Security skills

16,960 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 484bug-bounty 276agent 229generative-ai 179LangChain 176hacking 175autonomous-pentesting 134cloud-security 121skills 121claude-ai 118redteam 113LLM 108security-audit 105cors-exploitation 88

Cybercentry/verification-mcp

Skill Claude CodeCodex

Verify wallets, tokens, smart contracts, AI agents and web applications before trusting them, paying per call in USDC over x402.

not rated 2 20d ago A 33 tokens original MIT

lint-drupal-module

842

j4rk0r/claude-skills

Skill Claude Code

Lint review completo de un módulo Drupal 11 combinando 4 fuentes en paralelo — PHPStan level 5 + phpstan-drupal, PHPCS Drupal/DrupalPractice, agente drupal-qa (estándares) y agente drupal-security (OWASP). Dos modos — completo (todo el módulo) y diff (solo archivos cambiados vs develop). Genera informe markdown…

not rated 2 1mo ago A 225 tokens original MIT

red-button

843

Lum1104/red-button

Skill Claude CodeCodex

Use when an action could cause material, hard-to-reverse harm to production, data, security, finances, users, or external systems.

not rated 2 1mo ago A 31 tokens original MIT

code-audit

844

Rootx202/appsec-skills

Skill Claude CodeCodex

Elite full-codebase security auditor for any language or stack (JavaScript, TypeScript, Python, Java, Kotlin, PHP, Go, Rust, C/C++, Ruby, C#). Trigger this whenever the user asks to review, audit, scan, harden, or "check the security" of any project, before deploying/shipping/launching a site or app, after adding…

not rated 2 2mo ago A 144 tokens

canadian-grc

845

squizzle23/canadian-grc-skill

Skill Claude CodeCodex

Expert Canadian GRC and cyber law advisor covering OSFI B-10/B-13/E-21/I-CRT, FSRA, AMF/Loi 25, BCFSA, CIRO, AER Reg 84/CSA Z246.1, PIPEDA, PHIPA, PIPA BC, PIPA AB, Bill C-26, and AIDA. Use this skill whenever the user mentions any Canadian financial regulator, provincial privacy law, Alberta energy security, Canadian…

not rated 2 4mo ago A 195 tokens

Aidress-ai/aidress-skill-find-verified-code-generation-agent

Skill Claude CodeCodex

Find a Verified Code Generation Agent. Agent discovery, trust verification, and capability routing powered by Aidress — the coordination registry for autonomous AI agents. Use for software agent discovery, trust verification, and capability routing — via Aidress (https://api.aidress.ai).

not rated 2 2mo ago A 61 tokens original MIT

softwareasg-tools/information-security-for-vibecoded-apps

Skill Claude CodeCodex

Autonomous security auditor for AI-generated applications. Provide a codebase path and it will automatically detect the stack, execute a comprehensive 12-phase security scan, identify vulnerabilities, and provide a production decision.

not rated 2 changed 8d ago A 50 tokens original MIT

TanKimGwan/linmas

Skill Codex

Secure code review skill for application risk analysis, threat modeling, scanner tuning, and developer-focused remediation guidance.

not rated 2 8d ago A 29 tokens

public-release

849

eddmann/agent-toolkit

Skill Claude Code

Comprehensive pre-release audit for making a GitHub repository public.

not rated 2 4mo ago A 15 tokens

citedy/skills

Skill Claude Code

Parallel multi-agent code review using Agent Teams with 4 specialized reviewers. Spawns a coordinated team of security, performance, test coverage, and code quality agents. Teammates can share findings with each other for cross-domain insights. Produces unified report with severity-ranked findings saved to /output/.…

not rated 2 3mo ago A 204 tokens original MIT

vuln-research

851

Lu1sDV/skillsmd

Skill Claude CodeCodex

Use when performing vulnerability research, security auditing, code analysis, bug bounty hunting, CTF challenges, penetration testing, or exploit development. Covers source audit across 30+ attack domains, sink analysis for 12 languages, SAST/DAST integration, vulnerability chaining, and proof-of-concept development.…

not rated 2 yesterday A 179 tokens

virustotal-api

852

w33ts/virustotal-api-skill

Skill Claude CodeCodex

Comprehensive reference for the VirusTotal API v3, covering authentication, rate limits, endpoint usage, and the critical differences between Free (Public) and Premium (Enterprise) tiers. Use this skill whenever a user asks about VirusTotal, VT API, scanning files or URLs with VirusTotal, threat intelligence lookups…

not rated 2 6mo ago B 170 tokens original MIT

saas-preflight

853

Comoco235/saas-preflight

Skill Claude CodeCodex

Audit a vibe-coded or AI-generated SaaS for security and payment failures before it ships, focused on the Next.js + Supabase + Stripe stack. Use this whenever the user is about to deploy, launch, or "ship" a web app that handles authentication, user data, or payments. Trigger on phrases like "is my app secure", "can…

not rated 2 1mo ago A 173 tokens original MIT

securing-code

854

codeverbojan/claude-code-kickstart

Skill Claude Code

Enforces secure coding patterns for API routes, auth, input handling, and database queries. Triggered when writing server-side code, handling user input, or adding dependencies.

not rated 2 5mo ago A 39 tokens original MIT

security

855

edenfunf/promptc

Skill Claude Code

Project-wide security rules for handling untrusted input, secrets, and database access.

not rated 2 4mo ago A 18 tokens original MIT

db-supervisor

856

CarolMonroe22/supabase-db-supervisor

Skill Claude CodeCodex

Fresh-eyes supervision pass for any database work an AI agent just built (schema, RLS policies, migrations, edge functions touching the database, storage policies). The builder never grades its own homework - a separate agent plays the "Investigate" role, proves who-can-see-what with real queries, and gives an…

not rated 2 1mo ago A 101 tokens original MIT

mainframe-secrets

857

CATWILLgh/MAINFRAME

Skill Codex

Locate, register, update, deliver, or return credentials through the centralized MAINFRAME index and installed secret mechanism. Use proactively when authentication is needed, a credential is supplied or requested, registration or removal is requested, or a command, service, deployment, HTTP request, SSH connection…

not rated 2 changed 4d ago A 80 tokens original MIT

mariana-audit

858

ibaifernandez/mariana-audit

Skill Claude CodeCodex

Full-depth audit (a11y, UX, perf, SEO, security, DB, architecture, legal compliance, ops, observability) of a project. Audits by reading the source directly — installs nothing, writes nothing outside docs/audits/. Reports findings with file:line evidence and calibrated severity, optionally mitigates as discovered. Use…

not rated 2 27d ago A 111 tokens original MIT

reverse-engineer

859

mrigankad/SRE-CLI

Skill Claude CodeCodex

Authorized software reverse engineering, binary analysis, and program comprehension for legitimate purposes including security review, interoperability, migration, modernization, debugging, and documentation. USE WHEN: user needs to analyze software they own or have explicit authorization to inspect, including legacy…

not rated 2 5mo ago A 137 tokens

site-risk-check

860

kobimantzur/agent-skills

Skill Claude CodeCodex

Checks whether a website is legally covered against the complaints and demand letters sites actually receive: trackers and session recording running without consent, missing privacy or cookie policies, accessibility gaps. Detects the business profile and which countries it sells to, then shows exposure only for the…

not rated 2 2d ago B 0 tokens original MIT

report-writing

861

Mikacr1138/claude-bug-bounty

Skill Claude CodeCodex

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use…

not rated 2 yesterday A 82 tokens original MIT

secagent-knowledge

862

JesusConwellpy/secagent-skills

Skill Claude CodeCodex needs its repo

Local LLM-Wiki knowledge system. Bootstrap a structured wiki, write entries using precise templates, full-text search, cross-agent knowledge sharing, cross-session inheritance.

not rated 2 3mo ago A 37 tokens original MIT

saas-cybersecurity

863

YankielDBC2/saas-cybersecurity

Skill Claude CodeCodex

Audit and safely harden authorized SaaS web applications across frameworks and hosting providers. Use for OWASP-aligned reviews, runtime browser checks, HTTP headers, XSS/CSRF, access control, secrets, payments, uploads, privacy, abuse controls, supply-chain risk, link injection, or security remediation; do not use…

not rated 2 14d ago A 86 tokens original MIT

enil-ling-pesing

864

enilmalus/Enil-ling-pesing

Skill Claude Code

A Chinese-language guide for authorized penetration testing and security research. Penetration testing is controlled testing used to find security weaknesses in software or systems.

not rated 2 changed yesterday A 160 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: