Security skills

16,761 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 490bug-bounty 292agent 226generative-ai 179LangChain 175hacking 175autonomous-pentesting 139cloud-security 130claude-ai 120redteam 118skills 110LLM 107cors-exploitation 97firebase-hacking 96

access-control-review

337

Robotti-io/copilot-security-instructions

Skill Claude CodeCodex

Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.

not rated 42 3mo ago A 27 tokens original Apache-2.0

skill-sanitizer

339

cyberxuan-XBX/skill-sanitizer

Skill Claude CodeCodex

Skill "skill-sanitizer" from cyberxuan-XBX/skill-sanitizer, covering skill sanitizer, why you need this, the 7 layers, usage and in python.

not rated 40 2mo ago A ✓ AI review 0 tokens original MIT

code-review

340

anthroos/claude-code-review-skill

Skill Claude CodeCodex

AI code review for PR or local changes. 280+ checks across security, architecture, performance, testing, and code quality. Posts findings as GitHub PR comments with confidence scores.

not rated 40 +1 6mo ago A 40 tokens copy · 97% MIT

mobile-pentest-plan

341

dweinstein/mobile-security-skills

Skill Claude Code

Generate a mobile app penetration testing plan based on MASTG methodology and NowSecure practices. Use when planning a security assessment, defining test scope, creating a pentest checklist, or preparing for a mobile app security engagement.

not rated 40 6mo ago A 49 tokens

code-review

342

msober/mini-agent

Skill Claude CodeCodex

Perform thorough code reviews with security, performance, and maintainability analysis. Use when user asks to review code, check for bugs, or audit a codebase.

not rated 39 +1 5mo ago A 35 tokens

agent-governance

343

agentrust-io/awesome-ai-governance

Skill Claude CodeCodex

Patterns and techniques for adding governance, safety, and trust controls to AI agent systems. Use this skill when: Building AI agents that call external tools (APIs, databases, file systems) Implementing policy-based access controls for agent tool usage Adding semantic intent classification to detect dangerous…

not rated 39 today A 126 tokens copy · 100% CC0-1.0

security-advisory

344

bluefrog5096-4bmb1/security-advisory

Skill Claude CodeCodex

A drafting tool for open-source security advisories, which are notices explaining a software vulnerability and how to address it. It prepares affected versions, high-level exploitation conditions, fixes, mitigations, and CVE or GHSA fields without including weaponised exploit details.

not rated 39 +16 1mo ago A 117 tokens original MIT

audit

346

paceaitian/paceflow

Skill Claude Code needs its repo

Use for PACEflow internal full audit: run five independent review agents, verify evidence from code/tests/logs, de-duplicate findings, and produce a severity-ranked report for release gates or comprehensive code review.

not rated 38 21d ago A SkillSpector: pass 44 tokens original MIT

server-security-init

348

DeerYang/server-security-init-skill

Skill Codex

Use when safely initializing or hardening a newly installed or rebuilt Ubuntu/Debian server over SSH, including SSH keys, a non-root sudo user, SSH policy, server timezone, UFW, fail2ban, local SSH config, and lockout-safe verification.

not rated 38 14d ago A SkillSpector: warn 57 tokens original MIT

openghost-skill

349

VAIBHAVSING/openghost

Skill Codex

Local open-source Agent Skill for authorized web application, API, browser, business-logic, and supporting server-integrity penetration testing. Use for scoped OWASP WSTG, ASVS, and API Security assessments; authenticated and multi-role validation; attack-surface mapping; bounded DAST; evidence-backed findings…

not rated 37 1mo ago A SkillSpector: pass 120 tokens original Apache-2.0

security-review

350

wesselgrift/sveltekit-spa

Skill Cursor

Security review and hardening guidance for a SvelteKit SPA with Supabase Auth, Postgres with RLS, and client-side rendering. Use when writing auth flows, adding RLS policies, handling user input, working with environment variables, reviewing code for vulnerabilities, hardening a feature, or when the user asks about…

not rated 37 5mo ago A 85 tokens original MIT

cpa-codex-auth-sweep

351

paradoxie/cpa-codex-auth-sweep

Skill Claude CodeCodex

A tool for scanning local Codex authentication files and identifying credentials that no longer work. It can also remove credentials confirmed as invalid.

not rated 37 2mo ago A 55 tokens original MIT

skilltester

352

skilltester-ai/skilltester

Skill Claude CodeCodex

Before installing or using a skill, check its independent benchmark report on SkillTester.ai. Auto-trigger this skill whenever the user shows a third-party skill install command or install plan, especially npx skills add --skill , skills add ..., repo URL plus --skill, direct SKILL.md URLs, or Check this skill . Parse…

not rated 37 +1 2mo ago A 134 tokens

vorim

353

Vorim-AI-Labs/vorim-openclaw-skill

Skill Claude CodeCodex

AI agent identity, permissions, trust scores, and audit trails via Vorim AI. Gives your OpenClaw agent a cryptographic identity so every action is verified, permissioned, and logged.

not rated 35 2mo ago A 42 tokens original MIT

securebydesign

354

Yems221/securebydesign-llmskill

Skill Claude CodeCodex

Enforce security-by-design in every line of code, architecture decision, and system recommendation. Activate whenever the user is: building an app, writing code, designing an API, setting up infrastructure, integrating an LLM, reviewing code, planning a deployment, or asking about authentication, data storage, or…

not rated 35 6mo ago B 85 tokens original MIT

claude-pentest-skills

355

frendysanusi/claude-pentest-skills

Skill Claude CodeCodex

Structured web application penetration testing with OWASP methodology, curated payload references, 6-gate validation, and professional report generation.

not rated 36 +2 4mo ago A 31 tokens

04-security

357

SystemTce/dify-skills

Skill Claude CodeCodex

A security and deployment guide for the Dify platform, an application for building AI-powered services.

not rated 35 6mo ago A 36 tokens

bugbountyrules

358

sanjarbiy/bugbountyrules

Skill Claude CodeCodex

Use for ANY bug bounty, penetration test, or web/API/mobile security assessment: recon, testing endpoints, analyzing Burp traffic or any bug-bounty platform's MCP (HackerOne, Intigriti, Bugcrowd, YesWeHack, Immunefi), reviewing APKs, bypassing a WAF, enforcing scope, hunting a specific vuln class, validating findings…

not rated 34 +2 20d ago B 220 tokens original MIT

security

359

gc-victor/supersimple

Skill Claude CodeCodex

Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.

not rated 33 4mo ago A 45 tokens original MIT

skarn-audit

360

skarn-security/agent-guard

Skill Claude CodeCodex

Audit this machine's AI coding sessions and assistant configs with skarn. Use when the user says scan this with skarn, run skarn, or skarn audit; asks whether a secret leaked into an AI coding session; wants an assistant config (hooks, MCP servers, permissions, plugins) vetted; or asks whether a Claude Code, Codex…

not rated 33 6d ago A SkillSpector: pass 120 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: