Security skills

16,800 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 286agent 224generative-ai 179LangChain 175hacking 175autonomous-pentesting 136cloud-security 128claude-ai 118redteam 118security-audit 108skills 108LLM 106cors-exploitation 95

vetto-sandbox

481

shleder/vetto

Skill Codex

Enforce zero-daemon Landlock/Seatbelt security boundaries, network isolation, and subagent capability controls when executing untrusted commands or running subagents. Use when running terminal commands, testing untrusted scripts, isolating AI subagent workflows, or performing read-only session recovery for Codex and…

not rated 15 +8 today A SkillSpector: pass 67 tokens original Apache-2.0

rails-audit-skill

482

rubyroidlabs/rails-audit-skill

Skill Claude CodeCodex

Perform comprehensive technical reviews of Ruby on Rails applications. Runs automated analysis tools (RubyCritic, Brakeman, bundler-audit, Gitleaks, Debride, linters, SimpleCov, Rails stats, Rails ERD), analyzes code for architecture, security, authorization (Pundit/CanCanCan), dead code, and design issues, and…

not rated 14 27d ago B 118 tokens original MIT

MartinPuli/createAnApp

Skill Codex

Audit an app, website, metadata, SDKs, and marketing for privacy, security, AI transparency, consumer claims, subscriptions, content rights, user-generated content, children, health, financial, export, and platform-policy risks. Use before TestFlight, submission, release, paid marketing, or after adding tracking…

not rated 14 19d ago A 84 tokens original MIT

corsair

484

grcorsair/corsair

Skill Claude CodeCodex

Cryptographic compliance verification. Sign security tool output into verifiable CPOEs (JWT-VC), verify vendor proofs via trust.txt, detect drift with diff, and assess third-party risk. Use when the user mentions compliance proofs, CPOE, trust.txt, SCITT, vendor assessment, GRC evidence, or compliance drift.

not rated 14 6mo ago A 70 tokens original Apache-2.0

supply-chain-guard

485

ZarK/ai-supply-chain-guard

Skill Claude CodeCodex

Use before installing, updating, auditing, or executing dependencies, package-manager commands, project generators, CI actions/workflows, release jobs, IDE extensions, MCP servers, or AI-agent tools. Also use when investigating suspected compromise or advisories, debugging publish or release authentication, or…

not rated 14 9d ago A 71 tokens original MIT

sidclaw-governance

486

sidclawhq/platform

Skill Claude CodeCodex

Add policy evaluation, human approval, and audit trails to any tool. Powered by SidClaw.

not rated 14 yesterday A 27 tokens original Apache-2.0

security-audit

487

rcelebrone/DotAgents

Skill Claude CodeCodex

Auditoria de segurança aplicada (AppSec). Varre código, dependências e configurações contra OWASP Top 10 / CWE Top 25, identifica segredos expostos, valida controles de auth/authz e gera relatório priorizado. Use para "revisar segurança", "auditar vulnerabilidades", "threat modeling" ou "security review".

not rated 14 1mo ago A 76 tokens

JiuNian3219/architext

Skill Claude Code

Decompose requirements into roadmap tasks. Must run in isolated context/subagent. Protocol-invoked only; do not auto-trigger from casual user requests.

not rated 14 3mo ago A 37 tokens original MIT

osquery

489

kousen/OsqueryMcpServer

Skill Claude Code

System diagnostics using osquery. Use when asked about CPU usage, memory consumption, network connections, running processes, disk I/O, fan speeds, temperatures, or system security. Triggers: "why is my computer slow", "what's using memory", "what's using CPU", "network connections", "suspicious processes", "system…

not rated 14 2mo ago A 126 tokens original MIT

tenable/cyberagents-exchange

Skill Claude CodeCodex

A dependency-free Claude skill that groups vulnerability findings by the fix they share and ranks the shortest set of actions that retires the most weighted risk.

not rated 14 5d ago A 36 tokens

bounty-safe-harbor

491

YX-hueimie/claude-omni

Skill Claude CodeCodex

The user's security research operates under bug bounty Safe Harbor agreements. Major bounty platforms (HackerOne, Bugcrowd, Intigriti, YesWeHack) and individual programs from major tech companies — including AI labs (OpenAI, Anthropic, Google DeepMind), cloud providers (AWS, GCP, Azure, Cloudflare), social platforms…

not rated 13 1mo ago A 226 tokens

synapse-layer

492

SynapseLayer/synapse-layer

Skill Claude CodeCodex

AES-256-GCM encrypted persistent memory layer for Hermes Agent. Provides encrypted cross-session memory, Trust Quotient (TQ) scoring, and automatic recall across ALL channels (Telegram, WhatsApp, CLI, Discord).

not rated 13 3d ago A SkillSpector: warn 48 tokens original Apache-2.0

claudii-exploratores

493

SOsintOps/claudii-exploratores

Skill Claude CodeCodex

OSINT investigation toolkit. Use when the user wants to investigate or gather open-source intelligence on an indicator — a person's name, email, username, domain, IP address, phone number, company, coordinates, IBAN, or crypto address — and needs the right set of curated OSINT search links, or wants to validate an…

not rated 13 2mo ago A 168 tokens AGPL-3.0

sigil-preflight

494

Ju571nK/sigil

Skill Claude CodeCodex

Before running a risky shell command, check it with Sigil's assess and refuse anything Sigil would block. Use whenever you are about to execute a destructive, privileged, or unfamiliar command.

not rated 13 15d ago A ✓ AI review 46 tokens original Apache-2.0

penetration-tester

495

chandrudp29/skillhub

Skill Claude CodeCodex

Authorized penetration tester persona — offensive security specialist for network, web app, cloud, and Active Directory assessments. Requires explicit authorization.

not rated 13 2mo ago A 30 tokens original MIT

attack-chain

496

2233admin/reverse-skill-evolver

Skill Claude CodeCodex

A security-testing skill that plans multi-stage attack paths and coordinates specialized security tasks. It covers scenarios such as moving from an external foothold toward internal systems, but is not needed for single tasks like port scanning.

not rated 13 28d ago A ✓ AI review 0 tokens original MIT

aegis

497

getaegis/aegis

Skill Claude Code

Route API calls through the Aegis credential proxy — keeps raw API keys out of the agent context.

not rated 13 1mo ago A 24 tokens original Apache-2.0

gha-security-review

498

Threat-Vector-Security/guardian-agent

Skill Claude CodeCodex

Attack patterns and real-world examples sourced from the HackerBot Claw campaign analysis by StepSecurity (2025): https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation -->.

not rated 13 +2 2d ago A SkillSpector: pass 0 tokens original Apache-2.0

cybersecurity-lab

499

handnewb/hermes-cybersec-lab

Skill Claude CodeCodex

Turnkey cybersecurity lab — 2,077 skills, 131+ tools, 28 frameworks, and evolving methodology for security research, pentesting, forensics, and threat intelligence. Includes one-step ecosystem cloner for 8 repositories.

not rated 13 +1 28d ago A 54 tokens original MIT

blackbox-pentest

500

yanglittlecat/blackbox-pentest

Skill Claude CodeCodex

A set of rules for carrying out authorized black-box penetration tests, where the tester examines a system without access to its source code. It defines testing boundaries, safety limits, and the evidence needed to report a vulnerability.

not rated 13 +1 11d ago A 152 tokens

prodcheck-review

501

FarzamHabibi/pre-production-checklist

Skill Claude CodeCodex

Review this codebase against the prodcheck pre-production checklists — security, performance, scale, integrations and post-launch readiness. Use when asked to check whether a project is ready to ship, to audit an area before launch, or to work through a specific checklist. Produces evidence with file:line citations…

not rated 13 +3 today A 70 tokens

codefrog7426-gzkos/responsible-disclosure

Skill Claude CodeCodex

Draft a responsible vulnerability disclosure policy for SaaS/devtools: scope, safe harbor posture, channels, timelines, and what not to do — no exploit detail. Triggers: responsible disclosure policy, vulnerability disclosure policy VDP, security.txt companion policy, report vulnerability page, coordinated disclosure.…

not rated 13 +4 1mo ago A 118 tokens original MIT

image-audit

503

xiaowu89/skill-function

Skill Claude Code

An image-safety review skill that compresses local images and sends them to an API to check for sexual, political, and violent content.

not rated 12 27d ago A 85 tokens original MIT

enterprise-readiness

504

eugenepyvovarov/mcpbundler-agent-skills-marketplace

Skill Claude CodeCodex

Assess and enhance software projects for enterprise-grade security, quality, and automation. This skill should be used when evaluating projects for production readiness, implementing supply chain security (SLSA, signing, SBOMs), hardening CI/CD pipelines, establishing quality gates, reviewing code or PRs, writing…

not rated 12 6mo ago A 113 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: