Security skills

16,647 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 490bug-bounty 292agent 226generative-ai 179LangChain 175hacking 175autonomous-pentesting 139cloud-security 130claude-ai 120redteam 118skills 110LLM 107cors-exploitation 97firebase-hacking 96

santosomar/ethical-hacking-agent-skills

Skill Claude Code

Creates Nuclei YAML templates for vulnerability detection across HTTP, DNS, TCP, SSL, and other protocols. Use when converting a confirmed vulnerability, misconfiguration, or exposure into a reusable automated check — for example, turning a manual finding into a detection rule, writing a CVE check, or codifying a…

not rated 24 4mo ago A 73 tokens original Apache-2.0

hidden-admin-auth

386

bishopZ/2026-Boilerplate

Skill Claude CodeCodex

Configure the private route as a hidden admin utility. Moves credentials to env vars; operator updates .env using .envTemplate instructions. No credentials passed to the skill.

not rated 24 +1 1mo ago A 37 tokens original MIT

elastic/example-mcp-app-security

Skill Claude CodeCodex ✓ vendor

Triage Elastic Security Attack Discovery findings — fetch correlated attack narratives, assess confidence with entity risk and rule frequency signals, and present an interactive triage dashboard for approval, case creation, and acknowledgment. Use when triaging attack discoveries, reviewing correlated attacks…

not rated 24 +2 today A 114 tokens

security-review

388

JamalMohafil/claude-skills

Skill Claude CodeCodex

Run a security review of code changes exactly like Claude Code's /security-review command — but in ANY AI coding agent (Claude Code, Cursor, Codex, Windsurf, Gemini CLI, Cline…). Reviews the pending branch diff (or a specific PR, uncommitted changes, or a whole file/folder) for HIGH-CONFIDENCE, actually-exploitable…

not rated 24 +3 yesterday A SkillSpector: warn 211 tokens original MIT

Veridise/audithub-skills

Skill Codex

Coordinate full or multi-stage AuditHub OrCa fuzzing campaigns for Solidity projects. Use when a user asks to run an autonomous OrCa campaign, plan and execute setup/tuning/spec/long-run loops, resume an OrCa campaign, or coordinate target selection, deployment setup, smoke runs, callmetrics.json analysis, tuning, [V]…

not rated 23 20d ago A 89 tokens

code-security-review

390

ez-lbz/claude-code-security-skills

Skill Claude CodeCodex

Scans source code for security vulnerabilities — injection flaws, authentication bypasses, hardcoded secrets, XSS, and more — then filters false positives and ranks findings by severity and confidence. Supports all programming languages. Uses a three-phase audit-filter-report workflow with customizable scan categories…

not rated 23 4mo ago A 92 tokens

dcp-citizenship

391

dcp-ai-protocol/dcp-ai

Skill Claude CodeCodex

Digital Citizenship Protocol — identity, intent declaration, and audit trail for AI agents.

not rated 23 1mo ago A 22 tokens original Apache-2.0

depalmar/ai-dfir-toolkit

Skill Claude CodeCodex needs its repo

Research, author, and validate AI agent artifact catalog entries documenting the forensic artifacts AI agents leave on endpoints - install paths, config and credential files, MCP server configs, listening ports, process trees, registry keys, and the Windows event log records that prove a tool ran. Use this skill…

not rated 23 17d ago A SkillSpector: pass 197 tokens original Apache-2.0

nono-sandbox

393

always-further/nono-packs

Skill Claude CodeCodex

Understands nono security sandbox constraints. Use when running inside a nono sandbox, when tool operations fail with permission errors, or when the user asks about sandbox capabilities.

not rated 23 20d ago A 39 tokens

NikolasMarkou/epistemic-deconstructor

Skill Claude CodeCodex

Systematic reverse engineering of unknown systems using scientific methodology. Use when: (1) Black-box analysis, (2) Competitive intelligence, (3) Security analysis, (4) Forensics, (5) Building predictive models. Features 6-phase protocol with a mandatory abductive expansion sub-phase, Bayesian inference…

not rated 23 1mo ago A 82 tokens GPL-3.0

crudauth

395

benavlabs/crudauth

Skill Claude CodeCodex

Use when building or modifying authentication in a FastAPI app with crudauth (the crudauth PyPI package) — covers CRUDAuth, the AuthUserMixin / makeauthidentity user model, IdentityConfig, currentuser(...) gates, session + bearer transports, OAuth (Google/GitHub), email verification / password reset / change, custom…

not rated 23 2mo ago B 188 tokens original MIT

skarn-audit

397

skarn-security/cursor-plugin

Skill Claude CodeCodex

Audit this machine's AI coding sessions and assistant configs with skarn. Use when the user says scan this with skarn, run skarn, or skarn audit; asks whether a secret leaked into an AI coding session; wants an assistant config (hooks, MCP servers, permissions, plugins) vetted; or asks whether a Claude Code, Codex…

not rated 23 6d ago A 120 tokens copy · 100% MIT

reconbridge

398

lm060719/reconbridge

Skill Claude CodeCodex

Drive the ReconBridge toolchain to reverse-engineer / recon / tamper Android apps on a rooted (KernelSU) device from the PC side. Use whenever the task involves: pulling an APK or native .so off a device, decompiling with jadx, locating classes/methods with DexKit/androguard, Ghidra native analysis, hooking or tracing…

not rated 22 +2 1mo ago A 196 tokens original MIT

dynamic-verification

399

ShieldNet-360/secure-vibe

Skill Claude CodeCodex

Confirm or refute a vulnerability candidate against a live target with a deterministic probe, respecting authorization and scope. Use when a SAST or LLM review flags a possible injection or SSRF, when triaging a finding before filing a bug or shipping a fix, or when a verification result turns out wrong.

not rated 22 24d ago A 61 tokens original MIT

codescan-review

400

HeJiguang/codescan

Skill Codex

Use when reviewing source code for security issues and CodeScan MCP tools or CLI are available, especially for pre-merge diff review, repository intake, suspicious auth or input-handling code, or when a user explicitly asks for a CodeScan-based security scan.

not rated 22 5mo ago A 55 tokens original MIT

kroegha/kali-docker-pentesting

Skill Claude CodeCodex

Comprehensive pentesting toolkit using Kali Linux Docker container. Provides direct access to 200+ security tools without MCP overhead. Use when conducting security assessments, penetration testing, vulnerability scanning, or security research. Works via direct docker exec commands for maximum efficiency.

not rated 22 1mo ago B 58 tokens

security-research

402

rhysha/claude-security-research-skill

Skill Claude CodeCodex

Full-spectrum security research skill for web servers, REST APIs, web applications, and network/port enumeration. Triggers whenever the user wants to: find vulnerabilities, run a security assessment, scan a target, test an API for security issues, enumerate ports or services, check for OWASP Top 10 vulnerabilities…

not rated 22 5mo ago A 153 tokens original MIT

openclaw-vps-setup

403

AlexAtmtit/custom-skills

Skill Claude CodeCodex

Securely deploy OpenClaw (autonomous AI agent) on a Hetzner VPS with full hardening — Tailscale VPN, firewall, non-root user, loopback-only gateway, Telegram integration, and end-to-end security verification. Use this skill whenever the user mentions OpenClaw, ClawdBot, setting up an AI agent on a VPS, deploying…

not rated 22 6mo ago A 171 tokens original MIT

awesome-web-security

404

Correia-jpv/fucking-awesome-web-security

Skill Claude Code

Looks up curated web security learning resources (XSS, SQLi, CSRF, SSRF, OAuth/JWT, deserialization, SAML, recon, evasion, defensive tooling, CTF). Filters by topic, difficulty, language, and resource type. Returns top references with archive fallbacks. Defensive and educational use only.

not rated 22 yesterday A 71 tokens

java-deobfuscation

406

Stanislav-Povolotsky/jddlab

Skill Claude CodeCodex

Detect and reverse Java/Android obfuscation with jddlab - ProGuard/R8 renaming, string encryption, control-flow flattening and commercial protectors, using java-deobfuscator, simplify and dex2jar. Use when decompiled code is obfuscated or strings are encrypted.

not rated 22 6d ago A 65 tokens

gemtracker

407

spaquet/gemtracker

Skill Claude CodeCodex

Analyze Ruby gem dependencies, vulnerabilities, outdated packages, maintenance health, and insecure gem sources with the gemtracker CLI. Use when asked to audit Ruby gems, check Gemfile.lock security, review dependency health, or run gemtracker.

not rated 22 7d ago A SkillSpector: pass 49 tokens original MIT

bb-huge

408

ShulkwiSEC/bb-huge

Skill Codex needs its repo

Bug bounty findings secretary, tracker, and workspace initializer for the bb-huge portal. Use this skill for web security research, vulnerability hunting, and hunt workspace setup. Triggers on: "log finding", "save finding", "add to bb-huge", "record vulnerability", "update finding", "show findings", "bb-huge stats"…

not rated 22 +1 1mo ago A 204 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: