Security skills

18,123 tagged Security, measured the same way as everything else here.

Browse within: cybersecurity 485bug-bounty 285generative-ai 177LangChain 174hacking 174autonomous-pentesting 138cloud-security 127claude-ai 113openclaw 111redteam 111skills 104cors-exploitation 94firebase-hacking 93hermes-agent 90

mcp-usage-monitoring

193

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to monitor, audit, or analyze MCP (Model Context Protocol) server usage in the environment. Triggers on keywords like "MCP usage", "MCP server monitoring", "MCP activity", "Graph MCP", "Sentinel MCP", "Azure MCP", "MCP audit", "tool usage monitoring", "MCP breakdown", "who is using MCP", or…

not rated 244 yesterday A 159 tokens original MIT

ai-agent-security

194

ProgrammerAnthony/Expert-Coding-Harness

Skill Cursor

A security guide for AI agents—software that follows instructions and can use tools or data. It covers threats such as prompt injection, data leaks, unsafe code execution, unauthorized access, and compliance issues.

not rated 236 +1 3mo ago A 39 tokens original MIT

onionclaw

195

christinminor459/OnionClaw

Skill Claude CodeCodex

Search the Tor dark web, fetch .onion hidden service pages, rotate Tor identity, and run structured OSINT investigations. Use when user asks to search dark web, investigate .onion sites, find if data appeared on dark web, conduct Tor-based OSINT, look up dark web leaks, fetch any .onion URL, check for leaked…

not rated 236 2d ago B 82 tokens

maintenance

196

erikdarlingdata/PerformanceStudio

Skill Claude Code

Quarterly maintenance pass (every 1-3 months) — dependency/security audit, build health, and repo hygiene for PerformanceMonitor and PerformanceStudio.

not rated 236 yesterday A 31 tokens original MIT

secskills

197

Arenbai/SecSkills

Skill Claude Code

A Chinese-language guide for authorized penetration testing, covering information gathering, vulnerability discovery, exploitation, and post-exploitation. Penetration testing is security testing that imitates an attack on a specified target.

not rated 234 +1 3mo ago C 101 tokens original MIT

pytm

198

rohunj/claude-build-workflow

Skill Claude CodeCodex

Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification. Use when: (1) Creating threat models programmatically using Python code, (2) Generating data flow diagrams (DFDs) with automatic STRIDE threat identification…

not rated 231 +1 7mo ago A 125 tokens

graniet/kheish

Skill Claude CodeCodex

Pre-commit verification pipeline — static security scan, baseline-aware quality gates, independent reviewer subagent, and auto-fix loop. Use after code changes and before committing, pushing, or opening a PR.

not rated 227 1mo ago A 41 tokens original Apache-2.0

aki77/activestorage-validator

Skill Claude CodeCodex

Validate ActiveStorage attachments (content type, file size, file extension) with the activestorage-validator gem's blob validator. Use when adding validations to hasoneattached / hasmanyattached attributes.

not rated 226 2mo ago A 48 tokens original MIT

review

201

morganlinton/Albatross

Skill Claude CodeCodex

Review a change for correctness, security, and missing tests.

not rated 226 11d ago A 14 tokens original MIT

lazyown

202

grisuno/LazyOwn

Skill Claude CodeCodex

LazyOwn RedTeam Framework — penetration testing and C2 via MCP.

not rated 225 yesterday A 16 tokens GPL-3.0

bx33661/Wireshark-MCP

Skill Codex

Use when analyzing packet captures or live network traffic with Wireshark MCP; choose the right workflow for triage, security hunting, incident response, or troubleshooting, then produce evidence-backed findings with exact filters, streams, frames, and next steps.

not rated 225 +6 20d ago A 56 tokens original MIT

autoformalize

204

sondera-ai/sondera-coding-agent-hooks

Skill Claude CodeCodex

Turns one atomic governance intent ("the agent must not ") into a validated Cedar forbid policy for the Sondera OSS harness, or into a refusal that names what the engine cannot express. Drives the sondera MCP server (crates/mcp, run by cargo run -p sondera -- mcp): its served doctrine and schema, baseline coverage…

not rated 222 4d ago A 0 tokens original MIT

arkana-analyze

205

JameZUK/Arkana

Skill Claude Code

Binary analysis skill for Arkana. Handles malware triage, reverse engineering, PE/ELF/Mach-O analysis, shellcode emulation, firmware inspection, vulnerability auditing, C2 config extraction, unpacking, deobfuscation, and threat intelligence. Triggers on: binary, malware, PE, ELF, Mach-O, shellcode, firmware, analyze…

not rated 216 +8 12d ago A 158 tokens original MIT

penetration-flow

206

lingbol088-spec/ReiPenFlow

Skill Codex

Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research. Use when Codex is asked to run or plan a security assessment, triage a target or artifact, maintain pentest state, produce interim/final…

not rated 212 +2 1mo ago A 144 tokens original MIT

auth-setup

207

dilolabs/nosia

Skill Claude Code

Implements custom passwordless authentication without Devise. Use when setting up authentication, login flows, session management, passkeys (WebAuthn), magic links, or password resets. Passkeys are the primary auth method; magic links are the fallback. WHEN NOT: For authorization/permissions (use controller concerns…

not rated 212 2d ago A 88 tokens copy · 100% MIT

better-auth/skills

Skill Claude CodeCodex

Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for Better Auth. Use when users need to secure their auth setup, prevent brute force attacks, or harden a Better Auth…

not rated 212 5d ago A 70 tokens

ffuf-web-fuzzing

209

jthack/ffuf_claude_skill

Skill Claude CodeCodex

Expert guidance for ffuf web fuzzing during penetration testing, including authenticated fuzzing with raw requests, auto-calibration, and result analysis.

not rated 210 10mo ago A 34 tokens

feynman-auditor

210

NeverSight/learn-skills.dev

Skill Claude CodeCodex

Deep business logic bug finder using the Feynman technique. Language-agnostic — works on Solidity, Move, Rust, Go, C++, or any codebase. Questions every line, every ordering choice, every guard presence/absence, and every implicit assumption to surface logic bugs that pattern-matching misses. Triggers on /feynman…

not rated 208 +1 yesterday A 87 tokens

crowdsentinel-skills

211

thomasxm/CrowdSentinels-AI-MCP

Skill Claude CodeCodex

Comprehensive threat hunting and incident response skill for CrowdSentinel MCP Server. Provides decision frameworks (MITRE ATT&CK, NIST IR, Pyramid of Pain, Diamond Model), workflow guidance, executable scripts for Elasticsearch queries, field mapping assistance, and debugging tools.

not rated 206 1mo ago A 59 tokens GPL-3.0

api-spectral

212

AgentSecOps/SecOpsAgentKit

Skill Claude CodeCodex

API specification linting and security validation using Stoplight's Spectral with support for OpenAPI, AsyncAPI, and Arazzo specifications. Validates API definitions against security best practices, OWASP API Security Top 10, and custom organizational standards. Use when: (1) Validating OpenAPI/AsyncAPI specifications…

not rated 204 +2 4mo ago A 138 tokens

hm-llm-guardrails

213

rodrigohighermind/highermind-code-skills

Skill Claude CodeCodex

Catálogo de 14 patterns obrigatórios para app que integra LLM (Claude/GPT/Gemini) em produção. Use antes de shippar feature LLM pra produção, quando custo da API explode sem explicação, quando user reclama de "respostas demoram demais" ou "trava no meio", ao adicionar tool calling, agentes ou chat persistente. Cobre…

not rated 192 +1 2mo ago A 149 tokens original MIT

dependency-audit

214

databricks-industry-solutions/security-analysis-tool

Skill Claude CodeCodex

Audit npm and Python dependencies across all Databricks Apps in a workspace. Use when checking for malicious packages, generating dependency inventories, or investigating supply chain risks. Triggers on dependency audit, npm audit, package audit, supply chain, malicious package, dependency inventory.

not rated 186 +1 2d ago A 57 tokens

XSS_SKILL

215

BugTraceAI/BugTraceAI-CLI

Skill Claude CodeCodex

Cross-site scripting skill vision validation.

not rated 184 +1 3d ago A 11 tokens original Apache-2.0

keypo-signer

216

keypo-us/keypo-cli

Skill Claude CodeCodex

Use when managing Secure Enclave signing keys or encrypted secrets. Use for creating/listing/deleting P-256 keys, signing digests, running commands with secrets injected via vault exec, storing/retrieving encrypted secrets. Also use when an agent needs API keys, private keys, or credentials injected into a subprocess…

not rated 181 5mo ago A 86 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: