Skill Claude Code
Generate a PR-ready technique proposal when an attack step doesn't map to existing SITF techniques. Use after /attack-flow identifies technique gaps.
18,078 tagged Security, measured the same way as everything else here.
Browse within: cybersecurity 487bug-bounty 286generative-ai 178LangChain 174hacking 174autonomous-pentesting 138cloud-security 127claude-ai 113openclaw 113redteam 111skills 104cors-exploitation 94firebase-hacking 93hermes-agent 90
Skill Claude Code
Generate a PR-ready technique proposal when an attack step doesn't map to existing SITF techniques. Use after /attack-flow identifies technique gaps.
Skill Claude CodeCodex
600+ pattern AI agent security defense covering prompt injection, supply chain injection, memory poisoning, action gate bypass, unicode steganography, and cascade amplification. Optional API for early-access and premium patterns. Tiered loading, hash cache, 11 SHIELD categories, 10 languages.
Skill Claude CodeCodex
Zero-knowledge secrets infrastructure — AI agents manage the complete credential lifecycle without ever seeing values.
vinayaklatthe/microsoft-security-skills
Skill Claude CodeCodex
Guidance for governing the identities of AI agents and non-human identities (NHIs) — Microsoft 365 Copilot Studio agents, Microsoft Foundry agents, custom AI agents, and traditional service principals/managed identities — through their full lifecycle. Covers ownership and tagging, scoped permissions and consent…
Skill Claude Code
Security assessment of a codebase — minimal mode for runner validation.
Skill Claude Code
Remediate security vulnerabilities found by Grype or pnpm audit. Use when a security scan fails, a CVE needs fixing, or you need to analyze, upgrade, override, or ignore a vulnerable dependency.
Skill Claude Code
Use when working on Gryph's AARM security layer or policy engine. Trigger this whenever the user changes code under aarm/ or cli/policy.go, or works on policy evaluation, the PDP, policy rules, CEL conditions, receipts and the receipt hash chain, receipt signing, the context accumulator, approvals, deferrals, identity…
Skill Codex
Secure authentication and authorization when credentials, sessions, roles, or permissions change.
Skill Claude CodeCodex
Securely share files via encrypted, expiring links. Use this skill to (1) upload a local file to get a secure vnsh.dev URL, or (2) read a vnsh.dev URL to decrypt and access its content.
Skill Claude CodeCodex
Use when auditing a Gwxapkg unpacked WeChat Mini Program directory with LLM assistance; consumes .gwxapkg semantic artifacts, route maps, sensitivereport.json, and optional Burp raw requests to produce evidence-backed security findings.
Skill
Android APK decompiler that converts DEX bytecode to readable Java source code. Use when you need to decompile APK files, analyze app logic, search for vulnerabilities, find hardcoded credentials, or understand app behavior through readable source code.
Fausto-404/ai-mobile-reverse-skills
Skill Claude CodeCodex
A six-stage workflow for authorized security analysis of Android apps using decompiled code, captured network traffic, and native libraries such as JNI or SO files.
Skill Claude CodeCodex
Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
Skill Claude CodeCodex
The Dependency Auditor is a comprehensive toolkit for analyzing, auditing, and managing dependencies across multi-language software projects. This skill provides deep visibility into your project's dependency ecosystem, enabling teams to identify vulnerabilities, ensure license compliance, optimize dependency trees…
Skill Claude CodeCodex
A practical guide for AI agents that need to use vdb. If you are changing the code rather than using it, read AGENTS.md instead.
Skill Claude Code
Solves reCAPTCHA by clicking the checkbox, with audio challenge fallback.
Skill Claude CodeCodex
An automated workflow for checking an authorized GitHub repository for exposed secrets such as API keys, tokens, passwords, private keys, and webhook URLs.
awslabs/aws-cloudformation-iam-policy-validator
Skill Claude CodeCodex ✓ vendor
Validate the IAM policies in a CloudFormation template against AWS IAM Access Analyzer before deploying, using the cfn-policy-validator CLI. Use when reviewing or gating a CloudFormation (or CDK-synthesized) template that defines IAM identity or resource policies, when asked to check a template for policy errors…
Skill Claude CodeCodex
Binary analysis and reverse engineering workflow using checksec, strings, binwalk, radare2, ropgadget, and gdb for CTF and vulnerability research.
LF-Decentralized-Trust-labs/gitmesh
Skill Claude Code
GitMesh Agents UI design system. Invoke this skill when creating new components, modifying existing ones, adding pages or features to the frontend, styling UI elements, or when you need to understand the design language. Covers component creation, design tokens, typography, status/priority systems, composition…
Skill Claude CodeCodex
Comprehensive smart contract security audit framework with multi-expert analysis. Use for full audits of Ethereum / EVM Solidity and Vyper, Solana / SVM Anchor Rust, TON / FunC / Tact, or Sui / Move projects.
Skill Claude Code
Authoritative reference for the Lagune dashboard, a live view of a project's .lagune/ chain with a locked-down local action surface. Use before changing anything under src/dashboard/ or src/types/dashboard/.
EastSword/skill-dfyx_code_security_review
Skill Claude CodeCodex
A white-box code security review tool that examines source code, data flows, and business logic for security problems.
Awarexone/web3-bug-bounty-hunting-ai-skills
Skill Claude CodeCodex
Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for specific vulnerability types, need attack patterns for accounting desync, access control, incomplete path, off-by-one, oracle manipulation, ERC4626 vaults, reentrancy, flash loans, signature replay, or proxy/upgrade bugs.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: