Security skills

16,810 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 490bug-bounty 292agent 226generative-ai 179LangChain 175hacking 175autonomous-pentesting 139cloud-security 130claude-ai 120redteam 118skills 110LLM 107cors-exploitation 97firebase-hacking 96

crypto-misuse

409

ShieldNet-360/secure-vibe

Skill Claude CodeCodex

Block weak ciphers, predictable RNG, undersized keys, fast-hash password storage, nonce reuse, and non-constant-time comparison. Use when generating code that hashes, encrypts, or signs, code that compares secrets, MACs, or tokens, or config for key sizes and randomness.

not rated 22 25d ago A 60 tokens original MIT

codescan-review

410

HeJiguang/codescan

Skill Codex

Use when reviewing source code for security issues and CodeScan MCP tools or CLI are available, especially for pre-merge diff review, repository intake, suspicious auth or input-handling code, or when a user explicitly asks for a CodeScan-based security scan.

not rated 22 5mo ago A 55 tokens original MIT

kroegha/kali-docker-pentesting

Skill Claude CodeCodex

Comprehensive pentesting toolkit using Kali Linux Docker container. Provides direct access to 200+ security tools without MCP overhead. Use when conducting security assessments, penetration testing, vulnerability scanning, or security research. Works via direct docker exec commands for maximum efficiency.

not rated 22 1mo ago B 58 tokens

security-research

412

rhysha/claude-security-research-skill

Skill Claude CodeCodex

Full-spectrum security research skill for web servers, REST APIs, web applications, and network/port enumeration. Triggers whenever the user wants to: find vulnerabilities, run a security assessment, scan a target, test an API for security issues, enumerate ports or services, check for OWASP Top 10 vulnerabilities…

not rated 22 5mo ago A 153 tokens original MIT

openclaw-vps-setup

413

AlexAtmtit/custom-skills

Skill Claude CodeCodex

Securely deploy OpenClaw (autonomous AI agent) on a Hetzner VPS with full hardening — Tailscale VPN, firewall, non-root user, loopback-only gateway, Telegram integration, and end-to-end security verification. Use this skill whenever the user mentions OpenClaw, ClawdBot, setting up an AI agent on a VPS, deploying…

not rated 22 6mo ago A 171 tokens original MIT

awesome-web-security

414

Correia-jpv/fucking-awesome-web-security

Skill Claude Code

Looks up curated web security learning resources (XSS, SQLi, CSRF, SSRF, OAuth/JWT, deserialization, SAML, recon, evasion, defensive tooling, CTF). Filters by topic, difficulty, language, and resource type. Returns top references with archive fallbacks. Defensive and educational use only.

not rated 22 yesterday A 71 tokens

java-deobfuscation

415

Stanislav-Povolotsky/jddlab

Skill Claude CodeCodex

Detect and reverse Java/Android obfuscation with jddlab - ProGuard/R8 renaming, string encryption, control-flow flattening and commercial protectors, using java-deobfuscator, simplify and dex2jar. Use when decompiled code is obfuscated or strings are encrypted.

not rated 22 7d ago A 65 tokens

gemtracker

416

spaquet/gemtracker

Skill Claude CodeCodex

Analyze Ruby gem dependencies, vulnerabilities, outdated packages, maintenance health, and insecure gem sources with the gemtracker CLI. Use when asked to audit Ruby gems, check Gemfile.lock security, review dependency health, or run gemtracker.

not rated 22 8d ago A SkillSpector: pass 49 tokens original MIT

bb-huge

417

ShulkwiSEC/bb-huge

Skill Codex needs its repo

Bug bounty findings secretary, tracker, and workspace initializer for the bb-huge portal. Use this skill for web security research, vulnerability hunting, and hunt workspace setup. Triggers on: "log finding", "save finding", "add to bb-huge", "record vulnerability", "update finding", "show findings", "bb-huge stats"…

not rated 22 +1 1mo ago A 204 tokens original MIT

scholarly360/owasp-top10-web-skills

Skill Claude CodeCodex

Use this skill whenever you need to audit, test, or fix Authentication Failures (OWASP A07:2025) in Python web applications — especially FastAPI and Flask. Triggers include: any mention of JWT security, session management, brute force protection, credential stuffing, password policy, MFA enforcement, login rate…

not rated 22 +1 5mo ago A 166 tokens original MIT

mcp-review

419

stacklok/toolhive-catalog

Skill Claude Code

Review MCP server specifications and updates for compliance, security, and quality. Use when evaluating server.json files, PRs adding/updating servers, or assessing MCP server changes. NOT for creating new entries (use add-mcp-server instead).

not rated 22 today A SkillSpector: warn 51 tokens original Apache-2.0

reconbridge

420

lm060719/reconbridge

Skill Claude CodeCodex

Drive the ReconBridge toolchain to reverse-engineer / recon / tamper Android apps on a rooted (KernelSU) device from the PC side. Use whenever the task involves: pulling an APK or native .so off a device, decompiling with jadx, locating classes/methods with DexKit/androguard, Ghidra native analysis, hooking or tracing…

not rated 22 +2 1mo ago A 196 tokens original MIT

prism-scanner

421

aidongise-cell/prism-scanner

Skill Claude Code

Security scanner for AI Agent skills, plugins, and MCP servers. Use when: user asks to scan a skill, check if a plugin is safe, vet an MCP server, review skill security, detect malicious code, supply chain safety, or says 'is this safe to install', 'scan this skill', 'check this MCP server', 'security scan'…

not rated 22 +4 5mo ago A 117 tokens original Apache-2.0

trust-center-outline

422

neodeer3244-w5dry/trust-center-outline

Skill Claude CodeCodex

A planning guide for a public security and trust section on a SaaS or developer-tool website. It covers the site structure, page notes, evidence links, owners, and information gaps.

not rated 22 1mo ago A 109 tokens original MIT

meltedinhex/analyst-ai-pack

Skill Claude CodeCodex

Establishes safe practices for acquiring, storing, transferring, and disposing of malware samples: password-protected archives, neutralized extensions, hashing for identity, and chain-of-custody. Activates for requests about safely storing or sharing malware, sample handling hygiene, or defanging artifacts.

not rated 22 2mo ago A 67 tokens original Apache-2.0

code-review

424

vox-ai-app/vox

Skill Claude CodeCodex

Reviews code for bugs, security issues, and best practices. Suggests improvements with concrete examples.

not rated 21 2mo ago A 22 tokens original MIT

woohyun212/security-skill

Skill Claude CodeCodex

Business logic vulnerability testing covering workflow bypass, price manipulation, coupon abuse, rate limit bypass, and TOCTOU race conditions.

not rated 21 4mo ago A 32 tokens original MIT

rails-security

426

jorgegorka/ariadna

Skill Claude CodeCodex

Ruby on Rails security conventions — authentication, authorization, OWASP protections, CSRF, input validation. Use when implementing auth, handling sensitive data, or reviewing security.

not rated 21 +1 5mo ago A 36 tokens original MIT

vibe-architecture

427

jgnoonan/vibeArchitecture

Skill Claude CodeCodex

Apply architectural guardrails when building software. Runs an intake questionnaire to determine the project's tier, then enforces security, reliability, and best practice rules appropriate to the tier while writing code.

not rated 21 +1 7d ago A SkillSpector: warn 42 tokens original MIT

hush

428

royashbrook/hush

Skill Claude CodeCodex

Use whenever an agent needs to STORE, GENERATE, or USE a secret such as an API token, signing key, or password. Hush has one hard rule: the agent never sees plaintext, so it never enters chat, transcripts, stdout, logs, the clipboard, or a temp file. A user-provided value enters once through a hidden prompt; a strong…

not rated 20 changed 3d ago A 189 tokens original MIT

trap

429

bikr/TRAP

Skill Claude CodeCodex

Run a True Readiness Audit (TRAP) — an adversarial, evidence-first production-readiness and security audit of the current codebase. Use when the user asks to security-review, audit, threat-model, or check whether an app is production-ready / safe to ship / safe to deploy — especially for AI- or "vibe"-coded apps, or…

not rated 20 1mo ago A 79 tokens original MIT

panther-audit

431

pantheraudits/web3-sec-ai-prompts

Skill Claude CodeCodex

Automated smart contract security audit pipeline. Auto-detects codebase size and scales accordingly — standard mode for small codebases, chunk mode with persistent state for large ones. Runs context building, dual-expert review, adversarial triage, and structured reporting. Use when auditing smart contracts, reviewing…

not rated 20 6mo ago A 94 tokens

mnvsk97/agentbreak

Skill Codex

Orchestrates end-to-end resilience testing for LLM agents with AgentBreak, including LLM infrastructure failures, prompt injection, agent skill supply-chain risk, guardrail verification, and MCP server/tool failures. Use when the user asks to "test my agent for resilience", "chaos test this agent", "find failure modes…

not rated 20 3mo ago A 97 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: