Security skills

17,076 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 277agent 229generative-ai 179LangChain 176hacking 175autonomous-pentesting 135cloud-security 121skills 121claude-ai 118redteam 113LLM 108security-audit 105cors-exploitation 88

authos-web-integration

1033

drmhse/authos_skill

Skill Codex

Integrate AuthOS into browser, React, Vue, or plain TypeScript applications using @drmhse/sso-sdk and the AuthOS React/Vue adapters. Use when adding OAuth redirects, password login, magic links, passkeys, MFA callback handling, token refresh, or frontend session state.

not rated 1 3mo ago A 66 tokens original MIT

C31-plan

1034

ChianW/C31

Skill Claude CodeCodex

Turn requirements into validated, executable plans. C31-brainstorm defines WHAT; C31-plan defines HOW — with coverage gates, wave analysis, and threat modeling.

not rated 1 17d ago A 34 tokens original MIT

web3-audit

1035

guib1/red-team-docker

Skill Claude CodeCodex

Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for…

not rated 1 5mo ago A 103 tokens

smartbw-mcp

1036

ocoj/smartbw-mcp

Skill Claude CodeCodex

An MCP connection to Vaultwarden or Bitwarden, which are password managers for storing credentials and other secure fields.

not rated 1 yesterday A 59 tokens original MIT

zugashield

1038

Zuga-Technologies/ZugaShield

Skill Claude CodeCodex needs its repo

7-layer AI security + ML detection for OpenClaw. Covers all 10 OWASP Agentic AI risks — prompt injection, tool misuse, memory poisoning, data exfiltration, and more — across ALL channels (Signal, Telegram, Discord, WhatsApp, web) simultaneously.

not rated 1 12d ago A 61 tokens original MIT

skills

1039

Hao17/LiteGhidraMCP

Skill Claude CodeCodex

This document teaches AI assistants how to effectively use the Ghidra MCP tools for binary analysis. Install it as context for your AI client.

not rated 1 3mo ago A 0 tokens

perch

1040

adityaarsharma/perch

Skill Claude Code

Server intelligence layer for RunCloud-managed Linux servers. Use when the user mentions Perch, /perch, RunCloud, nginx-rc, server intelligence, server diagnosis, WordPress site auditing, plugin vulnerability scanning, or any time they want to investigate, monitor, or heal a server they own.

not rated 1 4mo ago A 65 tokens

audit-plugin-health

1041

AMATSUGI-120/plugin-health-auditor

Skill Codex

Audit Codex plugins, Agent Skills, hooks, scripts, and MCP configuration for always-on triggers, context overhead, recursive invocation, subagent amplification, instruction conflicts, risky commands, excessive capabilities, exposed secrets, and malformed manifests. Use only when the user explicitly asks to audit…

not rated 1 1mo ago A 84 tokens original MIT

browser-firefox-mcp

1042

ironessi/browser-firefox-mcp

Skill Claude CodeCodex

Firefox browser MCP server for penetration testing — XSS detection, session manipulation, network capture, recon.

not rated 1 23d ago B 26 tokens

skill

1043

nidhish28guhan-netizen/hachiman-agent

Skill Claude CodeCodex needs its repo

Hachiman is a watchman that thinks like an attacker. On an authorized target it runs.

not rated 1 19d ago A 0 tokens original MIT

legacy-shield

1044

bitatlas-group/bitatlas

Skill Claude CodeCodex

Secure zero-knowledge document vault for AI agents. Persistence for your secrets.

not rated 1 yesterday A 19 tokens original MIT

oidc-hosted-page-go

1045

MojoAuth/skills

Skill Claude CodeCodex

Implement passwordless authentication in Go applications using MojoAuth OIDC Hosted Login Page.

not rated 1 6mo ago A 23 tokens

setup-semgrep-plugin

1046

semgrep/cursor-plugin

Skill Claude CodeCodex

Set up the Semgrep plugin by installing Semgrep, authenticating, and verifying compatibility.

not rated 1 1mo ago A 22 tokens

team-qa

1047

huuanh20/awesome-ai-agent-skills

Skill Claude Code

QA/QC agent. Reads ALL pipeline artifacts (BA + TechLead + PM + BE + FE + Tester) and produces quality-report.md, compliance-check.md, and sign-off.md. Declares Gate 3: Release Sign-off (advisory only — operator has final authority). Part of the Virtual Team Skill pipeline.

not rated 1 1mo ago A 70 tokens original MIT

mcp-demo-enforcer

1048

danduh/mcp-security

Skill Claude CodeCodex

Forces the model to always use the mcp-security demo MCP server tools instead of native capabilities. Use this skill whenever the user is working in the mcp-security project and asks to read files, count lines, write files, check npm packages, inspect npm config, verify registry, or do any file/npm operation. This…

not rated 1 2mo ago A 119 tokens

sealgate

1049

Edison-Watch/sealgate-mcp

Skill Claude CodeCodex

Govern how AI agents access data through your organisation's Sealgate gateway. Use when you need to list governed MCP servers, review agent session and audit status, or check whether a tool call is allowed by policy.

not rated 1 +1 7d ago A 47 tokens original MIT

oakallow-governance

1050

oakallow/oakallow-mcp

Skill Claude CodeCodex

Use this skill when an AI agent needs to act safely through oakallow, the runtime permission, approval, and audit layer for AI agent tool execution. Trigger it whenever you are about to take a tool action that could be risky, irreversible, or that touches another system, and you need to know whether it is allowed…

not rated 1 2mo ago A 205 tokens original MIT

npm-research

1051

ofershap/mcp-server-npm-plus

Skill Claude CodeCodex

Research npm packages with bundle size, vulnerability scanning, and download trends via MCP. Use when comparing or auditing packages.

not rated 1 6mo ago A 27 tokens original MIT

airlock

1052

cjaston/airlock

Skill Claude CodeCodex

Use Airlock before installing or executing packages, running risky shell commands, committing generated code, or declaring an agent task complete. Airlock detects hallucinated/slopsquatted dependencies, destructive commands, leaked secrets, and suspicious test changes.

not rated 1 2mo ago A ✓ AI review 50 tokens original MIT

mcp2agy-fixer-agent

1053

uziii2208/mcp2agy

Skill Claude CodeCodex

Code Fixer subagent definition for the mcp2agy pipeline. This agent produces minimal, correct, testable fixes for verified security findings. Do NOT use this agent directly — it is invoked by the audit pipeline orchestrator.

not rated 1 13d ago A 54 tokens original MIT

codacy

1055

withoneai/one-agent-plugin

Skill Claude CodeCodex

A cloud-based code quality and static analysis tool that automatically reviews code for bugs, security issues, and style violations, tracks coverage and quality metrics across languages, and integrates with CI/CD pipelines to help teams maintain high standards and reduce technical debt. Read and write Codacy data…

not rated 1 23d ago A 119 tokens original MIT

72stack-sec

1056

Little-H-lying-flat/72stack-sec

Skill Claude CodeCodex

A Chinese-language workflow for authorized security testing and bug bounty work, where researchers look for and report vulnerabilities in websites, applications, and cloud systems.

not rated 0 changed today A 206 tokens original

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: