Security skills

16,868 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 489bug-bounty 286agent 226generative-ai 179LangChain 176hacking 175autonomous-pentesting 138cloud-security 126claude-ai 118redteam 117skills 111LLM 106security-audit 106cors-exploitation 93

skill-guardian

673

0xtresser/skill-guardian

Skill Claude CodeCodex

Pre-installation security gate for agent skills. This skill should be used when the user or agent attempts to install any skill — including requests like "install X", "add X skill", "help me set up the X skill", "npx skills add", or when the agent autonomously decides to install a skill. Also triggers on skill cleanup…

not rated 5 6mo ago B 125 tokens original MIT

lroy-stack/ai-pod-store

Skill Claude Code

Comprehensive audit of the SKAPARA AI shopping assistant — conversation quality, RAG retrieval, session memory, usage metering, tool execution, streaming UX, cost optimization, and security. Use when asked to audit the AI assistant, chatbot, conversation system, RAG pipeline, AI usage limits, or chat UX.

not rated 5 3mo ago A 69 tokens

osmedeus-expert

675

osmedeus/osmedeus-skills

Skill Claude CodeCodex

Expert guide for the Osmedeus security automation workflow engine. Use when: (1) writing or editing YAML workflows (modules and flows), (2) running osmedeus CLI commands (scan, workflow management, installation, server), (3) configuring steps, runners, triggers, or template variables, (4) debugging workflow execution…

not rated 5 5mo ago A 113 tokens

repo-cve-findings

677

mappedsky/seizu

Skill Claude Code

Resolve a GitHub repository in the security graph and list the CVEs recorded against it, confirming from the graph's dependency data which vulnerable versions are actually installed. Produces the finding set that a reachability review then judges against the source.

not rated 5 today A 54 tokens original Apache-2.0

pastewatch

678

ppiankov/pastewatch

Skill Claude Code

Sensitive data scanner — deterministic detection and obfuscation for text content.

not rated 5 7d ago A SkillSpector: warn 16 tokens original MIT

aiguard

679

zscaler/zguard-ai-integrations

Skill Claude Code

Scan prompts, AI responses, and code for security threats using Zscaler AI Guard. Supports 19 prompt detectors and 21 response detectors including: prompt injection, toxicity, DLP, PII, PII DeepScan, personal data, secrets, malicious URLs, code, gibberish, invisible text, brand risk, competition, language, legal…

not rated 5 8d ago A 230 tokens original MIT

rebar-audit

680

willackerly/rebar

Skill Claude Code

Use when asked about a rebar repo's health, compliance, tier, or contract status — and before claiming any tier, badge, or "green" state in docs or commits. Runs the three status surfaces and reads them without conflating the two maturity vocabularies.

not rated 5 28d ago A 60 tokens original Apache-2.0

cortex-secrets

681

davideuler/cortex-auth

Skill Claude CodeCodex

How to autonomously obtain secrets and API keys from a Cortex Auth server and launch projects with those secrets injected as environment variables — without any human intervention to configure keys. Use this skill whenever you need to: Run a project that requires API keys (OpenAI, Anthropic, SMTP, database passwords…

not rated 5 4mo ago B 161 tokens

raigo-owasp-llm

683

PericuloLimited/raigo

Skill Claude CodeCodex

RAIGO × OWASP LLM Top 10 — official OWASP LLM Application Security Top 10 (2025) enforcement rules for Hermes agents. Covers all 10 OWASP LLM risks: prompt injection, insecure output handling, training data poisoning, model denial of service, supply chain vulnerabilities, sensitive information disclosure, insecure…

not rated 5 5mo ago C 120 tokens

npm-safe-scan

684

nisconder/npm-safe

Skill Claude CodeCodex needs its repo

Automatically scan any npm package for supply-chain security risks BEFORE the user installs it. Trigger this skill whenever the user asks to install, add, or upgrade an npm package or dependency (e.g. "npm install X", "install X", "add X as a dependency", "yarn add X", "pnpm add X", "upgrade X"), or wants to…

not rated 5 7d ago A 128 tokens original Apache-2.0

OutlineDriven/odin-gemini-cli-extension

Skill Claude Code

Install a Claude-Code PreToolUse hook that blocks destructive git commands (push variants including force-push, hard reset, force clean, branch -D, checkout/restore overwrites) before Bash runs them. Use when the user wants git safety rails, force-push prevention, or repository-wipe protection.

not rated 5 2mo ago B 71 tokens original Apache-2.0

piranha

686

Falcon-Forge/PiRanha

Skill Claude CodeCodex

Autonomous agentic bug bounty hunting framework v2.0. BugHunter orchestrator with state-machine-driven phases, credential vault, auth flow automation, intelligent skill routing, Burp MCP bridge, parallel agent execution, LLM/AI target track, configurable severity profiles, and live dashboard. USE WHEN bug bounty…

not rated 5 2mo ago D 107 tokens original MIT

supply-chain-sentinel

687

aajj68/supply-chain-sentinel

Skill Claude CodeCodex

Security scanner for supply chain attacks, malicious dependencies, prompt injection, and suspicious code patterns. Use this skill whenever the user asks to audit a project, scan for malicious packages, check dependencies for threats, look for prompt injection, detect typosquatting, review supply chain security, or…

not rated 5 5mo ago B 159 tokens original MIT

MG-Cafe/agentic-coder-shield

Skill Claude Code

Security-hardened agentic coding assistant with 3 defense layers — input scanning, tool boundaries, and output scanning via Model Armor.

not rated 5 5mo ago C 33 tokens

team-governance

689

ketor/cto-fleet

Skill Claude Code

An AI-agent governance audit workflow that examines agent settings, permissions, data movement, prompts, and generated answers.

not rated 5 3mo ago A 154 tokens original Apache-2.0

security

690

olucasevangelista/security-skill

Skill Claude CodeCodex

Secure web and desktop application development. Use when writing authentication, authorization, API endpoints, form handling, database queries, file uploads, Electron apps, Tauri apps, IPC handlers, cryptography, secrets management, security headers, input validation, or when reviewing code for vulnerabilities. Covers…

not rated 5 5mo ago A 87 tokens

Veritas Acta Verify

691

VeritasActa/verify

Skill Claude CodeCodex

Signs every Claude Code tool call with an offline-verifiable Ed25519 receipt. Lets you audit exactly what Claude did and when, without trusting any server.

not rated 5 3mo ago A 37 tokens

llm-audit

693

punishell/SKILLS

Skill Claude CodeCodex

Use this skill when the user wants to run a full structured AI red team audit, generate a red team report, compile findings from multiple techniques across multiple models, produce a markdown or JSON report of jailbreak test results, score model resilience, summarize which techniques succeeded or failed, or wrap up an…

not rated 5 5mo ago A 73 tokens

security-skill

694

justinnoh/security-skill

Skill Claude CodeCodex

A software security review based on South Korea’s KISA 2021 security weakness guide. It checks 69 design and implementation categories and labels each one as passed, vulnerable, needing review, or not applicable.

not rated 5 2mo ago A 0 tokens original MIT

audit

695

robertknight/skills

Skill Claude CodeCodex

Quickly audit the current project for obvious malicious or untrustworthy behavior so the user can decide whether it is safe to run, build, or install. This is a triage pass, not a full security review — aim for a dozen targeted checks, not an exhaustive audit.

not rated 5 4mo ago A 0 tokens

security-review

696

mh2-lee/everything-claude-code

Skill Claude CodeCodex

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

not rated 5 7mo ago A 36 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: