Security skills

16,765 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 490bug-bounty 292agent 226generative-ai 179LangChain 175hacking 175autonomous-pentesting 139cloud-security 130claude-ai 120redteam 118skills 110LLM 107cors-exploitation 97firebase-hacking 96

cybercloudskills/cyber-cloud-skills

Skill Codex

Authorized Kubernetes, Docker, container runtime, workload and image supply-chain security testing. Use for scoped cluster, pod, node, container, registry or image assessment involving RBAC, service accounts, exposed control-plane services, workload isolation, runtime configuration, posture review, and explicitly…

not rated 48 +1 17d ago A 72 tokens

rootcx

314

RootCX/RootCX

Skill Claude CodeCodex

Build internal apps and AI agents on RootCX — the open-source platform with shared PostgreSQL, auto-generated CRUD APIs, OIDC SSO, role-based access control, audit logging, scheduled jobs, message queuing, encrypted secrets, file storage, managed deployment, and pre-built integrations. Get everything you need to ship…

not rated 48 3d ago B 76 tokens

iac-storage

315

senaykt/iac-security-scan-skills

Skill Claude CodeCodex

Deep storage and data security analysis for AWS Infrastructure-as-Code. Detects unencrypted data stores, public S3 buckets, missing backup/DR posture, dangerous access patterns, ransomware readiness gaps, data classification issues, and storage-layer attack surfaces. Consumes structured output from iac-analysis and…

not rated 48 3mo ago A 77 tokens original MIT

TeamArtisanThrive/r03-anthropics-skills-security

Skill Claude CodeCodex

🔒 Security & Compliance skill suite derived from anthropics/skills. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.

not rated 47 +2 4mo ago A 58 tokens

b01-gbrain--security

318

PulverizeDirector/b01-gbrain-security

Skill Claude CodeCodex

🔒 Threat Intelligence Brain — Self-wiring knowledge graph for threats, vulnerabilities and security incidents. Derived from gbrain (garrytan/gbrain). Security audits, vulnerability management, GDPR/SOC2.

not rated 47 4mo ago A 48 tokens

aws-samples/sample-agent-skills-for-builders

Skill Claude CodeCodex ✓ vendor

Walk a client through a Responsible AI assessment questionnaire and score their answers 0-5 across eight RAI dimensions (Governance, Privacy & Security, Safety, Veracity & Robustness, Controllability, Fairness, Explainability, Transparency). Use when a user asks to run a Responsible AI assessment, RAI scorecard…

not rated 47 11d ago A SkillSpector: pass 118 tokens original Apache-2.0

instancez

320

instancez/instancez

Skill Claude CodeCodex

Use when building, changing, or deploying an instancez backend - editing instancez.yaml (tables, RLS, auth, storage, rpc, functions), running the inz CLI, or debugging why a query is denied. instancez is a single-binary Supabase-compatible backend defined by one YAML file.

not rated 47 yesterday C 64 tokens original Apache-2.0

web-vuln-audit

322

zhiyuwang720-dev/CodeAuditSkill

Skill Claude CodeCodex

A source-code security audit tool for web projects written in Go, Java, Python, PHP, or JavaScript. It checks for high- and medium-risk flaws and writes reports in the audited project’s reports/ folder.

not rated 46 +1 2mo ago A 172 tokens original MIT

gplay-preflight

323

tamtom/gplay-cli-skills

Skill Claude CodeCodex needs its repo

Offline compliance and hygiene scanning of an AAB or APK with gplay preflight — manifest flags, restricted permissions, 64-bit and 16 KB page alignment, listing assets, secrets, billing, privacy SDKs, target API floor, and size. Use before uploading a build, as a CI gate, or when diagnosing a Play rejection. Runs…

not rated 45 1mo ago A SkillSpector: pass 83 tokens original MIT

workflow-creator

325

accuknox/agentZ

Skill Claude CodeCodex

Create or update reusable workflow DAGs. Use when authoring or revising saved workflows. Must be mandatorily used before calling the createworkflow tool.

not rated 45 +1 5d ago A SkillSpector: pass 36 tokens original Apache-2.0

aws/tools-for-devops-agent

Skill Claude CodeCodex

Amazon OpenSearch Service domain health assessment. Performs read-only, API-driven checks against a customer's OpenSearch domain(s) covering cluster health, node/shard configuration, performance metrics, security posture, and cost optimization signals. Activate this skill for requests about OpenSearch or Elasticsearch…

not rated 45 3d ago A SkillSpector: pass 136 tokens original Apache-2.0

agent-supply-chain

327

drvoss/everything-copilot-cli

Skill Claude CodeCodex

Use when auditing an AI agent plugin, skill bundle, or MCP tool package for supply chain integrity — generate deterministic SHA-256 manifests, detect modified or untracked files, flag unpinned dependencies, and gate promotion to production.

not rated 45 11d ago A SkillSpector: warn 51 tokens original MIT

codeinspectus-fix-one

329

Synvoya/codeinspectus

Skill Codex

Investigate and remediate exactly one user-selected CodeInspectus finding with evidence-gated reproduction, a separately approved minimal patch, focused regression testing, and an exact-prior-scan rescan. Use when a user asks an agent to examine, reproduce, fix, or verify one CodeInspectus finding without batching…

not rated 44 13d ago A SkillSpector: pass 76 tokens original Apache-2.0

review

330

bezael/ai-workflow-kit

Skill Claude CodeCodex

Review code with real engineering criteria — logic bugs, security vulnerabilities, and technical debt. Use when the user says /review, asks for a code review, or wants the branch diff checked before opening a PR.

not rated 44 7d ago A 44 tokens

gmh5225/awesome-ai-security

Skill Claude Code

Guide for understanding and contributing to the awesome-ai-security curated resource list. Use this skill when adding resources, organizing categories, or maintaining README.md consistency (no duplicates).

not rated 44 16d ago A SkillSpector: pass 39 tokens original MIT

burn-after-login

332

pbakaus/burn-after-login

Skill Claude CodeCodex

Create dev-only auth shortcuts so AI browser automation agents can authenticate instantly. Analyzes your auth system, creates guarded endpoints/scripts, detects your browser automation tools, and updates agent instructions. Use when setting up dev authentication for browser automation, or when agents struggle with…

not rated 44 5mo ago A 66 tokens original MIT

apk-recon

333

abisheikM1/Tribunal

Skill Claude CodeCodex

First-pass recon net for an Android APK — hunt secrets, insecure storage, weak crypto, broken TLS, and risky configuration in one broad sweep. Fires on manifest signals (android:debuggable="true", android:allowBackup="true", android:usesCleartextTraffic="true", a networkSecurityConfig that trusts user CAs or permits…

not rated 44 +1 1mo ago A 319 tokens

levelsio-vps-deploy

334

Avanderheyde/levelsio-vps-setup-skill

Skill Claude CodeCodex

Set up a web app on a single cheap, hardened VPS the "levels.io" way — one Hetzner/DigitalOcean box running Next.js (or any Node app) on SQLite + Caddy (auto-HTTPS) + systemd, secured with Tailscale, put behind a Cloudflare domain, and set up to charge money with Stripe. The whole "idea → app that makes money on a…

not rated 43 1mo ago D 356 tokens original MIT

agent-passport-system

335

aeoess/agent-passport-system

Skill Claude CodeCodex

Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when…

not rated 43 +1 changed 2d ago A SkillSpector: warn 291 tokens original Apache-2.0

clawmoat

336

darfaz/clawmoat

Skill Claude CodeCodex

Real-time AI agent security scanner. Detects prompt injection, jailbreak attempts, credential/secret leaks, PII exposure, and dangerous tool calls. Activate when: (1) scanning inbound messages or tool outputs for prompt injection, (2) checking outbound content for credential leaks or PII, (3) auditing agent session…

not rated 43 +1 20d ago A SkillSpector: warn 107 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: