Security skills

16,964 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 490bug-bounty 284agent 228generative-ai 179LangChain 176hacking 175autonomous-pentesting 139cloud-security 123skills 121claude-ai 118redteam 115LLM 107security-audit 106cors-exploitation 90

code-review

745

liubf21/ds-forge

Skill Claude Code

Review code changes for security, performance, and style issues.

not rated 4 +1 1mo ago A 15 tokens original MIT

ekyc-suite

746

wefi-ai/eKYC-Suite

Skill Claude CodeCodex

Skill "ekyc-suite" from wefi-ai/eKYC-Suite, covering ekyc suite, what is ekyc suite?, quick reference, external endpoints and security & privacy.

not rated 4 1mo ago A 694 tokens original MIT

security-triage

747

flytohub/flyto-indexer

Skill Claude CodeCodex

Turn a large codebase into a short, ranked reading list of security-relevant code paths worth a human researcher's time, using the flyto-indexer MCP tools. Use when asked to find, prioritize, or triage potential vulnerabilities / taint flows / attack surface in a repository indexed (or indexable) by flyto-indexer …

not rated 4 3d ago A 105 tokens original Apache-2.0

ComplyEdge/complyedge

Skill Claude CodeCodex

Runtime deny for EU AI Act Article 5 and Article 50 on this prompt or output via ComplyEdge TrustLint MCP. Use when the user wants agent I/O compliance enforcement, not system classification, FRIA forms, or C2PA watermarking.

not rated 4 changed 8d ago A 63 tokens original Apache-2.0

levelsofself/mcp-nervous-system

Skill Claude CodeCodex

Use this skill when building, managing, or auditing multi-agent AI systems. Provides governance patterns for behavioral enforcement, drift detection, audit trails, role management, and accountability across autonomous AI agents. Compatible with any orchestration framework.

not rated 4 1mo ago A 51 tokens original MIT

secure-code-auditor

751

n-shadloo/secure-code-auditor

Skill Claude Code

Backend security auditor for Django and DRF on an OWASP Top 10 (2025), API Security Top 10 (2023), and ASVS 5.0 foundation. Use when backend code is written or reviewed and touches authentication, sessions, cookies, JWT, OAuth2/OIDC, API keys, password hashing, permissions, access control, IDOR, SSRF, path traversal…

not rated 4 changed 7d ago B 259 tokens original MIT

should-i-care

752

moltenbit/should-i-care

Skill Claude CodeCodex

Single-CVE applicability triage that evaluates whether a CVE actually applies to the user's environment by reasoning about discriminating conditions against a skill-maintained environment profile; triggers when a user asks whether they are affected by a CVE, whether a CVE applies to them, or wants to assess a CVE…

not rated 4 3mo ago A 69 tokens original MIT

astro-security

753

roodlicht/accans-sec-skills

Skill Claude CodeCodex

Astro security review — render-mode attack surface (SSG/SSR/hybrid), set:html and MDX content collections (XSS + author trust), API routes and middleware (auth, scope), adapter-specific runtime models (Cloudflare/Vercel/Netlify/Node), env-var hygiene (PUBLIC prefix), and Decap CMS pairing (OAuth backend, token…

not rated 4 3mo ago A 85 tokens

ctf-pwn

754

MateoBogo/CLEAVE

Skill Claude Code

Binary exploitation (pwn): stack/heap/format-string/ROP, glibc heap (House-of-, leakless, FSOP/FSOPAgain), seccomp bypass, sandbox escape, Linux & Windows kernel exploitation (KASLR/SMEP/SMAP, token steal, cred swap, PreviousMode), BROP. Dispatch on binary/checksec signals.

not rated 4 3mo ago A 0 tokens

clerk

755

wrsmith108/clerk-claude-skill

Skill Claude CodeCodex

Clerk authentication integration for Astro/Next.js. Use when implementing authentication, handling Clerk middleware, testing with Playwright, or debugging auth issues. Trigger phrases include "Clerk auth", "sign in", "authentication", "middleware", "E2E testing with Clerk".

not rated 4 8mo ago A 58 tokens original MIT

omv-find

756

bx33661/oh-my-vul

Skill Claude CodeCodex

Finds and ranks open-source packages worth auditing for passive CVE/VulDB research. Use when the user asks for vulnerability research targets, CVE hunting candidates, packages to audit, projects to fuzz, or /omv-find. Supports npm, Python, Go, Rust, Java, Ruby, PHP, C#, Swift, Dart, Elixir, Perl, R, and Lua, with…

not rated 4 23d ago A 122 tokens original MIT

skill-governance

758

matt-bat/agent-command-center

Skill Claude CodeCodex

Govern release-affecting, policy-changing, externally mutating, destructive, or otherwise high-risk work through typed effects, mandatory evidence, independent safety gates, and an explicit go/no-go decision. Do not use for ordinary answers, read-only inspection, tiny reversible edits, or a task made "multi-skill"…

not rated 4 19d ago A 74 tokens

token-antiflash

759

0xlayerghost/solidity-agent-kit

Skill Claude CodeCodex

When this skill is triggered, DO NOT directly implement all strategies. Follow this workflow.

not rated 4 1mo ago A 91 tokens original MIT

audit-this-project

760

Mun1to/Vibeset

Skill Claude Code

Run an independent security audit of this repository before trusting it. Use when the user asks whether this project is safe, what it sends over the network, what it does to their computer, whether it is malware or spyware, or asks for a security review of this codebase.

not rated 4 11d ago A 59 tokens copy · 100% MIT

aislop

761

scanaislop/skills

Skill Claude CodeCodex

Code-quality gate and coding guardrail for AI coding agents. Always invoke when you finish editing and prepare to hand control back, even if the user did not explicitly ask. Trigger on commit, push, PR, or quality questions like any slop, is this clean, review my changes, score my code, any duplicates, or is this…

not rated 4 13d ago B 99 tokens original MIT

drata-cli-workflow

762

ethanolivertroy/drata-cli

Skill Claude CodeCodex

Use when querying or changing Drata/GRC data through the drata CLI, including compliance status, frameworks, certificates, Trust Center documents, controls, monitoring tests, evidence, risks, vendors, policies, personnel compliance, and background-check questions. Prefer versionless CLI commands, JSON output…

not rated 4 4mo ago A 83 tokens original MIT

code-reviewer

763

osouthgate/agent-plus

Skill Claude Code

Reviews code for quality, bugs, security, and best practices. Use when changing code or before merge. Checks security, authentication, and validation; ensures new code follows project rules and conventions.

not rated 4 2mo ago A 42 tokens original MIT

ch015-feedback

764

ch015/code-pentester

Skill Claude CodeCodex

Run CH015 security design review workflows for PRDs and specs to produce security opinions or review findings mapped to standards and regulatory requirements.

not rated 4 changed 2d ago A 30 tokens original MIT

planning

765

Roshu18/bearstrike-ai

Skill Claude CodeCodex

Pre-execution planning and priority-scored task list before running tools.

not rated 4 5mo ago A 16 tokens original MIT

skillsafe-scanner

766

adamoutler/joplin-server-vector-memory

Skill Claude CodeCodex

Run the skillsafe scan on the adamoutler/joplin-server-vector-memory package, then operate and improve/complete all issues identified. Use this when asked to scan or fix skillsafe issues.

not rated 4 3mo ago A 45 tokens

mcpvessel

767

okedeji/mcpvessel

Skill Claude CodeCodex

Cage, run, and audit MCP servers with mcpvessel: install an MCP server into an isolated container, serve it to Claude Code, and watch what it does with the network and the user's secrets. Use this whenever the user mentions mcpvessel by name, or wants to add, install, set up, try, run, or sandbox an MCP server, or…

not rated 4 1mo ago A 152 tokens original Apache-2.0

nsauditor-ai

768

nsasoft/nsauditor-ai-agent-skill

Skill Claude CodeCodex

Use this skill whenever the user wants network security scanning, auditing, vulnerability assessment, host reconnaissance, or cloud-account security/compliance auditing with NSAuditor AI (via the nsauditor-ai MCP server: scanhost, scancloud, getfindings, probeservice, getvulnerabilities, listplugins). Triggers include…

not rated 4 changed 2d ago B 248 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: