Security skills

18,827 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 368bug-bounty 226autonomous-pentesting 140openclaw 113claude-ai 83cloud-security 65aws 64ai-security 59redteam 59generative-ai 57ctf 56LangChain 53hacking 53penetration-testing 53

detection-signals

74

LinXiaoTao/FuckClaude

Skill Claude CodeCodex

A set of rules for detecting signals that may suggest a browser user is in China. It scans browser information locally and also reuses scoring functions in a server endpoint called /api/check.

not rated 921 yesterday A 69 tokens original MIT

laravel-brain

75

laramint/laravel-brain

Skill Claude CodeCodex

Analyze a Laravel application for complexity hotspots, security surface, and database access patterns using laravel-brain. Activate when: the user asks what needs work, what should be improved, what to work on next, where to focus, what is the most complex code, what are the security issues, audit the codebase…

not rated 895 4d ago A 118 tokens

tophant-ai/aibeat

Skill Claude CodeCodex

Use when a user needs help choosing Promptbeat attack goals, risk types, scenarios, seed files, dataset subscriptions, compliance profiles, or a small smoke-test scope.

not rated 877 +1 11d ago A 39 tokens

code-audit

77

3stoneBrother/code-audit

Skill Claude CodeCodex

Professional code security audit skill covering 55+ vulnerability types. Enhanced with WooYun 88,636 real-world vulnerability cases (2010-2016). This skill should be used when performing security audits, vulnerability scanning, penetration testing preparation, or code review for security issues. Supports 9 languages…

not rated 877 +2 6mo ago A 193 tokens

npm-security

78

bodadotsh/npm-security-best-practices

Skill Claude CodeCodex

Prevent JavaScript/TypeScript projects from supply-chain attacks across package managers like npm, pnpm, yarn, bun, and deno. Use whenever planning, installing, updating packages or configuring package managers.

not rated 856 11d ago A 43 tokens original MIT

mantis-reproduce

79

google/mantis

Skill Claude CodeCodex ✓ vendor

Generates and runs crash reproducers to verify security flaws. Use when viable findings exist and you need to write and execute a script or payload to verify the crash. Don't use for code auditing or patching.

not rated 905 +72 yesterday A 47 tokens original Apache-2.0

secure-software

80

suleimanodetoro/skills

Skill Claude CodeCodex

Threat-model, design, implement, and verify security controls in web, API, backend, React, and React Native software. Use when building authentication, session management, authorization, sensitive-data handling, secrets, cryptography integration, input validation, file upload, outbound requests, audit logging, error…

not rated 840 +60 1mo ago A 155 tokens original MIT

code-review

81

llama-farm/llamafarm

Skill Claude CodeCodex

Comprehensive code review for diffs. Analyzes changed code for security vulnerabilities, anti-patterns, and quality issues. Auto-detects domain (frontend/backend) from file paths.

not rated 837 2mo ago A 41 tokens original Apache-2.0

prose-skill

83

luckyPipewrench/pipelock

Skill Claude CodeCodex

Prose mentions that must not produce combination findings.

not rated 832 yesterday A 15 tokens original Apache-2.0

api-relay-audit

84

toby-bridges/api-relay-audit

Skill Claude CodeCodex

OpenClaw skill for local API Relay Audit. Use when an OpenClaw agent must audit a third-party AI API relay, LLM proxy, gateway, or resale API before trusting coding, tool, production, or wallet-sensitive traffic.

not rated 823 +2 6d ago A 54 tokens AGPL-3.0

analyze

85

H-mmer/pentest-agents

Skill Claude CodeCodex

Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze.

not rated 815 +2 2mo ago A 25 tokens

fastapi-guard

86

rennf93/fastapi-guard

Skill Claude CodeCodex

Production-ready security middleware for FastAPI. Use when adding IP filtering, rate limiting, per-route security decorators, route-resolution strict mode, global behavior rules, passive/log-only mode, or Guard Agent SaaS telemetry to a FastAPI app. Covers SecurityMiddleware setup, SecurityConfig tuning, and the…

not rated 813 yesterday A 72 tokens original MIT

claude-authenticity

87

agentscope-ai/OpenJudge

Skill Claude CodeCodex

Detect whether an API endpoint is backed by genuine Claude (not a wrapper, proxy, or impersonator) using 9 weighted rule-based checks that mirror the claude-verify project. Also extracts injected system prompts from providers that override Claude's identity. Fully self-contained — copy the code below and run, no extra…

not rated 811 +2 1mo ago A 121 tokens original Apache-2.0

irsdl/webhacklist

Skill Claude CodeCodex

Reviews and repairs references already published in the Top 10 Web Hacking Techniques Markdown-and-PDF archive. Use for one article, one collection such as 2019 or YYYY-ai, or a bounded period when asked to audit, validate, verify, QA, sanity-check or proofread archived references; investigate wrong-page captures…

not rated 807 +2 2d ago A 242 tokens

fix-ticket

89

hoophq/hoop

Skill Claude CodeCodex

Implement a Linear ticket end-to-end - fetch context, branch, code, tests, draft PR, update the ticket. Use when given a ticket ID like EVL-86 or DEP-123.

not rated 806 yesterday A 43 tokens original MIT

CTF•密码学

90

asdfgh1445/ctf-super-hub

Skill Claude CodeCodex

A cryptography skill for solving capture-the-flag challenges, which are security puzzles that require finding and exploiting weaknesses. It covers algorithms, attacks, mathematical techniques, and zero-knowledge proofs.

not rated 795 +3 4mo ago A 72 tokens

security-patcher

91

gemini-cli-extensions/security

Skill Claude CodeCodex

Invoke this as your absolute first action before using any other tools whenever a user requests to fix, patch, or remediate a vulnerability. Do not perform manual research first.

not rated 791 +1 1mo ago A 38 tokens original Apache-2.0

code-review

93

juicesharp/rpiv-mono

Skill Claude CodeCodex

Conduct comprehensive code reviews of pending changes, a branch, or a PR using parallel specialist agents that audit the diff, compare against peer code, and verify claims. Use when the user asks to 'review this', wants pending changes, a PR, a branch, or a diff reviewed, or asks for a code review. Produces review…

not rated 736 2d ago A 100 tokens original MIT

auditing-skills

94

dbt-labs/dbt-agent-skills

Skill Claude CodeCodex

Use when checking skills for security or quality issues, reviewing audit results from skills.sh or Tessl, or remediating findings across published skills.

not rated 699 yesterday B 34 tokens original Apache-2.0

arcjet/arcjet-js

Skill Claude CodeCodex

Integrate Arcjet security into a Claude Agent SDK agent using @arcjet/guard — wrap tool() handlers, screen inbound prompts with UserPromptSubmit, and deny unwrapped built-in/MCP tools with PreToolUse. Use when asked to add Arcjet to a Claude Agent SDK or Claude Code agent, rate limit its tools, screen inbound…

not rated 681 5d ago A 92 tokens original Apache-2.0

vz-risk/VCDB

Skill Claude CodeCodex

Encode a GitHub issue describing a data breach into a VERIS-schema JSON incident for VCDB. Invoke with a vz-risk/VCDB issue URL (e.g. https://github.com/vz-risk/VCDB/issues/23372) and an optional analyst GitHub handle. Reads the issue and its linked sources, finds an additional independent source via web search, maps…

not rated 669 1mo ago A 106 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: