Security skills

16,960 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 484bug-bounty 276agent 229generative-ai 179LangChain 176hacking 175autonomous-pentesting 134cloud-security 121skills 121claude-ai 118redteam 113LLM 108security-audit 105cors-exploitation 88

shield

817

kobepaw/goop-shield-community

Skill Claude Code needs its repo

AI agent guardrails — defends prompts against injection attacks, jailbreaks, and evasion; scans LLM responses for leaked secrets and harmful content. Up to 36 inline defenses (24 default), 3 output scanners, and adaptive ranking. Keywords: shield, guardrails, prompt injection, defense, security, scan.

not rated 3 5mo ago A 67 tokens original Apache-2.0

tailscale-mcp

818

GumbyEnder/mcp-tailscale

Skill Claude CodeCodex

Secure homelab networking with Tailscale + self-hosted Hermes agents via the mcp-tailscale MCP server.

not rated 3 2mo ago B ✓ AI review 29 tokens original MIT

agent-skill-risk-scan

819

doteyeso-ops/mcp-server-vibes-coded

Skill Claude CodeCodex

Use before installing an untrusted SKILL.md, MCP plugin, package script, or agent installer. Buys a deterministic supply-chain risk report for $0.05 USDC through FiatDock.

not rated 3 3d ago A 46 tokens original MIT

hunter

821

GeniusHu-tgty/Hunter

Skill Claude CodeCodex

Use for authorized web/API security assessment, CTF vulnerability research, Hunter health checks, MCP orchestration, local knowledge-base lookup, evidence registration, and report generation. All HTTP tools go through RequestBroker — WAF blocks, captchas, and rate limits never produce false findings.

not rated 3 1mo ago A 58 tokens GPL-3.0

arcjet

822

arcjet/skills

Skill Claude CodeCodex

Add Arcjet security protection to HTTP routes, AI agent tool calls, MCP servers, background jobs, and queue workers. Covers rate limiting, bot detection, email validation, prompt injection, sensitive information blocking (including Rampart NER), content moderation, capture/flush, remote Guard policies, typed inputs…

not rated 3 +1 changed 7d ago A Socket: passSnyk: pass 240 tokens original Apache-2.0

megaeth-labs/skills

Skill Claude CodeCodex

Reviews an existing MOSS wallet integration for security and correctness before launch on MegaETH. Use when auditing partner code rather than building it: produces findings grouped as Critical, Risky defaults, and Recommendations with concrete remediations. Checks for frontend-owned trust decisions, missing backend…

not rated 3 25d ago A 127 tokens

web

824

Shad0wMazt3r/The-Scaffolding

Skill Claude CodeCodex

Execute web-application assessment from setup and recon through injection, access control, auth/session issues, API, and SSRF chains.

not rated 3 22d ago A 28 tokens GPL-3.0

ASK191225/bugbounty-kit

Skill Claude CodeCodex

Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct…

not rated 3 1mo ago A 105 tokens

vibe-security-audit

826

ohong/agent-skills

Skill Claude CodeCodex

Audit and fix security vulnerabilities in "vibe-coded" apps — projects built fast with AI assistance, especially on Supabase, Firebase, or other BaaS backends. Trigger when building, reviewing, debugging, or deploying a web app with a BaaS backend, or when code touches databases, API keys, authentication, environment…

not rated 3 12d ago A 131 tokens original MIT

genai-governance

827

djimit/overheid-plugins

Skill Claude Code

Helpt bij het implementeren van technische governance-controls voor generatieve AI-systemen bij de Nederlandse overheid, conform de EU AI Act (hoog-risico), AVG en BIO2. Biedt model cards (Annex IV), conformiteitsbeoordeling (Art. 43), audit trails (Art. 12), menselijk toezicht (Art. 14), besluitregistratie, model…

not rated 3 +1 1mo ago A 292 tokens EUPL-1.2

burpsuite

828

nguyenthdat/burp-mcp

Skill Claude CodeCodex

Operate an already configured burp-mcp server for authorized web application security testing, penetration testing, vulnerability assessment, and Burp Suite automation: inspect Proxy HTTP/WebSocket history, scope, and site map; craft and replay requests in Repeater; run bounded parallel fuzzing, race condition jobs…

not rated 3 changed 5d ago A 168 tokens original MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Safely monitor ransomware group Tor-hosted data leak sites (DLS) to collect and extract structured victim posting data, track group activity trends over time, and produce sector- and geography-specific ransomware risk assessments. Use when performing threat intelligence gathering on active ransomware groups or…

not rated 3 17d ago A 77 tokens original MIT

cve-to-cme

830

stuwrtlttle/cme

Skill Claude CodeCodex

Map CVE IDs or OSIDB flaw IDs to applicable CME controls. Use when the user provides a CVE ID or flaw identifier and asks about mitigations.

not rated 3 2d ago A 39 tokens

vrchat-mcp

832

BASIC-BIT/vrchat-mcp

Skill Claude CodeCodex

Use when operating VRChat MCP tools, especially auth, privacy-sensitive results, writes, stale cache, or resolving names to IDs.

not rated 2 today A 31 tokens original MIT

guard-x402-payments

833

razel369/intentfence

Skill Codex

Guard an autonomous agent's x402 payment with the live IntentFence service before it signs. Use when an agent receives a PAYMENT-REQUIRED challenge, is about to pay an x402 endpoint, needs to enforce a USDC price ceiling or payee allowlist, or needs signed evidence that an exact Base USDC quote was checked. Also use…

not rated 2 1mo ago A 89 tokens original Apache-2.0

neura-openclaw-core

834

neurarelay/relay-action-card

Skill Claude CodeCodex

Use when an OpenClaw-style or local autonomous computer-use agent needs a single Neura Relay preflight workflow for messages, file changes, browser submits, shell commands, package or publisher changes, workflow state, memory writes, or data exports before execution.

not rated 2 19d ago A 58 tokens original MIT

secrets-management

835

1clawAI/1claw-mcp

Skill Claude CodeCodex

Use when the user asks to "store a secret", "fetch credentials", "rotate an API key", "manage secrets", "set up vault access", or any task involving secure credential storage and retrieval.

not rated 2 yesterday A 0 tokens original MIT

code-review-agent

836

GoodJobwilliam/aicraft

Skill Claude CodeCodex

Comprehensive code review with security, performance, and style analysis for Python, TypeScript, and Go. Detects OWASP Top 10 vulnerabilities, N+1 queries, race conditions, and logic errors before they reach production.

not rated 2 9d ago A 46 tokens original MIT

dimitrilaouanis-tech/onyx-mcp

Skill Claude CodeCodex

Pre-checkout verification for shopping agents. Before transacting with any storefront the user didn't explicitly type, fetch Ed25519-signed merchant facts (domain age, TLS age, brand-lookalike score, price deviation) from the Onyx oracle over x402, verify the signature, and surface the facts to the buyer. Use whenever…

not rated 2 1mo ago A 89 tokens original MIT

aishield

838

lm203688/aishield

Skill Claude CodeCodex

An AI and MCP security scanner aligned with the OWASP MCP Top 10, a list of common risks for tool-connected AI systems. It checks for issues such as prompt injection, command injection, poisoned tools, leaked secrets, unsafe permissions, supply-chain attacks, SSRF, and banned Chinese-language content.

not rated 2 today A 101 tokens original MIT

veriswarm

839

veriswarm/veriswarm-sdk

Skill Claude CodeCodex

Trust scoring, PII protection, and audit for OpenClaw agents. Strips personal data before it reaches the LLM. Blocks dangerous tools. Detects prompt injection. Audits everything.

not rated 2 2d ago A 43 tokens original MIT

network-sink-skill

840

HarperZ9/telos

Skill Claude CodeCodex

Use this synthetic helper to demonstrate a network boundary. The operator may pass an api key to the helper and the helper sends it to a remote endpoint.

not rated 2 yesterday A 0 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: