cybersecurity skills

1,196 tagged cybersecurity, measured the same way as everything else here.

Browse within: devsecops 476bug-bounty 400blue-team 369ai-security 324agent 293hacking 214generative-ai 202LangChain 200ctf 190ai-pentesting 170appsec 160autonomous-pentesting 157ai-hacking 154ctf-tools 151

screem500/prompt-injection-auditor

Skill Claude CodeCodex

Security audit of LLM system prompts, agent instruction files (SKILL.md, AGENTS.md, CLAUDE.md), and agent configurations against prompt injection attacks. Use when the user wants to (1) audit or harden a system prompt or agent instructions against prompt injection, (2) review an agent skill or system prompt for…

not rated 16 changed 2d ago A 159 tokens original Apache-2.0

idapython

26

VibRev/ida-headless-mcp

Skill Claude CodeCodex

IDA Pro Python scripting for reverse engineering. Use when writing IDAPython scripts, analyzing binaries, working with IDA's API for disassembly, decompilation (Hex-Rays), type systems, cross-references, functions, segments, or any IDA database manipulation. Covers ida modules (50+), idautils iterators, and common…

not rated 15 +6 8d ago A 77 tokens copy · 100% Apache-2.0

ouroboros-pentest

27

g4sk0/mergen-mcp

Skill Claude CodeCodex

Use when the user sends BB:, CTF:, Target:, or Pentest: followed by a domain or IP — activates autonomous JSON-only daemon mode for authorized penetration testing, bug bounty, and CTF challenges.

not rated 14 6mo ago A 47 tokens original MIT

tenable/cyberagents-exchange

Skill Claude CodeCodex

A dependency-free Claude skill that groups vulnerability findings by the fix they share and ranks the shortest set of actions that retires the most weighted risk.

not rated 14 2d ago A 36 tokens

cybersecurity-lab

29

handnewb/hermes-cybersec-lab

Skill Claude CodeCodex

Turnkey cybersecurity lab — 2,077 skills, 131+ tools, 28 frameworks, and evolving methodology for security research, pentesting, forensics, and threat intelligence. Includes one-step ecosystem cloner for 8 repositories.

not rated 13 +1 25d ago A 54 tokens original MIT

nuclei

30

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Nuclei CLI parameter reference and usage patterns - YAML-template vulnerability scanning, target input modes, template filters, output formats, rate limits, ProjectDiscovery dashboard upload, and common scan commands.

not rated 11 2mo ago A 42 tokens original Apache-2.0

container-security

32

EvilFreelancer/secs

Skill Claude CodeCodex

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning Docker/OCI images, auditing K8s clusters, reviewing Dockerfiles…

not rated 10 28d ago A 118 tokens original Apache-2.0

ibnsawad/Saudi-Regulatory-Compliance-Claude-Skill

Skill Claude CodeCodex

Senior cybersecurity, cloud, and data-protection compliance advisor for organisations in Saudi Arabia. Trigger for: NCA ECC-2:2024, CCC-2:2024, DCC-1:2022, CSCC-1:2019, OTCC-1:2022, TCC-1:2021, OSMACC-1:2021, CGEC-1:2019, CGESP-1:2019, NCS-1:2020; SAMA Cybersecurity/IT Governance/Business Continuity Frameworks; CST…

not rated 9 1mo ago A 243 tokens

security-kb

34

dinosn/security-knowledge-base

Skill Codex

Read, search, and inspect evidence in a Security Knowledge Base v1 repository, then validate or stage evidence-cited, revision-bound claim and finding proposals. Use when a task refers to a repository containing kb.json and the kb CLI, asks to check or update the security KB, or supplies an skb.context-packet/v1. Stop…

not rated 9 25d ago A 92 tokens original MIT

authz-recipe

35

tr4m0ryp/shor

Skill Claude CodeCodex

Broken Access Control is OWASP #1, but there is no drop-in CLI (Autorize / AuthMatrix are Burp extensions). This is the procedure that carries the whole category: an authorization-matrix + A/B session-replay method driving curl, the playwright skill (per-identity sessions), and ffuf (ID enumeration). Live →…

not rated 9 1mo ago A 62 tokens

pentest-findings

36

jayelbotvibe-web/hermes-pentest-lab

Skill Claude CodeCodex needs its repo

Pentest finding interpretation encyclopedia — maps tool output to finding severity, CVSS scoring rules, and report-ready language. Answers 'What severity is this? What's the CVSS? How do I write this up?'.

not rated 9 11d ago A 47 tokens original MIT

land-and-deploy

37

CarbeneAI/Forge

Skill Claude Code

Land and deploy workflow. Merges the PR, waits for CI and deploy, verifies production health via canary checks. Takes over after /ship creates the PR. Use when: "merge", "land", "deploy", "merge and verify", "land it", "ship it to production".

not rated 9 1mo ago A 67 tokens original MIT

minecraft-async

38

02loveslollipop/OpenCROW

Skill Claude CodeCodex

Manage a preinstalled local Minecraft Java client asynchronously for CTF and automation workflows. Use when an agent needs to launch Minecraft in offline mode with alternate usernames, inspect Minecraft logs, focus or type into the X11 game window, send chat or slash commands quickly, or join a multiplayer server by…

not rated 8 changed yesterday A 75 tokens original Apache-2.0

seedance-prompt-zh

39

mightyhuman101/seedance2-skill

Skill Claude CodeCodex

A guide for writing prompts for Seedance 2.0, an AI video generator that can use text, images, videos, and audio as input.

not rated 7 2d ago A 100 tokens copy · 100% MIT

soc-copilot

40

G4rb3n/SOC-Copilot

Skill Claude Code

An AI-assisted workflow for investigating security alerts in a security operations center, or SOC—the team and systems that monitor an organisation for attacks. It can analyse alerts, investigate their origins, prepare response scripts, and record approved rules and reports.

not rated 7 +1 5mo ago A 125 tokens original MIT

plan-iam-career

41

Sefyu24/master-iam-skills

Skill Claude CodeCodex

Interview a person who wants to start or advance an Identity and Access Management career, then create a short and evidence-based career plan with a downloadable Markdown document when file tools are available. Use when the user wants help selecting an IAM role, researching IAM opportunities or target employers…

not rated 6 18d ago A 107 tokens original MIT

appsec-playbook

42

maxwellokumu/okaudit-claude-skills

Skill Claude CodeCodex

Guide Claude through a structured application security audit covering threat modeling, testing, pipeline review, dependency risk, and vulnerability management.

not rated 6 5mo ago A 29 tokens

capybara-nexus-v2

43

pentrestion/capybara-nexus-v2

Skill Claude CodeCodex

Name: capybara-nexus-v2 Tier: Frontier (Capybara-class) Mandate: Autonomous Reasoning, Empirical Feedback, & Zero-Day Research.

not rated 6 2mo ago A 0 tokens

code-vulnscan

44

Bhanunamikaze/Code-VulnScan-Skill

Skill Claude CodeCodex

Use this when the user wants to find security vulnerabilities in a codebase, perform a security audit, scan for CVEs, detect secrets, review React/Next.js, Go, Java/Kotlin JVM, PHP, Ruby, .NET, or Rust web services, audit architecture/application/infrastructure flaws, review auth/API/crypto/business logic, check…

not rated 6 24d ago A 128 tokens original MIT

hardening

45

Cholulaa/claude-code-hardening-skill

Skill Claude Code

Complete security hardening of a Linux server based on CIS Benchmarks, NIST 800-123, and ANSSI BP-028. Smart service discovery to avoid disruption. 4 hardening levels (minimal/standard/enhanced/paranoid). Installs open-source security tools, hardens SSH/kernel/firewall/systemd/permissions, runs all scans, generates a…

not rated 5 5mo ago B 80 tokens original MIT

agent-security

46

olanokhin/agent-security-skill

Skill Codex

Use when reviewing or writing LLM, RAG, MCP, tool, or agent code for OWASP-aligned security issues; triggered by "owasp my code", "owasp this PR", AI security review, PR review, or changes to AI system code.

not rated 5 2mo ago A 57 tokens original MIT

symfony-security

47

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Symfony / PHP webapp security review — Security Component (firewalls, voters, accesscontrol, role hierarchies), Doctrine ORM injection patterns (raw DQL, QueryBuilder, expr()), Twig auto-escape and |raw, CSRF + session, PHP-specific RCE classes (unserialize, include/require, system/exec, eval, type juggling)…

not rated 4 3mo ago A 116 tokens

marq

48

rhaist/marq

Skill Claude CodeCodex

Skill "marq" from rhaist/marq, covering marq — cyber assistant, start here — scope and domains, how to call a tool, discover tools and long-running scans.

not rated 4 1mo ago A 69 tokens AGPL-3.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: