| 42crunch-api-security-testing | 42Crunch integrates with Claude Code to automatically audit OpenAPI specifications, identify OWASP-aligned vulnerabilities like BOLA/BFLA, and apply AI-driven fixes within a continuous security validation cycle. | Security | 42Crunch |
| aws-agents-for-devsecops | AWS DevOps Agent and AWS Security Agent assist software teams by investigating incidents, reviewing code, conducting user acceptance testing before releases, scanning for vulnerabilities, and performing penetration tests. | Development | Amazon Web Services |
| browser-use | Enables Claude to control a real browser—local Chrome or a cloud-based instance—for web tasks like browsing, scraping, form filling, site testing, screenshot capture, and workflow automation. | Automation | Browser Use |
| chrome-devtools-mcp | This tool lets coding agents control and inspect a live Chrome browser, capturing performance traces, network requests, console logs with stack traces, and automating actions via Puppeteer. | Development | — |
| claude-security | Performs in-depth code vulnerability scanning within Claude Code sessions at adjustable effort levels, verifying findings via code-based tallying and generating agent-panel-checked patches for optional application. | Security | Anthropic |
| code-review | This tool automates pull request code reviews by deploying multiple specialized agents that assign confidence scores to findings, reducing false positive results. | Productivity | Anthropic |
| code-simplifier | This tool refactors recently changed code to improve clarity, consistency, and maintainability without altering its original functionality. | Productivity | Anthropic |
| coderabbit | CodeRabbit is an AI-powered code review tool combining specialized architecture with 40+ static analyzers to detect bugs, vulnerabilities, and logic errors, using AST-based context analysis and project guidelines, offering actionable fixes at no cost. | Productivity | — |
| codspeed | CodSpeed is a performance testing toolkit offering benchmarking data, flamegraphs, and comparisons; its MCP server supplies Claude detailed profiling context to identify bottlenecks and independently refine performance. | Development | CodSpeed |
| datahub-skills | A DataHub-focused toolkit supporting connector design, pull request review, catalog search, metadata enhancement, lineage tracking, data quality checks, and connection configuration tasks. | Database | DataHub |
| deepeval | Provides capabilities for integrating DeepEval into AI applications, covering evaluation setup, tracing, dataset management, Confident AI reporting, and cycles of iterative refinement. | Development | Confident AI |
| feature-dev | This tool coordinates specialized agents to explore codebases, design architecture, and review quality throughout the software feature development process. | Development | Anthropic |
| fiftyone | A computer vision tool for building datasets and models, offering visualization, analysis, duplicate detection, inference, evaluation, and custom plugin development. | — | — |
| github | A GitHub MCP server enabling repository management—creating issues, handling pull requests, reviewing code, and searching repos via GitHub's API within Claude Code. | Productivity | — |
| greptile | Uses AI to search and interpret codebases, allowing natural-language queries to locate relevant code, trace dependencies, and explain architecture. | Development | — |
| mattpocock-skills | A collection of practical agent skills by Matt Pocock covering software engineering practices like requirement clarification, spec/ticket workflows, test-driven development, code review, and domain modeling, designed for ready-to-use application rather than improvised coding. | Development | Matt Pocock |
| mergify | A terminal-based skill set for the Mergify CLI, enabling management of merge queues, stacked pull requests, Test Insights (including flaky test detection and quarantine), merge protections, and Mergify configuration. | Development | Mergify |
| mlflow | A skillset for using MLflow to instrument, trace, evaluate, and iteratively refine AI agents, supporting a complete workflow from monitoring through validation. | Monitoring | MLflow Team |
| nightvision | Provides skills for configuring scan targets/authentication/scope, triaging scan results, extracting OpenAPI specs from source code, and integrating scanning into CI/CD pipelines; portable across agent tools like Claude Code, Codex, and Cursor. | — | — |
| pagerduty | Analyzes code changes by comparing them to historical incident data, generating PagerDuty-based risk scores to flag deployment risks before shipping. | Monitoring | — |
| playwright | This MCP server from Microsoft enables browser automation, letting Claude navigate web pages, capture screenshots, complete forms, and run automated testing tasks. | Testing | — |
| postman | A Claude Code tool for managing the full API lifecycle—syncing collections, generating client code, testing, mocking, publishing docs, and security auditing—via Postman MCP Server. | Development | — |
| pr-review-toolkit | A suite of automated agents that perform thorough pull request reviews, covering comment quality, test coverage, error handling, type design, overall code quality, and simplification opportunities. | Productivity | Anthropic |
| pyright-lsp | Pyright is a Python language server that provides static type checking and enhances code intelligence features like autocompletion and navigation. | Development | Anthropic |
| qodo | Qodo Skills offers a library of reusable AI agent capabilities enhancing Claude for software development, enabling code quality checks, testing, security scanning, and compliance validation throughout the SDLC. | Development | Qodo |
| qt-development-skills | A skill set for Qt software engineering tasks, covering reviewing Qt C++/QML code, writing QML code, and producing documentation for Qt C++/QML codebases. | Development | Qt Group |
| security-guidance | This tool checks Claude-generated code for security issues, combining pattern-based edit warnings, LLM diff review, and commit analysis to detect injection, XSS, SSRF, hardcoded secrets, and other vulnerabilities. | Security | Anthropic |
| sentry | Sentry integration for retrieving error reports and stack traces, searching issues by fingerprint, enabling developers to debug production errors from within their development environment. | Monitoring | — |
| serena | An MCP server that uses language server protocol integration to analyze code semantically, offering intelligent code comprehension, refactoring recommendations, and navigation across a codebase. | Development | — |
| sonarqube | Integrates SonarQube into AI coding agents, automatically checking code quality, security, and secrets across 40+ languages using hooks, CLI, MCP server, and slash commands. | Security | SonarSource |
| sourcegraph | This tool enables searching, reading, and tracing code references across repositories, assessing refactoring impact, investigating incidents through commit/diff history, and conducting security-focused code scans. | Development | — |
| stackhawk-hawkscan | Integrates HawkScan DAST scanning into Claude Code by creating stackhawk.yml configuration files, executing scans through CLI or Docker, and converting security findings into prioritized remediation tasks for coding agents. | Security | StackHawk |
| superpowers | Superpowers is a training resource enabling Claude to brainstorm, use subagent-driven development with code review, debug systematically, apply red/green TDD, and create and test new skills. | Development | — |
| ui5 | A plugin that helps coding agents build UI5 projects by supporting creation and validation, API reference access, linting, and adherence to UI5 development best practices. | Development | SAP SE |