# What a security engineer should install

> Capabilities measured for the work a security engineer does.

Source: https://tashan.sh/role/security.html
Ranked by fit for the task, then how well it documents itself, then the tashan score
  (upkeep and freshness, gated by real adoption). Public evidence only — nothing paid can
  change a rank. Method: https://tashan.sh/methodology.html

## The short answer

- **Security review** — [Shieldcortex](https://tashan.sh/capability/pkg-shieldcortex.html) · tashan score 69
- **Regulatory compliance** — [Korean Law](https://tashan.sh/capability/pkg-korean-law-mcp.html) · tashan score 72
- **Risk assessment** — [Scf](https://tashan.sh/capability/pkg-mcp-server-scf.html) · tashan score 69

## Ranked

| # | Capability | tashan score | Adoption evidence | Activity |
|---|---|---|---|---|
| 1 | [Korean Law](https://tashan.sh/capability/pkg-korean-law-mcp.html) | 72 | 5k/wk | active |
| 2 | [Zscaler](https://tashan.sh/capability/plugin-zscaler-zscaler-mcp-server-zscaler.html) | 63 | 41 ★ | active |
| 3 | [Openstates](https://tashan.sh/capability/pkg-cyanheads-openstates-mcp-server.html) | 60 | 317/wk | active |
| 4 | [GitHub Autopilot](https://tashan.sh/capability/plugin-shweta-mishra-ai-github-autopilot-github-autopilot.html) | 55 | 23 ★ | active |
| 5 | [Ato](https://tashan.sh/capability/pkg-ato-mcp.html) | 53 | 389/wk | active |
| 6 | [Courtlistener](https://tashan.sh/capability/pkg-cyanheads-courtlistener-mcp-server.html) | 53 | 157/wk | active |
| 7 | [Agentic Security](https://tashan.sh/capability/plugin-clear-capabilities-agentic-security-agentic-security.html) | 50 | 73 ★ | active |
| 8 | [Jfrog](https://tashan.sh/capability/plugin-jfrog-claude-plugin-jfrog.html) | 47 | 4 ★ | active |
| 9 | [Shieldcortex](https://tashan.sh/capability/pkg-shieldcortex.html) | 69 | 2k/wk | active |
| 10 | [Js Reverse](https://tashan.sh/capability/pkg-js-reverse-mcp.html) | 69 | 1k/wk | active |
| 11 | [Scf](https://tashan.sh/capability/pkg-mcp-server-scf.html) | 69 | 923/wk | active |
| 12 | [Sonarqube](https://tashan.sh/capability/plugin-sonarsource-sonarqube-agent-plugins-sonarqube.html) | 65 | 98 ★ | active |
| 13 | [Qodo](https://tashan.sh/capability/plugin-qodo-ai-qodo-skills-qodo.html) | 64 | 44 ★ | active |
| 14 | [Offensive Claude](https://tashan.sh/capability/plugin-hypnguyen1209-offensive-claude-offensive-claude.html) | 62 | 326 ★ | active |
| 15 | [NPM Sentinel](https://tashan.sh/capability/pkg-nekzus-mcp-server.html) | 62 | 924/wk | active |
| 16 | [Crowdstrike Falcon Foundry](https://tashan.sh/capability/plugin-crowdstrike-foundry-skills-crowdstrike-falcon-foundry.html) | 60 | 22 ★ | active |
| 17 | [Armorclaude](https://tashan.sh/capability/plugin-armoriq-armorclaude-armorclaude.html) | 60 | 44 ★ | active |
| 18 | [AI Agent Firewall](https://tashan.sh/capability/pkg-fidacy-mcp.html) | 60 | 454/wk | active |
| 19 | [Nist Nvd](https://tashan.sh/capability/pkg-cyanheads-nist-nvd-mcp-server.html) | 59 | 728/wk | active |
| 20 | [Architecture Studio](https://tashan.sh/capability/plugin-alpacalabsllc-skills-for-architects-architecture-studio.html) | 59 | 284 ★ | active |
| 21 | [Crowdsec](https://tashan.sh/capability/plugin-crowdsecurity-crowdsec-skill-crowdsec.html) | 55 | 21 ★ | active |
| 22 | [Healthclaw Guardrails](https://tashan.sh/capability/plugin-aks129-healthclawguardrails-healthclaw-guardrails.html) | 55 | 27 ★ | active |
| 23 | [Malchela](https://tashan.sh/capability/plugin-dwmetz-malchela-malchela.html) | 55 | 114 ★ | active |
| 24 | [Akf](https://tashan.sh/capability/plugin-hmakt99-akf-akf.html) | 50 | 13 ★ | active |
| 25 | [Descope Skills](https://tashan.sh/capability/plugin-descope-skills-descope-skills.html) | 49 | 12 ★ | active |
| 26 | [Onepassword Agent](https://tashan.sh/capability/pkg-onepassword-agent-mcp.html) | 49 | 90/wk | active |
| 27 | [Ris Austria](https://tashan.sh/capability/pkg-cyanheads-ris-austria-mcp-server.html) | 49 | 82/wk | active |
| 28 | [Fort](https://tashan.sh/capability/plugin-djadmin-fort-fort.html) | 45 | 73 ★ | active |
| 29 | [Nightvision](https://tashan.sh/capability/plugin-nvsecurity-nightvision-skills-nightvision.html) | 44 | 2 ★ | active |
| 30 | [Usap Skills](https://tashan.sh/capability/plugin-jaskaranhundal-usap-skills-usap-skills.html) | 44 | 3 ★ | active |
| 31 | [Kernel Vuln Analyzer](https://tashan.sh/capability/plugin-winmin-kernel-vuln-analyzer-kernel-vuln-analyzer.html) | 44 | 39 ★ | active |
| 32 | [Dotsecenv](https://tashan.sh/capability/plugin-dotsecenv-dotsecenv-dotsecenv.html) | 43 | 5 ★ | active |
| 33 | [Dreamforge Audit](https://tashan.sh/capability/plugin-brainit-consulting-dreamforgesoftwareagentskills-dreamforge-audit.html) | 43 | 6 ★ | active |
| 34 | [Secure Sdlc Agents](https://tashan.sh/capability/plugin-kaademos-secure-sdlc-agents-secure-sdlc-agents.html) | 41 | 12 ★ | active |
| 35 | [Tax Law](https://tashan.sh/capability/pkg-tax-law-mcp.html) | 41 | 2k/wk | abandoned |
| 36 | [Rugproof](https://tashan.sh/capability/plugin-omermaksutii-rugproof-rugproof.html) | 38 | 9 ★ | active |
| 37 | [Labor Law](https://tashan.sh/capability/pkg-labor-law-mcp.html) | 38 | 3k/wk | abandoned |
| 38 | [Prodsec Skills Ge Core](https://tashan.sh/capability/plugin-redhatproductsecurity-prodsec-skills-prodsec-skills-ge-core.html) | 55 | 43 ★ | active |
| 39 | [L4 Computational Law](https://tashan.sh/capability/plugin-smucclaw-l4-ide-l4-computational-law.html) | 55 | 37 ★ | active |
| 40 | [Stackhawk Skills For Claude](https://tashan.sh/capability/plugin-stackhawk-claude-skills-stackhawk-skills-for-claude.html) | 51 | 12 ★ | active |

Showing the top 40 of 184. The full ranked shelf is at https://tashan.sh/role/security.html.

## What these numbers are not

- The tashan score measures upkeep, freshness and adoption. It is **not** a security
  verdict and **not** a measure of whether the capability works well.
- `not scored` means too little public evidence to rank, never that something is bad.
- The security audit is separate and free per capability, on each page above.
