UnitOneAI/SecuritySkills

Open-source security skills for AI coding agents. Grounded in OWASP, NIST, MITRE ATT&CK, CIS. Works with Claude Code, Gemini CLI, Cursor, Codex CLI, OpenClaw, Kiro.

60Stars on the repository
50Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

pci-dss-review

25

UnitOneAI/SecuritySkills

Skill Claude Code

Performs a PCI DSS v4.0 compliance review across all 12 requirements and their sub-requirements. Auto-invoked when discussing payment card security, cardholder data protection, PCI compliance validation, or merchant/service provider assessment. Covers scope reduction strategies, SAQ vs ROC determination, compensating…

not rated 60 +2 2mo ago B 85 tokens original MIT

soc2-gap

26

UnitOneAI/SecuritySkills

Skill Claude Code

Performs a SOC 2 Type II readiness gap analysis against AICPA Trust Services Criteria. Auto-invoked when discussing SOC 2 compliance, audit preparation, or security program maturity. Walks through all Common Criteria (CC1-CC9) plus selected additional criteria, identifies gaps, and produces a remediation roadmap with…

not rated 60 +2 2mo ago B 78 tokens original MIT

dast-config

27

UnitOneAI/SecuritySkills

Skill Claude Code

Reviews DAST tool configurations against OWASP Top 10:2021 and OWASP Testing Guide v4.2. Auto-invoked when reviewing OWASP ZAP configurations, DAST CI/CD integration, scan policies, or authenticated scanning setups. Produces a DAST maturity assessment covering scan policy configuration, active vs passive scanning, API…

not rated 60 +2 2mo ago A 83 tokens original MIT

pipeline-security

28

UnitOneAI/SecuritySkills

Skill Claude Code needs its repo

Reviews CI/CD pipeline configurations against SLSA v1.0 build levels and OWASP Top 10 CI/CD Security Risks. Auto-invoked when reviewing GitHub Actions workflows, GitLab CI configs, Jenkins pipelines, or when discussing supply chain security. Produces a pipeline security assessment with SLSA level determination and…

not rated 60 +2 2mo ago B 75 tokens original MIT

sast-config

29

UnitOneAI/SecuritySkills

Skill Claude Code needs its repo

Reviews and tunes SAST tool configurations against OWASP ASVS 4.0.3 and CWE Top 25. Auto-invoked when reviewing Semgrep rules, CodeQL queries, SAST CI integration, or false positive triage workflows. Produces a SAST maturity assessment covering rule authoring, severity tuning, custom rule development, and CI…

not rated 60 +2 2mo ago A 78 tokens original MIT

secrets-management

30

UnitOneAI/SecuritySkills

Skill Claude Code

Performs a structured secrets management review against OWASP Secrets Management Cheat Sheet and NIST SP 800-57 Part 1 Rev 5 (Recommendation for Key Management). Auto-invoked when reviewing secret handling patterns, vault configurations, .env files, or credential rotation policies. Produces a secrets management…

not rated 60 +2 2mo ago A 82 tokens original MIT

access-review

31

UnitOneAI/SecuritySkills

Skill Claude Code

Conducts access review and entitlement audit against CIS Controls v8 (Controls 5, 6) and NIST SP 800-53 AC family. Auto-invoked when reviewing entitlement certifications, orphaned accounts, role explosion, segregation of duties violations, or quarterly access recertification campaigns. Produces findings with severity…

not rated 60 +2 2mo ago B 76 tokens original MIT

iam-review

32

UnitOneAI/SecuritySkills

Skill Claude Code

Reviews identity and access management configurations against NIST SP 800-63B, NIST SP 800-207 zero trust principles, and CIS Controls v8. Auto-invoked when reviewing IAM policies, role definitions, user provisioning workflows, or when asked to assess identity security posture. Produces findings on least privilege…

not rated 60 +2 2mo ago B 83 tokens original MIT

privileged-access

33

UnitOneAI/SecuritySkills

Skill Claude Code

Performs a Privileged Access Management (PAM) review against CIS Controls v8 (Controls 5.4, 6.5) and NIST SP 800-53 AC-6 (Least Privilege). Evaluates PAM tool effectiveness, just-in-time access patterns, break-glass procedures, session recording, and credential vaulting. Produces findings with severity, framework…

not rated 60 +2 2mo ago B 87 tokens original MIT

rbac-design

34

UnitOneAI/SecuritySkills

Skill Claude Code

Guides the design and assessment of RBAC and ABAC authorization models against the NIST RBAC model (Sandhu et al.) and NIST SP 800-162 (ABAC guide). Auto-invoked when designing role hierarchies, evaluating permission boundaries, implementing ABAC policy patterns, performing role mining, or preventing role explosion.…

not rated 60 +2 2mo ago B 84 tokens original MIT

UnitOneAI/SecuritySkills

Skill Claude Code

Performs a Zero Trust Architecture maturity assessment against NIST SP 800-207 and the CISA Zero Trust Maturity Model v2. Evaluates all five CISA ZT pillars (Identity, Devices, Networks, Applications & Workloads, Data) across maturity stages. Covers microsegmentation readiness, continuous verification, and produces a…

not rated 60 +2 2mo ago B 84 tokens original MIT

containment

36

UnitOneAI/SecuritySkills

Skill Claude Code

Provides structured incident containment strategies mapped to NIST SP 800-61 Rev 2 and MITRE ATT&CK techniques. Auto-invoked when a confirmed incident requires isolation decisions, credential revocation, network segmentation, or DNS sinkholing. Produces a containment plan with short-term and long-term actions…

not rated 60 +2 2mo ago A 80 tokens original MIT

forensics-checklist

37

UnitOneAI/SecuritySkills

Skill Claude Code

Guides digital forensic evidence collection following NIST SP 800-86 and RFC 3227 order of volatility. Auto-invoked when the user needs to collect forensic evidence, preserve chain of custody, capture volatile data, create disk images, or handle cloud forensics. Produces an evidence collection plan with…

not rated 60 +2 2mo ago B 85 tokens original MIT

ir-playbook

38

UnitOneAI/SecuritySkills

Skill Claude Code

Executes a structured incident response workflow based on NIST SP 800-61 Rev 2 and the SANS Incident Handler's Handbook. Auto-invoked when the user reports a security incident, asks how to respond to a breach, or needs help with incident classification, containment decisions, stakeholder notification, or evidence…

not rated 60 +2 2mo ago B 90 tokens original MIT

UnitOneAI/SecuritySkills

Skill Claude Code

Conducts a structured post-incident review following NIST SP 800-61 Rev 2 Post-Incident Activity guidance. Auto-invoked when an incident has been resolved and the team needs to conduct a blameless retrospective, reconstruct the timeline, perform root cause analysis, document lessons learned, and track remediation…

not rated 60 +2 2mo ago A 96 tokens original MIT

dns-security

40

UnitOneAI/SecuritySkills

Skill Claude Code

Performs a structured DNS security review against NIST SP 800-81 Rev 2 (Secure Domain Name System Deployment Guide) and CIS Controls v8 (Control 9.2 -- Use DNS Filtering Services). Auto-invoked when reviewing DNS configurations, DNSSEC deployment, or investigating DNS-based exfiltration and tunneling indicators.…

not rated 60 +2 2mo ago A 92 tokens original MIT

firewall-review

41

UnitOneAI/SecuritySkills

Skill Claude Code

Performs a structured firewall rule base audit against CIS Controls v8 (Controls 4.4 and 4.5) and NIST SP 800-41 Rev 1 (Guidelines on Firewalls and Firewall Policy). Auto-invoked when reviewing firewall configurations, ACLs, or network security policies. Produces a prioritized findings report covering overly…

not rated 60 +2 2mo ago A 92 tokens original MIT

segmentation

42

UnitOneAI/SecuritySkills

Skill Claude Code

Performs a structured network segmentation review against NIST SP 800-207 (Zero Trust Architecture) and CIS Controls v8 (Control 12 -- Network Infrastructure Management). Auto-invoked when reviewing network architecture, VLAN configurations, micro-segmentation policies, or DMZ designs. Produces a segmentation maturity…

not rated 60 +2 2mo ago A 78 tokens original MIT

alert-triage

43

UnitOneAI/SecuritySkills

Skill Claude Code

Guides structured triage of security alerts using a four-phase methodology (collect, correlate, classify, escalate) mapped to MITRE ATT&CK v16 and aligned with NIST SP 800-61 Rev 2 incident handling guidelines. Auto-invoked when the user discusses alert investigation, asks "is this a true positive?", or shares alert…

not rated 60 +2 2mo ago A 96 tokens original MIT

UnitOneAI/SecuritySkills

Skill Claude Code

Guides creation of detection rules using Sigma rule specification and the Palantir Alerting and Detection Strategy (ADS) framework, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user discusses detection logic, Sigma rules, ATT&CK coverage gaps, or asks "how do I detect this technique?" Produces…

not rated 60 +2 2mo ago B 93 tokens original MIT

log-analysis

45

UnitOneAI/SecuritySkills

Skill Claude Code

Guides structured security log analysis across authentication, network, endpoint, and cloud audit log sources. Auto-invoked when the user shares log data, asks about suspicious events, needs help interpreting Windows Event IDs or Linux auth logs, or is establishing baselines for anomaly detection. Produces log source…

not rated 60 +2 2mo ago B 84 tokens original MIT

siem-rules

46

UnitOneAI/SecuritySkills

Skill Claude Code

Guides development of SIEM detection rules using KQL (Microsoft Sentinel) and SPL (Splunk) query languages, mapped to MITRE ATT&CK v16 techniques. Auto-invoked when the user needs to write SIEM queries, tune alert thresholds, build correlation rules, or manage the detection rule lifecycle. Produces production-ready…

not rated 60 +2 2mo ago B 87 tokens original MIT

cve-triage

47

UnitOneAI/SecuritySkills

Skill Claude Code

Triages and prioritizes CVEs using CVSS 4.0, SSVC 2.1 decision trees, EPSS scores, and CISA KEV catalog cross-referencing. Auto-invoked when a CVE ID is mentioned, vulnerability scan results are shared, or the user asks "should we patch this?" Produces a prioritized remediation recommendation with SLA assignment and…

not rated 60 +2 2mo ago C 86 tokens original MIT

UnitOneAI/SecuritySkills

Skill Claude Code

Prioritizes patches and manages remediation SLAs using SSVC 2.1 decision outcomes, EPSS v3 trend analysis, and CISA KEV catalog cross-referencing. Covers SLA frameworks by severity tier, compensating controls assessment, patch window scheduling, risk acceptance criteria, and exception management. Auto-invoked when…

not rated 60 +2 2mo ago A 88 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: