Security skills

16,857 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 489bug-bounty 286agent 227generative-ai 179LangChain 176hacking 175autonomous-pentesting 138cloud-security 126claude-ai 118redteam 117skills 111LLM 107security-audit 106cors-exploitation 93

dmaynor/dmaynor-skills-marketplace

Skill Claude CodeCodex

Reliably diff a single macOS kext between two macOS versions (e.g. 26.4.1 vs 26.5) when both kexts ship inside the kernelcache. Use when: (1) you need to confirm whether a kext was actually changed across a point release (kext CFBundleVersion is unreliable in macOS 26+: bumps with no code change, AND code changes with…

not rated 5 yesterday A 337 tokens

bb-local-toolkit

698

x-cookie/cbughunter-k2

Skill Claude CodeCodex

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload…

not rated 5 3mo ago A ✓ AI review 372 tokens

automotive-syseng

699

duonghvu/automotive-syseng

Skill Claude CodeCodex

When the user wants to analyze automotive requirements, check INCOSE/EARS compliance, review MISRA-C code, assess ADAS levels, or verify ISO 26262/AUTOSAR/SOTIF conformance. Also use when the user says 'check requirements', 'EARS check', 'INCOSE analysis', 'MISRA check', 'ASIL assessment', 'V-model check'…

not rated 5 4mo ago A 122 tokens original MIT

rhombus-cli

700

RhombusSystems/rhombus-cli

Skill Claude CodeCodex

Operate the Rhombus physical-security platform (cameras, access control, sensors, alerts, footage) from the terminal using the official rhombus CLI. Use when a task involves checking camera or device status, pulling alerts or events, reviewing or stitching footage, managing access control, or automating anything in a…

not rated 5 16d ago A 73 tokens

repo-scout

701

BingJyun/repo-scout-skill

Skill Claude Code

Comprehensive GitHub repo analysis covering architecture, OWASP Top 10 security scanning (with file path + line number + fix), 4-dimension strategic value assessment (cost savings, efficiency, startup opportunities, community impact), auto-competitor discovery, and optional Traditional Chinese audio review via…

not rated 5 4mo ago A 127 tokens original MIT

review-plan-v2

702

Sierra-Code-Co/internal-speckit-template

Skill Claude Code

Pre-push gate for the current branch's diff. Runs review-plan-v2's deterministic analyzers (gitleaks, markdownlint, actionlint, shellcheck, ruff, structural) with --static-only, then the CodeRabbit CLI for the actual review. No API keys, nothing billed to you, and no diff leaves the machine on the first leg. The…

not rated 5 changed 6d ago A 105 tokens

arcium-dev

703

outsmartchad/arcium-dev-skill

Skill Claude Code

End-to-end Arcium MPC development playbook (Jan 2026). Build privacy-preserving Solana programs using Arcium's Cerberus MPC protocol. Covers encrypted instructions (Arcis), three-instruction callback pattern, encryption/sealing, MXE configuration, offchain circuit storage, ArgBuilder patterns, and integration with…

not rated 5 7mo ago A 93 tokens

idorDeep

704

stvm8/agentValentine

Skill Claude Code

Methodical deep-dive IDOR/BFLA testing with encoding tricks, parameter manipulation, and context-dependent failure detection (e.g., /idorDeep swagger.json --from-apiTesting).

not rated 5 3mo ago A 37 tokens

codeprobe

705

nishilbhave/codeprobe

Skill Claude Code needs its repo

Whole-codebase code quality audit system with 9 specialized sub-skills covering security, SOLID principles, architecture, error handling, performance, test quality, code smells, design patterns, and framework best practices. Produces a scored health dashboard (0-100 per category), severity-rated findings (P0-P3) with…

not rated 5 1mo ago A 181 tokens original MIT

xsoar-pack-dev

706

mdrobniu/xsoar-pack-dev-skill

Skill Claude Code

Cortex XSOAR content pack development lifecycle - create packs, integrations, scripts, playbooks, run demisto-sdk lint/validate/pre-commit, build zip packs, manage versions and release notes, run unit tests, deploy to XSOAR instances, manage git branches/tags, handle marketplace vs local pack workflows. Use when the…

not rated 5 5mo ago D 95 tokens original Apache-2.0

auth

707

agentry-ai/agentry

Skill Claude CodeCodex

Use when the user says something like "add login", "users need to sign in", "I want auth", "gate this behind a user account". The auth surface (login / signup / OAuth / sessions) is NOT something you build. Read this whole page before touching auth code.

not rated 5 1mo ago A 0 tokens original Apache-2.0

agentsec

708

semiotic-ai/agentsec

Skill Claude CodeCodex

Audit AI agent skills for security vulnerabilities. Use when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before running them, gating CI/CD on skill safety, or generating audit reports (text, JSON, SARIF, HTML) for stakeholders.

not rated 5 2mo ago A 57 tokens original MIT

skill-vetter

709

romancestarrysky/skill-vetter

Skill Claude CodeCodex

A security review method for an external coding-agent skill file. It looks for prompt injection, credential theft, unsafe code execution, misleading names, and social-engineering tactics before installation.

not rated 5 4mo ago D 55 tokens original MIT

security-audit

710

ky2renzzz/acp-forge

Skill Claude CodeCodex

Perform a security audit on code, checking for common vulnerabilities including injection, auth bypass, secrets leakage, and unsafe dependencies.

not rated 5 2mo ago A 27 tokens original MIT

ctf-pwn

711

a2ure123/ctf-pwn-skill

Skill Codex

CTF pwn solving workflow for Codex with tmux-CLI-driven persistent-GDB live debugging: protection checks, libc/loader matching, IDA or idalib reverse engineering, pwntools wrappers, mandatory GDB-pwndbg inferior-tty step debugging, heap/stack/libc state inspection, and exploit strategy selection by primitive, glibc…

not rated 5 2mo ago A 84 tokens original MIT

bb-local-toolkit

712

cybersecwoman/Kiro-BugHunter

Skill Claude CodeCodex

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload…

not rated 5 3mo ago A ✓ AI review 372 tokens

clawhub-skill-vetting

713

hugomrtz/skill-vetting-clawhub

Skill Claude CodeCodex

Vet ClawHub skills before installation. Use when the user asks about evaluating, auditing, or safely installing OpenClaw/ClawHub skills, or when a skill’s trustworthiness is in question.

not rated 5 6mo ago A 49 tokens

zey-2/security_skillpacks

Skill Claude CodeCodex

Collect natural-language environment context and generate evidence collection guidance for Mandate 2.2.3 Secure Training and Fine-Tuning. Use when code is insufficient and operational proof is required for final compliance evaluation.

not rated 5 6mo ago A 56 tokens

DorianGallo/hack-skills-local

Skill Claude CodeCodex needs its repo

Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.

not rated 5 3mo ago A 37 tokens copy · 100% MIT

kensho

716

cryptoduke01/kensho

Skill Claude CodeCodex

KENSHO (検証) — industry-grade playbook for offensive Web3 security assessment and responsible disclosure, covering EVM smart contracts / DeFi and Rust/Solana consensus & validator code. Usable by individual researchers, audit teams, and security firms. Invoke when a target is named (project, handle, repo, or website)…

not rated 5 changed 6d ago B 143 tokens

security

717

rekabytes/opencode-skills

Skill Claude CodeCodex

Security patterns, auth approach, and what NOT to do in this codebase.

not rated 5 5mo ago A 17 tokens original MIT

cybersecurity-audit

718

cesschneider/cybersec-audit-skill

Skill Claude CodeCodex

Full-spectrum security audit for any project — SAST, DAST, SCA, secret scanning, IaC security, container hardening, IAM/RBAC review, threat modeling, and API security. Step-by-step investigation with context-gathering questions before scanning. Produces triage findings, autofix patches, and a structured report.

not rated 5 3mo ago C 74 tokens original MIT

quake

719

Rubby2001/quake-skills

Skill Claude CodeCodex

A guide for querying 360 Quake, a Chinese internet asset-mapping service that reports hosts, services, domains, and certificates.

not rated 5 5mo ago D 27 tokens original MIT

kings0527/agent-skills

Skill Claude CodeCodex

Reverse engineering meta-cognitive activation engine. Manages attention allocation, noise suppression, task-mode routing, object typing, hypothesis branching, mental model switching, and analysis boundary judgment at a meta level. Use when performing reverse engineering, binary analysis, malware analysis, obfuscation…

not rated 5 1mo ago A 136 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: