Security skills

19,428 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 486bug-bounty 286generative-ai 177LangChain 174hacking 174autonomous-pentesting 138cloud-security 127claude-ai 113openclaw 111redteam 111skills 105cors-exploitation 94firebase-hacking 93hermes-agent 90

ctf-web

145

Unclecheng-li/DeepSec

Skill Claude CodeCodex

A reference library for web-security challenges in CTFs, or capture-the-flag security competitions. It focuses on common PHP weaknesses, injection bypasses, source-code discovery, file inclusion, and finding hidden challenge data.

not rated 392 +21 11d ago A 56 tokens copy · 100% MIT

break

146

JDArmy/BREAK

Skill Claude CodeCodex

A Chinese-language business-security knowledge base covering risks, defenses, attack tools, threat actors, terms, business areas, and documented cases.

not rated 383 changed today A 50 tokens original Apache-2.0

depsguard

147

arnica/depsguard

Skill Claude CodeCodex

Install and run DepsGuard, a zero-dependency CLI that scans and fixes package manager configs (npm, pnpm, yarn, bun, uv) for supply chain security best practices.

not rated 381 +1 24d ago A 41 tokens original MIT

agentsh-policy-edit

148

canyonroad/agentsh

Skill Claude CodeCodex

Use when adding, removing, or updating rules in an existing AgentSH policy, modifying security permissions, HTTP service declarations, Postgres-family database rules, resource limits, or policy YAML files.

not rated 382 +2 29d ago A 42 tokens original Apache-2.0

llm-testing

149

Eyadkelleh/awesome-skills-security

Skill Claude CodeCodex

Comprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.

not rated 376 +9 2mo ago A 27 tokens

humble-header-analyst

150

rfc-st/humble

Skill Claude CodeCodex

Expert-level parsing and remediation of 'humble' HTTP security header reports. Use this skill whenever the user provides a report generated by 'humble' (https://github.com/rfc-st/humble), mentions analyzing HTTP response headers, security header grades (A-E), or asks for remediation of findings such as missing…

not rated 373 today A 84 tokens original MIT

ahmadvh/octochains

Skill Claude CodeCodex

Analyzes authentication and authorization events for failed-login clustering, privilege-escalation chains, credential-stuffing patterns, and MFA-bypass indicators.

not rated 372 +4 15d ago A 35 tokens

vulnersCom/api

Skill Claude CodeCodex

Use when modifying, testing, documenting, or reviewing the Vulners Python SDK. Covers the v4 architecture (typed sync/async clients, resource namespaces, bulletin model hierarchy, unasync codegen), the preserved legacy v3 surface, uv-based tooling, the 100% branch-coverage gate, safe API-key handling, and defensive…

not rated 372 yesterday A 79 tokens original MIT

hyperplan

153

omagents/omagents

Skill Claude CodeCodex

Adversarial plan review with 3 parallel critics using loop engine tracking. Each critic attacks the plan from a different angle: security, architecture, and edge cases. Trigger when the user says 'hyperplan', 'review plan', 'critique plan', or wants adversarial analysis of a design.

not rated 366 +1 1mo ago A 63 tokens original MIT

author-saf-technique

154

secure-agentic-framework/saf-mcp

Skill Claude CodeCodex

Research, author, rewrite, validate, and prepare exactly one SAF-MCP technique and its evidence packet. Use for new or existing SAF technique work that requires source-or-omit traceability, an exclusion ledger, current breach and vulnerability research, tested detection, framework reconciliation, publication-rights…

not rated 361 +1 2d ago A 69 tokens

code-review

155

timwuhaotian/the-pair

Skill Claude CodeCodex

Comprehensive code review with security and performance checks.

not rated 360 +1 15d ago A 12 tokens original Apache-2.0

AndrewDryga/emisar

Skill Claude CodeCodex

Micro-detail polish for emisar's rendered UI — the small craft that makes an interface feel finished: concentric border radius, optical alignment, shadows vs borders, interruptible/staggered motion, tabular numbers, text-wrap, image outlines, scale-on-press, hit areas, transition specificity. Use when building or…

not rated 354 +2 today A 133 tokens

DragonJAR/Android-Pentesting-Skill

Skill Claude CodeCodex

Comprehensive Android APK security audit with static analysis, dynamic instrumentation, source-to-sink tracing, IPC/component abuse analysis, and CVSS 4.0 reporting. Covers decompilation, manifest analysis, deep links and intent injection, secrets detection, crypto analysis, Frida/Objection integration, and APK…

not rated 354 +5 2mo ago A 154 tokens original Apache-2.0

ghtkn

158

suzuki-shunsuke/ghtkn

Skill Claude CodeCodex

Read ghtkn's documentation with ghtkn docs list and ghtkn docs show before answering. ghtkn is a CLI that creates short-lived (8h) GitHub user access tokens from GitHub Apps. Use for any question about ghtkn, GHTKN environment variables, ghtkn get / exec / auth / agent / revoke, the ghtkn git credential helper, or…

not rated 354 +28 today A 146 tokens original MIT

wa-review

159

YoshiiRyo1/document-templates-for-aws

Skill Claude CodeCodex

This skill should be used when the user asks to "review architecture", "Well-Architected review", "check bestpractices", "security assessment",or "cost optimization analysis".

not rated 352 +5 6mo ago A 41 tokens original Unlicense

owasp-security

160

agamm/claude-code-owasp

Skill Claude CodeCodex

Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, LLM Top 10 (2025), and Agentic AI security (2026).

not rated 353 +4 1mo ago A 62 tokens original MIT

secureclaw

161

adversa-ai/secureclaw

Skill Claude CodeCodex

Security hardening toolkit for OpenClaw. Run audits, apply fixes, scan skills, monitor costs and memory integrity.

not rated 347 +2 4mo ago A 28 tokens

process-audit-report

162

zksecurity/zkbugs

Skill Claude CodeCodex

Extract ZK circuit bugs from an audit report PDF and add them to the zkbugs dataset. Creates branch, scaffolds directories, fills configs, finds similar bugs.

not rated 345 16d ago A 38 tokens original MIT

threat-modeling

163

fr33d3m0n/threat-modeling

Skill Claude CodeCodex

Threat model, security audit, find vulnerabilities, check security of my app, risk assessment, penetration test prep, analyze attack surface, what could an attacker exploit. Use this skill whenever a user wants holistic security analysis of a codebase, application, or project. MUST be invoked instead of analyzing…

not rated 341 +4 3mo ago A 178 tokens original BSD-3-Clause

oracle/netsuite-suitecloud-sdk

Skill Claude CodeCodex ✓ vendor

Comprehensive NetSuite SDF best practices based on the SAFE Guide (12 principles + appendices). Generates Object XML for all 14 script types, enforces governance limits, security patterns, and defensive coding. Includes N/cache, N/query, concurrency limits, OAuth 2.0 guidance, legacy TBA guardrails, CustomTool runtime…

not rated 336 +3 yesterday A 104 tokens UPL-1.0

security-review

166

zhukunpenglinyutong/ai-max

Skill Claude CodeCodex

A security checklist for code that handles login permissions, user input, uploaded files, passwords, API keys, payments, or other sensitive data.

not rated 336 6mo ago A 42 tokens original MIT

prismor

167

PrismorSec/prismor

Skill Claude CodeCodex

Runtime security for AI coding agents. Use when about to install a package, paste a secret, run a destructive command, reach an unfamiliar host, govern MCP servers, set up a new workspace, or recover from a Prismor block.

not rated 338 today D 51 tokens original Apache-2.0

flounder

168

adshao/flounder

Skill Claude CodeCodex

Operates Flounder, an autonomous white-hat security auditor. Use when a user asks for a security audit, bug-bounty review, vulnerability investigation, or exploit proof for a public-source or authorized repository, source tree, package, smart contract, Solidity/EVM project, ZK or proof-system code, deployed address…

not rated 330 +1 changed yesterday A 202 tokens AGPL-3.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: