Security skills

16,890 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 277agent 229generative-ai 179LangChain 176hacking 175autonomous-pentesting 135cloud-security 121skills 121claude-ai 118redteam 113LLM 108security-audit 105cors-exploitation 88

m2m-sentinel

985

M2M-Sentinel/m2m-sentinel-sdk

Skill Claude CodeCodex

Deterministic EVM bytecode capability observations, EIP-1967 proxy resolution, gas recommendations, and sourced telemetry for autonomous applications on Base (Chain ID 8453).

not rated 2 +1 5d ago A 42 tokens original MIT

security-review

986

95gabor/agentic-workflow

Skill Claude CodeCodex

Security review checklist: auth, secrets, API boundaries, data handling, and infra. Use with security-reviewer subagent after architect (design) and after QA pass (implementation).

not rated 2 1mo ago A 39 tokens

reverse-skill-router

987

Asaiuta/reverse-workbench-skill

Skill Codex

Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.

not rated 2 29d ago A 51 tokens original MIT

mcpkernel-security

988

piyushptiwari1/mcpkernel

Skill Claude CodeCodex

AI agent security gateway — policy enforcement, taint tracking, tool poisoning detection, DLP chain analysis, and SARIF output for CI/CD.

not rated 2 2mo ago A 34 tokens original Apache-2.0

security-recon

989

ewwhardik/nirikshak

Skill Claude CodeCodex

Use when the user wants a security/exposure check on a domain or website they own or are authorized to test — "audit my site", "what's my attack surface look like", "did anything change on my domain", etc. Drives the nirikshak MCP tools (fullsurfacescan, and the individual checks) and turns raw output into a…

not rated 2 1mo ago A 97 tokens original MIT

anti-tampering

990

almasumdev/awesome-mobile-security-agent-skills

Skill Claude CodeCodex

Anti-tampering on mobile — signature checks, runtime application self-protection (RASP), and realistic return on investment. Use to decide which integrity controls are worth shipping.

not rated 2 4mo ago A 40 tokens

gcp-iam

991

TrevorEdris/fellowship-of-the-workflows

Skill Claude Code

Audit and configure GCP IAM: roles/bindings, service accounts, Workload Identity Federation, Secret Manager, KMS (CMEK), and VPC Service Controls. Use when setting up least-privilege access, rotating secrets, or hardening GCP security posture.

not rated 2 2mo ago A 62 tokens

zitadel-api

993

Aidas-dev/k8s-agent-skills

Skill Claude CodeCodex

ZITADEL identity management platform (v4 GA, v2 API). Covers resource-based API for managing organizations, projects, applications (OIDC/SAML/API), roles, users, and OIDC settings via Connect RPC (HTTP/1.1 JSON) and REST endpoints. PAT or JWT assertion auth.

not rated 2 29d ago A 66 tokens original MIT

add-permission

994

alexmmatos/arthur-mcp

Skill Claude Code

Add or reuse a permission end-to-end (backend + frontend) for a new page, tab, endpoint, or protected action in Arthur MCP. Use whenever a feature introduces a new user-facing surface or protected action that needs a permission decision.

not rated 2 1mo ago A 52 tokens original MIT

cordon-install

995

ilyautov/cordon

Skill Claude Code

Install Cordon, a deterministic layer between untrusted content and agent actions, and verify that the harness actually calls it. Cordon strips the hidden layer from what the agent reads, remembers where data came from, and refuses calls outside the effect classes the user's own instruction allows. No model call on…

not rated 2 +1 yesterday A 156 tokens original MIT

agentaegis-security

996

astafford8488/agentaegis-mcp

Skill Claude Code

Run real security scans through the AgentAegis MCP server — vet an endpoint or third-party agent code before trusting it, look up CVEs and IP/domain reputation, scan a repo for vulnerabilities, secrets and vulnerable dependencies, audit DNS/TLS/email posture, or assess compliance readiness. Use when the user asks…

not rated 1 1mo ago A 108 tokens original MIT

phylax-skill-audit

997

usephylax/phylax-skill-audit

Skill Claude CodeCodex

Pre-install security audit for agent skills on Base. Scans SKILL.md + manifest for prompt-injection and secret-exfiltration, audits referenced contracts (unlimited approvals, upgradeable owner, honeypot), and validates x402 endpoints. Returns a deterministic risk verdict (ALLOW/WARN/DENY) with evidence. Read-only…

not rated 1 +1 2mo ago A 82 tokens original MIT

core

998

coelhobugado/antigravity-browser-bridge

Skill Claude Code

Core agent-browser usage guide. Read this before running any agent-browser commands. Covers the snapshot-and-ref workflow, navigating pages, interacting with elements (click, fill, type, select), extracting text and data, taking screenshots, managing tabs, handling forms and auth, waiting for content, running multiple…

not rated 1 1mo ago B 112 tokens copy · 78% Apache-2.0

palisadescan/palisade

Skill Claude CodeCodex

Onchain security scanner on Robinhood Chain — scan token approvals, detect honeypots, analyze contracts for rugpull indicators, check liquidity locks, and score contract safety. Use when a user asks an agent to evaluate, scan, or check a token or wallet before trading, swapping, signing an approval, or investing. 18…

not rated 1 1mo ago A 97 tokens original MIT

fossa-protect

1000

darthzen/fossa-mcp

Skill Claude CodeCodex

Turn a project's FOSSA findings into NeuVector runtime controls and push them to the cluster. Two tracks — vulnerability findings become WAF sensors (regex-matched request inspection); license-conflict findings become a workload quarantine (network isolation / deploy hold). Use when asked to mitigate, compensate for…

not rated 1 1mo ago A 151 tokens original Apache-2.0

guardian-check

1001

rudimentall1/agentic-wallet-guardian-v3

Skill Claude CodeCodex

Use before executing any MetaMask Agent Wallet (mm CLI) command that moves funds or changes on-chain state — mm send, mm swap, mm bridge, mm perps open/modify/close, mm predict trade, mm earn supply/withdraw, mm aave borrow/repay, mm pay. Sends the proposed action to a self-hosted Agentic Wallet Guardian instance for…

not rated 1 13d ago A 121 tokens original MIT

agentfence

1002

ANAMIZED/OpenMesha

Skill Claude CodeCodex

Apply OpenMesha two-layer AgentFence (ingest scan + act gate) and HOTL escalation. Use when reviewing untrusted tool output, inbound messages, or irreversible/money-moving actions.

not rated 1 16d ago A 43 tokens

pentagonal-clawd

1003

Pentagonal-ai/pentagonal

Skill Claude CodeCodex

Use when the user asks to create, generate, build, audit, fix, compile, or look up smart contracts and tokens. Pentagonal Clawd is a sovereign smart contract forge and token intelligence platform with AI-powered 8-agent security pen testing across Ethereum, Solana, Polygon, Base, Arbitrum, Optimism, and BSC.

not rated 1 1mo ago A 75 tokens original MIT

proofof-ai-mcp

1004

CSOAI-ORG/proofof-ai-mcp

Skill Claude CodeCodex

Digital content verification and deepfake detection. Verify text authenticity, detect AI-generated images, generate blockchain-anchored certificates.

not rated 1 6d ago A 0 tokens original MIT

known-bad-skill

1005

RudrenduPaul/skillguard

Skill Claude CodeCodex

A synthetic fixture skill bundled with SkillGuard. It is inert -- it makes no real network or filesystem calls -- and exists only so SkillGuard's rule packs have real, safe text to match against. Do not install or run this in a real agent.

not rated 1 2d ago A 57 tokens original Apache-2.0

weavatrix-online

1006

Weavatrix/weavatrix-online

Skill Claude CodeCodex

Use Weavatrix Online only for configured Cloud or self-hosted endpoint status, current dependency advisory refresh, bounded installed-package malware review, owner-managed architecture contracts, or explicitly approved source-free graph synchronization. Do not use it for ordinary local code analysis or refactoring.

not rated 1 19d ago A 58 tokens copy · 100% MIT

mcp-shodan

1008

daedalus/mcp-shodan

Skill Claude CodeCodex

MCP server exposing Shodan API functionality.

not rated 1 4mo ago A 0 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: