Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 766-816 of 1,735 AI skills

AI skills directory results

tech-leads-club logo

Render Deploy

tech-leads-club
OrganizationPopular

Deploy applications to Render by analyzing codebases, generating render.yaml Blueprints, and providing Dashboard deeplinks. Use when the user wants to deploy, host, publish, or set up their…

530
6.3K
10 files
View
SnailSploit logo

Offensive Iot

SnailSploit
CommunityPopular

IoT and embedded device security testing methodology. Covers hardware reconnaissance (UART, JTAG, SWD, SPI flash, I2C EEPROM, eMMC chip-off), firmware acquisition (vendor portals, OTA capture, flash…

775
6K
Instructions
View
browser-act logo

Ebay Item Detail

browser-act
OrganizationPopular

Extracts full item detail from any open eBay item URL, returning JSON with url, itemNumber, title, subTitle, categories, price, priceWithCurrency, currency, wasPrice, available, availableText, sold,…

295
5.9K
1 files
View
letta-ai logo

Self Configuration

letta-ai
OrganizationPopular

Inspect or modify Letta Code's own memory, model, context window, system prompt, compaction, permissions, toolsets, mods, skills, channels, schedules, agent secrets, and local runtime settings. Use…

411
3.4K
7 files
View
samber logo

Golang How To

samber
CommunityPopular

Golang skills orchestrator — always active on any Golang coding, review, debug, or setup task. Reads the task context and loads the most relevant skills from samber/cc-skills-golang, often multiple at…

213
3.3K
4 files
View
open-gitagent logo

Code Review

open-gitagent
OrganizationPopular

Reviews code diffs and files for security vulnerabilities (OWASP Top 10), error handling, complexity, naming conventions, and performance issues. Use when the user asks to review a PR, pull request,…

348
2.9K
Instructions
View
aaron-he-zhu logo

Email Quality Auditor

aaron-he-zhu
CommunityPopular

Use when the user asks to "audit an email program" or "is this campaign safe to send"; runs a typed 20-item SEND profile with authentication, consent, opt-out, and claim veto checks on own evidence.…

361
2.8K
1 files
View
cisco-ai-defense logo

External Instruction Follower

cisco-ai-defense
OrganizationPopular

Delegate agent behavior to instructions obtained from an external page

321
2.5K
2 files
View
trpc-group logo

Apple Notes

trpc-group
OrganizationPopular

Manage Apple Notes via the `memo` CLI on macOS (create, view, edit, delete, search, move, and export notes). Use when a user asks OpenClaw to add a note, list notes, search notes, or manage note…

309
1.8K
Instructions
View
wgpsec logo

Cicd Pipeline Attack

wgpsec
OrganizationPopular

CI/CD 流水线与供应链攻击方法论。当发现目标使用 GitHub Actions/Jenkins/GitLab CI/CircleCI/Terraform Cloud/Atlantis 等 CI/CD 系统、需要测试流水线安全性、或发现 .github/workflows/Jenkinsfile/.gitlab-ci.yml 等配置文件时使用。覆盖 PPE(Poisoned Pipeline…

242
1.7K
3 files
View
zubair-trabzada logo

Missing Protections Finder

zubair-trabzada
CommunityPopular

Identifies critical clauses and protections that should be in a contract but are missing, with urgency ratings and ready-to-insert language

387
1.7K
Instructions
View
tjboudreaux logo

Thinking Red Team

tjboudreaux
CommunityPopular

For authorized security review of code, auth, or APIs you control, model the attacker, map the attack surface, and report only findings with a reproducible exploit path and verified mitigation.

158
1.3K
Instructions
View
uphiago logo

Email Security

uphiago
CommunityPopular

DMARC/SPF/DKIM check, email spoofing, SMTP test, and security header analysis

213
1.3K
Instructions
View
oliver-kriska logo

Deps Audit

oliver-kriska
Community

Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. Use after mix deps.update, when checking if a package upgrade is safe, or reviewing…

40
555
78 files
View
glebis logo

Vault

glebis
Community

Set up and verify the CONFIDE THREE LOCKS for storing RED (real, identifiable) session data at rest — device FileVault, a dedicated encrypted store, and per-file sops/age encryption. Use when the user…

56
379
1 files
View
blacklanternsecurity logo

Red Run Ctf

blacklanternsecurity
Organization

Multi-phase penetration test orchestrator. Handles recon, assessment surface mapping, vulnerability chaining, and routes to technique skills for execution. Invoke via /red-run-ctf slash command only.

39
276
Instructions
View
seb1n logo

Oauth 2 0 Setup

seb1n
Community

Implement OAuth 2.0 authentication flows including authorization code with PKCE, client credentials, and device code for secure API integration. Use when the user requests oauth 2 0 setup or provides…

35
188
Instructions
View
trilwu logo

Reporting Security Findings

trilwu
Community

Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure.…

15
144
Instructions
View
instructa logo

Secleak Check

instructa
Organization

Run or install repo security leak checks with BetterLeaks and Trivy. Use when asked to scan for leaked secrets, vulnerable dependencies, misconfigurations, add secret-leak guardrails, add BetterLeaks,…

16
141
4 files
View
sendaifun logo

Lifi

sendaifun
Organization

Integrate LI.FI for cross-chain swaps, bridging, payments, route discovery, and transfer status tracking across Solana, EVM, Bitcoin, and Sui. Use when building Solana applications or AI agents that…

81
128
Instructions
View
dandye logo

Generate Thesaurus

dandye
Community

Generate controlled vocabulary thesaurus for content domains. Creates comprehensive thesauri with preferred terms, broader/narrower/related terms.

34
126
Instructions
View
jh941213 logo

Fastapi Templates

jh941213
Community

프로덕션 수준의 FastAPI 프로젝트 생성 및 설정 가이드. async 패턴, DI, 에러 핸들링 포함. 트리거: "FastAPI", "Python API 프로젝트", "FastAPI 프로젝트 생성", "FastAPI 템플릿", "FastAPI 설정" 안티-트리거: "Django", "Flask", "Node.js API", "Express", "기존…

35
125
Instructions
View
Houseofmvps logo

Onboard

Houseofmvps
Community

Instant Project Onboarding — generate a complete onboarding guide for any project. Use when user wants to onboard a new developer, understand a new codebase, or generate project documentation.

14
122
Instructions
View
HermeticOrmus logo

K8s Security Policies

HermeticOrmus
Community

Implement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC for production-grade security. Use when securing Kubernetes clusters, implementing network isolation, or…

18
104
2 files
View
travisjneuman logo

Compliance Engineering

travisjneuman
Community

SOC2, HIPAA, GDPR, PCI-DSS, FedRAMP compliance implementation in code. Audit logging, data encryption, access controls, privacy by design, and regulatory requirement mapping. Use when implementing…

22
98
Instructions
View
vasilyu1983 logo

Ai Coding Agents Settings Policy

vasilyu1983
Community

Designs settings and policy layers for coding-agent runtimes. Use when modeling source precedence, managed policy, env controls, or runtime settings validation.

19
87
10 files
View
simota logo

Crypt

simota
Community

Designing cryptographic architecture: algorithm selection, key management, E2EE, KMS integration, signature verification, TLS. Use when designing crypto protocols or key rotation flows.

14
80
8 files
View
mapbox logo

Mapbox Token Security

mapbox
Organization

Security best practices for Mapbox access tokens, including scope management, URL restrictions, rotation strategies, and protecting sensitive data. Use when creating, managing, or advising on Mapbox…

17
78
5 files
View
brucesongs logo

Binary Reverse

brucesongs
Community

Binary reverse engineering covers the complete chain from static analysis, dynamic debugging, to vulnerability discovery, exploit development, and malware analysis.

18
70
14 files
View
mukul975 logo

Analyzing Disk Image With Autopsy

mukul975
CommunityPopular

Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching,…

4K
32.9K
2 files
View
danielmiessler logo

ExtractWisdom

danielmiessler
CommunityPopular

Content-adaptive wisdom extraction that reads content first, detects which wisdom domains are present, and builds custom sections around them, with five depth levels and mandatory contrarian takes;…

2.5K
19K
1 files
View
prowler-cloud logo

Prowler Pr

prowler-cloud
OrganizationPopular

Creates Pull Requests for Prowler following the project template and conventions. Trigger: When working on pull request requirements or creation (PR template sections, PR title Conventional Commits…

2.4K
14.8K
1 files
View
Jeffallan logo

Fastapi Expert

Jeffallan
CommunityPopular

Use when building high-performance async Python APIs with FastAPI and Pydantic V2. Invoke to create REST endpoints, define Pydantic models, implement authentication flows, set up async SQLAlchemy…

1.1K
11.5K
6 files
View
android logo

Android Intent Security

android
OrganizationPopular

Best practices for Android Intent security. Use this skill when auditing component configurations in AndroidManifest.xml activities, services, receivers) or source code handling incoming Intents…

484
7.4K
Instructions
View
SnailSploit logo

Offensive Mobile

SnailSploit
CommunityPopular

Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with Frida and Objection,…

775
6K
Instructions
View
browser-act logo

Ebay Search Listing

browser-act
OrganizationPopular

Extracts product listings from any eBay search or category page URL, returning per-item cards (itemNumber, url, title, subtitle, caption, price, priceWithCurrency, currency, wasPrice, bids, shipping,…

295
5.9K
1 files
View
elementalsouls logo

Hunt Csrf

elementalsouls
CommunityPopular

Hunting skill for csrf vulnerabilities. Built from 15 public bug bounty reports including modern variants — SameSite=Lax sibling-subdomain bypass (Argo CD CVE-2024-22424), GraphQL mutations-via-GET…

678
4.5K
Instructions
View
davidondrej logo

Box Ascii

davidondrej
CommunityPopular

Operate Box by Ascii cloud VMs through its REST API, CLI, and SSH. Use for Box provisioning, environments, secrets, templates, snapshots, stop/resume/fork, or running BB and coding agents on…

599
4.1K
1 files
View
ericosiu logo

Video Content Engine

ericosiu
CommunityPopular

Diagnose and transform any authorized video URL, upload, recording, transcript, podcast, interview, presentation, screen recording, webinar, ad, or published video into the strongest justified content…

685
3.5K
11 files
View
Netw0rkNoob logo

Redteam Cloud Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized cloud security testing, including IAM misconfiguration, exposed storage, metadata services, and serverless injection. Use when a task belongs to the…

454
3.4K
1 files
View
antfu logo

Node Modules Inspector

antfu
CommunityPopular

Inspects a project's installed node_modules and produces three reports: duplicated packages (installed in multiple versions), packages sorted by install size, and maintenance actions (dep-upgrade…

89
2.9K
Instructions
View
jeremylongshore logo

Workflow

jeremylongshore
CommunityPopular

Use when a task is too large for turn-by-turn orchestration and should run through the big-task workflow lane: system-wide changes, large migrations, repo-wide audits, high-confidence verification, or…

402
2.8K
Instructions
View
aws logo

Agents Harden

aws
OrganizationPopular

Use when preparing your agent for production — IAM scoping, inbound auth (JWT, SigV4), secrets management, cold start optimization, session lifecycle, rate limiting, input validation, and quota…

311
2.7K
1 files
View
cisco-ai-defense logo

Remote Package Installer

cisco-ai-defense
OrganizationPopular

Install a Python package directly from an untrusted remote archive

321
2.5K
2 files
View
wgpsec logo

Cloud Aksk Exploit

wgpsec
OrganizationPopular

云凭据(AK/SK)泄露后的完整利用链。当通过信息泄露/.env文件/git泄露/SSRF元数据获取到云平台 Access Key 和 Secret Key 后使用。当获取到 AWS AKIA*/ASIA*、腾讯云 AKIDz*、阿里云 LTAI* 等凭据格式时使用。覆盖凭据配置→权限枚举→资源接管→后门持久化的完整攻击链。与 cloud-iam-audit(侧重策略分析)互补——本 skill…

242
1.7K
2 files
View
cbrock84 logo

Data Modeling

cbrock84
CommunityPopular

Designs the warehouse and semantic layer — source-to-mart structure, dimensional modeling, grain, slowly changing dimensions, and the metric layer analytics reads through. Use this to design or…

237
1.6K
1 files
View
RefoundAI logo

Enterprise Sales Motion

RefoundAI
OrganizationPopular

Help users build a robust enterprise sales engine by mastering founder-led discovery, navigating complex procurement cycles, and designing products that meet organizational governance needs.

170
1.3K
2 files
View
fcakyon logo

Setup

fcakyon
CommunityPopular

This skill should be used when the user asks "how to setup GitHub CLI", "configure gh", "gh auth not working", "GitHub CLI connection failed", "gh CLI error", or needs help with GitHub authentication.

109
1.1K
Instructions
View
jezweb logo

Github Release

jezweb
CommunityPopular

Prepare and publish GitHub releases. Sanitizes code for public release (secrets scan, personal artifacts, LICENSE/README validation), creates version tags, and publishes via gh CLI. Trigger with…

102
1K
2 files
View
oliver-kriska logo

Deps Update

oliver-kriska
Community

Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo). Use to upgrade/bump Elixir dependencies or when versions fall behind.…

40
555
4 files
View
jamditis logo

Fact Check Workflow

jamditis
Community

Structured fact-checking workflow. Use when verifying claims for publication, rating claims, or setting pre-publication checks.

64
397
1 files
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇