow · authScan codebase for exposed secrets, credentials, and sensitive informationNo signals yetNo commit datelisted armory install secrets-scanner --cli claude
3209Unrankedsecure-mcp-servermcp · authTemplate for deploying a remote MCP server with Cloudflare ZeroTrust Access authentication, supporting OAuth and container-based proxy.No signals yetNo commit datelisted No one-command install · Source
3210Unrankedsecurity-analyzersubagent · back-endPROACTIVELY USE this agent when you need to perform comprehensive security analysis on code to identify vulnerabilities, potential attack vectors, and…No signals yetNo commit datelisted armory install security-analyzer --cli claude
3211Unrankedsecurity-architectsubagent · front-endPROACTIVELY USE this agent when you need to design comprehensive security frameworks, authentication systems, authorization models, or data protection…No signals yetNo commit datelisted armory install security-architect --cli claude
3212Unrankedsecurity-auditworkflow · otherPerform comprehensive security assessment and vulnerability analysisNo signals yetNo commit datelisted armory install security-audit --cli claude
3213Unrankedsecurity-audit-2skill · back-endComprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security…No signals yetNo commit datelisted armory install security-audit-2 --cli claude
3214Unrankedsecurity-auditorsubagent · devopsUse this agent when conducting comprehensive security audits, compliance assessments, or risk evaluations across systems, infrastructure, and…No signals yetNo commit datelisted armory install security-auditor --cli claude
3215Unrankedsecurity-best-practicesskill · otherPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests…No signals yetNo commit datelisted armory install security-best-practices --cli claude
3216Unrankedsecurity-bounty-hunterskill · github-vcsHunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports…No signals yetNo commit datelisted armory install security-bounty-hunter --cli claude
3217Unrankedsecurity-compliance-security-auditorsubagent · authExpert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat…No signals yetNo commit datelisted armory install security-compliance-security-auditor --cli claude
3218Unrankedsecurity-controls-mcp-servermcp · back-endEnables searching and bidirectional mapping of 1,451 security controls across 262 SCF-mapped frameworks, including ISO 27001, NIST CSF, DORA, and many…No signals yetNo commit datelisted No one-command install · Source
3219Unrankedsecurity-dependenciesworkflow · ai-agentsDependency Vulnerability ScanningNo signals yetNo commit datelisted armory install security-dependencies --cli claude
3220Unrankedsecurity-devsecops-ssdls-appsecrules · authCursor rules for secure coding, secret handling, dependency hygiene, authentication, authorization, security testing, and compliance documentation.No signals yetNo commit datelisted armory install security-devsecops-ssdls-appsec --cli claude
3221Unrankedsecurity-engineersubagent · devopsUse this agent when implementing comprehensive security solutions across infrastructure, building automated security controls into CI/CD pipelines, or…No signals yetNo commit datelisted armory install security-engineer --cli claude
3222Unrankedsecurity-engineer-2subagent · devopsUse this agent when implementing comprehensive security solutions across infrastructure, building automated security controls into CI/CD pipelines, or…No signals yetNo commit datelisted armory install security-engineer-2 --cli claude
3223Unrankedsecurity-hardeningworkflow · otherHarden application security configuration with comprehensive security controlsNo signals yetNo commit datelisted armory install security-hardening --cli claude
3224Unrankedsecurity-hardening-2workflow · ai-agentsImplement security-first architecture and hardening measures with coordinated agent orchestration:No signals yetNo commit datelisted armory install security-hardening-2 --cli claude
3225Unrankedsecurity-ownership-mapskill · github-vcsAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON…No signals yetNo commit datelisted armory install security-ownership-map --cli claude
3226Unrankedsecurity-paper-search-mcp-servermcp · back-endEnables searching and retrieving security conference papers from major venues (S&P, USENIX, CCS, NDSS, etc.) using natural language queries through…No signals yetNo commit datelisted No one-command install · Source
3227Unrankedsecurity-reviewskill · back-endUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive…No signals yetNo commit datelisted armory install security-review --cli claude
3228Unrankedsecurity-sastworkflow · ai-agentsStatic Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworksNo signals yetNo commit datelisted armory install security-sast --cli claude
3229Unrankedsecurity-scanworkflow · ai-agentsRun AgentShield against agent, hook, MCP, permission, and secret surfaces.No signals yetNo commit datelisted armory install security-scan --cli claude
3230Unrankedsecurity-scannerhook · otherScan code for security vulnerabilities and secrets after modifications. Uses multiple security tools to detect potential issues.No signals yetNo commit datelisted armory install security-scanner --cli claude
3231Unrankedsecurity-scanning-security-auditorsubagent · authExpert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat…No signals yetNo commit datelisted armory install security-scanning-security-auditor --cli claude
3232Unrankedsecurity-scanning-toolsskill · otherThis skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security"…No signals yetNo commit datelisted armory install security-scanning-tools --cli claude
3233Unrankedsecurity-threat-modelskill · front-endRepository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a…No signals yetNo commit datelisted armory install security-threat-model --cli claude
3234Unrankedsecurity-vulnerability-mcp-servermcp · back-endProvides Claude with live access to multiple vulnerability databases (NVD, OSV, GitHub Advisories, Snyk) for querying CVEs, package vulnerabilities…No signals yetNo commit datelisted No one-command install · Source
3235Unrankedsecuritycopilotmcpservermcp · otherListed on mcp.so; Armory has only its name so far.No signals yetNo commit datelisted No one-command install · Source
3236Unrankedsecurityscan-api-securityscan-apimcp · ai-agentsScans AI agent skills and plugins for prompt injection, malware patterns, and OWASP LLM Top 10 vulnerabilities before installation.No signals yetNo commit datelisted No one-command install · Source
3237Unrankedsenior-backendskill · back-endComprehensive backend development skill for building scalable backend systems using NodeJS, Express, Go, Python, Postgres, GraphQL, REST APIs…No signals yetNo commit datelisted armory install senior-backend --cli claude
3238Unrankedsenior-code-reviewersubagent · authUse this agent when you need comprehensive code review from a senior fullstack developer perspective, including analysis of code quality, architecture…No signals yetNo commit datelisted armory install senior-code-reviewer --cli claude
3239Unrankedsenior-secopsskill · otherComprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security…No signals yetNo commit datelisted armory install senior-secops --cli claude
3240Unrankedsenior-securityskill · front-endComprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes…No signals yetNo commit datelisted armory install senior-security --cli claude
3241Unrankedservercard-trustmcp · ai-agentsMCP server-card validation, auth checks, and trust packet generation for agent security.No signals yetNo commit datelisted No one-command install · Source
3242Unrankedservice-mesh-expertsubagent · back-endExpert service mesh architect specializing in Istio, Linkerd, and cloud-native networking patterns. Masters traffic management, security policies…No signals yetNo commit datelisted armory install service-mesh-expert --cli claude
3243Unrankedsetup-kubernetes-deploymentworkflow · devopsConfigure comprehensive Kubernetes deployment with manifests, security, scaling, and production best practicesNo signals yetNo commit datelisted armory install setup-kubernetes-deployment --cli claude
3244Unrankedsf-opensearch-logging-mcpmcp · authEnables querying ShareFile OpenSearch production logs via MCP with automatic EntraID OAuth authentication.No signals yetNo commit datelisted No one-command install · Source
3245Unrankedshannon-lite-mcpmcp · ai-agentsMCP server for Shannon Lite security workflows, enabling configuration, scan orchestration, workspace management, and report reading.No signals yetNo commit datelisted No one-command install · Source
3246Unrankedshell-wrapper-guardhook · databaseDetects destructive commands hidden inside shell wrappers (sh -c, bash -c, python3 -c, node -e, perl -e, ruby -e). Complements…No signals yetNo commit datelisted armory install shell-wrapper-guard --cli claude
3247Unrankedshell-wrapper-guard-2hook · othershell-wrapper-guard.sh — Detect destructive commands hidden in shell wrappersNo signals yetNo commit datelisted armory install shell-wrapper-guard-2 --cli claude
3248Unrankedshodan-reconnaissance-and-pentestingskill · back-endThis skill should be used when the user asks to "search for exposed devices on the internet," "perform Shodan reconnaissance," "find vulnerable…No signals yetNo commit datelisted armory install shodan-reconnaissance-and-pentesting --cli claude
3249Unrankedshopee-mcp-servermcp · back-endEnables AI agents to automate product listing on Shopee via the Shopee Open Platform API, including OAuth2 authentication, product creation, image…No signals yetNo commit datelisted No one-command install · Source
3250Unrankedskeleton-mcpmcp · back-endA starter template for building an MCP server with Vault-based secret management and Postgres-backed configuration, featuring tool-level authorization…No signals yetNo commit datelisted No one-command install · Source
3251Unrankedskyxtools-mcpmcp · back-endManual listener MCP server that bridges OpenCode with local security tools via a Flask HTTP service, enabling AI-assisted security operations.No signals yetNo commit datelisted No one-command install · Source
3252Unrankedslack-expertsubagent · back-endUse this agent when developing Slack applications, implementing Slack API integrations, or reviewing Slack bot code for security and best practices.No signals yetNo commit datelisted armory install slack-expert --cli claude
3253Unrankedsleekbeat-keyvault-promcp · back-endProvides secure encrypted storage and intelligent auto-fill for API keys across development environments through browser extension, CLI tool, and…No signals yetNo commit datelisted No one-command install · Source
3254Unrankedsmartpark-central-mcp-servermcp · back-endRecords approved parking reservations to a secure text file via the Model Context Protocol, with token authentication and input sanitization.No signals yetNo commit datelisted No one-command install · Source
3255Unrankedsmtp-penetration-testingskill · back-endThis skill should be used when the user asks to "perform SMTP penetration testing", "enumerate email users", "test for open mail relays", "grab SMTP…No signals yetNo commit datelisted armory install smtp-penetration-testing --cli claude
3256Unrankedsolidity-sentinelmcp · devopsEnables static security audit of Solidity smart contracts by analyzing source code or deployed bytecode for vulnerabilities, providing risk scores and…No signals yetNo commit datelisted No one-command install · Source
3257Unrankedspringboot-securityskill · authSpring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot…No signals yetNo commit datelisted armory install springboot-security --cli claude
3258Unrankedspringboot-verificationskill · other"Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR."No signals yetNo commit datelisted armory install springboot-verification --cli claude
3259Unrankedsql-injection-testingskill · databaseThis skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL…No signals yetNo commit datelisted armory install sql-injection-testing --cli claude
3260Unrankedsqli-detectormcp · databaseEnables AI-assisted security assessments by scanning URLs for SQL injection vulnerabilities using error-based, boolean-based, and time-based detection…No signals yetNo commit datelisted No one-command install · Source
3261Unrankedsqlmap-database-penetration-testingskill · databaseThis skill should be used when the user asks to "automate SQL injection testing," "enumerate database structure," "extract database credentials using…No signals yetNo commit datelisted armory install sqlmap-database-penetration-testing --cli claude
3262Unrankedssh-penetration-testingskill · authThis skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH…No signals yetNo commit datelisted armory install ssh-penetration-testing --cli claude
3263Unrankedstackhawk-security-onboardingsubagent · github-vcsAutomatically set up StackHawk security testing for your repository with generated configuration and GitHub Actions workflowNo signals yetNo commit datelisted armory install stackhawk-security-onboarding --cli claude
3264Unrankedstaticapkauditor-mcpmcp · observabilityEnables Android APK security auditing through natural language by decompiling APKs with Apktool and running static analysis heuristics for attack…No signals yetNo commit datelisted No one-command install · Source
3265Unrankedsubstance-designer-mcpmcp · front-endA security-focused MCP server for Adobe Substance 3D Designer that reads application state, creates and manipulates nodes, and saves packages, with…No signals yetNo commit datelisted No one-command install · Source
3266Unrankedsupabase-security-auditworkflow · databaseConduct comprehensive Supabase security audit with RLS analysis and vulnerability assessmentNo signals yetNo commit datelisted armory install supabase-security-audit --cli claude
3267Unrankedsuper-rag-mcp-servermcp · searchEnables AI agents to perform offline cybersecurity research and penetration testing by querying a local knowledge base of curated security data, with…No signals yetNo commit datelisted No one-command install · Source
3268Unrankedsupply-chain-securitysubagent · ai-agentsAn AI security specialist focused on software supply chain threats: dependencyNo signals yetNo commit datelisted armory install supply-chain-security --cli claude
3269Unrankedsuprawallmcp · observabilityZero-trust runtime security layer for AI agents with policy enforcement, human approval workflows, and audit logging.No signals yetNo commit datelisted No one-command install · Source
3270Unrankedswift-securityrules · otherswift rule: apply when working on swift and you need Swift Security.No signals yetNo commit datelisted armory install swift-security --cli claude
3271Unrankedtdd-workflows-code-reviewersubagent · ai-agentsElite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production…No signals yetNo commit datelisted armory install tdd-workflows-code-reviewer --cli claude
3272Unrankedteam-reviewersubagent · ai-agentsMulti-dimensional code reviewer that operates on one assigned review dimension (security, performance, architecture, testing, or accessibility) with…No signals yetNo commit datelisted armory install team-reviewer --cli claude
3273Unrankedteam-spawnworkflow · ai-agentsSpawn an agent team using presets (review, debug, feature, fullstack, research, security, migration) or custom compositionNo signals yetNo commit datelisted armory install team-spawn --cli claude
3274Unrankedtenable-mcpmcp · otherExposes Tenable security operations as MCP tools for AI-powered security workflows, enabling asset, vulnerability, scan, plugin, and tag management…No signals yetNo commit datelisted No one-command install · Source
3275Unrankedterraformsubagent · devopsTerraform infrastructure specialist with automated HCP Terraform workflows. Leverages Terraform MCP server for registry integration, workspace…No signals yetNo commit datelisted armory install terraform --cli claude
3276Unrankedtest-automatorsubagent · devopsUse this agent when you need to build, implement, or enhance automated test frameworks, create test scripts, or integrate testing into CI/CD…No signals yetNo commit datelisted armory install test-automator --cli claude
3277Unrankedthornguardmcp · authMCP security gateway for auth enforcement, request blocking, data redaction, policy control, and audit logging.No signals yetNo commit datelisted No one-command install · Source
3278Unrankedthreat-modeling-expertskill · front-endExpert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security…No signals yetNo commit datelisted armory install threat-modeling-expert --cli claude
3279Unrankedthreat-modeling-expertsubagent · front-endExpert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security…No signals yetNo commit datelisted armory install threat-modeling-expert --cli claude
3280Unrankedtinyfishmcp · authTinyFish Web Agent - Web browsing and data extraction via MCP with real-time progress streaming, async tasks, and stealth browser profiles. Requires a…No signals yetNo commit datelisted No one-command install · Source
3281Unrankedtool-use-threat-intel-enrichment-agentworkflow · ai-agentsBuild an agent that autonomously investigates IOCs by querying multiple threat intel sources, cross-referencing findings, mapping to MITRE ATT&CK, and…No signals yetNo commit datelisted armory install tool-use-threat-intel-enrichment-agent --cli claude
3282Unrankedtop-100-web-vulnerabilities-referenceskill · back-endThis skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability…No signals yetNo commit datelisted armory install top-100-web-vulnerabilities-reference --cli claude
3283Unrankedtvcmall-customer-mcpmcp · back-endA remote MCP server for TVCMall customers to query products, orders, shipping, points, and balance transactions via natural language, with PAT-based…No signals yetNo commit datelisted No one-command install · Source
3284Unrankedtyox-all-mundmcp · ai-agentsSecurity scanner for AI agents detecting prompt injection, secrets, PII, dangerous code patterns, and malicious tool descriptions.No signals yetNo commit datelisted No one-command install · Source
3285Unrankedtypescript-reviewersubagent · ai-agentsExpert TypeScript/JavaScript code reviewer specializing in type safety, async correctness, Node/web security, and idiomatic patterns. Use for all…No signals yetNo commit datelisted armory install typescript-reviewer --cli claude
3286Unrankedtypescript-securityrules · othertypescript rule: apply when working on typescript and you need TypeScript/JavaScript Security.No signals yetNo commit datelisted armory install typescript-security --cli claude
3287Unrankedugreen-nas-mcp-servermcp · front-endA secure MCP server designed for Ugreen NAS, enabling AI clients to list and access shared directories over SSE with token authentication and…No signals yetNo commit datelisted No one-command install · Source
3288Unrankedui-ux-testersubagent · front-endUse this agent when you need exhaustive UI and UX functionality testing driven by documented user flows, with browser or desktop interaction tooling…No signals yetNo commit datelisted armory install ui-ux-tester --cli claude
3289Unrankedunifi-mcp-servermcp · ai-agentsMCP server providing Claude Code with full UniFi network management capabilities -- devices, clients, ports, bandwidth auditing, firewall policies…No signals yetNo commit datelisted No one-command install · Source
3290Unrankedusing-neonskill · back-endGuides and best practices for working with Neon Serverless Postgres. Covers getting started, local development with Neon, choosing a connection…No signals yetNo commit datelisted armory install using-neon --cli claude
3291Unrankedvalidate-branch-name-2hook · auth❌ Invalid Git Flow branch name: {branch_name} Git Flow branches must follow these patterns: • feature/<descriptive-name> •…No signals yetNo commit datelisted armory install validate-branch-name-2 --cli claude
3292Unrankedvercelmcp · authOfficial Vercel integration that provides secure access to deployments, project configuration, and team resources through OAuth authentication for…No signals yetNo commit datelisted No one-command install · Source
3293Unrankedvercel-edge-functionworkflow · front-endGenerate optimized Vercel Edge Functions with geolocation, authentication, and data transformationNo signals yetNo commit datelisted armory install vercel-edge-function --cli claude
3294Unrankedverrysimatupang99-aegismcp · devopsDefensive security scanning for secrets, dependency vulnerabilities, obfuscation, Docker misconfigurations, and filesystem permission issues.No signals yetNo commit datelisted No one-command install · Source
3295Unrankedvsa-x-mcpmcp · back-endMCP server that wraps the VSA X API to enable querying and managing devices, assets, organizations, and rate limits, with centralized configuration…No signals yetNo commit datelisted No one-command install · Source
3296Unrankedvulnebifymcp · observabilityReal-time vulnerability monitoring and threat intelligence for developersNo signals yetNo commit datelisted No one-command install · Source
3297Unrankedvulnerability-scannerskill · otherAdvanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.No signals yetNo commit datelisted armory install vulnerability-scanner --cli claude
3298Unrankedwascer-gtm-mcp-servermcp · authA remote MCP server for Google Tag Manager that enables AI assistants to manage GTM accounts, containers, tags, triggers, variables, and more via…No signals yetNo commit datelisted No one-command install · Source
3299Unrankedweb-check-mcpmcp · back-endMCP server that exposes 31 OSINT checks from Lissy93/web-check as tools for website analysis, including SSL, DNS, headers, WHOIS, and security…No signals yetNo commit datelisted No one-command install · Source
3300Unrankedweb-doctormcp · otherEnables live website health checks including TLS, HTTPS, and security headers, returning an A-F grade with specific fixes.No signals yetNo commit datelisted No one-command install · Source

Score colour shows how many signals stand behind it, never how good it is: amber, three or more; dimmer amber, two; grey, one. The Evidence column names them.

Stars, forks and last commit are as GitHub reported them when Armory last read each repository: for most, or later. A repository may have changed since.

Leaderboard · Armory