Security skills

16,789 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 489bug-bounty 288agent 226generative-ai 178LangChain 174hacking 174autonomous-pentesting 140cloud-security 127claude-ai 113redteam 113LLM 105skills 105cors-exploitation 94firebase-hacking 93

panguard

265

panguard-ai/panguard-ai

Skill Claude CodeCodex

AI agent security platform — audit skills, scan for threats, and run 24/7 protection with 9,700+ detection rules.

not rated 63 14d ago A 30 tokens original MIT

AegisGate

266

ax128/AegisGate

Skill Claude CodeCodex

An open-source security gateway that sits between an AI application and an LLM service. It can remove or clean sensitive information from requests and responses before they are passed through.

not rated 63 +1 7d ago B 0 tokens original MIT

ctf-crypto

267

DekaPrayoga/AurixAgent

Skill Claude Code

Provides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP, number theory, Coppersmith, Pollard, Wiener, padding oracle, GCM, key derivation, or stream/block cipher weaknesses.

not rated 63 +1 1mo ago A 78 tokens

snyk-fix

268

snyk/studio-recipes

Skill Claude Code

Complete security remediation workflow. Scans code for vulnerabilities using Snyk, fixes them, validates the fix, and optionally creates a PR. Supports both single-issue and batch mode for multiple vulnerabilities. Use this skill when: User asks to fix security vulnerabilities User mentions "snyk fix", "security fix"…

not rated 62 3d ago A 143 tokens original Apache-2.0

behavioral-analysis

269

HuTa0kj/vetix

Skill Claude CodeCodex

Analyzes security risks in the AI Agent/MCP Skill catalog. Used when users request to inspect, audit, review, or scan the Skill catalog for potential security risks, including command injection, data leakage, prompt word attacks, stealth access, remote execution, or other malicious activities within the SKILL package.

not rated 61 1mo ago C 65 tokens original MIT

fastapi-templates

270

HermeticOrmus/claude-code-game-development

Skill Claude CodeCodex

Create production-ready FastAPI projects with async patterns, dependency injection, and comprehensive error handling. Use when building new FastAPI applications or setting up backend API projects.

not rated 61 +3 3mo ago A 37 tokens copy · 100% MIT

skill-vetter

271

app-incubator-xyz/skill-vetter

Skill Claude Code

Multi-scanner security gate. TRIGGER when: user mentions installing, adding, or reviewing a skill to Claude Code, OpenClaw, or any other AI agent. Detects malicious code, vulnerabilities, and suspicious patterns.

not rated 60 +1 6mo ago A 49 tokens

yara-skill

272

YARAHQ/yara-rule-skill

Skill Claude CodeCodex

Expert YARA rule authoring, review, and optimization. Use when writing new YARA rules, reviewing existing rules for quality issues, optimizing rule performance, or converting detection logic to YARA syntax. Covers rule naming conventions, string selection, condition optimization, performance tuning, and automated…

not rated 59 7mo ago A 68 tokens

preflight

273

preflightsh/preflight

Skill Claude CodeCodex

This skill should be used when the user asks to "run Preflight", "scan launch readiness", "check production readiness", "audit before deploy", "fix preflight findings", "set up preflight.yml", "wire Preflight into CI", or mentions the Preflight.sh CLI.

not rated 59 13d ago B 61 tokens original MIT

zettelforge

274

ThreatRecall/zettelforge

Skill Claude CodeCodex

ZettelForge v2.0.0 — Production CTI agentic memory system. Hybrid TypeDB (STIX 2.1 ontology) + LanceDB (vector search). Zero external AI dependencies: fastembed for embeddings, llama-cpp-python for LLM. 75% accuracy on CTI queries, 18% on LOCOMO. Use when agents need persistent memory, threat intel retrieval, entity…

not rated 59 +1 24d ago A 97 tokens original MIT

ai-data-privacy

275

UnitOneAI/SecuritySkills

Skill Claude Code

Reviews AI/ML systems for data privacy and governance risks including training data privacy, PII exposure in prompts and completions, data retention policies, model memorization risks, and regulatory compliance. Auto-invoked when reviewing systems that process personal data through LLMs, train or fine-tune models on…

not rated 59 +1 2mo ago A 106 tokens original MIT

clawseccheck

276

gl0di/clawseccheck

Skill Claude CodeCodex

Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills — read-only against your OpenClaw setup, plus a bounded host-security scan; writes only its own local report/history (removable with --purge). Scores your setup…

not rated 58 29d ago A 203 tokens original MIT

solana-scanner

277

0x-Shashi/WEB3-AUDIT-SKILLS

Skill Claude CodeCodex

Use when auditing Solana programs for security vulnerabilities, reviewing Anchor or Pinocchio/native Rust smart contracts, checking CPI safety, PDA validation, account ownership, signer verification, or Token-2022 security.

not rated 58 +1 6mo ago A 41 tokens

di-ting-audit

278

L-Serim/webauto-audit-skiils

Skill Claude CodeCodex

A web security audit system for PHP, Java, .NET, and Node.js applications. It identifies the technology used, checks code and runtime behaviour for common weaknesses, and documents fixes.

not rated 57 3mo ago A 37 tokens original Apache-2.0

wrdn-gha-workflows

280

getsentry/warden-skills

Skill Claude Code needs its repo

Detects exploitable GitHub Actions workflow vulnerabilities, including pullrequesttarget pwn requests, unsafe PR checkout, expression injection in run steps and actions/github-script blocks, workflowdispatch and workflowcall input command injection, comment- and discussion-triggered commands, TOCTOU between approval…

not rated 57 15d ago A 151 tokens original MIT

1claw

282

lxyeternal/MalSkillBench

Skill Claude CodeCodex

HSM-backed secret management for AI agents — store, retrieve, rotate, and share secrets via the 1Claw vault without exposing them in context.

not rated 57 +1 2mo ago A 35 tokens

selfhost-emem-guard

283

Vortx-AI/emem

Skill Claude CodeCodex needs its repo

Stand up an emem-guard verdict server, verify it against the conformance checks, and point any agent at it. Use when asked to self-host emem-guard, add a grounding gate to an agent on any model or framework, wire a checkpoint into Claude Code or Claude Enterprise or MCP, or run a signed allow/deny server for…

not rated 56 today A 81 tokens original Apache-2.0

vajra-code-review

285

zamana-inc/vajra

Skill Claude CodeCodex

Use for Vajra code review stages to perform a blocking review of the implementation, writing findings or approval.

not rated 55 +1 1mo ago A 26 tokens original MIT

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC teams need to scale malware analysis beyond manual sandbox…

not rated 55 +2 8d ago A 72 tokens original MIT

spring-security-6

287

xuansenpa1/skillrevise

Skill Claude CodeCodex

Migrate Spring Security 5 to Spring Security 6 configuration. Use when removing WebSecurityConfigurerAdapter, replacing @EnableGlobalMethodSecurity with @EnableMethodSecurity, converting antMatchers to requestMatchers, or updating to lambda DSL configuration style. Covers SecurityFilterChain beans and authentication…

not rated 55 yesterday A 63 tokens original MIT

code-review-hardening

288

lindoelio/spec-driven-steroids

Skill Claude CodeCodex

Use this skill for rigorous, structured code review with a self-repair loop. Applies change-type-aware strategies (feat, fix, hotfix, refactor, migrate, docs). Findings are severity-classified, then auto-fixed where possible. Triggers on PR reviews, code review requests, or when reviewing any change set.

not rated 54 28d ago A 70 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: