harness · market
Harness
Put raw intelligence to work.
Skills, MCP servers, prompts, assistants and connectors. Every listing shows its author, version and the permissions it needs.
On the shelves20,989
- MCP servers18,838
- Skills1,282
- Assistants651
- Prompts218
0 items
Security
addyosmani 103kSecurity AuditorSecurity engineer focused on vulnerability detection, threat modeling, and secure coding practices. Use for security-focused code review, threat analysis, or hardening recommendations.AssistantSecurityCoding- affaan-m 275kC# reviewerExpert C# code reviewer specializing in .NET conventions, async patterns, security, nullable reference types, and performance. Use for all C# code changes.AssistantSonnetSecurity
anthropics 38kScan redactorRestricted agent dispatched by the Claude Security scan jobs to replace the credential values in a finished scan's report files with [REDACTED]; not for direct invocation.AssistantSonnetFilesSecurity
addyosmani 103kSenior Code ReviewerSenior code reviewer that evaluates changes across five dimensions — correctness, readability, architecture, security, and performance. Use for thorough code review before merge.AssistantSecurityCodingArchitecture- affaan-m 275kDatabase ReviewerPostgreSQL database specialist for query optimization, schema design, security, and performance. Incorporates Supabase best practices.AssistantSonnetDatabasesSecurity
- affaan-m 275kFastAPI reviewerReviews FastAPI applications for async correctness, dependency injection, Pydantic schemas, security, OpenAPI quality, testing, and production readiness.AssistantSonnetSecurityTestingBackend
- affaan-m 275kNetwork config reviewerReviews router and switch configurations for security, correctness, stale references, risky change-window commands, and missing operational guardrails.AssistantSonnetSecurity
addyosmani 103kDoubt-Driven DevelopmentSubjects every non-trivial decision to a fresh-context adversarial review before it stands. Use when you want every assumption cross-examined before proceeding, when stress-testing a plan for hidden failure modes, when correctness matters more than speed, when working in unfamiliar code, when stakes are high (production auth, security-sensitive logic, a high-stakes migration, irreversible operations), or any time a confident output would be cheaper to verify now than to debug later.SkillNo codeSecurityTesting- msitarzewski 158kThreat Intelligence AnalystCyber threat intelligence specialist who tracks adversary groups, maps attack campaigns to MITRE ATT&CK, produces actionable intelligence reports, and builds detection rules that catch real threats.AssistantSecurityMaps and placesMarketing and SEO
- affaan-m 275kTypeScript reviewerExpert TypeScript/JavaScript code reviewer specializing in type safety, async correctness, Node/web security, and idiomatic patterns. Use for all TypeScript and JavaScript code changes.AssistantSonnetSecurity
anthropics 38kScan inventoryRestricted read-only repository cartographer dispatched by the Claude Security scan workflow to partition the tree into components and account for every top-level directory; not for direct invocation or vulnerability research.AssistantSonnetSecurityResearch
trailofbits 7.4kDimensional Analysis SkillAnnotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling. Use when someone asks to annotate units in a codebase, perform a dimensional analysis, or find vulnerabilities in a DeFi protocol, offchain code, or other blockchain-related codebase with arithmetic. Prevents dimensional mismatches and catches formula bugs early.SkillNo codeSecurity
openai 28kSecurity Best PracticesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.SkillNo codeSecurityCoding
wshobson 40kReverse engineerExpert reverse engineer specializing in binary analysis, disassembly, decompilation, and software analysis. Masters IDA Pro, Ghidra, radare2, x64dbg, and modern RE toolchains. Handles executable analysis, library inspection, protocol extraction, and vulnerability research.AssistantOpusSecurityResearch- msitarzewski 158kApplication Security EngineerAppSec specialist who secures the software development lifecycle through threat modeling, secure code review, SAST/DAST integration, and developer security education that makes secure code the default.AssistantSecurityEducationCoding
- affaan-m 275kJava reviewerExpert Java code reviewer for Spring Boot and Quarkus projects. Automatically detects the framework and applies the appropriate review rules. Covers layered architecture, JPA/Panache, MongoDB, security, and concurrency.AssistantSonnetDatabasesSecurityBackend
- affaan-m 275kPython reviewerExpert Python code reviewer specializing in PEP 8 compliance, Pythonic idioms, type hints, security, and performance. Use for all Python code changes.AssistantSonnetSecurityLegal
wshobson 40kIncident response code reviewerReviews code for logic flaws, type safety gaps, error handling issues, architectural concerns, and similar vulnerability patterns. Provides fix design recommendations.AssistantSonnetSecurity- affaan-m 275kSecurity ReviewerSecurity vulnerability detection and remediation specialist. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.AssistantSonnetFinanceSecurity
- affaan-m 275kReact reviewerExpert React/JSX code reviewer specializing in hook correctness, render performance, server/client component boundaries, accessibility, and React-specific security. Use for any change touching .tsx/.jsx files or React component logic.AssistantSonnetFilesSecurityFrontend
anthropics 38kCode reviewerReviews code for bugs, logic errors, security vulnerabilities, code quality issues, and adherence to project conventions, using confidence-based filtering to report only high-priority issues that truly matterAssistantSonnetSecurity
trailofbits 7.4kSemgrep Rule CreatorCreates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.SkillNo codeSecurityWriting
wshobson 40kGraphQL architectMaster modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems.AssistantOpusSecurityBackendArchitecture
anthropics 38kScan loaderRestricted read-only loader dispatched by the Claude Security scan workflow to return one JSON file from the run directory; not for direct invocation.AssistantSonnetSecurity