harness · market
Harness
Put raw intelligence to work.
Skills, MCP servers, prompts, assistants and connectors. Every listing shows its author, version and the permissions it needs.
On the shelves21,000
- MCP servers18,849
- Skills1,282
- Assistants651
- Prompts218
0 items
SecuritySpecialist assistants, also called subagents. Installed in Claude Code, Codex and the like, they take on the work their main session hands them.
- Security Auditoraddyosmani 103kSecurity engineer focused on vulnerability detection, threat modeling, and secure coding practices. Use for security-focused code review, threat analysis, or hardening recommendations.SecurityCoding
- C# revieweraffaan-m 275kExpert C# code reviewer specializing in .NET conventions, async patterns, security, nullable reference types, and performance. Use for all C# code changes.SonnetSecurity
- Scan redactoranthropics· claude-security 38kRestricted agent dispatched by the Claude Security scan jobs to replace the credential values in a finished scan's report files with [REDACTED]; not for direct invocation.SonnetFilesSecurity
- Senior Code Revieweraddyosmani 103kSenior code reviewer that evaluates changes across five dimensions — correctness, readability, architecture, security, and performance. Use for thorough code review before merge.SecurityCodingArchitecture
- Database Revieweraffaan-m 275kPostgreSQL database specialist for query optimization, schema design, security, and performance. Incorporates Supabase best practices.SonnetDatabasesSecurity
- FastAPI revieweraffaan-m 275kReviews FastAPI applications for async correctness, dependency injection, Pydantic schemas, security, OpenAPI quality, testing, and production readiness.SonnetSecurityTestingBackend
- Network config revieweraffaan-m 275kReviews router and switch configurations for security, correctness, stale references, risky change-window commands, and missing operational guardrails.SonnetSecurity
- Threat Intelligence Analystmsitarzewski 158kCyber threat intelligence specialist who tracks adversary groups, maps attack campaigns to MITRE ATT&CK, produces actionable intelligence reports, and builds detection rules that catch real threats.SecurityMaps and placesMarketing and SEO
- TypeScript revieweraffaan-m 275kExpert TypeScript/JavaScript code reviewer specializing in type safety, async correctness, Node/web security, and idiomatic patterns. Use for all TypeScript and JavaScript code changes.SonnetSecurity
- Scan inventoryanthropics· claude-security 38kRestricted read-only repository cartographer dispatched by the Claude Security scan workflow to partition the tree into components and account for every top-level directory; not for direct invocation or vulnerability research.SonnetSecurityResearch
- Reverse engineerwshobson· reverse-engineering 40kExpert reverse engineer specializing in binary analysis, disassembly, decompilation, and software analysis. Masters IDA Pro, Ghidra, radare2, x64dbg, and modern RE toolchains. Handles executable analysis, library inspection, protocol extraction, and vulnerability research.OpusSecurityResearch
- Application Security Engineermsitarzewski 158kAppSec specialist who secures the software development lifecycle through threat modeling, secure code review, SAST/DAST integration, and developer security education that makes secure code the default.SecurityEducationCoding
- Java revieweraffaan-m 275kExpert Java code reviewer for Spring Boot and Quarkus projects. Automatically detects the framework and applies the appropriate review rules. Covers layered architecture, JPA/Panache, MongoDB, security, and concurrency.SonnetDatabasesSecurityBackend
- Python revieweraffaan-m 275kExpert Python code reviewer specializing in PEP 8 compliance, Pythonic idioms, type hints, security, and performance. Use for all Python code changes.SonnetSecurityLegal
- Incident response code reviewerwshobson· incident-response 40kReviews code for logic flaws, type safety gaps, error handling issues, architectural concerns, and similar vulnerability patterns. Provides fix design recommendations.SonnetSecurity
- Security Revieweraffaan-m 275kSecurity vulnerability detection and remediation specialist. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.SonnetFinanceSecurity
- React revieweraffaan-m 275kExpert React/JSX code reviewer specializing in hook correctness, render performance, server/client component boundaries, accessibility, and React-specific security. Use for any change touching .tsx/.jsx files or React component logic.SonnetFilesSecurityFrontend
- Code revieweranthropics· feature-dev 38kReviews code for bugs, logic errors, security vulnerabilities, code quality issues, and adherence to project conventions, using confidence-based filtering to report only high-priority issues that truly matterSonnetSecurity
- GraphQL architectwshobson· api-scaffolding 40kMaster modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems.OpusSecurityBackendArchitecture
- Scan loaderanthropics· claude-security 38kRestricted read-only loader dispatched by the Claude Security scan workflow to return one JSON file from the run directory; not for direct invocation.SonnetSecurity
- AI-Generated Code Security Auditormsitarzewski 158kSecurity reviewer for AI-generated and vibe-coded apps — hunts the hardcoded secrets, broken row-level security, and prompt-injection sinks that coding assistants ship by default, then drives a scan, fix, and rescan loop with honest, CWE-mapped findings.Security
- Infrastructure Maintainermsitarzewski 158kExpert infrastructure specialist focused on system reliability, performance optimization, and technical operations management. Maintains robust, scalable infrastructure supporting business operations with security, performance, and cost efficiency.Security
- Solidity Smart Contract Engineermsitarzewski 158kExpert Solidity developer specializing in EVM smart contract architecture, gas optimization, upgradeable proxy patterns, DeFi protocol development, and security-first contract design across Ethereum and L2 chains.SecurityLegalArchitecture
- Incident response test automatorwshobson· incident-response 40kCreates comprehensive test suites including unit, integration, regression, and security tests. Validates fixes with full coverage and cross-environment testing.SonnetSecurityTesting