Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 970-1,020 of 1,735 AI skills

AI skills directory results

matlab logo

Simulink Requirements

matlab
Organization

Use this skill for all requirements-related work in a MATLAB MBSE project using the Requirements Toolbox (slreq). Covers creating and populating requirement sets, derivation links, test case…

32
179
10 files
View
jwynia logo

Story Idea Generator

jwynia
Community

Generate story concepts using a genre-first approach. Use when starting a new project, when brainstorming ideas, when a concept needs strengthening, or when you want to ensure emotional impact drives…

20
159
Instructions
View
trilwu logo

Reversing Unity Il2cpp

trilwu
Community

Reverse engineer Unity games and apps built with IL2CPP or Mono, using Il2CppDumper, Il2CppInspector, and dnSpy. Use when an APK or IPA contains global-metadata.dat, libil2cpp.so, UnityFramework, or…

15
144
Instructions
View
luongnv89 logo

Agent Config

luongnv89
Community

Create or update CLAUDE.md and AGENTS.md files following official best practices. Use when asked to create, audit, or improve agent config files (CLAUDE.md, AGENTS.md). Don't use for…

18
124
6 files
View
Houseofmvps logo

Revise Claude Md

Houseofmvps
Community

Audit and improve CLAUDE.md files in repositories. Use when user asks to check, audit, update, improve, or fix CLAUDE.md files. Scans for all CLAUDE.md files, evaluates quality against templates,…

14
122
3 files
View
einverne logo

Mongodb

einverne
Community

Guide for implementing MongoDB - a document database platform with CRUD operations, aggregation pipelines, indexing, replication, sharding, search capabilities, and comprehensive security. Use when…

24
121
Instructions
View
Factory-AI logo

Security Review

Factory-AI
Organization

Scan code changes for security vulnerabilities using STRIDE threat modeling, validate findings for exploitability, and output structured results for downstream patch generation. Supports PR review,…

15
111
Instructions
View
dykyi-roman logo

Check Access Control Model

dykyi-roman
Community

Analyzes PHP code for access control issues. Detects inline role checks, hardcoded permissions, mixed ACL/RBAC models, missing Voter/Policy pattern, and authorization logic in controllers.

25
98
Instructions
View
simota logo

Flux

simota
Community

Refracting thinking by challenging assumptions, combining cross-domain knowledge, and shifting perspectives to reframe problems. Use for stuck situations or paradigm shifts. Does not write code.

14
80
20 files
View
jiaxiaojunQAQ logo

Deps Mgmt

jiaxiaojunQAQ
Community

Deep dependency management workflow—inventory, upgrade policy, security patches, licensing, lockfiles, and supply-chain hygiene. Use when upgrading frameworks, resolving CVEs, or standardizing how…

8
79
1 files
View
brucesongs logo

Ci Cd Supply Chain Attack

brucesongs
Community

CI/CD pipeline and software supply chain compromise covering Jenkins (script console, Jenkinsfile injection, shared library abuse, CVE-2024-23897 args4j), GitLab CI/CD (runner abuse, .gitlab-ci.yml…

18
70
12 files
View
mukul975 logo

Analyzing Heap Spray Exploitation

mukul975
CommunityPopular

Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address…

4K
32.9K
2 files
View
prowler-cloud logo

Prowler Test Sdk

prowler-cloud
OrganizationPopular

Testing patterns for Prowler SDK (Python). Trigger: When writing tests for the Prowler SDK (checks/services/providers), including provider-specific mocking rules (moto for AWS only).

2.4K
14.8K
4 files
View
tech-leads-club logo

Subagent Creator

tech-leads-club
OrganizationPopular

Guide for creating AI subagents with isolated context for complex multi-step workflows. Use when users want to create a subagent, specialized agent, verifier, debugger, or orchestrator that requires…

530
6.3K
Instructions
View
SnailSploit logo

Offensive Windows Privesc

SnailSploit
CommunityPopular

Comprehensive Windows privilege escalation methodology for offensive security engagements. Covers the full attack surface from a standard user shell to NT AUTHORITY\SYSTEM: token impersonation via…

775
6K
Instructions
View
zebbern logo

Ethical Hacking Methodology

zebbern
CommunityPopular

This skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance", "conduct security scanning", "exploit vulnerabilities",…

464
4.6K
Instructions
View
Netw0rkNoob logo

Redteam Csrf Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized CSRF testing, including token bypasses, SameSite bypasses, and JSON CSRF. Use when a task belongs to the CSRF testing domain and needs scope,…

454
3.4K
1 files
View
samber logo

Golang Popular Libraries

samber
CommunityPopular

Golang library and framework selection — vetted production-ready options by category (web, database, testing, logging, messaging), new and experimental stdlib packages, standard-library-first…

213
3.3K
4 files
View
xu-xiang logo

Springboot Security

xu-xiang
CommunityPopular

Spring Boot 服务的 Spring Security 身份验证/授权、验证、CSRF、密钥、响应头、速率限制和依赖项安全最佳实践。

318
1.9K
Instructions
View
trpc-group logo

Skill Creator

trpc-group
OrganizationPopular

Create or update AgentSkills, especially when a user wants the agent to learn a reusable capability, workflow, integration, domain rule, team process, or tool usage pattern for future tasks. Use when…

309
1.8K
3 files
View
open-mercato logo

Om System Extension

open-mercato
OrganizationPopular

Extend installed Open Mercato modules through UMES enrichers, interceptors, mutation guards, widgets, menus, entity extensions, events, component/page replacements, and overrides. Use for "extend…

415
1.8K
5 files
View
wgpsec logo

Gcp Workspace Pivot

wgpsec
OrganizationPopular

GCP 到 Google Workspace 的穿越攻击方法论。当已获取 GCP Service Account 或 Project 权限并发现目标组织使用 Google Workspace、需要从云平台穿越到企业邮件/文档/管理控制台、或发现 Domain-Wide Delegation 配置时使用。覆盖 Domain-Wide Delegation 滥用、OAuth…

242
1.7K
1 files
View
uphiago logo

Hardcoded Credential Hunt

uphiago
CommunityPopular

Detect hardcoded passwords in HTML forms, JavaScript, and API responses.

213
1.3K
Instructions
View
ww-w-ai logo

Pdca Watch

ww-w-ai
Organization

Live PDCA dashboard ticking every 30s — reads pdca-status.json + token-ledger.ndjson tail, renders fixed-width panel via CC /loop. Triggers: pdca watch, live dashboard, watch progress

154
601
Instructions
View
oliver-kriska logo

Examples

oliver-kriska
Community

Provide Phoenix, LiveView, Ecto, OTP, or Oban examples. Use when asked for sample code, a walkthrough, a proper implementation, or expected workflow output. Pair with domain skills. NOT for debugging,…

40
555
Instructions
View
mizchi logo

Frontend Review Deps

mizchi
Community

Use when auditing dependency health — outdated packages, CVE triage with attack-vector weighting, deprecated/declining library detection (trend-watch). Runs `audit-deps.sh` and `audit-trend-watch.sh`.…

4
333
Instructions
View
blacklanternsecurity logo

Pivoting Tunneling

blacklanternsecurity
Organization

Network pivoting, port forwarding, and tunneling through compromised hosts to reach internal networks.

39
276
Instructions
View
Kilo-Org logo

Azure Databricks

Kilo-Org
Organization

Expert knowledge for Azure Databricks development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations &…

168
179
6 files
View
datadog-labs logo

Dd Audit

datadog-labs
Organization

Audit Trail investigations - who changed what, key compromise, cost spike root cause, compliance evidence (SOC 2/PCI), and AI activity auditing.

28
172
1 files
View
bobmatnyc logo

Mpm Ticket Wizard

bobmatnyc
Community

Interactive ticket creation wizard with Q&A flow for bugs, features, tasks, and epics

34
152
5 files
View
trilwu logo

Reversing Xamarin Maui

trilwu
Community

Reverse engineer Xamarin and .NET MAUI mobile apps by extracting assemblies.blob and XALZ-compressed DLLs with pyxamstore, then decompiling with dnSpy or ILSpy. Use when an APK contains…

15
144
Instructions
View
luongnv89 logo

Appstore Review Checker

luongnv89
Community

Audit iOS/macOS apps against App Store Review Guidelines before submission, with evidence-backed verdicts and fixes. Don't use for Google Play, general code review, or rejection appeals.

18
124
10 files
View
Houseofmvps logo

Security Audit

Houseofmvps
Community

Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers. Use when user wants to harden their project.

14
122
Instructions
View
neo4j-contrib logo

Neo4j Security Skill

neo4j-contrib
Organization

Programmatic security management in Neo4j — RBAC/ABAC, user lifecycle (CREATE/ALTER/DROP USER), role lifecycle (CREATE/GRANT ROLE/DROP ROLE), privilege grants and denies (GRANT/DENY/REVOKE on graph,…

38
112
1 files
View
Factory-AI logo

Threat Model Generation

Factory-AI
Organization

Generate a STRIDE-based security threat model for a repository. Use when setting up security monitoring, after architecture changes, or for security audits.

15
111
1 files
View
brucesongs logo

Cloud Identity Attack

brucesongs
Community

Cloud identity provider attacks covering Azure AD/Entra ID, Okta, Auth0, Ping, AWS IAM Identity Center, and Google Workspace — including OAuth 2.0 token theft, OIDC redirect abuse, SAML response…

18
70
14 files
View
viralcode logo

Smtp Send

viralcode
Community

Send emails via SMTP with support for plain text, HTML, and attachments. Use when the user asks to send an email, email someone, or compose and send a message. Supports single recipients and can…

11
65
3 files
View
affaan-m logo

Quarkus Patterns

affaan-m
CommunityPopular

Patrones de arquitectura Quarkus 3.x LTS con Camel para mensajería, diseño de API RESTful, servicios CDI, acceso a datos con Panache y procesamiento asíncrono.

39.1K
261.1K
Instructions
View
anthropics logo

Plugin Settings

anthropics
OrganizationPopular

This skill should be used when the user asks about "plugin settings", "store plugin configuration", "user-configurable plugin", ".local.md files", "plugin state files", "read YAML frontmatter",…

23.8K
146.3K
7 files
View
googleworkspace logo

Gws Modelarmor Sanitize Prompt

googleworkspace
OrganizationPopular

Google Model Armor: Sanitize a user prompt through a Model Armor template.

1.8K
31K
Instructions
View
prowler-cloud logo

Prowler Test Ui

prowler-cloud
OrganizationPopular

E2E testing patterns for Prowler UI (Playwright). Trigger: When writing Playwright E2E tests under ui/tests in the Prowler UI (Prowler-specific base page/helpers, tags, flows).

2.4K
14.8K
1 files
View
Jeffallan logo

Graphql Architect

Jeffallan
CommunityPopular

Use when designing GraphQL schemas, implementing Apollo Federation, or building real-time subscriptions. Invoke for schema design, resolvers with DataLoader, query optimization, federation directives.

1.1K
11.5K
6 files
View
trailofbits logo

Entry Point Analyzer

trailofbits
OrganizationPopular

Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level (public,…

611
7.1K
9 files
View
SnailSploit logo

Offensive Osint

SnailSploit
CommunityPopular

Comprehensive OSINT methodology skill for offensive security, red team intelligence gathering, and bug bounty reconnaissance. Covers domain recon, email harvesting, social media profiling, GitHub/code…

775
6K
Instructions
View
zebbern logo

File Path Traversal

zebbern
CommunityPopular

This skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vulnerabilities",…

464
4.6K
Instructions
View
elementalsouls logo

Hunt Forgot Password

elementalsouls
CommunityPopular

Hunt Forgot Password / Account Recovery Authentication Flaws — 5 distinct patterns: (1) username enumeration via different responses for valid vs invalid email, (2) reset token exposed directly in the…

678
4.5K
Instructions
View
Netw0rkNoob logo

Redteam Cve Lookup

Netw0rkNoob
OrganizationPopular

CVE lookup and applicability assessment domain card. Use after reconnaissance has identified products, versions, services, or fingerprints and red-team mode needs evidence-based CVE matching before…

454
3.4K
1 files
View
openakita logo

Openakita/Skills@Code Review

openakita
CommunityPopular

Review code changes for correctness, security, and maintainability. Supports local git diffs (staged or working tree) and remote Pull Requests (by ID or URL). Use when the user asks to review code,…

277
2K
1 files
View
a5c-ai logo

Security Scanning

a5c-ai
OrganizationPopular

AgentShield security audit with 5 scanning categories, 102 static analysis rules, and optional red-team simulation.

106
1.8K
Instructions
View
wgpsec logo

Huawei Pentesting

wgpsec
OrganizationPopular

华为云渗透测试方法论。当目标使用华为云服务、发现 obs.*.myhuaweicloud.com 资产、获取华为云 AK/SK、在 ECS 实例内可访问 169.254.169.254 OpenStack 风格元数据、或需要对华为云 IAM/ECS/OBS/RDS/CCE/FunctionGraph 等服务进行安全评估时使用。覆盖 IAM 提权(OpenStack Keystone)、ECS…

242
1.7K
2 files
View
tjboudreaux logo

Thinking Thought Experiment

tjboudreaux
CommunityPopular

When a real test is too rare, large, or irreversible, run a controlled counterfactual: isolate one variable, fix conditions, trace the mechanistic chain, and bound what the result implies.

158
1.3K
Instructions
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇