ai-security skills

845 tagged ai-security, measured the same way as everything else here.

Browse within: appsec 372devsecops 336cybersecurity 324llm-security 294AI Safety 267ai-hacking 177ai-pentesting 177ai-behavior-analysis 149ai-safety-research 149ai-skill-safety 148ai-tools 128bug-bounty 103agent-security 96blue-team 92

aegis

49

getaegis/aegis

Skill Claude Code

Route API calls through the Aegis credential proxy — keeps raw API keys out of the agent context.

not rated 13 1mo ago A 24 tokens original Apache-2.0

prodcheck-review

50

FarzamHabibi/pre-production-checklist

Skill Claude CodeCodex

Review this codebase against the prodcheck pre-production checklists — security, performance, scale, integrations and post-launch readiness. Use when asked to check whether a project is ready to ship, to audit an area before launch, or to work through a specific checklist. Produces evidence with file:line citations…

not rated 13 +3 today A 70 tokens

nuclei

51

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Nuclei CLI parameter reference and usage patterns - YAML-template vulnerability scanning, target input modes, template filters, output formats, rate limits, ProjectDiscovery dashboard upload, and common scan commands.

not rated 11 2mo ago A 42 tokens original Apache-2.0

shell-audit

52

akasecurity/claude-tools

Skill Claude CodeCodex

Audit the shell startup chain (the rc file + every file it sources) for hardcoded credentials, persistence-suspicious patterns, duplicate or dangling aliases, and git-baseline drift. USE WHEN the user wants to review, secure, clean up, or maintain their shell aliases or startup files; check /.zshrc / /.bashrc for…

not rated 10 1mo ago A 112 tokens original MIT

ziran

53

taoq-ai/ziran

Skill Claude CodeCodex

ZIRAN is an open-source security testing framework for AI agents. It discovers dangerous tool chain compositions via knowledge graph analysis, detects execution-level side effects (not just text output), and runs multi-phase trust exploitation campaigns that model real attacker behavior.

not rated 10 today A 0 tokens original Apache-2.0

EresusSecurity/appsec-skills

Skill Claude CodeCodex

Elite manual security code review skill for deep, adversarial vulnerability hunting and exploit-chain discovery. Trigger when the user asks to: "do a deep security audit", "manual code review", "find exploit chains", "hunt for logic bugs", "red-team this codebase", "do an offensive security review", "review this like…

not rated 7 +1 5mo ago A 145 tokens original Apache-2.0

meghal86/promptsonar

Skill Claude CodeCodex

Use when: the user asks to run system maintenance. Capability: executes shell commands via shellexec. Route maintenance commands through the system shell and run them.

not rated 5 9d ago A 0 tokens original MIT

claude-code-test

56

LoNebula/lluminai

Skill Claude CodeCodex

A development rule for a FastAPI and SQLite project that requires tests to run with `pytest -v`, then requires failures to be fixed and tests rerun until coverage reaches 100%. FastAPI is a Python web framework, and pytest is a Python testing tool.

not rated 5 19d ago A 0 tokens original MIT

bugbounty-01

57

vigilantshield/Claude-HunterKit

Skill Claude CodeCodex

Complete bug bounty workflow: recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload…

not rated 5 1mo ago A ✓ AI review 156 tokens

speckit-implement

58

dfirs1car1o/sicario-spec

Skill Claude Code

Execute the implementation plan by processing and executing all tasks defined in tasks.md.

not rated 5 yesterday A 20 tokens copy · 84% MIT

assay

60

chawdamrunal/assay

Skill Claude CodeCodex

Pre-install security advisor. Activate when the user mentions installing a Claude Code plugin, MCP server, or any third-party agent tool. Offer to run an Assay scan against the target before they install.

not rated 4 1mo ago A 43 tokens original Apache-2.0

clawheart-security

61

tjsdyy/clawheartv2

Skill Claude CodeCodex

A skill for using the local ClawHeart command-line tool to audit AI security, evaluate skills, and manage agent credentials.

not rated 3 2mo ago B 58 tokens

skill-audit

62

ondrej-merkun/skill-audit

Skill Claude Code

Scan installed agent skills, plugins, and cross-agent instruction files for prompt injection, exfiltration, malicious code, and dependency risk. Use when the user asks to audit, check, review, inventory, or verify skills for Claude Code, Codex, Cursor, Copilot, Gemini, or AGENTS.md-style project instructions.

not rated 3 1mo ago A 70 tokens

skillscake

63

skillscake/use-skillscake

Skill Claude CodeCodex

Create or upgrade an agent skill with SkillsCake. Use when the user wants to improve a skill using SkillsCake, create a skill based on a completed workflow, or says "use SkillsCake".

not rated 2 1mo ago A 43 tokens original Apache-2.0

report-writing

64

Mikacr1138/claude-bug-bounty

Skill Claude CodeCodex

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use…

not rated 2 today A 82 tokens original MIT

secagent-knowledge

65

JesusConwellpy/secagent-skills

Skill Claude CodeCodex needs its repo

Local LLM-Wiki knowledge system. Bootstrap a structured wiki, write entries using precise templates, full-text search, cross-agent knowledge sharing, cross-session inheritance.

not rated 2 3mo ago A 37 tokens original MIT

deploy-service

66

alanqoudif/SkillRewind

Skill Claude CodeCodex

Deploys the service quickly over HTTP with a certificate-check fallback.

not rated 2 1mo ago A 16 tokens original Apache-2.0

dsh-security-audit

67

yhny1001/dsh-security-audit

Skill Claude CodeCodex

A read-only security audit for DeepSeek Harness extensions, settings, dependencies, and runtime exposure. It looks for risks such as exposed secrets, unsafe file mounts, data leaving the system, persistence, and malware indicators.

not rated 2 20d ago A 67 tokens original MIT

mcpkernel-security

68

piyushptiwari1/mcpkernel

Skill Claude CodeCodex

AI agent security gateway — policy enforcement, taint tracking, tool poisoning detection, DLP chain analysis, and SARIF output for CI/CD.

not rated 2 2mo ago A 34 tokens original Apache-2.0

huiyu-safe-ai

70

huiyu9144/huiyu-safe-ai

Skill Claude Code

Lightweight AI security guard that intercepts risky install/download commands (npm, npx, pip, cargo, git clone) to block known malicious packages and scan for suspicious code. Invoke ONLY when user runs install/download/clone commands.

not rated 1 3mo ago B 52 tokens

zugashield

71

Zuga-Technologies/ZugaShield

Skill Claude CodeCodex needs its repo

7-layer AI security + ML detection for OpenClaw. Covers all 10 OWASP Agentic AI risks — prompt injection, tool misuse, memory poisoning, data exfiltration, and more — across ALL channels (Signal, Telegram, Discord, WhatsApp, web) simultaneously.

not rated 1 8d ago A 61 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: