Security skills

16,787 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 489bug-bounty 288agent 226generative-ai 178LangChain 174hacking 174autonomous-pentesting 140cloud-security 127claude-ai 113redteam 113LLM 105skills 105cors-exploitation 94firebase-hacking 93

dependency-audit

241

BARMPlus/locklens

Skill Codex

A security review of project dependencies managed by npm, Yarn, or pnpm. It can inspect a local project directory or a remote Git repository for known dependency risks.

not rated 83 3mo ago A 56 tokens original MIT

scammer

243

naxiaoduo/Scammer.skill

Skill Claude Code

A scam-message checker that analyzes suspicious texts, images, or conversation descriptions. It can identify the likely stage of a scam and suggest what the sender may try next.

not rated 78 5mo ago A 50 tokens original MIT

slb

244

Dicklesworthstone/slb

Skill Claude CodeCodex

Simultaneous Launch Button - Two-person rule for destructive commands. Use when coordinating dangerous operations between agents, requiring peer review for rm -rf, git push --force, kubectl delete, DROP TABLE, or terraform destroy.

not rated 78 today E 48 tokens

review

245

lkimuk/Wuwe

Skill Claude CodeCodex

Review the supplied artifact for correctness, security, maintainability, and test coverage. Report concrete findings before general suggestions, and distinguish verified defects from risks.

not rated 78 +1 3d ago A 0 tokens original Apache-2.0

resemble-detect

246

resemble-ai/detect-skill

Skill Claude CodeCodex

Deepfake detection and media safety — detect AI-generated audio, images, video, and text, trace synthesis sources, and analyze media intelligence using direct Resemble AI API calls.

not rated 78 +7 changed 2d ago A 40 tokens original Apache-2.0

security-audit-rlm

247

mitkox/megacode

Skill Claude CodeCodex

Run and troubleshoot privacy-preserving, local DSPy RLM security audits for large legacy .NET codebases. Use when asked to scan repositories for vulnerabilities, tune RLM/tool limits, fix truncation/stall issues, or produce actionable markdown/json audit outputs without loading entire codebases into model context.

not rated 78 6mo ago A 67 tokens original MIT

spec-converge

248

JKHeadley/instar

Skill Claude CodeCodex

Iteratively review an instar-development spec with multi-angle internal reviewers (security, scalability, adversarial, integration, decision-completeness, lessons-aware) and real cross-model external reviewers routed through the agent's own installed CLIs (codex → GPT-tier, gemini → Gemini-tier; one pass per available…

not rated 77 today A 135 tokens original MIT

ad-attacks

249

mukul975/Threatswarm

Skill Claude Code

Active Directory attack reference — BloodHound Cypher queries, Kerberos attack decision tree, ACE/ACL abuse, ADCS ESC1-8, and AD misconfig checklist.

not rated 77 4mo ago A 39 tokens original MIT

deepsafe-scan

250

XiaoYiWeio/deepsafe-scan

Skill Claude Code

Preflight security scanner for AI coding agents — scans deployment config, skills/MCP servers, memory/sessions, and AI agent config files (hooks injection) for secrets, PII, prompt injection, and dangerous patterns. Runs 4 model behavior probes (persuasion, sandbagging, deception, hallucination). Supports LLM-enhanced…

not rated 76 3mo ago A 120 tokens

authz-security

251

superagent-ai/skills

Skill Claude CodeCodex

Review application source code for broken authorization — IDOR / Broken Object Level Authorization (OWASP API1), Broken Function Level Authorization (API5), mass assignment (API3), multi-tenant isolation gaps, and privilege escalation. Reads routes, controllers, resolvers, and data models offline and reports the…

not rated 76 21d ago A 150 tokens original MIT

dotfiles-bootstrap

253

sebastienrousseau/dotfiles

Skill Claude CodeCodex

Bootstrap a workstation with the dotfiles framework. Takes a GitHub user / owner+repo / explicit clone URL and runs dot init (which shells out to chezmoi) with the right safety prompts. Honors the active agent profile (ask / plan / apply / audit) so it defaults to dry-run in safer modes and full apply in apply.

not rated 75 2d ago A 88 tokens original Apache-2.0

system-control

254

iammm0/secbot

Skill Claude CodeCodex

Comprehensive system control operations for security testing. Use this skill when you need unified access to file operations, process management, system information, and command execution through a single interface during authorized penetration testing.

not rated 73 4d ago A 43 tokens

report

255

v-yun/vuln-report-skill

Skill Claude CodeCodex

A procedure for turning a confirmed security vulnerability into a submission-ready DOCX report. DOCX is the Microsoft Word document format.

not rated 72 +11 16d ago A 183 tokens copy · 89% MIT

config-hardener

256

UseAI-pro/openclaw-skills-security

Skill Claude CodeCodex

Audit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission policies for security weaknesses.

not rated 71 6mo ago A 32 tokens original MIT

cloud_api

257

tubecreate/zhiying

Skill Claude CodeCodex

Manages cloud AI provider API keys for Gemini, OpenAI, Claude, DeepSeek, Grok.

not rated 71 5mo ago A 0 tokens

bug-reaper

258

shaniidev/bug-reaper

Skill Claude CodeCodex

Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF, IDOR, auth bypass, RCE, SSTI, LFI, XXE, CORS, CSRF, prototype pollution, subdomain takeover, HTTP smuggling, open…

not rated 71 6mo ago A 192 tokens original MIT

ricmmartins/azure-sre-agent-skills

Skill Claude CodeCodex

Assess security, reliability, and cost posture of Azure OpenAI and Microsoft Foundry deployments. Detects critical anti-patterns: API keys instead of Managed Identity, public endpoints without firewall, disabled content filtering, missing diagnostic settings, deprecated model versions, over-provisioned PTU, absence of…

not rated 70 12d ago A 142 tokens original MIT

nuke-on-rails

260

nuke-on-rails/nuke-on-rails

Skill Claude Code

Full health and security audit for Rails apps, the review a principal engineer would do. Runs rubycritic, Brakeman, bundler-audit and rubyaudit, triages every finding with the LLM as judge, brings an OWASP Top 10 arsenal of checks for what scanners miss, and returns one impact-ranked action plan. Use for a Rails…

not rated 70 +1 1mo ago A 105 tokens original MIT

security-assessment

261

Security-Phoenix-demo/security-skills-claude-code

Skill Claude CodeCodex needs its repo

Run comprehensive security assessment covering OWASP Top 10 2025 and ASVS Level 1 requirements. This skill provides automated, full-codebase security analysis with real-time token monitoring, knowledge graph integration, and automated test generation.

not rated 69 +1 4mo ago A 0 tokens original MIT

remove-ai-marks

263

anshaneja5/markscrub

Skill Claude CodeCodex needs its repo

Scrub AI provenance marks from text and files using the markscrub CLI: invisible Unicode (Layer A), optional statistical rewrite (Layer B), and C2PA/EXIF/XMP/container metadata on PNG/JPEG/SVG/PDF/DOCX/HTML/MD. Use when the user asks to strip watermarks, remove Content Credentials, clean AI metadata, remove invisible…

not rated 66 +1 3d ago A 91 tokens original MIT

onionclaw

264

JacobJandon/OnionClaw

Skill Claude CodeCodex

Search the Tor dark web, fetch .onion hidden service pages, rotate Tor identity, and run structured OSINT investigations. Use when user asks to search dark web, investigate .onion sites, find if data appeared on dark web, conduct Tor-based OSINT, look up dark web leaks, fetch any .onion URL, check for leaked…

not rated 64 2mo ago B 82 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: