Security skills

16,852 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 488bug-bounty 285agent 227generative-ai 179LangChain 176hacking 175autonomous-pentesting 137cloud-security 126claude-ai 118redteam 117skills 108security-audit 107LLM 106cors-exploitation 93

panel-review

577

mollyretter/forward-deployed-engineer-toolkit

Skill Claude CodeCodex

Multi-agent panel review of a PR or current-branch diff. Three-model fan-out across Opus, Sonnet, and Haiku. Opus and Sonnet review for regressions, security issues, and bugs; Haiku reviews convention drift, naming, dead code, and comment quality. Discrete severity levels (nit, question, blocker). Sonnet confidence…

not rated 9 17d ago A SkillSpector: pass 116 tokens original MIT

ibnsawad/Saudi-Regulatory-Compliance-Claude-Skill

Skill Claude CodeCodex

Senior cybersecurity, cloud, and data-protection compliance advisor for organisations in Saudi Arabia. Trigger for: NCA ECC-2:2024, CCC-2:2024, DCC-1:2022, CSCC-1:2019, OTCC-1:2022, TCC-1:2021, OSMACC-1:2021, CGEC-1:2019, CGESP-1:2019, NCS-1:2020; SAMA Cybersecurity/IT Governance/Business Continuity Frameworks; CST…

not rated 9 1mo ago A 243 tokens

vibeguard-sql-safety

579

MuddySheep/vibeguard-local

Skill Claude CodeCodex

MANDATORY pre-flight for ALL SQL operations. Fire this skill IMMEDIATELY whenever the conversation involves SQL of any kind — writing it, proposing it, executing it, reviewing it, or even talking about it concretely. Triggers include any of these keywords appearing in user input or your own draft output…

not rated 9 4mo ago A 268 tokens original Apache-2.0

review-all

580

paultyng/skill-issue

Skill Claude CodeCodex

Use when the user asks for a deep review, full review, comprehensive review, production readiness assessment, full audit, multi-domain audit, "security and reliability and code review", or "review everything". Also use when the user explicitly requests performance review alongside the comprehensive request (e.g.…

not rated 9 28d ago A 102 tokens original MIT

security-kb

581

dinosn/security-knowledge-base

Skill Codex

Read, search, and inspect evidence in a Security Knowledge Base v1 repository, then validate or stage evidence-cited, revision-bound claim and finding proposals. Use when a task refers to a repository containing kb.json and the kb CLI, asks to check or update the security KB, or supplies an skb.context-packet/v1. Stop…

not rated 9 28d ago A 92 tokens original MIT

prereview

582

singhharsh1708/kitbash

Skill Claude CodeCodex

Review the current diff against this team's conventions and invariants before it ships. Invoke with /prereview before opening a PR, or run as a pre-push gate.

not rated 9 4d ago A 0 tokens original Apache-2.0

xfstudio/skills

Skill Claude CodeCodex

Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities.

not rated 9 6mo ago A 29 tokens

ai_llm_attacks

584

1ikeadragon/awesome-offsec-claude

Skill Claude CodeCodex

Elite AI/LLM exploitation specialist - prompt injection, jailbreaking, agent exploitation, RAG poisoning, multi-modal attacks, model extraction, and system prompt leakage for CTF and red team engagements.

not rated 9 5mo ago A ✓ AI review 45 tokens

slartz/agent-security-awareness-training

Skill Claude CodeCodex

Mandatory security awareness onboarding for AI agents. Run this skill at the start of EVERY agent session, before performing any task — especially tasks involving tools, credentials, external content, email, file systems, cloud resources, or production systems. Also run it whenever the security policy file changes…

not rated 9 2mo ago A 117 tokens original MIT

authz-recipe

586

tr4m0ryp/shor

Skill Claude CodeCodex

Broken Access Control is OWASP #1, but there is no drop-in CLI (Autorize / AuthMatrix are Burp extensions). This is the procedure that carries the whole category: an authorization-matrix + A/B session-replay method driving curl, the playwright skill (per-identity sessions), and ffuf (ID enumeration). Live →…

not rated 9 1mo ago A 62 tokens

resource-index

588

ArianHobson333/claude-bug-bounty-stack

Skill Claude CodeCodex

Curated index of external hacking resources — meta-lists, frameworks, wordlists, payload banks, recon/OSINT, network, exploitation, and CTF tooling. Load when the user asks "what's the tool for X", "where do I find payloads for Y", "is there a wordlist for Z", or when planning which external resource to pull for a…

not rated 9 4mo ago A 92 tokens

terraform-hardening

589

CaseyLabs/kc-secure-repo-template

Skill Claude CodeCodex

Use when changing or reviewing the Terraform-backed GitHub repository hardening workspace under config/infra, including provider pins, rulesets, default branch protection, required checks, secret scanning, Dependabot security updates, token handling, plan/apply behavior, and infra documentation. Do not use for…

not rated 9 changed yesterday A 89 tokens

openclaw

590

edimuj/vexscan

Skill Claude CodeCodex

Scans extensions, skills, and code for security threats: prompt injection, malicious code, obfuscation, data exfiltration. Also scans inbound messages for injection patterns automatically.

not rated 9 4mo ago A 0 tokens original Apache-2.0

pentest-findings

591

jayelbotvibe-web/hermes-pentest-lab

Skill Claude CodeCodex needs its repo

Pentest finding interpretation encyclopedia — maps tool output to finding severity, CVSS scoring rules, and report-ready language. Answers 'What severity is this? What's the CVSS? How do I write this up?'.

not rated 9 15d ago A SkillSpector: warn 47 tokens original MIT

AI45Lab/SentrySkills

Skill Claude CodeCodex

Establish security boundaries before execution. Trigger this skill whenever involving command execution, file writing, sensitive data reading, external tool result adoption, or potential unauthorized requests; first output risk assessment and allowed/forbidden action lists.

not rated 9 2mo ago A 50 tokens original MIT

vigolium-scanner

593

vigolium/skills

Skill Claude CodeCodex

Use when operating the vigolium CLI for web vulnerability scanning, security testing, or traffic analysis. Covers scanning a URL/spec/raw request, running AI agent scans (autopilot, swarm, audit, query), triaging findings, confirming them with replay/fuzz, handing off to Burp or Caido, browsing stored traffic, writing…

not rated 9 changed 3d ago A 136 tokens

deep-review

594

Jmosier69/refute

Skill Claude Code

Multi-angle code review that adapts to what is being reviewed — a mid-flight worktree increment, a full PR before production, a merge-window integration sweep, or a security-only pass. Findings are scored, adversarially refuted, widened to the same defect elsewhere in the codebase, and reported to the native review…

not rated 9 29d ago A 97 tokens original MIT

re-electron-skill

595

iceman1001/awesome_rfid_claude_skills

Skill Claude CodeCodex

Electron application reverse engineering — ASAR unpacking, webpack bundle analysis, auth/payment logic discovery, IPC channel mapping, and client-side authorization bypass analysis. Use when the user needs to: reverse engineer an Electron app (.deb/.dmg/.exe), analyze auth/subscription/license logic in Electron apps…

not rated 9 2mo ago A 101 tokens

skillguard

596

LLMSecurity/skillguard

Skill Claude CodeCodex

Security audit agent skills for vulnerabilities and malicious patterns. Use when asked to "scan a skill", "check if a skill is safe", "audit a skill for security", "review skill security", "is this skill malicious", or when installing/reviewing any third-party agent skill. Accepts local SKILL.md files, skill…

not rated 9 +1 6mo ago A 100 tokens

encryption-file-ops

597

hebulin/mcp-read-file-server

Skill Claude CodeCodex

A guide for working with files protected by enterprise encryption software when an AI agent’s normal file tools show unreadable text.

not rated 9 changed today A 51 tokens original MIT

cube-sandbox

598

runzhliu/aik8s

Skill Claude CodeCodex

Execute requested Python code inside an isolated CubeSandbox MicroVM. Use when the user explicitly asks for CubeSandbox, MicroVM isolation, offline execution, or proof that code did not run on the DSH host.

not rated 9 yesterday A 46 tokens

rls-patterns

600

bybren-llc/a-safe-pulse

Skill Claude CodeCodex

Row Level Security patterns for database operations. Use when writing any database query, creating API routes that access data, implementing webhooks that write to the database, or working with user data. This project uses direct pg (node-postgres) queries with raw SQL -- no ORM.

not rated 9 5mo ago A 60 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: