hardw00t/ai-security-arsenal

A collection of skills, agents, commands, and workflows for security researchers. Compatible with Claude Code, Claude Desktop, OpenCode, and other AI coding tools.

98Stars on the repository
12Mods indexed here, across every type
4mo agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

android-pentest

01

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze…

not rated 98 +3 4mo ago A 87 tokens

api-security

02

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Router skill for API penetration testing across REST, GraphQL, gRPC, and WebSocket. Covers OWASP API Top 10 (2023) including BOLA/BFLA/BOPLA, JWT attack chains, GraphQL introspection abuse, and mass assignment. Invoke when the user asks to pentest an API, analyze OpenAPI/Swagger, test auth/authorization, fuzz…

not rated 98 +3 4mo ago A 87 tokens

cloud-security

03

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Multi-cloud security assessment skill for AWS, Azure, and GCP. Use when performing cloud security audits, scanning for misconfigurations, testing IAM policies, auditing storage permissions, and identifying privilege escalation paths. Triggers on requests to audit cloud security, scan AWS/Azure/GCP, check cloud…

not rated 98 +3 4mo ago A 85 tokens

container-security

04

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning Docker/OCI images, auditing K8s clusters, reviewing Dockerfiles…

not rated 98 +3 4mo ago A 118 tokens

dast-automation

05

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these…

not rated 98 +3 4mo ago A 81 tokens

iac-security

06

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s…

not rated 98 +3 4mo ago A 105 tokens

ios-pentest

07

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Thin router for an iOS app security assessment. Full OWASP MASTG coverage (recon → static → dynamic → network → storage → crypto → auth → reporting). Detailed runbooks live under workflows/ and methodology/; load them only when needed.

not rated 98 +3 4mo ago A 95 tokens

llm-security

08

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

LLM and AI application security testing skill for prompt injection (direct, indirect, multimodal), system-prompt extraction, RAG poisoning, memory poisoning, MCP server injection, skill-file injection, agentic tool misuse, computer-use UI injection, and excessive agency. Authorization required — this skill tests AI…

not rated 98 +3 4mo ago A 118 tokens

network-pentest

09

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket…

not rated 98 +3 4mo ago A 103 tokens

sast-orchestration

10

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output…

not rated 98 +3 4mo ago A 138 tokens

sca-security

11

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems…

not rated 98 +3 4mo ago A 137 tokens

threat-modeling

12

hardw00t/ai-security-arsenal

Skill Claude CodeCodex

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to…

not rated 98 +3 4mo ago A 117 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: