Security skills

16,921 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 277agent 229generative-ai 179LangChain 176hacking 175autonomous-pentesting 135cloud-security 121skills 121claude-ai 118redteam 113LLM 108security-audit 105cors-exploitation 88

mordiaky/vouchspec

Skill Claude CodeCodex

Verify an exact public GitHub Agent Skill commit before installation, optionally purchase fresh isolated evidence over x402, and validate the signed receipt plus live lifecycle status. Use before installing or activating an unfamiliar SKILL.md package, when prior evidence may be stale, or when policy requires…

not rated 1 1mo ago A 66 tokens

hexwitness

1010

siaginw/HexWitness

Skill Claude CodeCodex

Investigate authorized binaries and runtime behavior with HexWitness's durable evidence MCP and optional Binary Ninja or IDA live tools. Use for function or class discovery, UUID and field mapping, protocol reconstruction, capture comparison, contradiction analysis, evidence-gap planning, and promotion of live…

not rated 1 11d ago A 64 tokens

huiyu-safe-ai

1011

huiyu9144/huiyu-safe-ai

Skill Claude Code

Lightweight AI security guard that intercepts risky install/download commands (npm, npx, pip, cargo, git clone) to block known malicious packages and scan for suspicious code. Invoke ONLY when user runs install/download/clone commands.

not rated 1 3mo ago B 52 tokens

agents-md

1012

AgentValet/AgentValet

Skill Claude CodeCodex

Routes all platform API calls through AgentValet's credential proxy. Your raw API keys and OAuth tokens are never exposed to this agent — AgentValet injects the correct credential per platform call.

not rated 1 1mo ago A 0 tokens original MIT

fetch-guard

1013

Erodenn/fetch-guard

Skill Claude CodeCodex

LLM-ready web fetching — extracts clean markdown and metadata from URLs with prompt injection defense.

not rated 1 5mo ago A 21 tokens original MIT

bumblebee

1014

mycelos-ai/bumblebee-skill

Skill Claude CodeCodex

Run Bumblebee supply-chain inventory and exposure scans on the local machine. Use this skill whenever the user wants to check developer endpoints for compromised npm/PyPI/Go/RubyGems/Composer packages, audit installed editor or browser extensions, inspect MCP host configs, or perform supply-chain incident response on…

not rated 1 3mo ago A 189 tokens original MIT

configure-permissions

1015

ashray/claude-permissions-wizard

Skill Claude CodeCodex

Interactive wizard to configure Claude Code permission rules. Sets up granular allow/ask permissions so you can work without --dangerously-skip-permissions while keeping safety nets for destructive commands. Use when user says "configure permissions", "set up permissions", "permission settings", or "stop asking me for…

not rated 1 6mo ago A ✓ AI review 65 tokens original MIT

weakpass

1016

ibnaleem/weakpass-skill

Skill Claude CodeCodex

Search hashes through 25 billion leaked passwords using the Weakpass API (no API key required).

not rated 1 3mo ago A 22 tokens GPL-3.0

Cicada

1017

Synthrun/Cicada

Skill Claude CodeCodex

Command: /cicada Audit your backend and mobile apps for vulnerabilities — and optionally fix them — without deploying or breaking anything.

not rated 1 2mo ago B 0 tokens

markus-smile/ios-app-agentic-engineering

Skill Claude CodeCodex

End-to-end agentic engineering for iPhone apps, from idea to a secure App Store release through 8 gated phases. Use when someone wants to build, plan, or ship an iPhone/iOS app — especially a non-programmer ("vibe coder") asking to create an app, pick a tech stack (SwiftUI, React Native, Flutter), choose a backend…

not rated 1 1mo ago A 138 tokens original MIT

dianpo

1019

jyuwaaw/dianpo-skill

Skill Claude CodeCodex

A Chinese-language guide for explaining the hidden roles and trust relationships in technical systems. It clarifies who owns tokens, keys, certificates, and endpoints, who checks them, and what each party proves.

not rated 1 28d ago A 253 tokens original MIT

github-skills

1020

he8um/github-skills

Skill Codex

Act as a senior GitHub platform architect, open-source maintainer, DevSecOps engineer, and repository governance specialist. Produce repository systems that are understandable, maintainable, secure by default, automation-friendly, and practical for real teams.

not rated 1 1mo ago A 101 tokens original MIT

security-claude

1022

rahozosman/security-claude

Skill Claude CodeCodex

Skill "security-claude" from rahozosman/security-claude, covering security architecture & threat modeling intelligence, how this skill is organized (progressive disclosure), 1. pick a mode, 2. core method (applies to every mode) and 3. doing a focused review.

not rated 1 13d ago A 0 tokens original MIT

news

1023

mfeo/claude-news-plugin

Skill Claude Code

A skill that collects recent news from RSS feeds about hackers, artificial intelligence, security, and technology, then categorises and summarises it in Traditional Chinese. RSS is a format websites use to publish updates.

not rated 1 3mo ago A 47 tokens

dependency-auditor

1024

nariatrip191/my-claude-skills

Skill Claude CodeCodex

The Dependency Auditor is a comprehensive toolkit for analyzing, auditing, and managing dependencies across multi-language software projects. This skill provides deep visibility into your project's dependency ecosystem, enabling teams to identify vulnerabilities, ensure license compliance, optimize dependency trees…

not rated 1 today A 7 tokens

code-review

1025

evgenii-studitskikh/Claude-Code-SaaS-Studio

Skill Claude Code

Review the current diff against path-scoped rules (secrets, RLS/tenant scoping, Stripe webhook verification, input validation, scope), flag changed code lacking tests, and run a quick security pass. Reports findings; nothing auto-fixed without approval.

not rated 1 3mo ago A 54 tokens original MIT

aegis

1026

Erkan3034/aegis

Skill Claude CodeCodex

Production-grade red-team security audit skill for AI coding assistants. Audits codebases for OWASP Top 10 vulnerabilities, auth flaws, IDOR, XSS, SSRF, JWT misuse, Supabase policies, and provides drop-in secure code replacements with zero exfiltration risk.

not rated 1 1mo ago A 61 tokens original MIT

code-execution

1027

lubochka/xiigen-general-skills

Skill Claude CodeCodex

Run commands safely and intentionally. Use before executing build, test, lint, generation, migration, deploy, or cleanup commands.

not rated 1 1mo ago A 29 tokens original Apache-2.0

curl-exfil-demo

1028

SuperMarioYL/capsule

Skill Claude CodeCodex needs its repo

A deliberately malicious demo Skill that tries to exfiltrate secrets over the network and read /.ssh/idrsa. Used to show Capsule blocking the calls at the call site.

not rated 1 5d ago D 40 tokens original Apache-2.0

ubuntu-server-audit-eu

1029

bugroo/ubuntu-server-audit-eu

Skill Claude CodeCodex

Use when performing strict read-only SSH inspections of Ubuntu/Linux servers for security review, EU cybersecurity compliance evidence, server readiness, operational disorder, waste, drift, CIS-style hardening gaps, runtime visibility, identity/access, network exposure, backups, observability, and unknowns. Requires…

not rated 1 3mo ago A 86 tokens original MIT

bootstrap-sdd-tdd

1030

kxdds/sdd-tdd

Skill Claude CodeCodex

Use when a project needs the OpenSpec + Superpowers sdd-tdd (spec-to-plan-to-TDD) workflow checked, installed, and configured -- or cleanly removed -- in any coding agent (Codex, Claude Code, Cursor, Antigravity, OpenCode, Gemini CLI, Copilot CLI, or others).

not rated 1 2mo ago A 72 tokens original MIT

sonar-manage-findings

1031

Nick2bad4u/SonarCloud-Skill

Skill Codex

Use this skill whenever the user needs SonarCloud or SonarQube issue and hotspot triage, measures, gates, profiles, settings, tags, or safe mutations with environment-variable tokens.

not rated 1 10d ago A 46 tokens original Unlicense

vapt

1032

bhuvangupta/vapt-claude

Skill Claude Code

Full-spectrum web application Vulnerability Assessment and Penetration Testing (VAPT). Automates reconnaissance, scanning, injection testing, authentication analysis, and report generation. Supports --mode pro (terse) and --mode dev (educational). Enforces authorization gate before any active testing.

not rated 1 5mo ago A 60 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: