Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 715-765 of 1,735 AI skills

AI skills directory results

blacklanternsecurity logo

Trust Attacks

blacklanternsecurity
Organization

Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation. Covers trust enumeration (nltest, PowerView, BloodHound), SID history…

39
276
Instructions
View
Mindrally logo

Aws Development

Mindrally
Organization

AWS development best practices for Lambda, SAM, CDK, DynamoDB, IAM, and serverless architecture using Infrastructure as Code.

41
259
Instructions
View
meta-quest logo

Hz Unity Fbx Import

meta-quest
Organization

Ensures complete FBX URLs or absolute paths are used when importing external 3D models into Unity projects targeting Meta Quest and Horizon OS. Use when adding FBX files, 3D models, or external…

17
195
1 files
View
trilwu logo

Mapping Attack Techniques

trilwu
Community

Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the…

15
144
Instructions
View
Houseofmvps logo

Launch

Houseofmvps
Community

Launch Day Autopilot — prepare everything for a product launch. Use when user wants to launch, go live, announce, or prepare for Product Hunt / Hacker News / social media launch.

14
122
Instructions
View
einverne logo

Gcloud

einverne
Community

Guide for implementing Google Cloud SDK (gcloud CLI) - a command-line tool for managing Google Cloud resources. Use when installing/configuring gcloud, authenticating with Google Cloud, managing…

24
121
1 files
View
neo4j-contrib logo

Neo4j Graphql Skill

neo4j-contrib
Organization

Build and configure a GraphQL API backed by Neo4j using @neo4j/graphql v7 (current) or v5 (LTS). Covers Neo4jGraphQL constructor, getSchema(), assertIndexesAndConstraints(), type definitions with…

38
112
1 files
View
simota logo

Compass

simota
Community

Navigating the skill ecosystem and guiding onboarding. Lists agents, recommends best fit for tasks. Don't use for task execution (Nexus), agent design (Architect).

14
80
11 files
View
wshaddix logo

Data Protection

wshaddix
Community

ASP.NET Core Data Protection API patterns for encryption, key management, and secure data handling in web applications. Use when protecting sensitive data at rest or in transit, managing encryption…

13
79
Instructions
View
AsyrafHussin logo

Project Docs

AsyrafHussin
Community

Project documentation lifecycle for PHP/Laravel and Node/TypeScript/React projects — bootstrapping essential docs, naming and folder conventions, freshness, and cleanup of AI-generated junk and stale…

10
78
29 files
View
serac-labs logo

Code Review

serac-labs
Organization

Review ServiceNow server-side scripts for ES5 violations, ACL/injection/XSS issues, N+1 queries, missing setLimit/error handling, hard-coded sys_ids, and business-rule recursion risks.

26
78
Instructions
View
nahisaho logo

Project Manager

nahisaho
Community

Copilot agent that assists with project planning, scheduling, risk management, and progress tracking for software development projects Trigger terms: project management, project plan, WBS, Gantt…

7
77
2 files
View
brucesongs logo

Autonomous Loops

brucesongs
Community

Performing repetitive enumeration across many targets - Running batch vulnerability scans on multiple hosts - Monitoring for changes in target environment - Executing attack chains that require…

18
70
17 files
View
bytedance logo

Skill Reviewer

bytedance
OrganizationPopular

Reviews DeerFlow skill packages for readiness, triggers, safety boundaries, resources, and evidence. Invoke when users ask to audit, grade, or production-check an existing skill.

11.4K
82.6K
6 files
View
sickn33 logo

Active Directory Attacks

sickn33
CommunityPopular

Provide comprehensive techniques for attacking Microsoft Active Directory environments. Covers reconnaissance, credential harvesting, Kerberos attacks, lateral movement, privilege escalation, and…

6.8K
46.5K
1 files
View
mukul975 logo

Analyzing Command And Control Communication

mukul975
CommunityPopular

Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom protocols to reverse-engineer beacon patterns, command structures, data encoding, and infrastructure (primary servers, fallback…

4K
32.9K
2 files
View
googleworkspace logo

Gws Gmail Read

googleworkspace
OrganizationPopular

Gmail: Read a message and extract its body or headers.

1.8K
31K
Instructions
View
prowler-cloud logo

Prowler Docs

prowler-cloud
OrganizationPopular

Prowler documentation style guide and writing standards. Trigger: When writing documentation for Prowler features, tutorials, or guides.

2.4K
14.8K
1 files
View
Jeffallan logo

Dotnet Core Expert

Jeffallan
CommunityPopular

Use when building .NET 8 applications with minimal APIs, clean architecture, or cloud-native microservices. Invoke for Entity Framework Core, CQRS with MediatR, JWT authentication, AOT compilation.

1.1K
11.5K
5 files
View
Tencent logo

Edgeone Clawscan

Tencent
OrganizationPopular

The first security skill to install after setting up OpenClaw — powered by Tencent Zhuque Lab. Works like an antivirus for your AI environment: audits installed skills, scans skills before…

594
6.4K
Instructions
View
browser-act logo

Amazon Search Listing

browser-act
OrganizationPopular

Amazon search and category listing scraper: extract product listings from any Amazon search results page, keyword search URL, or category browse page and return per-item cards (asin, title, url,…

295
5.9K
1 files
View
maziyarpanahi logo

Checking Hipaa Compliance

maziyarpanahi
CommunityPopular

Runs a HIPAA Privacy and Security Rule checklist over a data pipeline and produces a gap report before deploying OpenMed on PHI. Use when the user is about to process protected health information,…

677
5.3K
1 files
View
Netw0rkNoob logo

Redteam Cache Poison Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized web cache poisoning testing, including unkeyed headers, unkeyed parameters, cache deception, and CDN-specific behavior. Use when a task belongs to…

454
3.4K
1 files
View
samber logo

Golang Grpc

samber
CommunityPopular

Provides gRPC usage guidelines, protobuf organization, and production-ready patterns for Golang microservices. Use when implementing, reviewing, or debugging gRPC servers/clients, writing proto files,…

213
3.3K
3 files
View
aaron-he-zhu logo

Cold Outbound Sequencer

aaron-he-zhu
CommunityPopular

Use when the user asks to "build a B2B cold-outbound sequence", "design reply-triage branching", "plan a domain warmup / sending throttle", or "make my outbound CAN-SPAM / opt-in compliant"; produces…

361
2.8K
Instructions
View
rlaope logo

Omh Codebase Onboarding

rlaope
CommunityPopular

[omh] Hermes Codebase Onboarding workflow: create a repo map, reading path, glossary, risk map, and first-task runway for unfamiliar codebases. Use when the user says: codebase-onboarding, codebase…

194
2.7K
Instructions
View
cisco-ai-defense logo

Attacker Forwarding

cisco-ai-defense
OrganizationPopular

Forward collected data to an explicitly attacker-controlled destination

321
2.5K
2 files
View
redhat-et logo

Ripwire Security Scan

redhat-et
OrganizationPopular

Security review: (1) vet an untrusted SKILL.md or .mcp.json BEFORE installing it — the injection/exfiltration scanner; CRITICAL blocks the install; (2) audit code on an untrusted-input path (a…

141
2.2K
Instructions
View
wgpsec logo

Azure Pentesting

wgpsec
OrganizationPopular

Azure 云环境渗透测试总体方法论。当目标使用 Azure/Microsoft 365/Entra ID、发现 Azure 相关资产(Blob Storage/App Service/Azure VM/Azure Functions)、获取 Azure 凭据(Service Principal/Managed Identity/Access Token)、或需要对 Azure…

242
1.7K
2 files
View
uphiago logo

Deep Invade

uphiago
CommunityPopular

Deep pentest WP: SSRF, plugin CVE, JS mine, port scan chain.

213
1.3K
Instructions
View
majiayu000 logo

Auth Security

majiayu000
Community

OAuth 2.1 + JWT authentication security best practices. Use when implementing auth, API authorization, token management. Follows RFC 9700 (2025).

26
280
4 files
View
blacklanternsecurity logo

Password Spraying

blacklanternsecurity
Organization

Performs password spraying against authentication services with lockout-safe techniques. Works against AD (SMB/Kerberos/LDAP), SSH, web login forms, OWA, and any service with username/password auth.…

39
276
Instructions
View
jdrhyne logo

Ga4

jdrhyne
Community

Read Google Analytics 4 reporting data through the GA4 Data API. Use for explicit GA4 property metadata, compatible metric/dimension reports, traffic analysis, key events, quotas, and bounded exports.

30
240
5 files
View
team-telnyx logo

Telnyx Email Suppressions Curl

team-telnyx
Organization

Manage email suppressions (blocks), import and export suppression lists, and manage unsubscribe groups. Use for deliverability compliance and bounce handling.

21
217
1 files
View
Dynatrace logo

Dt Obs Log Semantic Mapping

Dynatrace
Organization

Suggest and validate semantic dictionary (SD) mappings for audit log integrations using raw vendor log payloads or live ingested events. Use when: mapping a vendor audit log feed, authentication logs,…

30
156
8 files
View
TerminalSkills logo

Ag2

TerminalSkills
Organization

You are an expert in AG2 (formerly AutoGen), the open-source multi-agent conversation framework. You help developers build systems where multiple AI agents collaborate through structured conversations…

21
155
1 files
View
trilwu logo

Orchestrating Vulnerability Research

trilwu
Community

Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh…

15
144
Instructions
View
Houseofmvps logo

Learn

Houseofmvps
Community

Manage project learnings across sessions. Save, search, recall, digest, prune, and export learnings that compound over time. Use when user wants to record, recall, or share project knowledge.

14
122
Instructions
View
HermeticOrmus logo

K8s Manifest Generator

HermeticOrmus
Community

Create production-ready Kubernetes manifests for Deployments, Services, ConfigMaps, and Secrets following best practices and security standards. Use when generating Kubernetes YAML manifests, creating…

18
104
5 files
View
wasintoh logo

Security Engineer

wasintoh
Community

Security-first auditing of AI-generated code — Level 1 quick checks during /toh-dev and /toh-test (hardcoded secrets, dangerous code execution, obvious injection vectors) and Level 2 full audits for…

19
96
Instructions
View
vanillagreencom logo

Project Management

vanillagreencom
Organization

Load to plan a cycle, audit issues, build a roadmap, or decompose research into issues.

31
80
22 files
View
reason-machines logo

Aube Package Manager

reason-machines
Organization

Expert guidance for using aube, a fast Rust-based Node.js package manager compatible with pnpm, npm, yarn, and bun lockfiles.

15
80
Instructions
View
zhaono1 logo

Qa Expert

zhaono1
Community

Quality assurance expert for testing strategies and quality gates. Use when planning test coverage, setting up QA processes, or improving quality standards.

12
79
5 files
View
vm0-ai logo

Finicity

vm0-ai
Organization

Use the platform-managed banking gateway backed by Finicity to list enabled bank accounts, balances, and transactions. Use when the user mentions Finicity, connected bank accounts, banking balances,…

18
76
Instructions
View
brucesongs logo

Av Edr Evasion

brucesongs
Community

AV/EDR evasion covers techniques for bypassing antivirus (AV) and Endpoint Detection/Response (EDR) solutions during payload delivery, execution, and post-exploitation.

18
70
16 files
View
mukul975 logo

Analyzing Cyber Kill Chain

mukul975
CommunityPopular

Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have…

4K
32.9K
2 files
View
alirezarezvani logo

Vendor Management

alirezarezvani
CommunityPopular

Use when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim flags, classifying…

3.7K
26.1K
7 files
View
RightNow-AI logo

Crypto Expert

RightNow-AI
OrganizationPopular

Cryptography expert for TLS, symmetric/asymmetric encryption, hashing, and key management

2.3K
18.2K
Instructions
View
prowler-cloud logo

Prowler Mcp

prowler-cloud
OrganizationPopular

Creates MCP tools for Prowler MCP Server. Covers BaseTool pattern, model design, and API client usage. Trigger: When working in mcp_server/ on tools (BaseTool), models…

2.4K
14.8K
3 files
View
AIPentest logo

Source Code Hunting

AIPentest
OrganizationPopular

源码狩猎:.git泄露,危险函数grep,JS RC4解混淆,semgrep/CodeQL,trufflehog,patch diff,供应链/CI。Use when hunting source leaks, secrets, JS deobfuscation, or supply-chain issues.

1.2K
6.9K
Instructions
View
Tencent logo

Edgeone Skill Scanner

Tencent
OrganizationPopular

Scan any agent skill for security risks before you install or use it. Powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). 100% local static analysis — no file contents or credentials leave your…

594
6.4K
Instructions
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇