Security skills

16,641 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 286agent 224generative-ai 179LangChain 175hacking 175autonomous-pentesting 136cloud-security 128claude-ai 118redteam 118skills 109security-audit 108LLM 106cors-exploitation 95

review-pii-redaction

529

lucasviola/specwiki

Skill Claude CodeCodex

Audit Parcel Path changes for PII leaks in logs and error messages. Use before opening a PR, after adding verbose logging, or when touching carrier responses.

not rated 11 1mo ago A 37 tokens original MIT

asset_hunt

530

intimatep/PenTestClaw

Skill Claude CodeCodex

An asset-discovery workflow that searches Fofa, checks which results are reachable, removes duplicates, and exports the results. Fofa is a search engine for internet-connected systems and services.

not rated 11 5mo ago A 29 tokens

CyberHuaTuo Rescue

531

JinNing6/CyberHuaTuo

Skill Claude CodeCodex

An AI-assisted workflow for diagnosing and fixing coding errors, agent problems, and security issues. CyberHuaTuo is the name of the included AI clinic concept.

not rated 11 today A SkillSpector: pass 52 tokens original Apache-2.0

write-detection-rule

532

akasecurity/ai-tc

Skill Claude CodeCodex

This skill teaches Claude Code how to write detection rules for the AI Traffic Control rule engine. Read this before creating or modifying anything in rules/. The full rule schema is Rule in packages/schema/src/zod/rule.ts — it is the source of truth for every field below.

not rated 11 +1 today A SkillSpector: warn 0 tokens original Apache-2.0

kyvault

533

webkubor/kyvault

Skill Claude CodeCodex

A local encrypted vault for storing passwords, API keys, tokens, and other access details under account or key aliases. It can inject those values into a command’s environment without exposing the plain text to the AI.

not rated 11 +1 10d ago B 78 tokens original MIT

lingfengz/llm-dengbao-assessment

Skill Claude CodeCodex

A Chinese-language assessment method for checking large-language-model systems against China’s classified cybersecurity protection requirements and related AI security standards.

not rated 11 +1 26d ago A 234 tokens original MIT

lark-bot-permissions

535

cloveric/tarocub

Skill Claude Code needs its repo

A browser-driven helper for opening permission scopes for an existing Feishu bot app. Feishu is a workplace collaboration platform, and permission scopes control what a bot can read or do.

not rated 12 +3 today A SkillSpector: warn 157 tokens original MIT

dark-web-recon

536

liortesta/ClawdAgent

Skill Claude Code

Da7rkx0 represents dark web reconnaissance capabilities used during authorized threat intelligence gathering and security assessments. Understanding dark web monitoring is essential for proactive defense — identifying leaked credentials, sold data, and emerging threats before they are exploited.

not rated 11 12d ago A SkillSpector: pass 0 tokens original Apache-2.0

shell-audit

538

akasecurity/claude-tools

Skill Claude CodeCodex

Audit the shell startup chain (the rc file + every file it sources) for hardcoded credentials, persistence-suspicious patterns, duplicate or dangling aliases, and git-baseline drift. USE WHEN the user wants to review, secure, clean up, or maintain their shell aliases or startup files; check /.zshrc / /.bashrc for…

not rated 10 1mo ago A 112 tokens original MIT

dxkit-action

539

vyuh-labs/dxkit

Skill Claude Code

Read a dxkit report and execute fixes — prioritize findings by severity, plan the fix sequence, run the fix, verify the score moved, re-baseline if appropriate. Supports a SCOPED pass to burn down one category at a time (dependency/BOM vulnerabilities, security, code quality, tests, docs), and a BASELINE-CLEANUP pass…

not rated 10 11d ago A SkillSpector: warn 201 tokens original MIT

skill-sanitizer

540

animaresearch/skills

Skill Claude CodeCodex

Pre-share leak scanner for Claude Code skills (or any folder). Scans BEFORE you publish for secrets (API keys, tokens, private keys, .env values, high-entropy strings), PII (emails/phones), local machine paths (C:\Users\ , /home/ , /Users/ , UNC, internal hostnames), and client/proper-noun names from a LOCAL private…

not rated 10 2mo ago A 193 tokens

sealed-secrets

541

ashfulcra/fulcra-tools

Skill Claude Code

Use when an agent or role needs credentials on a machine that does not have them — a fresh container, a rebuilt host, a successor session — or when sealing, rotating, or verifying secrets kept in a shared object store.

not rated 10 today A SkillSpector: warn 49 tokens original MIT

ChainAware/behavioral-prediction-mcp

Skill Claude CodeCodex

Use this skill whenever a user asks about wallet safety, fraud risk, rug pull detection, wallet behavior analysis, DeFi personalization, on-chain reputation scoring, AML checks, token ranking by holder quality, airdrop screening, lending risk, token launch auditing, or AI agent trust scoring. Triggers on questions…

not rated 10 28d ago A 440 tokens original MIT

ziran

543

taoq-ai/ziran

Skill Claude CodeCodex

ZIRAN is an open-source security testing framework for AI agents. It discovers dangerous tool chain compositions via knowledge graph analysis, detects execution-level side effects (not just text output), and runs multi-phase trust exploitation campaigns that model real attacker behavior.

not rated 10 today A 0 tokens original Apache-2.0

dependency-analysis

544

usrrname/cursorrules

Skill Cursor

This rule automatically analyzes dependencies before they're installed to provide insights about maintenance frequency, security vulnerabilities, and popularity in the developer ecosystem.

not rated 10 5mo ago A 28 tokens original ISC

circom-auditor

545

zksecurity/zk-skills

Skill Codex

Audit Circom circuits for soundness, completeness, privacy, and constraint bugs. Use when the user asks to audit, review, check, or find vulnerabilities in Circom code, or when they ask to run circom-auditor on a repo or specific .circom files.

not rated 10 1mo ago A 63 tokens original MIT

agent-shielded

546

Michae2xl/freedom-stack

Skill Claude CodeCodex

Agent Shielded — Agent Privacy Cloud. Private infrastructure for AI agents in one command: Ollama, n8n, Qdrant, Agent Sandbox, Tor Rotator, Privoxy, Gotify, Agent Dashboard + Prometheus, Grafana, Portainer. Zero data leaks. Triggers: 'agent shielded', 'agent privacy', 'AI agent infrastructure', 'private LLM', 'Ollama…

not rated 10 5mo ago B 123 tokens

nis2-incident-report

547

TheDarkMist/nis2-incident-report

Skill Claude CodeCodex

Drafts NIS2 incident reports for a small WordPress agency or freelancer, especially one acting as supply chain to a regulated client rather than as a regulated entity itself. Use this skill whenever someone needs to draft or produce a NIS2 incident notification: a 24-hour early warning, a 72-hour notification, a…

not rated 10 3mo ago A 185 tokens

evm-audit-master

548

austintgriffith/evm-audit-skills

Skill Claude CodeCodex

Master index for EVM smart contract security audit skills. Load this FIRST for every audit to determine which specialized skills to load. Contains routing table and audit methodology.

not rated 10 2mo ago A 38 tokens

JS Reverse Analyzer

549

sjhhh024-cmyk/Spider-JS-Mcp-Skills

Skill Claude CodeCodex

A general-purpose guide for examining JavaScript code to identify website encryption, request signatures, and anti-bot checks, then documenting the findings in Python.

not rated 10 7mo ago A 37 tokens original Apache-2.0

golang-manual-di

550

soulcodex/agentic

Skill Claude CodeCodex

Guides manual dependency injection wiring for Go services: three-tier naming taxonomy (Provide/MustProvide/Must), Must-pattern entrypoints, OS-signal-driven context lifecycle, common provider structs, infrastructure must-builders, interface-segregated bus registration, decorator/tracing wrappers, and…

not rated 10 4d ago A SkillSpector: pass 97 tokens original MIT

ag2ai/ag2-skills

Skill Claude CodeCodex

Govern an AG2 multi-agent network — identity (Passport, Resume), per-agent Rule with two top-level blocks access (AccessBlock) and limits (LimitsBlock, which nests RateBlock + InboxBlock), the swappable HubArbiter / RuleBasedArbiter access-&-routing seam, AuthAdapter / AuthRegistry registration, channel-level…

not rated 10 1mo ago A 264 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: