Security skills

18,078 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 487bug-bounty 286generative-ai 178LangChain 174hacking 174autonomous-pentesting 138cloud-security 127claude-ai 113openclaw 113redteam 111skills 104cors-exploitation 94firebase-hacking 93hermes-agent 90

technique-proposal

217

wiz-sec-public/SITF

Skill Claude Code

Generate a PR-ready technique proposal when an attack step doesn't map to existing SITF techniques. Use after /attack-flow identifies technique gaps.

not rated 179 +1 1mo ago A 0 tokens

prompt-guard

218

seojoonkim/prompt-guard

Skill Claude CodeCodex

600+ pattern AI agent security defense covering prompt injection, supply chain injection, memory poisoning, action gate bypass, unicode steganography, and cascade amplification. Optional API for early-access and premium patterns. Tiered loading, hash cache, 11 SHIELD categories, 10 languages.

not rated 175 +1 4mo ago B 61 tokens original MIT

agentsecrets

219

The-17/agentsecrets

Skill Claude CodeCodex

Zero-knowledge secrets infrastructure — AI agents manage the complete credential lifecycle without ever seeing values.

not rated 172 changed 2d ago A 21 tokens original MIT

vinayaklatthe/microsoft-security-skills

Skill Claude CodeCodex

Guidance for governing the identities of AI agents and non-human identities (NHIs) — Microsoft 365 Copilot Studio agents, Microsoft Foundry agents, custom AI agents, and traditional service principals/managed identities — through their full lifecycle. Covers ownership and tagging, scoped permissions and consent…

not rated 171 +1 2mo ago A 241 tokens original MIT

lyrik

221

gebruder/wirken

Skill Claude Code

Security assessment of a codebase — minimal mode for runner validation.

not rated 171 2d ago A 15 tokens original MIT

stacklok/toolhive-studio

Skill Claude Code

Remediate security vulnerabilities found by Grype or pnpm audit. Use when a security scan fails, a CVE needs fixing, or you need to analyze, upgrade, override, or ignore a vulnerable dependency.

not rated 163 today A 50 tokens original Apache-2.0

aarm-policy-layer

223

safedep/gryph

Skill Claude Code

Use when working on Gryph's AARM security layer or policy engine. Trigger this whenever the user changes code under aarm/ or cli/policy.go, or works on policy evaluation, the PDP, policy rules, CEL conditions, receipts and the receipt hash chain, receipt signing, the context accumulator, approvals, deferrals, identity…

not rated 161 6d ago A 133 tokens original Apache-2.0

auth-security

224

KbWen/agentic-os

Skill Codex

Secure authentication and authorization when credentials, sessions, roles, or permissions change.

not rated 157 +2 today A 18 tokens original MIT

vnsh

225

raullenchai/vnsh

Skill Claude CodeCodex

Securely share files via encrypted, expiring links. Use this skill to (1) upload a local file to get a secure vnsh.dev URL, or (2) read a vnsh.dev URL to decrypt and access its content.

not rated 156 23d ago D 51 tokens original MIT

gwxapkg-ai-audit

226

25smoking/Gwxapkg

Skill Claude CodeCodex

Use when auditing a Gwxapkg unpacked WeChat Mini Program directory with LLM assistance; consumes .gwxapkg semantic artifacts, route maps, sensitivereport.json, and optional Burp raw requests to produce evidence-backed security findings.

not rated 154 +3 16d ago A 57 tokens original MIT

jadx

227

Paresh-Maheshwari/morphe-ai

Skill

Android APK decompiler that converts DEX bytecode to readable Java source code. Use when you need to decompile APK files, analyze app logic, search for vulnerabilities, find hardcoded credentials, or understand app behavior through readable source code.

not rated 154 +3 1mo ago A 51 tokens GPL-3.0

Fausto-404/ai-mobile-reverse-skills

Skill Claude CodeCodex

A six-stage workflow for authorized security analysis of Android apps using decompiled code, captured network traffic, and native libraries such as JNI or SO files.

not rated 153 +3 22d ago A 89 tokens original MIT

shashankswe2020-ux/whoop-mcp

Skill Claude CodeCodex

Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.

not rated 150 yesterday A 48 tokens original MIT

dependency-auditor

230

mar-antaya/my-claude-skills

Skill Claude CodeCodex

The Dependency Auditor is a comprehensive toolkit for analyzing, auditing, and managing dependencies across multi-language software projects. This skill provides deep visibility into your project's dependency ecosystem, enabling teams to identify vulnerabilities, ensure license compliance, optimize dependency trees…

not rated 148 5mo ago A 7 tokens

vulnerability-db

231

AppThreat/vulnerability-db

Skill Claude CodeCodex

A practical guide for AI agents that need to use vdb. If you are changing the code rather than using it, read AGENTS.md instead.

not rated 148 7d ago A 0 tokens original MIT

recaptcha-bypass

232

byt3bl33d3r/figaro

Skill Claude Code

Solves reCAPTCHA by clicking the checkbox, with audio challenge fallback.

not rated 149 +1 5mo ago A 19 tokens original MIT

github-secret-auditor

233

DjangoPeng/agentic-ai

Skill Claude CodeCodex

An automated workflow for checking an authorized GitHub repository for exposed secrets such as API keys, tokens, passwords, private keys, and webhook URLs.

not rated 147 +1 1mo ago A 71 tokens original MIT

iam-policy-validator

234

awslabs/aws-cloudformation-iam-policy-validator

Skill Claude CodeCodex ✓ vendor

Validate the IAM policies in a CloudFormation template against AWS IAM Access Analyzer before deploying, using the cfn-policy-validator CLI. Use when reviewing or gating a CloudFormation (or CDK-synthesized) template that defines IAM identity or resource policies, when asked to check a template for policy errors…

not rated 146 2mo ago A 81 tokens MIT-0

binary-analysis

235

CommonHuman-Lab/nyxstrike

Skill Claude CodeCodex

Binary analysis and reverse engineering workflow using checksec, strings, binwalk, radare2, ropgadget, and gdb for CTF and vulnerability research.

not rated 145 +1 yesterday A 35 tokens

design-guide

236

LF-Decentralized-Trust-labs/gitmesh

Skill Claude Code

GitMesh Agents UI design system. Invoke this skill when creating new components, modifying existing ones, adding pages or features to the frontend, styling UI elements, or when you need to understand the design language. Covers component creation, design tokens, typography, status/priority systems, composition…

not rated 143 +1 today A 83 tokens original Apache-2.0

smart-contract-audit

237

forefy/.context

Skill Claude CodeCodex

Comprehensive smart contract security audit framework with multi-expert analysis. Use for full audits of Ethereum / EVM Solidity and Vyper, Solana / SVM Anchor Rust, TON / FunC / Tact, or Sui / Move projects.

not rated 144 +3 2d ago A 55 tokens original MIT

dashboard

238

wellwelwel/lagune

Skill Claude Code

Authoritative reference for the Lagune dashboard, a live view of a project's .lagune/ chain with a locked-down local action surface. Use before changing anything under src/dashboard/ or src/types/dashboard/.

not rated 147 6d ago A 43 tokens original MIT

web3-bug-classes

240

Awarexone/web3-bug-bounty-hunting-ai-skills

Skill Claude CodeCodex

Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for specific vulnerability types, need attack patterns for accounting desync, access control, incomplete path, off-by-one, oracle manipulation, ERC4626 vaults, reentrancy, flash loans, signature replay, or proxy/upgrade bugs.

not rated 140 +3 11d ago A 72 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: