Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 868-918 of 1,735 AI skills

AI skills directory results

zhaoxuya520 logo

Competition Linux Credential Pivot

zhaoxuya520
CommunityPopular

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Linux credential artifacts, service tokens, SSH material, cloud and container secrets, socket-level trust, and…

5K
36.3K
2 files
View
mukul975 logo

Analyzing Docker Container Forensics

mukul975
CommunityPopular

Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.

4K
32.9K
2 files
View
RightNow-AI logo

Data Pipeline

RightNow-AI
OrganizationPopular

Data pipeline expert for ETL, Apache Spark, Airflow, dbt, and data quality

2.3K
18.2K
Instructions
View
prowler-cloud logo

Prowler Readme Table

prowler-cloud
OrganizationPopular

Updates the "Prowler at a Glance" table in README.md with accurate provider statistics. Trigger: When updating README.md provider stats, checks count, services count, compliance frameworks, or…

2.4K
14.8K
Instructions
View
spinabot logo

Himalaya

spinabot
OrganizationPopular

CLI to manage emails via IMAP/SMTP. Use `himalaya` to list, read, write, reply, forward, search, and organize emails from the terminal. Supports multiple accounts and message composition with MML…

50
4.4K
2 files
View
davidondrej logo

Create Readonly Db Role

davidondrej
CommunityPopular

Set up read-only PostgreSQL access for agents. Use only when the user explicitly invokes /create-readonly-db-role.

599
4.1K
1 files
View
Netw0rkNoob logo

Redteam Code Audit Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized source code security review, including dangerous function tracing, data-flow analysis, logic flaw detection, and dependency review. Use when a task…

454
3.4K
1 files
View
cisco-ai-defense logo

Weather Assistant

cisco-ai-defense
OrganizationPopular

Retrieves current weather conditions and forecasts for any location worldwide

321
2.5K
Instructions
View
trpc-group logo

Healthcheck

trpc-group
OrganizationPopular

Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron…

309
1.8K
Instructions
View
open-mercato logo

Om Judge Agent Session

open-mercato
OrganizationPopular

Judge generated Open Mercato code from a standalone harness eval or a user-shared agent session bundle. Use for LLM-as-judge validation, generative eval review, session/artifact analysis,…

415
1.8K
6 files
View
wgpsec logo

Cloud Metadata

wgpsec
OrganizationPopular

云元数据利用。当通过 SSRF 或已获取的 shell 可以访问云实例元数据服务时使用。覆盖 AWS/Azure/GCP/阿里云/腾讯云的元数据端点、IAM/CAM 凭据提取、IMDSv2 绕过、从元数据到云服务枚举的完整攻击链。发现任何 SSRF 场景、内网可访问 169.254.169.254 或 100.100.100.200 的场景都应使用此技能

242
1.7K
3 files
View
uphiago logo

Firebase Supabase Attack

uphiago
CommunityPopular

Exploit Firebase/Supabase for data via JS config leak probe.

213
1.3K
Instructions
View
fcakyon logo

Hetzner Deploy

fcakyon
CommunityPopular

This skill should be used when user asks to "deploy to Hetzner", "create Hetzner server", "manage Hetzner Cloud", "hcloud CLI", or works with Hetzner Cloud infrastructure including servers, networks,…

109
1.1K
20 files
View
oliver-kriska logo

Document

oliver-kriska
Community

Generate @moduledoc/@doc for tested Elixir features; may update their README section or ADR. Not for docs lookup, documentation audits/reviews, or capturing standalone decisions.

40
555
4 files
View
aj-geddes logo

Api Security Hardening

aj-geddes
Community

Secure REST APIs with authentication, rate limiting, CORS, input validation, and security middleware. Use when building or hardening API endpoints against common attacks.

55
340
4 files
View
mizchi logo

Formal Methods Reconciler

mizchi
Community

Use when reconciling software specs, docs, tests, configs, code, logs, or incidents with formal methods. Helps Codex extract claims, decide whether docs or implementation are the source of truth,…

4
333
10 files
View
Mathews-Tom logo

Devils Advocate

Mathews-Tom
Community

Challenges AI-generated plans, code, and designs via pre-mortem, inversion, and Socratic questioning to surface blind spots and failure modes. Triggers on: "challenge this", "devils advocate", "stress…

47
318
4 files
View
blacklanternsecurity logo

Container Escapes

blacklanternsecurity
Organization

Container escape, Docker breakout, and Kubernetes exploitation.

39
276
Instructions
View
seb1n logo

Code Review

seb1n
Community

Perform thorough code reviews on files or pull requests, checking for bugs, security vulnerabilities, performance issues, and style violations. Use when the user requests code review or provides…

35
188
Instructions
View
trilwu logo

Reversing Network Protocols

trilwu
Community

Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums…

15
144
Instructions
View
jh941213 logo

Harness Audit

jh941213
Community

하네스(hooks, skills, agents, rules) 전체 건강도를 진단하고 점수 산출. 대상: ~/.claude 전역 하네스 (프로젝트 진단은 harness-diagnostics). Triggers on: harness audit, 하네스 진단, 설정 점검, 하네스 점검. NOT for: 코드 작성, 구현.

35
125
Instructions
View
Houseofmvps logo

Release

Houseofmvps
Community

Generate changelog from commits, bump version, create GitHub release, publish to npm. Use when user wants to release, publish, or ship a new version.

14
122
Instructions
View
dykyi-roman logo

Changelog Template

dykyi-roman
Community

Generates CHANGELOG.md files following Keep a Changelog format. Creates version history documentation.

25
98
Instructions
View
simota logo

Experiment

simota
Community

Designing A/B tests: hypothesis docs, sample size, feature flags, significance analysis, CUPED, SRM detection, switchback experiments. Use when hypothesis validation is needed.

14
80
14 files
View
AsyrafHussin logo

Technical Debt

AsyrafHussin
Community

Technical debt inventory, prioritization, and audit for PHP/Laravel (MySQL) and Node/TypeScript/React projects. Use when assessing code health, identifying refactoring candidates, planning debt…

10
78
46 files
View
nahisaho logo

Security Auditor

nahisaho
Community

security-auditor skill Trigger terms: security audit, vulnerability scan, OWASP, security analysis, penetration testing, security review, threat modeling, security best practices, CVE Use when: User…

7
77
3 files
View
elastic logo

Docs Skill Review

elastic
Organization

Review an Elastic agent skill against official documentation for accuracy, completeness, and coverage gaps. Use when a writer wants to review, audit, or validate a skill from a repository of agent…

10
71
1 files
View
brucesongs logo

Bluetooth Rfid Nfc

brucesongs
Community

Near-field wireless penetration testing skills covering Bluetooth Classic device enumeration and exploitation, BLE GATT service attacks against IoT devices, RFID card cloning (MIFARE Classic/DESFire),…

18
70
12 files
View
addyosmani logo

Source Driven Development

addyosmani
CommunityPopular

Grounds every implementation decision in official documentation. Use when you want to verify an approach against the official docs before implementing it, or when you want authoritative, source-cited…

10.1K
95.8K
Instructions
View
github logo

Arize Ai Provider Integration

github
OrganizationPopular

Creates, reads, updates, and deletes Arize AI integrations that store LLM provider credentials used by evaluators and other Arize features. Supports any LLM provider (e.g. OpenAI, Anthropic, Azure…

5K
39.1K
2 files
View
zhaoxuya520 logo

Competition Lsass Ticket Material

zhaoxuya520
CommunityPopular

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for LSASS-resident secrets, Windows logon sessions, Kerberos ticket caches, DPAPI-backed material, SSP artifacts, and…

5K
36.3K
2 files
View
mukul975 logo

Analyzing Email Headers For Phishing Investigation

mukul975
CommunityPopular

Parse and analyze email headers (Received chain, Return-Path, Message-ID) to trace the true origin of a phishing email and validate SPF, DKIM, and DMARC results to confirm or rule out sender spoofing.…

4K
32.9K
2 files
View
prowler-cloud logo

Prowler Sdk Check

prowler-cloud
OrganizationPopular

Creates Prowler security checks following SDK architecture patterns. Trigger: When creating or updating a Prowler SDK security check (implementation + metadata) for any provider (AWS, Azure, GCP, K8s,…

2.4K
14.8K
7 files
View
huggingface logo

Huggingface Vision Trainer

huggingface
OrganizationPopular

Trains and fine-tunes vision models for object detection (D-FINE, RT-DETR v2, DETR, YOLOS), image classification (timm models — MobileNetV3, MobileViT, ResNet, ViT/DINOv3 — plus any Transformers…

744
11.1K
11 files
View
tech-leads-club logo

Technical Design Doc Creator

tech-leads-club
OrganizationPopular

Creates comprehensive Technical Design Documents (TDD) with mandatory and optional sections through interactive discovery. Use when user asks to "write a design doc", "create a TDD", "technical spec",…

530
6.3K
Instructions
View
SnailSploit logo

Offensive Lateral Movement

SnailSploit
CommunityPopular

Comprehensive lateral movement tradecraft for authorized red team engagements covering credential-based movement (pass-the-hash, pass-the-ticket, overpass-the-hash), NTLM relay attacks (ntlmrelayx…

775
6K
Instructions
View
internet-court logo

Agent Wallet

internet-court
OrganizationPopular

Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection. Encrypted keystore (AES-256-GCM, scrypt KDF), policy file the agent has no tool…

106
5.8K
Instructions
View
elementalsouls logo

Hunt Dom

elementalsouls
CommunityPopular

Hunt client-side DOM vulnerabilities — DOM Clobbering (overwrite JS globals via HTML injection), PostMessage hijacking (missing origin check), Service Worker abuse (intercept requests from same-origin…

678
4.5K
Instructions
View
Netw0rkNoob logo

Redteam Container Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized container and orchestration security testing, including Docker escape, Kubernetes privilege escalation, image vulnerabilities, and service mesh…

454
3.4K
1 files
View
jeremylongshore logo

Hyperflow Deploy

jeremylongshore
CommunityPopular

Hyperflow ship phase. Use when the user is ready to release — verbs like ship, push, release, deploy, "cut a release", "ready to push". Runs pre-push gates (lint + typecheck + build + tests + security…

402
2.8K
Instructions
View
aws logo

Amazon Bedrock

aws
OrganizationPopular

Builds generative AI applications on Amazon Bedrock. Covers model invocation (Converse API, InvokeModel), RAG with Knowledge Bases, Bedrock Agents, Guardrails, and AgentCore (including the Harness…

311
2.7K
33 files
View
cisco-ai-defense logo

Prompt Injection Test

cisco-ai-defense
OrganizationPopular

A test skill with prompt injection patterns

321
2.5K
Instructions
View
xu-xiang logo

Security Review

xu-xiang
CommunityPopular

在添加身份验证、处理用户输入、操作机密信息(Secrets)、创建 API 端点以及实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。

318
1.9K
1 files
View
wgpsec logo

Docker Pentesting

wgpsec
OrganizationPopular

Docker 安全测试与容器渗透方法论。当需要评估 Docker 容器、Docker Daemon、Docker Registry、镜像层、构建产物或容器逃逸风险时使用。覆盖容器环境识别、特权容器逃逸、docker.sock/Remote API 利用、procfs/cgroup/capabilities 滥用、Docker 用户组提权、运行时/内核 CVE、Registry 枚举、镜像层…

242
1.7K
3 files
View
codeaholicguy logo

Security Review

codeaholicguy
CommunityPopular

AI DevKit · Review code, skills, and prompts for security vulnerabilities — OWASP Top 10, prompt injection, business logic flaws, and insecure defaults. Use when reviewing PRs, auditing modules,…

252
1.6K
2 files
View
CloudAI-X logo

Security Patterns

CloudAI-X
CommunityPopular

Implements authentication, authorization, encryption, secrets management, and security hardening patterns. Use when designing auth flows, managing secrets, configuring CORS, implementing rate…

188
1.4K
Instructions
View
first-fluke logo

Oma Qa

first-fluke
OrganizationPopular

Review changes for correctness, security, accessibility, and performance. Use for scoped quality reviews or verification plans; bug fixes use oma-debug.

149
1.3K
5 files
View
amElnagdy logo

Woo Guard

amElnagdy
CommunityPopular

Review generated or changed WooCommerce code — extensions, payment and shipping integrations, checkout customizations, and order/product logic — before it ships. Best used reactively after an agent…

141
1.2K
5 files
View
BankrBot logo

Aeon Skill Security Scan

BankrBot
OrganizationPopular

Audit installed Bankr skills before you run them — scan SKILL.md and companion scripts for shell injection, secret exfiltration, path traversal, prompt-override payloads, destructive commands, and…

622
1.2K
1 files
View
jezweb logo

Project Health

jezweb
CommunityPopular

All-in-one project configuration and health management. Sets up new projects (settings.local.json, CLAUDE.md, .gitignore), audits existing projects (permissions, context quality, MCP coverage, leaked…

102
1K
5 files
View
codewithmukesh logo

Health Check

codewithmukesh
Organization

Multi-dimensional health assessment for .NET projects with letter grades (A-F) using Roslyn MCP tools. Evaluates 8 dimensions: build health, code quality, architecture, test coverage, dead code, API…

170
721
1 files
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇