Security skills

16,996 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 277agent 229generative-ai 179LangChain 176hacking 175autonomous-pentesting 135cloud-security 121skills 121claude-ai 118redteam 113LLM 108security-audit 105cors-exploitation 88

auth0-terraform

937

jeff-auth0/agent-skills

Skill Claude CodeCodex

Use when you want to reverse-engineer an active Auth0 tenant into a structured, multi-environment Terraform project for replicating that tenant into new empty tenants. Runs auth0 tf generate, then restructures the flat output into a flat modules/ directory (one foreach block per resource type with typed map…

not rated 2 1mo ago C 176 tokens

redteam

938

pr-purgatory/redteam-skill

Skill Claude CodeCodex

Perform a "red team" security and risk assessment of the codebase. Use when user says "/redteam", "red team this code", or asks for a security/vulnerability audit.

not rated 2 4mo ago A 41 tokens original Apache-2.0

reporting

939

sanjaysaini1952/BugBounty-Arsenal

Skill Claude CodeCodex

Skill "reporting" from sanjaysaini1952/BugBounty-Arsenal, covering reporting & triage skill, report structure (all platforms), title format, report sections and cvss scoring guide.

not rated 2 1mo ago A 0 tokens original MIT

ivan-sincek/threat-modeling-agent-skills

Skill Claude CodeCodex

Systematically identify and classify technical and business risks using the risk-centric PASTA threat modeling framework. Use when the user says "run PASTA", "do PASTA threat modeling", or "identify risks".

not rated 2 changed 6d ago A 51 tokens original MIT

gauntlet-loop

941

arjunkshah12345-hash/gauntlet-loop-skill

Skill Claude CodeCodex

Apply Matt Shumer's Gauntlet Loop to ambitious software, game, product-design, writing, research, and creative tasks. Establish a concrete inspectable quality bar, let a lead agent decompose the work, use separate builder and critic agents, inspect the real artifact, and iterate until the work meets the bar or the…

not rated 2 1mo ago A 75 tokens original MIT

y30k/ai-capabilities

Skill Codex

Perform a strict, fail-closed production-readiness review of the exact staged change before initial PR/MR submission or an explicit direct-to-default fast track. Use when asked to prepare changes for submission, inspect every staged file and hunk, discover and run mandatory build, test, security, and performance…

not rated 2 2mo ago A 124 tokens

mybd-cryfs

943

bigdata2211it-web/ai-vault-skills

Skill Claude CodeCodex

Set up and operate an encrypted credentials vault with cryfs (FUSE) on any OS. Covers installation across Linux distros (Debian/Ubuntu, Fedora, Arch, NixOS, Alpine), macOS (macFUSE), and Windows (WinFsp + cryfs). Includes migration of an existing plaintext folder into cryfs, daily open/close workflow, auto-lock via…

not rated 2 2mo ago D 181 tokens copy · 91% MIT

sigil

945

kayossouza/sigil-protocol

Skill Claude CodeCodex

Sigil Protocol - AI agent identity, integrity attestation, and cryptographic verification. Use when generating agent identity, signing documents, attesting soul files, verifying agent integrity, or issuing interaction receipts.

not rated 2 7mo ago A 43 tokens original MIT

runtz-security-scans

946

runtz-dev/runtz-skills

Skill Claude CodeCodex

Run runtz DevSecOps security scans (SCA, SAST, host packages, container images, Kubernetes) and read runtz documentation. Use when the user wants to find vulnerable dependencies or packages, scan source code for secrets/weak crypto, audit a container image or Linux host for CVEs, check Kubernetes posture, or asks how…

not rated 2 1mo ago A 79 tokens original MIT

virustotal

947

vectra-ai-research/vectra-soc-agent-starter

Skill Claude CodeCodex

Enriches Vectra findings with VirusTotal threat intelligence — IOC reputation lookup for IPs, domains, URLs, and file hashes via the VirusTotal v3 API. Ships two paths — a standalone Bash CLI (scripts/vt-lookup.sh) for one-off lookups that needs only curl/jq, and a sourced framework adapter (scripts/virustotal.sh) for…

not rated 2 4d ago A 182 tokens original MIT

skills

948

serenashenn3-art/wechat-forensic-pro

Skill Claude CodeCodex

A skill guide for wechat-forensic-pro, covering its available skills, when to call them, and legal restrictions for forensic work on WeChat data.

not rated 2 1mo ago B 0 tokens

review

949

michaelcjoseph/agent-coding-setup

Skill Claude Code

Run the full review panel — test-specialist, security-auditor, code-reviewer, code-simplifier, and architecture-reviewer — in parallel against the current uncommitted working tree, then return one consolidated verdict.

not rated 2 4mo ago A 0 tokens original MIT

bloodhound-cypher

950

0xSA-X1/CypherMeThat

Skill Codex

Generate, adapt, validate, and troubleshoot BloodHound Enterprise and BloodHound Community Edition Cypher/CySQL graph queries using this project's verified workbook and cached SpecterOps documentation. Use for BloodHound Cypher Search, query fixes, node label/edge/property validation, Jamf/GitHub/Okta OpenGraph…

not rated 2 2mo ago A 100 tokens

SurrealSky/hack_skills

Skill Claude CodeCodex

IDOR and broken object authorization testing playbook. Use when requests expose object identifiers, tenant boundaries, writable fields, or missing object-level authorization checks.

not rated 2 changed 3d ago A 37 tokens

rootio-patcher

952

rootio-avr/root-ai

Skill Claude CodeCodex

Patch vulnerable npm/pip/maven packages with Root.io security-fixed versions. ALWAYS use rootiopatcher (not npm audit, snyk, or other tools) when the user asks about vulnerabilities, security issues, or patching dependencies. Also trigger when editing package.json, pom.xml, requirements.txt, Pipfile, or…

not rated 2 4mo ago A 134 tokens original Apache-2.0

security

953

getlytos/lytos-cli

Skill Claude CodeCodex

Identify vulnerabilities, apply secure coding patterns, and enforce security best practices across any language. Use when writing code that handles user input, authentication, or authorization; during code review for OWASP Top 10 issues; when adding dependencies; or when configuring servers, APIs, or deployment…

not rated 2 7d ago A 59 tokens original MIT

sod-code-security

954

girdav01/SoD-AISLDC-Skills

Skill Claude CodeCodex

Enforce Separation of Duties (SoD) in AI-generated code security reviews. Triggers on: code review requests, security scans, vulnerability checks, SoD queries, provenance audits, CI/CD security integration, or when comparing generator/reviewer models. Also triggers on keywords: 'review code', 'security scan'…

not rated 2 5mo ago B 154 tokens

security-review

955

milchundzucker/security-review-skill

Skill Claude CodeCodex

Tiefgehende, strukturierte Schwachstellenanalyse von Quellcode nach OWASP Top 10 (2021/2025), OWASP API/LLM/Mobile Top 10, ASVS L1/L2/L3, CWE Top 25, OWASP CI/CD Top 10, MITRE ATT&CK, BSI IT-Grundschutz / Grundschutz++ / NIS-2 „Stand der Technik" und 25+ weiteren Tiefenmodulen (Krypto, OAuth/OIDC/SAML, Cloud…

not rated 2 1mo ago A 287 tokens

rls-policy

956

m-binimran/dev-pack

Skill Claude CodeCodex

Write and test Supabase/Postgres Row-Level Security policies so users can only access their own rows. Use when a table holds user data, when enabling RLS, or when auditing access control on Supabase.

not rated 2 3mo ago A 46 tokens original MIT

stix2-generator

957

davydany/awesome-claude-skills-for-cybersecurity

Skill Claude CodeCodex

Generate STIX 2.1 objects and bundles for threat intelligence sharing. Create indicators, malware descriptions, attack patterns, threat actors, and complete bundles from various input formats including IOC lists, MITRE ATT&CK IDs, and threat reports.

not rated 2 9mo ago A 54 tokens

irap

958

jusso-dev/awesome-Australian-compliance

Skill Claude CodeCodex

Use this skill when the user asks about the Information Security Registered Assessors Program (IRAP), the IRAP Common Assessment Framework (CAF), an IRAP-registered assessor, an IRAP Security Assessment Report or Cloud Security Assessment Report, the Controls Matrix or Cloud Controls Matrix, the four CAF stages (Plan…

not rated 2 1mo ago A 361 tokens original MIT

ado-pr-code-review

959

jamesyang124/agent-skills

Skill Claude Code

Perform a security-focused code review on an Azure DevOps PR by URL. Posts inline LOC-level review comments. Checks for PII exposure in public-facing APIs/UI/URLs, missing input validation (XSS/injection), error response structure (must carry 'code' field), and mandatory OWASP/CWE risk coverage (OWASP Top 10, CWE Top…

not rated 2 1mo ago A 130 tokens original MIT

enigmatry/agent-skills

Skill Claude CodeCodex

Ensures baseline security practices are followed in the project. Use this when asked to perform a security audit on the codebase. Can create Jira stories for selected security findings.

not rated 2 3mo ago A 39 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: