ai security skills

1,362 tagged ai security, measured the same way as everything else here.

Browse within: appsec 232llm-security 223devsecops 209cybersecurity 206AI Safety 188agent-security 145ai-skills 99bug-bounty 99ai-governance 82ai-hacking 74ai-pentesting 74cis 66ai-security-tool 65red-teaming 60

skill-inspector

01

NVIDIA/SkillSpector

Skill Claude CodeCodex

Review AI agent skills before installation using NVIDIA SkillSpector and source-aware semantic review. Use when asked whether a skill or downloaded skill folder is safe, trustworthy, installable, over-permissioned, or malicious.

15k yesterday A 47 tokens original Apache-2.0

chef-assistant

02

NVIDIA/SkillSpector

Skill Claude CodeCodex

Use when cooking or planning meals, troubleshooting recipes, learning culinary techniques.

15k yesterday A 17 tokens original Apache-2.0

argus

07

Awarexone/Agentic-Bug-Hunter

Skill Claude CodeCodex

Argus — the all-seeing scanner suite. Six automated scanners for high-value web + LLM bug classes — CORS misconfiguration (origin reflection / null / credentialed read), CRLF & host-header injection, NoSQL injection (operator auth-bypass / $where blind), JWT attacks (alg:none / RS256→HS256 confusion / secret crack)…

4.7k +30 today A 166 tokens original MIT

credential-attack

08

Awarexone/Agentic-Bug-Hunter

Skill Claude CodeCodex

Password spray methodology for bug bounty — when to do it vs web-vuln hunting, the wordlist-gen + breach-check + osint-employees + spray pipeline, mode selection (http-form / oauth / o365 / okta), rate-limit + lockout tactics, BBP legal guardrails, success detection, and the spray → authenticated /hunt chain pattern.…

4.7k +30 today A 102 tokens original MIT

graphql-audit

09

Awarexone/Agentic-Bug-Hunter

Skill Claude CodeCodex

GraphQL security hunting — introspection abuse, field suggestion enumeration (clairvoyance), batching DoS, IDOR via aliasing, auth bypass, injection via arguments, subscription abuse, depth/complexity bombs, and WAF bypass. Covers graphw00f fingerprinting, gqlmap, graphql-cop, and inql. Use when a target exposes a…

4.7k +30 today A 92 tokens original MIT

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, intent-injection probes. Built from an authorized external…

3.9k 2d ago A 145 tokens original MIT

bugcrowd-reporting

11

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints…

3.9k 2d ago A 171 tokens original MIT

hunt-aspnet

12

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pattern, request-validator bypass, trace.axd/elmah.axd disclosure, load-balanced ViewState cross-node failures, SafeControl enumeration via reflection, customErrors mode=Off…

3.9k 2d ago A 98 tokens original MIT

deflake

13

stacklok/toolhive

Skill Claude CodeCodex

Finds flaky tests on the main branch by analyzing GitHub Actions failures, ranks them by frequency, and enters parallel plan mode to design deflake strategies. Use when you want to find and fix the flakiest tests.

2.1k +1 today A 48 tokens original Apache-2.0

release-notes

14

stacklok/toolhive

Skill Claude CodeCodex

Generates polished GitHub release notes for a ToolHive release by analyzing every merged PR, cross-referencing linked issues, dispatching expert agents to assess breaking changes, and producing a formatted release body. Use when the user provides a GitHub release URL, tag name, or says "release notes".

2.1k +1 today A 64 tokens original Apache-2.0

toolhive-cli-user

15

stacklok/toolhive

Skill Claude CodeCodex

Guide for using ToolHive CLI (thv) to run and manage MCP servers and skills. Use when running, listing, stopping, building, or configuring MCP servers locally. Covers server lifecycle, registry browsing, secrets management, client registration, groups, container builds, exports, permissions, network isolation…

2.1k +1 today A 98 tokens original Apache-2.0

sast-fileupload

16

utkusen/sast-skills

Skill Claude CodeCodex

Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first).…

1.3k 4mo ago A 92 tokens original MIT

sast-pathtraversal

17

utkusen/sast-skills

Skill Claude CodeCodex

Detect path traversal vulnerabilities in a codebase using a three-phase approach: recon (find file-loading sinks with dynamic paths), batched verify (trace user input and mitigations in parallel subagents, 3 sinks each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first).…

1.3k 4mo ago A 98 tokens original MIT

sast-ssti

18

utkusen/sast-skills

Skill Claude CodeCodex

Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user input to those sites in parallel subagents, 3 candidates each), and merge (consolidate batch results). Requires…

1.3k 4mo ago A 99 tokens original MIT

attackgen-tabletop

19

mrwadams/attackgen

Skill Claude CodeCodex

Turn a MITRE ATT&CK/ATLAS threat group or case study — or a frontier AI agent deployed inside the organisation — into a full incident-response tabletop exercise (MSEL): scenario narrative, kill chain or agent threat scope, timestamped injects, discussion questions, and a detection-coverage scorecard, using the…

1.2k 10d ago A 155 tokens GPL-3.0

tophant-ai/aibeat

Skill Claude CodeCodex

Use when connecting Codex, Claude Code, OpenCode, OpenClaw, coding-agent CLIs, agent gateways, workspaces, sandbox policies, provider files, or trace capture to Promptbeat as an evaluation target.

878 7d ago A 51 tokens

tophant-ai/aibeat

Skill Claude CodeCodex

Use when a user wants to start using a downloaded Promptbeat full package, connect an HTTP agent, LLM, coding agent, choose an evaluation path, run a first red-team test, or asks where to begin.

878 7d ago A 51 tokens

tophant-ai/aibeat

Skill Claude CodeCodex

Use when a user needs help choosing Promptbeat attack goals, risk types, scenarios, seed files, dataset subscriptions, compliance profiles, or a small smoke-test scope.

878 7d ago A 39 tokens

clean-skill

23

luckyPipewrench/pipelock

Skill Claude CodeCodex

Reads a local status file and calls a local health endpoint.

823 yesterday A 16 tokens original Apache-2.0

deps-skill

24

luckyPipewrench/pipelock

Skill Claude CodeCodex

Mentions dependency install commands for inventory.

823 yesterday A 12 tokens original Apache-2.0