cybersecurity skills

1,196 tagged cybersecurity, measured the same way as everything else here.

Browse within: devsecops 476bug-bounty 400blue-team 369ai-security 324agent 293hacking 214generative-ai 202LangChain 200ctf 190ai-pentesting 170appsec 160autonomous-pentesting 157ai-hacking 154ctf-tools 151

breachproof

49

Mikaru0Mystic/breachproof

Skill Claude CodeCodex

Autonomous security audit and hardening that scans, exploits, fixes, and re-scans a codebase to zero findings, mapped to SOC 2.

not rated 4 1mo ago A 35 tokens original Apache-2.0

bughunterpro

50

sector-b79/web-hunter-pro

Skill Claude CodeCodex

Operate only in authorized scope: bug bounty targets explicitly in scope, owned systems, defensive reviews, or labs. Decline or pause on requests involving unauthorized access, stealth, persistence, service disruption, credential abuse, real data theft, or abuse of third-party systems.

not rated 3 4mo ago A 0 tokens

canadian-grc

51

squizzle23/canadian-grc-skill

Skill Claude CodeCodex

Expert Canadian GRC and cyber law advisor covering OSFI B-10/B-13/E-21/I-CRT, FSRA, AMF/Loi 25, BCFSA, CIRO, AER Reg 84/CSA Z246.1, PIPEDA, PHIPA, PIPA BC, PIPA AB, Bill C-26, and AIDA. Use this skill whenever the user mentions any Canadian financial regulator, provincial privacy law, Alberta energy security, Canadian…

not rated 2 4mo ago A 195 tokens

virustotal-api

52

w33ts/virustotal-api-skill

Skill Claude CodeCodex

Comprehensive reference for the VirusTotal API v3, covering authentication, rate limits, endpoint usage, and the critical differences between Free (Public) and Premium (Enterprise) tiers. Use this skill whenever a user asks about VirusTotal, VT API, scanning files or URLs with VirusTotal, threat intelligence lookups…

not rated 2 5mo ago B 170 tokens original MIT

reverse-engineer

53

mrigankad/SRE-CLI

Skill Claude CodeCodex

Authorized software reverse engineering, binary analysis, and program comprehension for legitimate purposes including security review, interoperability, migration, modernization, debugging, and documentation. USE WHEN: user needs to analyze software they own or have explicit authorization to inspect, including legacy…

not rated 2 5mo ago A 137 tokens

secagent-knowledge

54

JesusConwellpy/secagent-skills

Skill Claude CodeCodex needs its repo

Local LLM-Wiki knowledge system. Bootstrap a structured wiki, write entries using precise templates, full-text search, cross-agent knowledge sharing, cross-session inheritance.

not rated 2 3mo ago A 37 tokens original MIT

saas-cybersecurity

55

YankielDBC2/saas-cybersecurity

Skill Claude CodeCodex

Audit and safely harden authorized SaaS web applications across frameworks and hosting providers. Use for OWASP-aligned reviews, runtime browser checks, HTTP headers, XSS/CSRF, access control, secrets, payments, uploads, privacy, abuse controls, supply-chain risk, link injection, or security remediation; do not use…

not rated 2 9d ago A 86 tokens original MIT

xorcise-playbooks

56

xorcise-ai/xorcise-skills

Skill Claude CodeCodex

Run a standardized XORCISE agent benchmark — pick a ready-made playbook (or build your own from existing missions), point it at any OpenHands-supported model(s), and get a polished eval-card HTML report of how each model performed across the missions. Warns you about cost before spending anything.

not rated 2 1mo ago B 66 tokens

setup-dev-env

57

yu-iskw/skill-inspector

Skill Claude Code

Set up the development environment for the project. Use when starting work on the project, when dependencies are out of sync, or to fix environment setup failures.

not rated 2 5d ago A 35 tokens original Apache-2.0

KxlSys/OpenSkill

Skill Claude CodeCodex

Audit professionnel complet d'un projet logiciel couvrant architecture, code mort, dette technique, dépendances, API, authentification, autorisation, sécurité applicative, CI/CD, performance, production et validation finale.

not rated 2 14d ago A 50 tokens original MIT

burpsuite

59

nguyenthdat/burp-mcp

Skill Claude CodeCodex

Operate an already configured burp-mcp server for authorized web application security testing, penetration testing, vulnerability assessment, and Burp Suite automation: inspect Proxy HTTP/WebSocket history, scope, and site map; craft and replay requests in Repeater; run bounded parallel fuzzing, race condition jobs…

not rated 2 2d ago A 168 tokens original MIT

Asaiuta/reverse-workbench-skill

Skill Codex

Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.

not rated 2 +1 23d ago A 51 tokens original MIT

huiyu-safe-ai

61

huiyu9144/huiyu-safe-ai

Skill Claude Code

Lightweight AI security guard that intercepts risky install/download commands (npm, npx, pip, cargo, git clone) to block known malicious packages and scan for suspicious code. Invoke ONLY when user runs install/download/clone commands.

not rated 1 3mo ago B 52 tokens

bugroo/ubuntu-server-audit-eu

Skill Claude CodeCodex

Use when performing strict read-only SSH inspections of Ubuntu/Linux servers for security review, EU cybersecurity compliance evidence, server readiness, operational disorder, waste, drift, CIS-style hardening gaps, runtime visibility, identity/access, network exposure, backups, observability, and unknowns. Requires…

not rated 1 3mo ago A 86 tokens original MIT

web3-audit

64

guib1/red-team-docker

Skill Claude CodeCodex

Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for…

not rated 1 5mo ago A 103 tokens

zugashield

65

Zuga-Technologies/ZugaShield

Skill Claude CodeCodex needs its repo

7-layer AI security + ML detection for OpenClaw. Covers all 10 OWASP Agentic AI risks — prompt injection, tool misuse, memory poisoning, data exfiltration, and more — across ALL channels (Signal, Telegram, Discord, WhatsApp, web) simultaneously.

not rated 1 6d ago A 61 tokens original MIT

skill

66

nidhish28guhan-netizen/hachiman-agent

Skill Claude CodeCodex needs its repo

Hachiman is a watchman that thinks like an attacker. On an authorized target it runs.

not rated 1 13d ago A 0 tokens original MIT

anjian-audit

67

ck3938700-ship-it/anjian-agent

Skill Claude CodeCodex

Use AnJian MCP tools for an authorization-gated website security assessment and Chinese report.

not rated 0 1mo ago A 23 tokens original MIT

sbomapp-mcp-server

68

mcpsbom/sbomapp-mcp-server

Skill Claude CodeCodex

SBOMApp is a remote MCP server that provides Software Bill of Materials (SBOM) generation, vulnerability scanning, and dependency analysis capabilities to AI assistants. It enables any MCP-compatible AI client to analyze software projects for security risks, license compliance, and dependency health — directly from…

not rated 0 6mo ago A 0 tokens

security-weekly-tw

69

astroicers/security-weekly-mcp

Skill Claude CodeCodex

A workflow for maintaining a Taiwan-focused security glossary and producing weekly security reports. It supports Chinese-language term management, terminology checks, news collection, and report generation.

not rated 0 3d ago A 124 tokens original MIT

threadlinqs-cmd/intelthreadlinqs-mcp

Skill Claude CodeCodex

Operate the Threadlinqs Intelligence MCP server — 73 threat-intelligence tools covering threats, detection rules in Splunk SPL / Microsoft KQL / Sigma, IOCs, threat actors, CVE/CWE enrichment, MITRE ATT&CK coverage and prediction, C2 infrastructure, the correlation graph, and STIX 2.1 / ATT&CK Navigator export. Use…

not rated 0 13d ago A 285 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: