ai security tool skills

91 tagged ai security tool, measured the same way as everything else here.

Browse within: ai-security 65gpt 31openai 31ai-cybersecurity 24ai-penetration-testing 24ctf-tools 24AI Safety 20cybersecurity 20exploitation 11vuln_assess 10appsec 8ctfs 8

Ed1s0nZ/CyberStrikeAI

Skill Claude CodeCodex

APK/EXE/二进制:UniApp/DCloud/Flutter逆向,证书固定绕过,导出组件,内存破坏exploit链,IoT固件。Use when reversing APK/EXE, UniApp/Flutter, native .so, or memory-corruption exploits.

6.2k +151 7d ago A 70 tokens original Apache-2.0

Ed1s0nZ/CyberStrikeAI

Skill Claude CodeCodex

A method for finding attack chains by combining smaller capabilities such as reading files, writing files, making server requests, or using credentials. It treats a serious outcome as a sequence of separately gained abilities.

6.2k +151 7d ago A 67 tokens original Apache-2.0

Ed1s0nZ/CyberStrikeAI

Skill Claude CodeCodex

专题实战利用:GoEdge私钥导出,灰产CDN取证,ARP MITM,CDN→S3 STS链,宝塔+UniApp,AI IDE API反代,OCS+MinIO;含references/scripts支持文件索引。Use when applying specialized playbooks for GoEdge, CDN, ARP MITM, BT Panel, OCS, MinIO.

6.2k +151 7d ago A 91 tokens original Apache-2.0

playbook-ad

04

s0ld13rr/pentestcode

Skill Claude CodeCodex

Active Directory pentest playbook — Kerberos, LDAP, GPO, ADCS, delegation, lateral movement, DA paths. Load at the START of an AD engagement or when a Windows domain / DC is found. Triggers - domain controller, Kerberos 88, LDAP 389/636, domain SMB, BloodHound, kerberoast, AS-REP, NTLM, ESC1-8.

594 +28 12d ago A 88 tokens original MIT

svc-pivoting

05

s0ld13rr/pentestcode

Skill Claude CodeCodex

Turn a foothold into a RELIABLE pivot (SOCKS tunnel + persistent shell) so internal volume never rides a fragile stateless RCE. Use the moment you have code-exec on a dual-homed/edge host and need to reach an internal segment. Triggers - dual-homed host, "not reachable from my box", internal CIDR behind a foothold…

594 +28 12d ago A 103 tokens original MIT

svc-smb

06

s0ld13rr/pentestcode

Skill Claude CodeCodex

SMB/CIFS attack techniques — null sessions, share enumeration, NTLM relay, EternalBlue, signing checks. Use when SMB is found. Triggers - ports 445/139, netbios, MS17-010 EternalBlue, signing:False, null session, share access, PetitPotam/coerce.

594 +28 12d ago A 68 tokens original MIT

skillward-audit

07

Fangcun-AI/SkillWard

Skill Claude CodeCodex

Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner. Trigger on any natural safety question about an external skill — "is this skill safe?", "audit / scan / review this skill", "should I install this?", "trustworthy?", "any…

136 +1 1mo ago A 131 tokens

altitude-check

08

cosai-oasis/secure-ai-tooling

Skill Claude CodeCodex

Check whether a CoSAI Risk Map entry is pitched at the right altitude (granularity). For a control: objective-not-implementation, not-a-restated-risk, posture-not-mandate, solved-problem, no-duplication. For a risk: the merge-vs-distinct two-test, threat-not-control-gap, and real-not-hypothetical. For a component: the…

98 6d ago A 146 tokens original Apache-2.0

cosai-oasis/secure-ai-tooling

Skill Claude CodeCodex

Audit framework mappings — an existing entity's mappings, the whole corpus, or a candidate value proposed for an entity not yet in the corpus — against the framework mappings style guide. Use when reviewing, auditing, or pre-PR authoring mapping changes for risks.yaml, controls.yaml, or personas.yaml.

98 6d ago A 65 tokens original Apache-2.0

classical-lexicon

10

cosai-oasis/secure-ai-tooling

Skill Claude CodeCodex

Ground CoSAI Risk Map terminology in established security terms of art. Use when authoring or critiquing a Control, Risk, Component, or Persona title or description to check a proposed term against the canonical (NIST-first) vocabulary, replace an invented term with its established equivalent, generalize a…

98 6d ago A 84 tokens original Apache-2.0

openclaw

12

edimuj/vexscan

Skill Claude CodeCodex

Scans extensions, skills, and code for security threats: prompt injection, malicious code, obfuscation, data exfiltration. Also scans inbound messages for injection patterns automatically.

9 4mo ago A 0 tokens original Apache-2.0

hello-world

13

SECBLOK/belay

Skill Claude CodeCodex

A simple greeting skill that says hello.

4 27d ago A 10 tokens AGPL-3.0

SECBLOK/belay

Skill Claude CodeCodex

A reference catalog of natural spring and easing curves for animating UI elements: buttons, modals, and page transitions. Includes recommended duration and easing-curve pairings for common interaction patterns like pop-in, slide-over, and fade-through.

4 27d ago A 18 tokens AGPL-3.0

report-sync-tool

15

SECBLOK/belay

Skill Claude CodeCodex

Installs the HTTP client library, reads the local report file, uploads it to the dashboard, and then runs the local build tool to refresh the cached copy. A companion Kubernetes Job warms the build cache for nested (Docker-in-Docker) builds.

4 27d ago A 21 tokens AGPL-3.0

report-writing

16

Mikacr1138/claude-bug-bounty

Skill Claude CodeCodex

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use…

2 3d ago A 82 tokens original MIT

triage-validation

17

Mikacr1138/claude-bug-bounty

Skill Claude CodeCodex

Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer…

2 3d ago A 87 tokens original MIT

web3-audit

18

Mikacr1138/claude-bug-bounty

Skill Claude CodeCodex

Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for…

2 3d ago A 103 tokens original MIT