Skill Claude CodeCodex
Audit Parcel Path changes for PII leaks in logs and error messages. Use before opening a PR, after adding verbose logging, or when touching carrier responses.
16,641 tagged Security, measured the same way as everything else here.
Browse within: cybersecurity 485bug-bounty 286agent 224generative-ai 179LangChain 175hacking 175autonomous-pentesting 136cloud-security 128claude-ai 118redteam 118skills 109security-audit 108LLM 106cors-exploitation 95
Skill Claude CodeCodex
Audit Parcel Path changes for PII leaks in logs and error messages. Use before opening a PR, after adding verbose logging, or when touching carrier responses.
Skill Claude CodeCodex
An asset-discovery workflow that searches Fofa, checks which results are reachable, removes duplicates, and exports the results. Fofa is a search engine for internet-connected systems and services.
Skill Claude CodeCodex
An AI-assisted workflow for diagnosing and fixing coding errors, agent problems, and security issues. CyberHuaTuo is the name of the included AI clinic concept.
Skill Claude CodeCodex
This skill teaches Claude Code how to write detection rules for the AI Traffic Control rule engine. Read this before creating or modifying anything in rules/. The full rule schema is Rule in packages/schema/src/zod/rule.ts — it is the source of truth for every field below.
Skill Claude CodeCodex
A local encrypted vault for storing passwords, API keys, tokens, and other access details under account or key aliases. It can inject those values into a command’s environment without exposing the plain text to the AI.
lingfengz/llm-dengbao-assessment
Skill Claude CodeCodex
A Chinese-language assessment method for checking large-language-model systems against China’s classified cybersecurity protection requirements and related AI security standards.
Skill Claude Code needs its repo
A browser-driven helper for opening permission scopes for an existing Feishu bot app. Feishu is a workplace collaboration platform, and permission scopes control what a bot can read or do.
Skill Claude Code
Da7rkx0 represents dark web reconnaissance capabilities used during authorized threat intelligence gathering and security assessments. Understanding dark web monitoring is essential for proactive defense — identifying leaked credentials, sold data, and emerging threats before they are exploited.
falcoschaefer99-eng/michael-security-agent
Skill Claude CodeCodex
Invoked via /security-audit, /michael, or when your orchestrator dispatches for security review.
Skill Claude CodeCodex
Audit the shell startup chain (the rc file + every file it sources) for hardcoded credentials, persistence-suspicious patterns, duplicate or dangling aliases, and git-baseline drift. USE WHEN the user wants to review, secure, clean up, or maintain their shell aliases or startup files; check /.zshrc / /.bashrc for…
Skill Claude Code
Read a dxkit report and execute fixes — prioritize findings by severity, plan the fix sequence, run the fix, verify the score moved, re-baseline if appropriate. Supports a SCOPED pass to burn down one category at a time (dependency/BOM vulnerabilities, security, code quality, tests, docs), and a BASELINE-CLEANUP pass…
Skill Claude CodeCodex
Pre-share leak scanner for Claude Code skills (or any folder). Scans BEFORE you publish for secrets (API keys, tokens, private keys, .env values, high-entropy strings), PII (emails/phones), local machine paths (C:\Users\ , /home/ , /Users/ , UNC, internal hostnames), and client/proper-noun names from a LOCAL private…
Skill Claude Code
Use when an agent or role needs credentials on a machine that does not have them — a fresh container, a rebuilt host, a successor session — or when sealing, rotating, or verifying secrets kept in a shared object store.
ChainAware/behavioral-prediction-mcp
Skill Claude CodeCodex
Use this skill whenever a user asks about wallet safety, fraud risk, rug pull detection, wallet behavior analysis, DeFi personalization, on-chain reputation scoring, AML checks, token ranking by holder quality, airdrop screening, lending risk, token launch auditing, or AI agent trust scoring. Triggers on questions…
Skill Claude CodeCodex
ZIRAN is an open-source security testing framework for AI agents. It discovers dangerous tool chain compositions via knowledge graph analysis, detects execution-level side effects (not just text output), and runs multi-phase trust exploitation campaigns that model real attacker behavior.
Skill Cursor
This rule automatically analyzes dependencies before they're installed to provide insights about maintenance frequency, security vulnerabilities, and popularity in the developer ecosystem.
Skill Codex
Audit Circom circuits for soundness, completeness, privacy, and constraint bugs. Use when the user asks to audit, review, check, or find vulnerabilities in Circom code, or when they ask to run circom-auditor on a repo or specific .circom files.
Skill Claude CodeCodex
Agent Shielded — Agent Privacy Cloud. Private infrastructure for AI agents in one command: Ollama, n8n, Qdrant, Agent Sandbox, Tor Rotator, Privoxy, Gotify, Agent Dashboard + Prometheus, Grafana, Portainer. Zero data leaks. Triggers: 'agent shielded', 'agent privacy', 'AI agent infrastructure', 'private LLM', 'Ollama…
TheDarkMist/nis2-incident-report
Skill Claude CodeCodex
Drafts NIS2 incident reports for a small WordPress agency or freelancer, especially one acting as supply chain to a regulated client rather than as a regulated entity itself. Use this skill whenever someone needs to draft or produce a NIS2 incident notification: a 24-hour early warning, a 72-hour notification, a…
austintgriffith/evm-audit-skills
Skill Claude CodeCodex
Master index for EVM smart contract security audit skills. Load this FIRST for every audit to determine which specialized skills to load. Contains routing table and audit methodology.
sjhhh024-cmyk/Spider-JS-Mcp-Skills
Skill Claude CodeCodex
A general-purpose guide for examining JavaScript code to identify website encryption, request signatures, and anti-bot checks, then documenting the findings in Python.
Skill Claude CodeCodex
Guides manual dependency injection wiring for Go services: three-tier naming taxonomy (Provide/MustProvide/Must), Must-pattern entrypoints, OS-signal-driven context lifecycle, common provider structs, infrastructure must-builders, interface-segregated bus registration, decorator/tracing wrappers, and…
sergekostenchuk/xray-xhttp-vpn-orchestrator
Skill Claude CodeCodex
Coordinate the local Xray/VLESS/XHTTP VPN workflow, route tasks to internal worker modules, enforce scoped alarms, and accept outputs only after evidence and review.
Skill Claude CodeCodex
Govern an AG2 multi-agent network — identity (Passport, Resume), per-agent Rule with two top-level blocks access (AccessBlock) and limits (LimitsBlock, which nests RateBlock + InboxBlock), the swappable HubArbiter / RuleBasedArbiter access-&-routing seam, AuthAdapter / AuthRegistry registration, channel-level…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: