Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 52-102 of 1,735 AI skills

AI skills directory results

brianlovin logo

Agent Browser

brianlovin
Community

Browser automation CLI for AI agents. Use when the user needs to interact with websites, including navigating pages, filling forms, clicking buttons, taking screenshots, extracting data, testing web…

31
370
Instructions
View
Mathews-Tom logo

Adr Writer

Mathews-Tom
Community

Generates Architecture Decision Records capturing context, rationale, alternatives, and consequences in numbered status-tracked format. Triggers on: "write an ADR", "document this decision",…

47
318
5 files
View
Narwhal-Lab logo

C To Ast

Narwhal-Lab
Organization

Parse C source code into an Abstract Syntax Tree (AST). Use when analyzing C programs, understanding code structure, performing static analysis, or preparing code for further program analysis (e.g.,…

24
317
6 files
View
blacklanternsecurity logo

<Skill Name>

blacklanternsecurity
Organization

<What this skill does in 2-3 sentences. Focus on technique scope and when to use it. No trigger phrases, negative conditions, or OPSEC details here.>

39
276
Instructions
View
speakeasy-api logo

Add Existing Mcp Servers

speakeasy-api
Organization

Use when adding existing remote MCP servers from a local client inventory to an explicit Speakeasy AI Control Plane project, including discovering which servers are missing.

33
269
Instructions
View
jamesrochabrun logo

Anthropic Architect

jamesrochabrun
Community

Determine the best Anthropic architecture for your project by analyzing requirements and recommending the optimal combination of Skills, Agents, Prompts, and SDK primitives.

25
209
4 files
View
oasm-platform logo

Command Execution

oasm-platform
Organization

Execute security scanning commands on remote worker agents. Use when you need to run CLI tools like nmap, subfinder, httpx, nuclei, or any shell command on worker nodes.

30
192
Instructions
View
trilwu logo

Analyzing Binaries

trilwu
Community

Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. Use when analyzing an executable, ELF/PE/Mach-O…

15
144
Instructions
View
Houseofmvps logo

A11y

Houseofmvps
Community

Accessibility audit + auto-fix (WCAG 2.2 A/AA). Scans built/static HTML for screen-reader, keyboard, and structure failures, fixes the deterministic ones, and escalates to a rendered scan for contrast…

14
122
Instructions
View
MADTeacher logo

Agents Md Generator

MADTeacher
Community

Create, generate, update, repair, trim, or split minimal AGENTS.md files for repository roots and confirmed nested modules using progressive disclosure. Use for missing, bloated, contradictory, or…

20
109
2 files
View
solanabr logo

Solana Ai Kit

solanabr
Organization

Skill hub for the solana-ai-kit Claude Code plugin. Routes the bundled go-to-market skills and the opt-in add-on catalog, and points to upstream marketplaces (and the install.sh full install) for…

59
104
4 files
View
olorehq logo

Olore A2a Latest

olorehq
Organization

Local A2A (Agent-to-Agent) protocol documentation (latest). Use for agent communication, task management, streaming, push notifications, and enterprise-ready agent interoperability.

6
103
32 files
View
agent-skills-hub logo

Active Directory Attacks

agent-skills-hub
Organization

This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP…

35
101
1 files
View
AccessLint logo

Accessibility Audit

AccessLint
Organization

Whole site or product — a full web accessibility (a11y) audit against WCAG 2.2, following the WCAG-EM methodology. Defines scope, samples representative pages and flows, runs the automated tier…

14
99
Instructions
View
dykyi-roman logo

Access Control Knowledge

dykyi-roman
Community

Access Control knowledge base. Provides ACL, RBAC, ABAC, ReBAC models, multi-tenancy patterns, and PHP implementations (Symfony Voters, Laravel Gates) for security audits and generation.

25
98
2 files
View
wasintoh logo

Backend Engineer

wasintoh
Community

Supabase integration specialist. Handles database schema, authentication, Row Level Security (RLS), real-time subscriptions, and storage. Connects existing UI to real backend. Only called AFTER UI…

19
96
Instructions
View
squirrelscan logo

Audit Website

squirrelscan
Organization

Audit a website with the squirrelscan CLI and fix the findings in code. Runs SEO, performance, security, technical, content, accessibility, and 15 other rule categories (260+ rules), returns an…

10
89
4 files
View
mcouthon logo

Architecture

mcouthon
Community

Use when documenting architecture, understanding system structure, creating diagrams, or analyzing component relationships. Focuses on interfaces and high-level design. Triggers on: 'use architecture…

11
79
Instructions
View
wshaddix logo

Asp Net Core Identity Patterns

wshaddix
Community

Production-grade patterns for ASP.NET Core Identity in Razor Pages and web apps. Covers setup, customization, security hardening, auth flows, roles/claims, external providers, and integration best…

13
79
Instructions
View
AsyrafHussin logo

Api Design Patterns

AsyrafHussin
Community

RESTful API design, error handling, versioning, and best practices. Use when designing APIs, reviewing endpoints, implementing error responses, or setting up API structure. Triggers on "design API",…

10
78
42 files
View
brucesongs logo

5g 6g Telecom Attack Advanced

brucesongs
Community

Advanced 5G/6G telecom attacks covering 5G Core (SBA) exploitation, IMSI catcher evolution (5G Stingray), SIP/Diameter protocol attacks, Open RAN vulnerabilities, network slicing abuse, and early 6G…

18
70
9 files
View
LangConfig logo

Code Review

LangConfig
Organization

Systematic code review guidance covering best practices, security, performance, and maintainability. Use when reviewing code, checking PRs, or analyzing code quality.

19
69
Instructions
View
kaivyy logo

Perseus:Audit

kaivyy
Community

Use when analyzing components for vulnerabilities (Phase 2 - Parallel Analysis)

14
68
Instructions
View
usestrix logo

Application Security Testing

usestrix
OrganizationPopular

Application security testing (AppSec) across a whole product with Strix — decide which asset needs which test (source code, running web app, API, CI pipeline), run it, and turn the results into a…

6.9K
63.3K
Instructions
View
sickn33 logo

007

sickn33
CommunityPopular

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

6.8K
46.5K
15 files
View
Yeachan-Heo logo

Ask

Yeachan-Heo
CommunityPopular

Process-first advisor routing for Claude, Codex, Gemini, Antigravity, Grok, or Cursor via `omc ask`, with artifact capture and no raw CLI assembly

3.5K
39.2K
Instructions
View
mukul975 logo

Abusing Shadow Credentials For Privesc

mukul975
CommunityPopular

Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or Certipy, then authenticate via PKINIT to…

4K
32.9K
3 files
View
phuryn logo

Intended Vs Implemented

phuryn
CommunityPopular

The method for finding the gap between what a system is supposed to do and what the code actually does — the class of bug generic scanners miss because they have no model of intent. Defines what…

2.8K
26.4K
Instructions
View
tradecatlabs logo

Web3 Ai Tools

tradecatlabs
CommunityPopular

AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery.

1.6K
16.3K
Instructions
View
prowler-cloud logo

Ai Sdk 5

prowler-cloud
OrganizationPopular

Vercel AI SDK 5 patterns. Trigger: When building AI features with AI SDK v5 (chat, streaming, tools/function calling, UIMessage parts), including migration from v4.

2.4K
14.8K
Instructions
View
trailofbits logo

Audit Context Building

trailofbits
OrganizationPopular

Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an audit, threat model, or architecture review…

611
7.1K
5 files
View
Tencent logo

Cascading Failure Detection

Tencent
OrganizationPopular

Detect error propagation, chain failures, and single-point breakdowns that cascade across agent workflows.

594
6.4K
Instructions
View
SnailSploit logo

Offensive Api Abuse

SnailSploit
CommunityPopular

Advanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call…

775
6K
Instructions
View
FlorianBruniaux logo

Audit Codebase

FlorianBruniaux
CommunityPopular

Codebase health audit scoring 7 categories with progression plan

782
6K
Instructions
View
ageerle logo

Repository Investigation

ageerle
CommunityPopular

Investigate an unfamiliar repository before changing it. Use this whenever a coding task spans multiple modules, asks for architecture or root-cause analysis, names behavior whose implementation…

1.4K
5.7K
Instructions
View
zebbern logo

Active Directory Attacks

zebbern
CommunityPopular

This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP…

464
4.6K
1 files
View
elementalsouls logo

Bb Local Toolkit

elementalsouls
CommunityPopular

Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for THIS variant when you also need to resolve where tools, wordlists, and clones are…

678
4.5K
Instructions
View
spinabot logo

Apple Notes

spinabot
OrganizationPopular

Manage Apple Notes via the `memo` CLI on macOS (create, view, edit, delete, search, move, and export notes). Use when a user asks Brigade to add a note, list notes, search notes, or manage note…

50
4.4K
Instructions
View
inkeep logo

Codebase Wiki

inkeep
OrganizationPopular

How to work in a Codebase Wiki project (the `codebase-wiki` starter pack): an agent-authored, source-grounded wiki of the surrounding codebase. Read when the project has a `wiki/` knowledge base with…

279
4.2K
2 files
View
ljagiello logo

Ctf Crypto

ljagiello
CommunityPopular

Provides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP,…

380
3.3K
19 files
View
aaron-he-zhu logo

Conversion Signal Qa

aaron-he-zhu
CommunityPopular

Use when the user asks to "QA my conversion tracking before launch", "check my UTMs / pixel / event firing", "set up a tracking pre-flight", or "set the dedup rule so Meta and Google stop…

361
2.8K
2 files
View
jeremylongshore logo

Audit

jeremylongshore
CommunityPopular

Use when the user wants a code review on recent changes — quality, spec, security, or performance feedback. Triggers a multi-level (L1-L5) review with a standalone Reviewer; on NEEDS_FIX, offers to…

402
2.8K
7 files
View
supabase logo

Supabase

supabase
OrganizationPopular

Use when doing ANY task involving Supabase. Triggers: Supabase products (Database, Auth, Edge Functions, Realtime, Storage, Vectors, Cron, Queues); client libraries and SSR integrations (supabase-js,…

206
2.6K
3 files
View
cisco-ai-defense logo

Dynamic Code Compiler

cisco-ai-defense
OrganizationPopular

Compile caller-provided source text into an executable code object

321
2.5K
2 files
View
RevylAI logo

Greenlight

RevylAI
OrganizationPopular

Pre-submission compliance scanner for the Apple App Store and Google Play. Use this skill when reviewing iOS, macOS, tvOS, watchOS, visionOS, or Android app code (Swift, Objective-C, Kotlin, Java,…

145
2.4K
Instructions
View
Core-Mate logo

Opengui Coremate Install

Core-Mate
OrganizationPopular

Install the latest stable OpenGUI release into a DeepSeek Harness web profile on macOS. Use when the user asks to download, install, update, open, or verify OpenGUI for DSH.

111
1.8K
6 files
View
wgpsec logo

Ai Data Security

wgpsec
OrganizationPopular

AI 系统数据安全测试方法论。当需要评估 LLM/AI 系统的数据泄露风险、训练数据安全、 或 RAG/向量库数据完整性时触发。覆盖: System Prompt 泄露(元 Prompt/角色扮演/关键字定位)、 训练数据推导与提取、成员推断攻击、模型反演攻击、RAG 数据投毒、API 信息泄露、 级联幻觉攻击、外部数据源信息泄露。

242
1.7K
1 files
View
noobnooc logo

Wtf

noobnooc
CommunityPopular

Pre-launch and pre-commit audit for vibe coding projects. Use when asked to check whether a project is ready to ship, deploy, merge, or commit, especially for common AI-built app mistakes: broken…

129
1.4K
1 files
View
Dataojitori logo

Memory Audit Dead Data Purge

Dataojitori
CommunityPopular

死数据清洗。当一条记忆读不读你的行为都不会变、感悟没有现实锚点时使用。

167
1.4K
Instructions
View
BankrBot logo

1claw

BankrBot
OrganizationPopular

HSM-backed secret management for AI agents. Store API keys (including Bankr `bk_` keys), passwords, and credentials in an encrypted vault; retrieve them at runtime via MCP without keeping secrets in…

622
1.2K
3 files
View
codewithmukesh logo

Arch Check

codewithmukesh
Organization

Architecture conformance check: verifies an existing codebase against its declared architecture (VSA, Clean Architecture, DDD, Modular Monolith) — dependency direction, layer violations, module…

170
721
Instructions
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇