Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 562-612 of 1,735 AI skills

AI skills directory results

jnMetaCode logo

Systematic Debugging

jnMetaCode
CommunityPopular

遇到任何 bug、测试失败或异常行为时使用,在提出修复方案之前执行

758
8.1K
10 files
View
trailofbits logo

Token Integration Analyzer

trailofbits
OrganizationPopular

Token integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/ERC721 conformity, checks for 20+ weird token patterns,…

611
7.1K
4 files
View
Tencent logo

Tool Abuse Detection

Tencent
OrganizationPopular

Detect tool misuse and unexpected code execution via dialogue testing. Use when the agent exposes file, code-execution, or network tools.

594
6.4K
Instructions
View
zebbern logo

Cloud Penetration Testing

zebbern
CommunityPopular

This skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud resources", "exploit cloud misconfigurations", "test O365…

464
4.6K
1 files
View
gotalab logo

Kiro Steering Custom

gotalab
CommunityPopular

Create custom steering documents for specialized project contexts

283
3.7K
Instructions
View
rlaope logo

Omh Backend

rlaope
CommunityPopular

[omh] Hermes backend workflow: prepare server, API, and data-layer contracts — auth boundary, error paths, response shape, and schema/migration discipline — before implementation. Use when the user…

194
2.7K
3 files
View
sergebulaev logo

Linkedin Repurposer

sergebulaev
CommunityPopular

Repurpose existing content into a native LinkedIn post. Take a tweet, thread, YouTube video, blog, or newsletter and rebuild it for LinkedIn: re-hook before the fold, expand to the 900 to 1300 char…

456
2.6K
Instructions
View
cisco-ai-defense logo

Unbounded Data Analyzer

cisco-ai-defense
OrganizationPopular

Analyze an input repeatedly without a termination condition

321
2.5K
2 files
View
Bitterbot-AI logo

Moltbook

Bitterbot-AI
OrganizationPopular

Participate in Moltbook — the social network for AI agents. Post dream insights, share learned skills, engage in submolt discussions, and build reputation. Use when your human asks you to post on…

418
2.5K
Instructions
View
wgpsec logo

Aws Iam Privesc

wgpsec
OrganizationPopular

AWS IAM 权限提升专项方法论。当已获取 AWS 凭据并需要提升权限、发现当前 IAM 用户/角色权限有限需要横向或纵向提权、或需要分析 IAM Policy 寻找提权路径时使用。覆盖 46 个 AWS 服务的提权技术,包括 PassRole 滥用、AssumeRole 链式提权、Lambda/EC2/ECS 计算服务提权、以及 NotAction 隐式权限利用

242
1.7K
3 files
View
secondsky logo

Sap Btp Cloud Logging

secondsky
Community

This skill provides comprehensive guidance for SAP Cloud Logging service on SAP BTP. Use when setting up Cloud Logging instances, configuring log ingestion from Cloud Foundry or Kyma runtimes,…

117
445
8 files
View
waynesutton logo

Convex Security Audit

waynesutton
Community

Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations

32
404
3 files
View
giuseppe-trisciuoglio logo

Aws Cloudformation Iam

giuseppe-trisciuoglio
Community

Provides AWS CloudFormation patterns for IAM roles, policies, managed policies, permission boundaries, and trust relationships. Use when modeling least-privilege access, cross-account assumptions,…

41
345
2 files
View
aj-geddes logo

Api Changelog Versioning

aj-geddes
Community

Document API changes, breaking changes, migration guides, and version history for APIs. Use when documenting API versioning, breaking changes, or creating API migration guides.

55
340
7 files
View
blacklanternsecurity logo

Kerberos Roasting

blacklanternsecurity
Organization

Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.

39
276
Instructions
View
omer-metin logo

Ai Code Security

omer-metin
Community

Security vulnerabilities in AI-generated code and LLM applications, covering OWASP Top 10 for LLMs, secure coding patterns, and AI-specific threat modelsUse when "ai code security, llm…

22
152
3 files
View
trilwu logo

Devirtualizing Vm Protected Code

trilwu
Community

Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher,…

15
144
Instructions
View
Houseofmvps logo

Grow

Houseofmvps
Community

Post-Ship Growth Intelligence — track how your shipped product is performing. Use when user wants to check growth metrics, SEO trajectory, uptime, deploy frequency, or overall project health over…

14
122
Instructions
View
jonathimer logo

Developer Email Sequences

jonathimer
Community

When the user wants to create email sequences for developers including onboarding, product updates, re-engagement, or changelog communications. Trigger phrases include "developer emails," "onboarding…

6
87
Instructions
View
simota logo

Cast

simota
Community

Casting personas: rapid generation from diverse inputs, registry-based persistence and lifecycle, data-driven evolution, inter-agent sync. Not for UI walkthroughs (Echo) or user research (Field).

14
80
16 files
View
seaworld008 logo

Arena

seaworld008
Community

Specialist orchestrating codex exec / Antigravity CLI through dual paradigms — COMPETE (multi-variant comparison, select best) and COLLABORATE (decompose tasks across engines, integrate). Supports…

11
70
11 files
View
brucesongs logo

Anti Forensics

brucesongs
Community

Anti-forensics is the offensive counterpart to digital forensics.

18
70
12 files
View
kaivyy logo

Perseus Logic

kaivyy
Community

Business logic, race conditions, and AI security analysis

14
68
Instructions
View
JuliusBrussee logo

Caveman Review

JuliusBrussee
CommunityPopular

Compressed code review - one line per finding with location, problem and fix. Use for /caveman-review, "review this PR", or "review the diff".

6.2K
106.3K
Instructions
View
mukul975 logo

Analyzing Certificate Transparency For Phishing

mukul975
CommunityPopular

Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.

4K
32.9K
2 files
View
prowler-cloud logo

Prowler Ci

prowler-cloud
OrganizationPopular

Helps with Prowler repository CI and PR gates (GitHub Actions workflows). Trigger: When investigating CI checks failing on a PR, PR title validation, changelog gate/no-changelog label, conflict marker…

2.4K
14.8K
Instructions
View
trailofbits logo

Ton Vulnerability Scanner

trailofbits
OrganizationPopular

Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. Use when auditing FunC…

611
7.1K
3 files
View
AIPentest logo

Pentest Output Standards

AIPentest
OrganizationPopular

输出规范:中文分析,思维链,漏洞报告模板,负结果,黑板状态总览,改动台账,死锁突破。 Use when reporting findings, maintaining change ledger, or formatting pentest output.

1.2K
6.9K
Instructions
View
Tencent logo

Unexpected Code Execution Detection

Tencent
OrganizationPopular

Detect command injection, eval/exec usage, remote execution, or arbitrary code loading.

594
6.4K
Instructions
View
czlonkowski logo

N8n Validation Expert

czlonkowski
CommunityPopular

Interpret validation errors and guide fixing them. Use when encountering validation errors, validation warnings, false positives, operator structure issues, or need help understanding validation…

1K
6.2K
3 files
View
SnailSploit logo

Offensive Anti Forensics

SnailSploit
CommunityPopular

Anti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux…

775
6K
Instructions
View
awarexone logo

Triage Validation

awarexone
OrganizationPopular

Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity…

868
4.9K
Instructions
View
gotalab logo

Kiro Steering

gotalab
CommunityPopular

Manage {{KIRO_DIR}}/steering/ as persistent project knowledge

283
3.7K
Instructions
View
markdown-viewer logo

Security

markdown-viewer
OrganizationPopular

Create security architecture diagrams using PlantUML syntax with identity, encryption, firewall, and compliance stencil icons. Best for IAM flows, zero-trust models, encryption pipelines, and threat…

190
3.3K
8 files
View
aws logo

Threat Modeling With Aws Security Agent

aws
OrganizationPopular

Run an AWS Security Agent threat model review on spec/design documents. Use when the user asks to review a spec for security, run a threat model, check if a design introduces security risks, review…

311
2.7K
Instructions
View
cisco-ai-defense logo

File Validator

cisco-ai-defense
OrganizationPopular

Validate a filename extension without opening any filesystem path

321
2.5K
2 files
View
yaklang logo

Attack Surface Mapping

yaklang
OrganizationPopular

Draw a testable attack surface from one authorized target URL or one application. Use when the user says 攻击面, 供给面, 画攻击面, map the surface, application recon, find the business host, JS inventory, or…

292
2.2K
1 files
View
wgpsec logo

Aws Pentesting

wgpsec
OrganizationPopular

AWS 云环境渗透测试总体方法论。当目标使用 AWS 云服务、发现 AWS 相关资产(S3 Bucket/EC2 实例/Lambda 函数/CloudFront 分发)、获取 AWS 凭据(AK/SK/Session Token/IAM Role)、或需要对 AWS 环境进行安全评估时使用。提供从未授权枚举到提权、后渗透、持久化的全流程攻击决策树,引导到专项技能深入。覆盖 47+ AWS…

242
1.7K
2 files
View
agent0ai logo

Backend Reference

agent0ai
OrganizationPopular

Read-only reference for the backend contracts that the frontend depends on, including routing, APIs, auth, layers, and module resolution.

323
1.4K
Instructions
View
RefoundAI logo

Competitive Strategy

RefoundAI
OrganizationPopular

Help users identify sources of durable competitive power, evaluate market threats, and design products that are uniquely differentiated rather than just better versions of existing tools.

170
1.3K
2 files
View
davekilleen logo

Tech Debt

davekilleen
Community

Use when technical debt needs linked code or operational evidence, deduplication, first-seen provenance, or impact, effort, confidence, and cost-of-delay prioritization.

130
481
Instructions
View
waynesutton logo

Convex Security Check

waynesutton
Community

Quick security audit checklist covering authentication, function exposure, argument validation, row-level access control, and environment variable handling

32
404
3 files
View
jamditis logo

Zero Build Frontend

jamditis
Community

Zero-build frontend development for static apps, browser extensions, maps, and lightweight data-backed interfaces. Use when deployment must not require a build step.

64
397
10 files
View
blacklanternsecurity logo

Kerberos Ticket Forging

blacklanternsecurity
Organization

Forges Kerberos tickets for domain persistence and privilege escalation. Covers Golden Ticket (krbtgt hash → forged TGT), Silver Ticket (service hash → forged TGS), Diamond Ticket…

39
276
Instructions
View
Mindrally logo

Auth0 Authentication

Mindrally
Organization

Guidelines for implementing Auth0 authentication with best practices for security, rules, actions, and SDK integration

41
259
Instructions
View
trilwu logo

Diffing Binary Patches

trilwu
Community

Locate the vulnerability a security patch fixes by diffing the pre- and post-patch binaries — using BinDiff, Diaphora, or ghidriff to find the changed functions, reading the added checks to recover…

15
144
Instructions
View
happycapy-ai logo

Claude Code Templates

happycapy-ai
Community

CLI tool for configuring and monitoring Claude Code with a comprehensive collection of 600+ AI agents, 200+ custom commands, 55+ external service integrations (MCPs), 60+ settings, 39+ hooks, and 14+…

30
138
Instructions
View
Houseofmvps logo

Guard

Houseofmvps
Community

Safety guardrails — blocks destructive commands (rm -rf, DROP TABLE, force-push, git reset --hard) and optionally restricts file edits to a specific directory. Use when working on critical systems or…

14
122
Instructions
View
HermeticOrmus logo

Nodejs Backend Patterns

HermeticOrmus
Community

Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices. Use when…

18
104
Instructions
View
agent-skills-hub logo

API Fuzzing For Bug Bounty

agent-skills-hub
Organization

This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or…

35
101
Instructions
View
dykyi-roman logo

Api Design Knowledge

dykyi-roman
Community

API Design knowledge base. Provides REST constraints, Richardson Maturity Model, HTTP semantics, content negotiation, and GraphQL/gRPC comparison for API audits and generation.

25
98
3 files
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇