ai-security skills

822 tagged ai-security, measured the same way as everything else here.

Browse within: appsec 352devsecops 336cybersecurity 324llm-security 274AI Safety 267ai-hacking 177ai-pentesting 177ai-behavior-analysis 149ai-safety-research 149ai-skill-safety 148ai-tools 128bug-bounty 103agent-security 96blue-team 92

skill-auditor

25

UseAI-pro/openclaw-skills-security

Skill Claude CodeCodex

Comprehensive security auditor for OpenClaw skills. Checks for typosquatting, dangerous permissions, prompt injection, supply chain risks, and data exfiltration patterns — before you install anything.

not rated 71 6mo ago A ✓ AI review Socket: passSnyk: warn 44 tokens original MIT

panguard

26

panguard-ai/panguard-ai

Skill Claude CodeCodex

AI agent security platform — audit skills, scan for threats, and run 24/7 protection with 9,700+ detection rules.

not rated 63 16d ago A SkillSpector: pass 30 tokens original MIT

ai-data-privacy

27

UnitOneAI/SecuritySkills

Skill Claude Code

Reviews AI/ML systems for data privacy and governance risks including training data privacy, PII exposure in prompts and completions, data retention policies, model memorization risks, and regulatory compliance. Auto-invoked when reviewing systems that process personal data through LLMs, train or fine-tune models on…

not rated 60 +2 2mo ago A 106 tokens original MIT

clawseccheck

28

gl0di/clawseccheck

Skill Claude CodeCodex

Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills — read-only against your OpenClaw setup, plus a bounded host-security scan; writes only its own local report/history (removable with --purge). Scores your setup…

not rated 58 1mo ago A 203 tokens original MIT

Mindburn-Labs/helm-ai-kernel

Skill Claude CodeCodex

Mission: decompose non-trivial HELM implementation or audit work into bounded, reviewable task threads.

not rated 55 yesterday A SkillSpector: pass 0 tokens original Apache-2.0

nist-ai-rmf

30

mastepanoski/claude-skills

Skill Claude CodeCodex

AI risk assessment using NIST AI RMF 1.0 framework. Evaluate AI systems across 4 core functions (Govern, Map, Measure, Manage) for trustworthy and responsible AI deployment.

not rated 53 +1 3mo ago A 44 tokens original MIT

brin-check

31

superagent-ai/brin

Skill Claude CodeCodex

Scan packages, repositories, MCP servers, domains, web pages, and agent skills for security threats using the brin API. Use this skill before installing dependencies, visiting URLs, or integrating external resources.

not rated 50 5mo ago A 44 tokens

Synvoya/codeinspectus

Skill Codex

Investigate and remediate exactly one user-selected CodeInspectus finding with evidence-gated reproduction, a separately approved minimal patch, focused regression testing, and an exact-prior-scan rescan. Use when a user asks an agent to examine, reproduce, fix, or verify one CodeInspectus finding without batching…

not rated 45 +1 yesterday A SkillSpector: pass 76 tokens original Apache-2.0

clawmoat

33

darfaz/clawmoat

Skill Claude CodeCodex

Real-time AI agent security scanner. Detects prompt injection, jailbreak attempts, credential/secret leaks, PII exposure, and dangerous tool calls. Activate when: (1) scanning inbound messages or tool outputs for prompt injection, (2) checking outbound content for credential leaks or PII, (3) auditing agent session…

not rated 43 +1 22d ago A SkillSpector: warn 107 tokens original MIT

bex-co/bex-security

Skill Codex

Turn vulnerability notes, disclosure reports, PoCs, source code, or Codex Security findings into self-contained, sceptically validated, natural-sounding vulnerability reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional.

not rated 43 +3 yesterday A SkillSpector: warn 54 tokens original Apache-2.0

opena2a-org/hackmyagent

Skill Claude CodeCodex

Turns ARIApulse index telemetry into the weekly cross-property attribution digest.

not rated 39 5d ago A 19 tokens original Apache-2.0

agent-bom

36

msaad00/agent-bom

Skill Codex

Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust across MCP discovery, CVEs, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS v1.0, MAESTRO layer tagging, and vector database security checks. Use when the user mentions…

not rated 31 changed today A SkillSpector: warn 107 tokens original Apache-2.0

stacklok/toolhive-registry-server

Skill Claude Code needs its repo

Deploy the ToolHive Registry Server to a Kind cluster with telemetry enabled. Use when you need to deploy the registry server for testing with OTEL metrics and tracing.

not rated 26 +2 2d ago A SkillSpector: warn 40 tokens original Apache-2.0

vuln-chain-composer

38

Orizon-eu/claude-code-pentest

Skill Claude CodeCodex

Composes multi-step exploit chains by correlating vulnerabilities across domains, calculates real impact of chained findings, generates end-to-end PoC scripts, and produces bug bounty ready reports. Use when user asks to "chain vulnerabilities", "compose exploit chain", "correlate findings", "calculate real impact"…

not rated 24 6mo ago A 98 tokens original MIT

depalmar/ai-dfir-toolkit

Skill Claude CodeCodex needs its repo

Research, author, and validate AI agent artifact catalog entries documenting the forensic artifacts AI agents leave on endpoints - install paths, config and credential files, MCP server configs, listening ports, process trees, registry keys, and the Windows event log records that prove a tool ran. Use this skill…

not rated 23 18d ago A SkillSpector: pass 197 tokens original Apache-2.0

panther-audit

41

pantheraudits/web3-sec-ai-prompts

Skill Claude CodeCodex

Automated smart contract security audit pipeline. Auto-detects codebase size and scales accordingly — standard mode for small codebases, chunk mode with persistent state for large ones. Runs context building, dual-expert review, adversarial triage, and structured reporting. Use when auditing smart contracts, reviewing…

not rated 20 6mo ago A 94 tokens

secureai-scan

42

akanthed/SecureAI-Scan

Skill Claude CodeCodex

Use when the user asks to scan a repo for AI/LLM security issues, wants to know "is this skill safe?" before installing an Agent Skill, needs to "scan my MCP config" or check an MCP server before trusting it, asks about prompt injection / tool poisoning / RAG poisoning risk in their code, or is about to install any…

not rated 19 2d ago A SkillSpector: warn 109 tokens original MIT

loop-engineering

43

aiconnai/agentshield

Skill Claude CodeCodex

Use when designing, implementing, auditing, hardening, or operating autonomous agent loops in this repository, including Codex/Grok/Claude Code style /loop workflows, explicit /goal runs, Git worktree orchestration, connector-backed automation, sub-agent execution, STATE.md handoffs, cost controls, maker/checker…

not rated 18 14d ago A 77 tokens

skill-sentinel

44

EvolutionUnleashed/skill-sentinel

Skill Claude CodeCodex

Security scanner and threat analyzer for AI agent skills. Activate this skill whenever a new skill is added to the workspace, when the user imports or installs a skill from an external source, when asked to audit or review an existing skill for safety, or when the user mentions scanning, vetting, checking, or…

not rated 17 6mo ago D 125 tokens

android-security

45

GoldenWing-360/claude-security-skills

Skill Claude CodeCodex

Harden Android apps against the platform-specific failure modes. Covers Android Keystore and StrongBox, encrypted local storage, network security config and certificate pinning, WebView hardening, exported components and intent hijacking, backup rules, and Play Integrity with root detection as a signal. Invoke when…

not rated 17 +1 1mo ago A 83 tokens original MIT

screem500/prompt-injection-auditor

Skill Claude CodeCodex

Security audit of LLM system prompts, agent instruction files (SKILL.md, AGENTS.md, CLAUDE.md), and agent configurations against prompt injection attacks. Use when the user wants to (1) audit or harden a system prompt or agent instructions against prompt injection, (2) review an agent skill or system prompt for…

not rated 16 changed 4d ago A 159 tokens original Apache-2.0

agent-shield

47

elliotllliu/agent-shield

Skill Claude CodeCodex

Scan AI agent skills, MCP servers, and plugins for security vulnerabilities. Use when: user asks to check a skill/plugin for safety, audit security, scan for backdoors/data exfiltration/credential leaks, or evaluate trust of a third-party skill. Triggers: "is this skill safe", "scan for security issues", "audit this…

not rated 15 5mo ago A 92 tokens original MIT

sigil-preflight

48

Ju571nK/sigil

Skill Claude CodeCodex

Before running a risky shell command, check it with Sigil's assess and refuse anything Sigil would block. Use whenever you are about to execute a destructive, privileged, or unfamiliar command.

not rated 13 15d ago A ✓ AI review 46 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: