Security skills

16,805 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 286agent 224generative-ai 179LangChain 175hacking 175autonomous-pentesting 136cloud-security 128claude-ai 119redteam 118security-audit 108skills 108LLM 106cors-exploitation 95

ctf-qa-validation

433

mr-pmillz/gogatoz

Skill Codex

QA testing and validation of GoGatoZ features against the local GoGatoZ CTF lab. Invoke for post-change testing, live flag validation, lab infrastructure checks, payload smoke tests, enumerate/attack/search/pivot/notify validation, or any request to confirm that GoGatoZ still works.

not rated 20 7d ago A 68 tokens

analyze-repo

434

miles990/claude-software-skills

Skill Claude Code

Enterprise-grade repository analysis with arc42/C4 architecture documentation, technical debt quantification, security assessment, and multi-stakeholder reporting.

not rated 20 7mo ago A 31 tokens original MIT

convex-security-audit

435

igor9silva/meseeks

Skill Claude CodeCodex

Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations.

not rated 20 2mo ago A 28 tokens AGPL-3.0

ci-secure

436

starslingdev/skills

Skill Claude CodeCodex

Scans a repo's GitHub Actions workflows for the ten critical CI/CD attack vectors — template injection, fork code executed with privileges (pwn requests), cache poisoning, impostor action SHAs, secrets dumps, GITHUBENV hijack, write-token untrusted triggers, credentials in caches/artifacts, unverified remote code…

not rated 20 3d ago A SkillSpector: warn 230 tokens original MIT

safedeps

437

aldegad/safedeps

Skill Claude CodeCodex

Gate dependency installs (npm/pip/cargo/go/gem/maven/nuget) with OSV-backed advisory checks, approved-spec ledger, and post-install reorg rollback. Run safedeps check @ before any install command.

not rated 20 +1 18d ago A 62 tokens original Apache-2.0

pass-cli-mcp

438

hesreallyhim/proton-pass-community-mcp

Skill Claude CodeCodex

Canonical protocol for model-side skill behavior when orchestrating proton-pass-community-mcp tools in chat sessions.

not rated 20 +2 today A 25 tokens GPL-3.0

microsandbox

439

superradcompany/skills

Skill Codex needs its repo

Create and manage isolated microsandbox microVMs for safe code execution, testing, development, and agent workflows. Use when the user needs to run untrusted code, create ephemeral or persistent sandboxes, execute commands, copy files, inspect logs and metrics, configure networking or secrets, mount volumes, manage…

not rated 20 +1 4d ago C 78 tokens original Apache-2.0

pe-reverse-analyzer

440

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

A general reverse-engineering toolkit for Windows programs, Android apps, iOS apps, web interfaces, and APIs. Reverse engineering means examining software to understand how it works and, where appropriate, how to modify and rebuild it.

not rated 20 +3 11d ago A 90 tokens

security-assessment

441

Njones17/AI-agent-master-cyber-skills-list

Skill Claude CodeCodex

Use when planning, scoping, or executing a comprehensive security assessment, penetration test, red team engagement, or security audit. Use when the user needs to coordinate multiple security testing activities, define assessment scope and rules of engagement, perform threat modeling, rate risk using CVSS, map…

not rated 20 6mo ago A 114 tokens

review

442

fall-out-bug/sdp

Skill Claude CodeCodex

Multi-agent quality review (QA + Security + DevOps + SRE + TechLead + Documentation + PromptOps).

not rated 19 3mo ago A 25 tokens original MIT

secureai-scan

443

akanthed/SecureAI-Scan

Skill Claude CodeCodex

Use when the user asks to scan a repo for AI/LLM security issues, wants to know "is this skill safe?" before installing an Agent Skill, needs to "scan my MCP config" or check an MCP server before trusting it, asks about prompt injection / tool poisoning / RAG poisoning risk in their code, or is about to install any…

not rated 19 2d ago A SkillSpector: warn 109 tokens original MIT

yultyyev/better-auth-firebase-auth

Skill Claude CodeCodex

Add Firebase Authentication (Phone SMS OTP, Google Sign-In, Email/Password) to a Better Auth app using the better-auth-firebase-auth plugin. Use when adding phone authentication to Better Auth without Twilio, integrating Firebase Auth with Better Auth sessions, working with the better-auth-firebase-auth package, or…

not rated 19 yesterday A 82 tokens original MIT

audit-code

445

Swader/agent-skills-audit

Skill Claude CodeCodex

Audit code for concrete correctness, security, performance, UX, and maintainability risks within an agreed scope. Use for code audits, PR feedback, or adversarial review. Produce evidence-backed findings, focused verification, and a bounded independent review when permitted.

not rated 19 10d ago A 53 tokens

okjpg/skill-checkup-openclaw

Skill Claude CodeCodex

Use when auditing OpenClaw agents, workspaces, or hosts for production readiness, safety, backup/GitHub, memory/recall, skills, heartbeat, crons, watchdog, security, access, runtime bloat, or course baseline fit.

not rated 19 4mo ago A 58 tokens

sanitize

447

agentward-ai/agentward

Skill Claude CodeCodex

Detect and redact PII from text files. Supports 15 categories including credit cards, SSNs, emails, API keys, addresses, and more — with zero dependencies.

not rated 19 2mo ago A 36 tokens

pin-guard

448

walidboulanouar/pin-guard

Skill Claude CodeCodex

Enforce exact, pinned package versions across a JavaScript/TypeScript repo and its agent tooling. Scans package.json dependencies, npm scripts, MCP server configs (.mcp.json, Claude/Cursor settings), and CI workflows for unpinned specs (^, , , latest, missing versions on npx). Pins everything to exact versions…

not rated 19 2mo ago A 156 tokens original MIT

sector-b79/Malware-And-Reverse-Engineering-Skill-for-AI-Agents

Skill Claude CodeCodex

Defensive malware analysis and reverse-engineering workflow. Use for authorized lab analysis of suspicious Windows executables, DLLs, shellcode, packed samples, malicious documents, indicators of compromise, static and dynamic triage, IDA/Ghidra/debugger reasoning, anti-analysis handling, unpacking, host/network…

not rated 19 +1 4mo ago A 75 tokens

mapick

450

mapick-ai/mapick

Skill Claude CodeCodex

Mapick — Skill recommendation & privacy protection for OpenClaw. Scans your local skills, suggests what you're missing, and keeps other skills from seeing your sensitive data.

not rated 18 3mo ago C 37 tokens original MIT

auth-rbac-scaffold

451

apisec-inc/apisec-skills

Skill Claude CodeCodex

Use when developer is implementing authentication, building login/logout flows, writing JWT validation, adding middleware, creating role-based access control, building permission systems, or asking how to protect routes. Also triggers on keywords: auth, bearer token, JWT, session, middleware, permissions, roles…

not rated 18 5mo ago A 98 tokens original MIT

privacy

452

gpdir16/tabyAgent

Skill Claude CodeCodex

Privacy tools and alternatives to mainstream services with verified details on licensing, ads, and pricing.

not rated 18 7d ago A 20 tokens AGPL-3.0

AgentConnect/awiki-agent-id-message

Skill Claude Code

Verifiable DID identity and end-to-end encrypted inbox for AI Agents. Built on ANP (Agent Network Protocol) and did:wba. Provides self-sovereign identity, Handle (short name) registration, content pages publishing, federated messaging, group communication, and HPKE-based E2EE — Web-based, not blockchain. Designed…

not rated 18 5mo ago A 155 tokens original Apache-2.0

cs-policy

454

3D-Tech-Solutions/code-scalpel

Skill Claude Code

Verify code compliance with policies and standards: HIPAA, SOC2, PCI-DSS, custom style guides. Validate policy file integrity with cryptographic verification.

not rated 18 +1 2mo ago A 34 tokens

ClawdStrike

455

cantinaxyz/clawdstrike-skill

Skill Claude CodeCodex

Security audit and threat model for OpenClaw gateway hosts. Use to verify OpenClaw configuration, exposure, skills/plugins, filesystem hygiene, and to produce an OK/VULNERABLE report with evidence and fixes.

not rated 18 7mo ago A 47 tokens

edr-evasion-dev

456

AeonDave/malskill

Skill Claude CodeCodex

Auth/lab dev: Windows + Linux detection-resilience research; syscall dispatch, stack/call-chain spoofing, sleep-state, memory permissions, ETW/AMSI + eBPF/iouring/LDPRELOAD telemetry tradeoffs, kernel-visible signals, and cross-platform loader OPSEC with signal-cost budgeting.

not rated 18 changed 4d ago A 70 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: