Security skills

18,123 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 285generative-ai 177LangChain 174hacking 174autonomous-pentesting 138cloud-security 127claude-ai 113openclaw 111redteam 111skills 104cors-exploitation 94firebase-hacking 93hermes-agent 90

netwatch

169

sepivip/SeekerClaw

Skill Claude CodeCodex

Network monitoring and security audit. Use when: user asks to scan network, check open ports, network audit, who's on wifi, check connection, port scan, firewall check, network status, or network security. Don't use when: user asks about crypto transactions (use solana tools) or web search (use research skill).

not rated 313 yesterday A 68 tokens original MIT

pentest-redteam

170

0rangec3t/Black-cat

Skill Claude Code

An authorized red-team framework for testing systems through stated assumptions. Red teaming is a permitted security exercise that imitates attacks to find weaknesses.

not rated 309 +5 1mo ago A 41 tokens

review

171

apollographql/apollo-mcp-server

Skill Claude Code

Review a GitHub pull request for a Rust codebase. Focuses on security, performance, test coverage, and Rust idioms. Runs in GitHub Actions and posts comments directly to the PR.

not rated 307 yesterday A 42 tokens original MIT

happy-app-audit

172

iamzhihuix/happy-claude-skills

Skill Claude CodeCodex

Audit a local macOS app's telemetry / reporting behavior using static analysis only. Reverse-engineers an .app bundle to identify embedded SDKs (AppLog/TEA, Parfait, TTNet, mars, MMKV, Sentry, Firebase, Bugly, Umeng, etc.), mapped upload endpoints, local on-disk queues, and privacy-relevant fields — without packet…

not rated 306 4mo ago A 152 tokens original MIT

exploit-xss

173

crazyMarky/pentest-skills

Skill Claude CodeCodex

Cross-site scripting (XSS) vulnerability detection and exploitation. Supports reflected XSS, stored XSS, DOM-based XSS, and blind XSS testing. Use this skill when user mentions XSS, cross-site scripting, script injection, or needs to test JavaScript injection in parameters, forms, headers, or DOM sources.

not rated 303 +4 3mo ago A 71 tokens original Apache-2.0

superagents-lab/xcode27-skills

Skill Claude CodeCodex

Audit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up…

not rated 300 +1 2mo ago A 111 tokens

mrphrazer/agentic-malware-analysis

Skill Claude CodeCodex

Structured malware triage and reverse-engineering orchestration for PE, ELF, and Mach-O binaries with strict artifact dumping to a status folder. Use when requests involve malware sample analysis, strings triage, API/import analysis, behavioral hypothesis generation, component mapping, deep-analysis planning, Binary…

not rated 298 5mo ago A 92 tokens GPL-2.0

develop-disguise

176

cha0upup/LeoAI

Skill Claude CodeCodex

A specialised helper for creating or updating Disguises on a platform, including the code that changes and restores traffic data.

not rated 297 +7 8d ago A 72 tokens GPL-3.0

vibe-pentest

177

ok-helloworld/vibe-pentest

Skill Claude CodeCodex

An AI skill for black-box penetration testing of web applications, meaning security testing without relying on the application's source code. It uses multiple agents across steps such as identifying the application, scanning entry points and APIs, crawling it, testing for vulnerabilities, and reviewing evidence.

not rated 295 changed 2d ago A 126 tokens AGPL-3.0

semgrep

178

semgrep/skills

Skill Claude CodeCodex

Run Semgrep static analysis scans and create custom detection rules. Use when asked to scan code with Semgrep, find security vulnerabilities, write custom YAML rules, or detect specific bug patterns. IMPORTANT: Also use this skill when users ask to 'scan for bugs', 'check code quality', 'find vulnerabilities', 'static…

not rated 294 +4 1mo ago A 112 tokens

hunt-ad

180

Encod3d-Sec/TORCH

Skill Claude CodeCodex

Active Directory attack hunting - enumeration to domain dominance. Spray-safe (lockout gate), AS-REP/Kerberoast, ACL + ADCS (ESC1-16), delegation, DCSync, lateral movement. Wiki-first, FIND schema output.

not rated 286 +2 4d ago A 54 tokens original MIT

llm-sast-scanner

181

SunWeb3Sec/llm-sast-scanner

Skill Claude CodeCodex

General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. Trigger when the user asks to: "analyze code for vulnerabilities", "review code security", "find security bugs", "do a SAST scan", "check for [vulnerability type] in code", "audit source code", or requests a security code…

not rated 283 15d ago A 100 tokens

PlamenTSV/plamen

Skill Claude CodeCodex

L1 trigger - detects non-determinism, state transition completeness violations, and safety/liveness invariant breaks in consensus code. Inject into depth-consensus-invariant or depth-state-trace.

not rated 281 1mo ago A 45 tokens original MIT

XPolicyLab/XPolicyLab

Skill Claude CodeCodex

Audit a policy/ / adapter for XPolicyLab standard compliance and PR readiness — file completeness, deploy.yml, Model contract, decodeimagebit-only decoding, script conventions, static checks, debug-mode eval, README and checkpoint requirements. Use when asked to check, validate, review, or pre-flight a policy adapter…

not rated 275 +2 changed 2d ago A 85 tokens original Apache-2.0

caido-mode

184

caido/skills

Skill Claude CodeCodex

Full Caido SDK integration for Claude Code. Search HTTP history with HTTPQL, test with curl proxied through Caido (caching auth in reusable static curl config files), add match & replace rules, and organize handoffs into named replay sessions and collections - all via the official @caido/sdk-client. PAT auth…

not rated 271 +1 23d ago C 70 tokens original MIT

xmpp-enumeration

185

blacklanternsecurity/red-run

Skill Claude CodeCodex

XMPP/Jabber service enumeration for Openfire, ejabberd, Prosody, and other XMPP servers. Trigger when ports 5222 (client), 5223 (legacy TLS), or 5269 (server-to-server) are found open. Covers authentication testing, user enumeration, MUC room discovery, and server fingerprinting. Do NOT use for AD enumeration or…

not rated 266 5mo ago A 92 tokens GPL-3.0

vbs-scan-security

186

tanviet12/vbsec

Skill Claude CodeCodex

Use when scanning code for security vulnerabilities. Use when user says "scan security", "kiểm tra bảo mật", "security audit", "review security", or invokes /vbs-scan-security. For large scans (>20 main-language files OR >30 total OR >14 days) processes chunks sequentially. Outputs bilingual reports (vi/en).

not rated 265 3mo ago A 75 tokens original MIT

lasso-security/claude-hooks

Skill Claude Code

Defense against indirect prompt injection attacks for Claude Code. This skill provides PostToolUse hooks that scan tool outputs (files, web pages, command results) for injection attempts and warn Claude about suspicious content.

not rated 265 +1 8mo ago B 0 tokens original MIT

cyberowlai

189

karimhabush/cyberowl

Skill Claude CodeCodex

Check if recent cybersecurity alerts from 10 international CERTs affect your current project. Use when the user asks about security vulnerabilities, CVEs, "is my project affected", "any new security alerts", "check for vulnerabilities", "cyberowlai", or "/cyberowlai". Also trigger when the user is working on…

not rated 263 yesterday A 155 tokens original MIT

hermes-vault-access

190

asimons81/hermes-vault

Skill Claude CodeCodex

Use Hermes Vault as the canonical credential broker for Hermes and persistent sub-agents.

not rated 260 10d ago A 22 tokens original MIT

pentest-playbook

191

SeaOf0/dsh-redteam-model

Skill Claude CodeCodex

A penetration-testing playbook for examining authorized websites, applications, and services for real, verified security weaknesses.

not rated 248 +65 yesterday A 429 tokens original MIT

address-review

192

finos/git-proxy

Skill Claude Code

Address review comments on a GitHub pull request.

not rated 246 +2 yesterday A 12 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: