Security skills

16,761 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 488bug-bounty 285agent 227generative-ai 179LangChain 176hacking 175autonomous-pentesting 137cloud-security 126claude-ai 118redteam 117skills 108security-audit 107LLM 106cors-exploitation 93

adcp-scorecard

625

Pubx-ai/skills

Skill Claude CodeCodex

Evaluate whether AdCP (Ad Context Protocol, agenticadvertising.org) — or a concrete AdCP implementation such as a seller agent, buyer agent, or orchestrator — is safe, interoperable, operationally viable, and ready for pilot or production use. Combines a weighted decision scorecard, hard safety gates that override any…

not rated 6 4d ago A 198 tokens

using-openlens

626

Traves-Theberge/openlens

Skill Claude CodeCodex

Guide for using openlens to review code. Triggers on: "review my code", "check for bugs", "security scan", "run openlens", "set up code review", "openlens".

not rated 6 5mo ago A 46 tokens original MIT

capybara-nexus-v2

627

pentrestion/capybara-nexus-v2

Skill Claude CodeCodex

Name: capybara-nexus-v2 Tier: Frontier (Capybara-class) Mandate: Autonomous Reasoning, Empirical Feedback, & Zero-Day Research.

not rated 6 2mo ago A 0 tokens

audit

628

telus-labs/stagecraft

Skill Claude CodeCodex

Run a structured codebase audit — map architecture, assess health (compliance / tests / docs), perform deep analysis (security / performance / code quality), and synthesize a prioritized roadmap. Use this skill when the user says things like 'audit the codebase', 'understand this project', 'find problems', '/audit'…

not rated 6 3d ago A SkillSpector: pass 103 tokens original MIT

JoviDeCroock/skills

Skill Codex

Use when hardening npm package release workflows with trusted publishing, OIDC, GitHub environments, pinned GitHub Actions, disabled publish-path caching, Changesets release PRs, direct tag-based npm publish flows, staged publishing, or npm release-supply-chain reviews.

not rated 6 1mo ago A 59 tokens

security-scan

630

ArmisSecurity/armis-appsec-mcp

Skill Claude CodeCodex

On-demand AI-powered security scanning. Use when the user asks to scan code for vulnerabilities, run a security check, scan code for security issues, scan a file, scan a diff, scan staged changes, check for security issues, check for secrets, find hardcoded credentials, or run an appsec scan. Triggers: /security-scan…

not rated 6 28d ago A 110 tokens original Apache-2.0

sumsub/agent-skills

Skill Claude Code

Configure KYT transaction monitoring rules with tags, applicant risk scoring and risk levels. TRIGGER when the user says "create / add / set up KYT rules / TM rules", "configure transaction monitoring", describes scoring logic (flag/block/hold transactions by amount, country, direction, peer, or other conditions)…

not rated 6 changed 6d ago A Socket: passSnyk: pass 139 tokens

unmark-files

632

Dhirenderchoudhary/unmarkk

Skill Claude CodeCodex

Inspect and remove identifying metadata and provenance marks from files — GPS coordinates, camera serial numbers, author names, editing timestamps, C2PA content credentials, and invisible Unicode carriers. Works on PNG, JPEG, WebP, PDF, DOCX, ODT, SVG, HTML, Markdown and plain text. Use when someone asks to strip…

not rated 6 10d ago A 113 tokens original MIT

code-vulnscan

633

Bhanunamikaze/Code-VulnScan-Skill

Skill Claude CodeCodex

Use this when the user wants to find security vulnerabilities in a codebase, perform a security audit, scan for CVEs, detect secrets, review React/Next.js, Go, Java/Kotlin JVM, PHP, Ruby, .NET, or Rust web services, audit architecture/application/infrastructure flaws, review auth/API/crypto/business logic, check…

not rated 6 27d ago A 128 tokens original MIT

ncf-backend

634

PoulpYBifle/NCF-Coding-Best-Practices

Skill Claude CodeCodex

Patterns et regles backend/API/DB/securite pour projets Next.js + TypeScript. Utiliser des que l'utilisateur travaille sur une mutation, une query, une route API, une migration de base de donnees, de l'authentification, de la securite, des schemas Zod, de l'observabilite, ou toute logique serveur. Couvre : template…

not rated 6 6mo ago A 121 tokens

code-review

635

ryanda9910/crucible

Skill Claude Code

Review code for correctness, security, TypeScript quality, and performance. Run before any PR or deploy.

not rated 6 3mo ago A 24 tokens

LeoKemp223/embedded-llm-guardrails

Skill Claude CodeCodex

Safety instructions for using an AI coding assistant in embedded projects, such as microcontroller, real-time operating system, driver, and board-support code. Embedded software runs on dedicated hardware, where mistakes can affect the device itself.

not rated 6 3mo ago C 98 tokens

access

638

tendhearth/wechat-cc

Skill Claude Code

Manage WeChat channel access — edit allowlists and set DM policy. Use when the user asks to add/remove users, check who's allowed, or change policy.

not rated 6 today A 34 tokens original MIT

TabletopExercise

639

SecurityTalent/bugskill-ai

Skill Claude CodeCodex needs its repo

Comprehensive cybersecurity tabletop exercise design and facilitation framework. USE WHEN designing incident response scenarios, creating executive or technical tabletops, generating atomics for exercise runners, identifying missing SOPs/playbooks, or evaluating organizational preparedness. Includes threat model…

not rated 6 24d ago A 64 tokens original MIT

qa-e2e-security

640

Agent-Hellboy/mcp-runtime

Skill Codex needs its repo

Real-cluster security regression QA — backend auth enforcement, grant/session policy, gateway deny paths, audit emission, trust escalation, UI/API security headers, HTTPS redirect modes, and secret-leak scanning in live logs. Use when Codex is asked to verify a change did not regress auth, governance, gateway policy…

not rated 6 2d ago A SkillSpector: warn 116 tokens original Apache-2.0

dev-qa

641

songoao25/dsh-virtual-product-team

Skill Claude CodeCodex

A development and quality process for building software, testing it, and checking it for security problems. It separates implementation, quality assurance, and security review while coordinating their handoffs.

not rated 5 5d ago A 50 tokens original MIT

code-reviewing

642

PacktPublishing/The-Claude-Code-Operating-Model

Skill Claude Code

Review code for security vulnerabilities, performance issues, and coding best practices. Activate when the user asks to review code, check code quality, give feedback on code changes, or audit a file.

not rated 7 +1 1mo ago A 42 tokens copy · 100% MIT

web-reverse-algorithm

643

guccig4366/xbsReverseSkill

Skill Codex

A workflow for reconstructing calculations in web JavaScript from their final outputs, such as request parameters, cookies, headers, or WebSocket messages. It covers signatures, encryption, verification challenges, WebAssembly, and heavily obfuscated code.

not rated 6 +1 today A 226 tokens copy · 100% MIT

wtf-approve

644

Sassine/wtf-approve

Skill Claude CodeCodex

Use when presenting shell commands or tool calls for user approval. Adds a human-readable explanation of intent, scope, and risk before the approval prompt.

not rated 6 5mo ago C ✓ AI review 34 tokens original MIT

sentinela

645

fonsecafns/sentinela

Skill Claude CodeCodex

Realiza uma auditoria de segurança completa em um projeto de código (web, API, backend, mobile etc), cobrindo OWASP Top 10 e CWE, dependências desatualizadas com CVEs, segredos expostos (incluindo histórico do git), CORS, TLS/HSTS, rate limiting, WAF, autenticação e cookies, controle de acesso, exposição excessiva de…

not rated 6 12d ago A 219 tokens

AshExplained/roblox-skills

Skill Claude CodeCodex

Audit Roblox Creator Store, Toolbox, inventory, group, universe, package, model, UI, gameplay, plugin-like, and other third-party imported assets for malicious or risky scripts. Use whenever Claude imports, inserts, reviews, or trusts Creator Store assets, especially assets with Scripts, LocalScripts, ModuleScripts…

not rated 6 2mo ago A 93 tokens original MIT

secure-browser

647

tkhq/secure-browser-mcp

Skill Claude CodeCodex

Fill stored secrets (passwords, card numbers, API keys) into web pages through the secure-browser MCP server without ever seeing the secret values. Use when a task needs a login, checkout, payment form, or any credential entered into a website and the credentials live in a secret store rather than in the conversation.

not rated 6 8d ago A 66 tokens

security-triage

648

Cantara/kcp-triage

Skill Claude CodeCodex

Builder-level security assessment methodology for web services. Use when performing security header audits, identifying exposed API keys, analyzing cookie behavior, checking CSRF protection, or compiling security reports for site owners.

not rated 6 +1 today A 43 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: