Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 664-714 of 1,735 AI skills

AI skills directory results

elementalsouls logo

Hunt Cicd

elementalsouls
CommunityPopular

Hunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_request_target Pwnrequest + ${{ }}-into-shell), self-hosted runner poisoning, OIDC trust-policy abuse, Jenkins…

678
4.5K
Instructions
View
davepoon logo

Ai Search Visibility Audit

davepoon
CommunityPopular

Audit whether a website can be found, crawled, and cited by AI answer engines such as ChatGPT Search, Perplexity, Google AI Overviews, and Microsoft Copilot. Use when someone asks why their brand is…

509
3.5K
Instructions
View
Netw0rkNoob logo

Redteam Api Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized API security testing, including BOLA/IDOR, authentication bypass, mass assignment, missing rate limits, and GraphQL issues. Use when a task belongs…

454
3.4K
1 files
View
samber logo

Golang Gopls

samber
CommunityPopular

Golang semantic code intelligence via `gopls`, the official Go language server — go-to-definition, find references, call/implementation hierarchy, workspace symbol search, package API discovery,…

213
3.3K
5 files
View
cloudflare logo

Workers Best Practices

cloudflare
OrganizationPopular

Cloudflare Workers best practices for production applications. Use when writing, reviewing, or configuring Workers.

277
2.8K
3 files
View
cisco-ai-defense logo

Interpolated Database Query

cisco-ai-defense
OrganizationPopular

Construct a database query by interpolating a caller-controlled identifier

321
2.5K
2 files
View
tsingyuai logo

Screenshot Assets

tsingyuai
OrganizationPopular

Capture authenticated product screenshots through the repository-owned Playwright CDP script and archive them in the invoking loop's Memory. Use when content needs truthful UI evidence, reusable…

170
2K
2 files
View
wgpsec logo

Azure Ad Attack

wgpsec
OrganizationPopular

Azure AD / Entra ID 攻击方法论。当目标使用 Microsoft 365/Azure 云环境、发现 Azure AD 认证流程、或获取到 Azure 凭据时使用。覆盖初始访问(Password Spray/Phishing)、令牌窃取、Service Principal 滥用、条件访问绕过、跨租户攻击

242
1.7K
2 files
View
ww-w-ai logo

Code Review

ww-w-ai
Organization

Code review — analyze quality, detect bugs, ensure best practices with actionable feedback. Triggers: code review, quality check, bug detection

154
601
Instructions
View
levnikolaevich logo

Ln 42 Dependency Upgrader

levnikolaevich
Community

Upgrades dependencies in reversible batches with version-specific compatibility and regression checks.

84
565
Instructions
View
secondsky logo

Sap Btp Connectivity

secondsky
Community

SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Use when configuring destinations (HTTP, RFC,…

117
445
19 files
View
mizchi logo

Dep Lib Review

mizchi
Community

Periodic dependency review for Node.js/pnpm projects — outdated package triage, security audit, update batching strategy (patch/minor/major), validation checklist. Run monthly or before major…

4
333
Instructions
View
blacklanternsecurity logo

Sccm Exploitation

blacklanternsecurity
Organization

Enumerates and exploits Microsoft SCCM/MECM (System Center Configuration Manager / Microsoft Endpoint Configuration Manager) infrastructure for credential harvesting, lateral movement, and domain…

39
276
Instructions
View
LerianStudio logo

Ring:Reviewing Code

LerianStudio
Organization

Reviewing code by dispatching the default reviewer subagents in parallel (plus conditional specialists for lib-observability, lib-systemplane, or lib-streaming when the diff triggers them), then…

28
215
1 files
View
jamesrochabrun logo

Openai Prompt Engineer

jamesrochabrun
Community

Generate and improve prompts using best practices for OpenAI GPT-5 and other LLMs. Apply advanced techniques like chain-of-thought, few-shot prompting, and progressive disclosure.

25
209
4 files
View
TheBushidoCollective logo

Plan

TheBushidoCollective
Organization

Create tactical implementation plan for a feature or task

20
195
Instructions
View
bobmatnyc logo

Mpm Orchestrator

bobmatnyc
Community

Multi-Agent Project Manager orchestration - delegation patterns, agent types, and verification protocol

34
152
Instructions
View
yezannnnn logo

Senior Security

yezannnnn
Community

Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security…

49
149
5 files
View
trilwu logo

Maintaining Engagement State

trilwu
Community

Keep the durable record that outlives a session — credential provenance, access inventory, artifacts left on target for cleanup, findings with evidence, and a dead-end log — so work spanning days or…

15
144
Instructions
View
Houseofmvps logo

Investigate

Houseofmvps
Community

Root cause investigation — structured debugging with module freeze. No fixes without investigation. Use when encountering any bug, error, or unexpected behavior.

14
122
Instructions
View
mblode logo

Pr Reviewer

mblode
Community

Reviews a diff or security scope read-only using evidence-tiered findings, structural and context-error rubrics, and repository review policy. Use when asked to "review my changes", "structural…

11
118
8 files
View
agent-skills-hub logo

Api Security Best Practices

agent-skills-hub
Organization

Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities

35
101
Instructions
View
travisjneuman logo

Business Strategy

travisjneuman
Community

Business strategy expertise for strategic planning, competitive analysis, market entry, M&A strategy, portfolio management, and strategic decision-making. Use when analyzing competitive positioning,…

22
98
1 files
View
antoniolg logo

Learnworlds Cli

antoniolg
Community

Use the private LearnWorlds CLI to inspect DevExpert Academy users, find students by email, list their enrolled courses/products, look up products, and perform safe enrollment workflows. Trigger when…

16
97
1 files
View
dylantarre logo

Character Appeal

dylantarre
Community

Use when creating or animating characters that need to connect with audiences—hero protagonists, memorable villains, lovable sidekicks, or any figure that must have personality and presence.

12
84
Instructions
View
simota logo

Cloak

simota
Community

Engineering privacy and data governance: PII detection, data flow mapping, consent patterns, GDPR/CCPA-compliant implementation, DPIA. Use when privacy-by-design is needed.

14
80
9 files
View
mcouthon logo

Tech Debt

mcouthon
Community

Use when finding code smells, auditing TODOs, removing dead code, cleaning up unused imports, or assessing code quality. Triggers on: 'use tech-debt mode', 'tech debt', 'code smells', 'clean up',…

11
79
Instructions
View
brucesongs logo

Automotive Vehicle Security

brucesongs
Community

CAN/CAN-FD bus analysis, UDS diagnostics, IVI pentest, OBD-II exploitation, key fob replay/relay attacks, GNSS spoofing, EV charging station (ISO 15118), and connected vehicle red team operations.

18
70
17 files
View
kaivyy logo

Using Perseus

kaivyy
Community

Use when starting a security conversation to understand the Perseus methodology

14
68
Instructions
View
github logo

Anti Ui Slop

github
OrganizationPopular

Stop coding agents from shipping generic UI. Use UIZZE's 800,000+ real web and iOS screens to build product-specific interfaces, define a design contract, cover required states, and run a hard finish…

5K
39.1K
12 files
View
mukul975 logo

Analyzing Cobaltstrike Malleable C2 Profiles

mukul975
CommunityPopular

Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers,…

4K
32.9K
2 files
View
vercel-labs logo

Vercel Cli With Tokens

vercel-labs
OrganizationPopular

Deploy and manage projects on Vercel using token-based authentication. Use when working with Vercel CLI using access tokens rather than interactive login — e.g. "deploy to vercel", "set up vercel",…

2.8K
31.3K
Instructions
View
RightNow-AI logo

Compliance

RightNow-AI
OrganizationPopular

Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

2.3K
18.2K
Instructions
View
kubesphere logo

Kubesphere Multi Tenant Management

kubesphere
OrganizationPopular

KubeSphere multi-tenant management Skill. Use when user requests to create users, workspaces, projects, or assign roles/permissions. Supports user lifecycle management, workspace configuration,…

2.8K
17.1K
4 files
View
prowler-cloud logo

Prowler Compliance

prowler-cloud
OrganizationPopular

Creates, syncs, audits and manages Prowler compliance frameworks end-to-end. Covers the two supported JSON schemas (universal multi-provider and legacy per-provider), the SDK model tree (legacy…

2.4K
14.8K
16 files
View
Tencent logo

Aig Scanner

Tencent
OrganizationPopular

A.I.G Scanner — AI security scanning for infrastructure, AI tools / skills, AI Agents, and LLM jailbreak evaluation via Tencent Zhuque Lab AI-Infra-Guard. Uses built-in exec + Python script, no plugin…

594
6.4K
2 files
View
SnailSploit logo

Offensive Advanced Redteam

SnailSploit
CommunityPopular

Comprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2…

775
6K
Instructions
View
FlorianBruniaux logo

Diagnose

FlorianBruniaux
CommunityPopular

Interactive troubleshooting assistant for Claude Code issues

782
6K
Instructions
View
awarexone logo

Web3 Audit

awarexone
OrganizationPopular

Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill…

868
4.9K
Instructions
View
elementalsouls logo

Hunt Clickjacking

elementalsouls
CommunityPopular

Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons they cannot see (UI redressing).…

678
4.5K
Instructions
View
Netw0rkNoob logo

Redteam Auth Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized authentication, authorization, and session security testing, including password policy, JWT/token, OAuth, and MFA bypass issues. Use when a task…

454
3.4K
1 files
View
cisco-ai-defense logo

Unpinned Dependency

cisco-ai-defense
OrganizationPopular

Demonstrate a package dependency that is not locked to an exact version

321
2.5K
2 files
View
yaklang logo

Binary Protection Bypass

yaklang
OrganizationPopular

Binary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET, and MTE protections in ELF binaries to enable exploitation.

292
2.2K
1 files
View
wgpsec logo

Azure Hybrid Lateral

wgpsec
OrganizationPopular

Azure Cloud 到本地 AD 的横向移动方法论。当已获取 Azure/Entra ID 权限并需要穿越到本地 Active Directory 环境、发现目标使用 Azure AD Connect/Cloud Sync/PTA/Federation 等混合身份架构、或需要利用 PRT/Certificate/Cookie 等凭据进行 Cloud-to-OnPrem 横向时使用。覆盖 14…

242
1.7K
2 files
View
NeoLabHQ logo

Create Hook

NeoLabHQ
OrganizationPopular

Create and configure git hooks with intelligent project analysis, suggestions, and automated testing

159
1.7K
Instructions
View
rmyndharis logo

Backend Security Coder

rmyndharis
CommunityPopular

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

264
1.6K
Instructions
View
openonion logo

Review Pr

openonion
OrganizationPopular

Review GitHub pull requests. Use when user says "review PR", "review pull request", or "/review-pr".

218
1.5K
Instructions
View
oliver-kriska logo

Compound

oliver-kriska
Community

Capture solved problems as searchable solution docs. Use after fixing bugs, when "that worked", or after successful /phx:review or /phx:investigate.

40
555
1 files
View
giuseppe-trisciuoglio logo

Aws Cloudformation Security

giuseppe-trisciuoglio
Community

Provides AWS CloudFormation patterns for security infrastructure including KMS encryption, Secrets Manager, IAM security, VPC security, ACM certificates, parameter security, outputs, and secure…

41
345
3 files
View
aj-geddes logo

Api Gateway Configuration

aj-geddes
Community

Configure API gateways for routing, authentication, rate limiting, and request/response transformation. Use when deploying microservices, setting up reverse proxies, or managing API traffic.

55
340
7 files
View
mizchi logo

Dotenvx

mizchi
Community

Use when working with the `dotenvx` env-var management tool — encrypting .env files, juggling multiple environments (.env.production / .env.staging / .env.ci), committing encrypted secrets to git with…

4
333
3 files
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇