Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 1,021-1,071 of 1,735 AI skills

AI skills directory results

first-fluke logo

Oma Scm

first-fluke
OrganizationPopular

Manage Git branches, merges, conflicts, commits, and release baselines. Use for repository history and change-management operations.

149
1.3K
5 files
View
BankrBot logo

Aeon Vuln Scanner

BankrBot
OrganizationPopular

Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed…

622
1.2K
1 files
View
secondsky logo

Sap Datasphere

secondsky
Community

SAP Datasphere development skill with 3 specialized agents, 5 slash commands, and validation hooks. Use when building data warehouses on SAP BTP, creating analytic models, configuring data flows and…

117
445
19 files
View
aj-geddes logo

Artifact Management

aj-geddes
Community

Manage build artifacts, Docker images, and package registries. Configure artifact repositories, versioning, and distribution strategies.

55
340
5 files
View
mizchi logo

Frontend Review Hygiene

mizchi
Community

Use when assessing code quality hygiene — TypeScript strictness, lint violations, dead code, and duplication. Runs `audit-typescript.sh`, `audit-lint.sh`, `audit-similarity.sh`. Does NOT cover…

4
333
Instructions
View
OneWave-AI logo

Code Review Pro

OneWave-AI
Organization

Comprehensive code review covering security vulnerabilities, performance bottlenecks, best practices, and refactoring opportunities. Use when user requests code review, security audit, or performance…

49
293
Instructions
View
vercel logo

Next Forge

vercel
Organization

next-forge expert guidance — production-grade Turborepo monorepo SaaS starter by Vercel. Use when working in a next-forge project, scaffolding with `npx next-forge init`, or editing @repo/* workspace…

56
286
9 files
View
majiayu000 logo

Codebase Audit

majiayu000
Community

全面代码库审计 — 自适应并行深度分析(前后端契约、数据完整性、异常处理/安全、架构/技术债、配置/缓存),结构化 findings + 对抗验证 + 基线对比,输出按严重程度排序的统一报告和修复路线图。支持 quick 快速体检模式。Use when user asks to audit, analyze, or review an entire codebase for design…

26
280
6 files
View
blacklanternsecurity logo

Remote Access Enumeration

blacklanternsecurity
Organization

Enumeration of remote access services: FTP, SSH, RDP, VNC, and WinRM. Checks anonymous access, default credentials, version vulnerabilities, and authentication methods. Use after network-recon…

39
276
Instructions
View
datadog-labs logo

Dd Audit Ai Activity

datadog-labs
Organization

Audit what the Bits AI assistant (MCP server) has done in your Datadog org — tool calls by user, resources accessed, and anomaly flags for AI governance.

28
172
Instructions
View
Dynatrace logo

Dt Sec Contextualization

Dynatrace
Organization

Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity. Covers identity-to-Smartscape…

30
156
4 files
View
bitwarden logo

Action Audit

bitwarden
Organization

Audit GitHub Actions action usage across an org. Searches for a specific action (incident mode) or sweeps all workflow files for non-compliant action references (audit mode). Produces a read-only…

19
149
Instructions
View
diegosouzapw logo

Activecampaign Automation V2

diegosouzapw
Community

ActiveCampaign Automation via Rube MCP workflow skill. Use this skill when the user needs Automate ActiveCampaign tasks via Rube MCP (Composio): manage contacts, tags, list subscriptions, automation…

32
145
2 files
View
trilwu logo

Reviewing Code Changes

trilwu
Community

Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline. Use when asked to…

15
144
Instructions
View
Houseofmvps logo

Seo Audit

Houseofmvps
Community

Run SEO audit (39 rules) with AI visibility checks — GEO (20 rules for AI bot access, snippet restrictions) and AEO (4 schema checks). Auto-fix included. Use when user wants to check or improve search…

14
122
Instructions
View
Factory-AI logo

Vulnerability Validation

Factory-AI
Organization

Validate security findings from commit-security-scan by assessing exploitability, filtering false positives, and generating proof-of-concept exploits. Use after running commit-security-scan to confirm…

15
111
1 files
View
AIDotNet logo

Env Manager

AIDotNet
Organization

管理环境变量和.env文件,支持验证、加密和模板生成。

17
85
1 files
View
simota logo

Frame

simota
Community

Extracting and structuring design context from Figma via MCP Server for downstream implementation agents. Use for Figma-to-code bridging or Code Connect management.

14
80
13 files
View
seaworld008 logo

Cloudflare Troubleshooting

seaworld008
Community

Diagnose Cloudflare DNS, TLS, redirects, and configuration issues using live API settings and request evidence.

11
70
5 files
View
brucesongs logo

Cloud Native Vuln Research

brucesongs
Community

CVE research methodology, PoC reproduction, patch gap analysis, and exploit chain composition across container/k8s/cloud-native surfaces; SBOM-driven vuln management and nuclei template authoring.

18
70
8 files
View
affaan-m logo

Quarkus Security

affaan-m
CommunityPopular

Buenas prácticas de seguridad en Quarkus para autenticación, autorización, JWT/OIDC, RBAC, validación de entrada, CSRF, gestión de secretos y seguridad de dependencias.

39.1K
261.1K
Instructions
View
nexu-io logo

Html Ppt Taste Brutalist

nexu-io
OrganizationPopular

16:9 HTML deck in tactical-telemetry / CRT-terminal taste. Deactivated-CRT charcoal slides, white-phosphor monospace, hazard-red accent, scanline overlay, ASCII syntax, density over decoration.…

11.2K
96.7K
1 files
View
ruvnet logo

Cross Host Federation

ruvnet
CommunityPopular

Join and operate a signed cross-host agentbbs federation, and coordinate work claims across nodes. Use when: connecting ruflo agents across machines, sharing status/tasks/results between hosts,…

8.6K
72.7K
Instructions
View
mukul975 logo

Analyzing Ios App Security With Objection

mukul975
CommunityPopular

Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile…

4K
32.9K
6 files
View
googleworkspace logo

Gws Modelarmor Sanitize Response

googleworkspace
OrganizationPopular

Google Model Armor: Sanitize a model response through a Model Armor template.

1.8K
31K
Instructions
View
prowler-cloud logo

Prowler Tour

prowler-cloud
OrganizationPopular

Keeps product-tour definitions aligned with the UI features they describe. Trigger: When modifying UI components that have associated tours, editing tour definition files, or renaming data-tour-id…

2.4K
14.8K
3 files
View
Jeffallan logo

Java Architect

Jeffallan
CommunityPopular

Use when building, configuring, or debugging enterprise Java applications with Spring Boot 3.x, microservices, or reactive programming. Invoke to implement WebFlux endpoints, optimize JPA queries and…

1.1K
11.5K
5 files
View
trailofbits logo

Firebase Apk Scanner

trailofbits
OrganizationPopular

Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzing APK files for Firebase…

611
7.1K
4 files
View
SnailSploit logo

Offensive Phishing

SnailSploit
CommunityPopular

Phishing campaign execution methodology for authorized red team engagements. Covers end-to-end campaign lifecycle: infrastructure provisioning (GoPhish, SMTP relay configuration, domain acquisition…

775
6K
Instructions
View
zebbern logo

Html Injection Testing

zebbern
CommunityPopular

This skill should be used when the user asks to "test for HTML injection", "inject HTML into web pages", "perform HTML injection attacks", "deface web applications", or "test content injection…

464
4.6K
Instructions
View
Netw0rkNoob logo

Redteam Cve Validation

Netw0rkNoob
OrganizationPopular

CVE validation domain card. Use after CVE lookup has produced applicable or candidate CVEs and red-team mode needs scoped evidence to decide whether to continue, pivot, or report.

454
3.4K
1 files
View
addyosmani logo

Best Practices

addyosmani
CommunityPopular

Apply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", "code quality review", or…

246
2.8K
1 files
View
jeremylongshore logo

Hyperflow Status

jeremylongshore
CommunityPopular

Hyperflow project status. Use to see current hyperflow state — "what is hyperflow doing", "show task progress", "where are we". Read-only — reports in-flight tasks, memory count, and progress. Never…

402
2.8K
Instructions
View
xu-xiang logo

Springboot Verification

xu-xiang
CommunityPopular

Spring Boot 项目的验证循环:构建、静态分析、带有覆盖率的测试、安全扫描以及发布或 PR 前的差异审查。

318
1.9K
Instructions
View
wgpsec logo

K8s Container Escape

wgpsec
OrganizationPopular

Kubernetes 容器逃逸与集群攻击。当目标运行在 K8s 环境中、发现 6443/10250/2379 端口、获取到 ServiceAccount Token、或已在容器内时使用。覆盖容器逃逸、Pod 提权、API Server 未授权、etcd 泄露、RBAC 滥用、节点接管。任何涉及 Kubernetes、容器编排、云原生安全的场景都应使用此技能

242
1.7K
4 files
View
levnikolaevich logo

Ln 54 Codebase Auditor

levnikolaevich
Community

Audits cross-cutting codebase health, security and maintainability; not a single-change review or specialist audit.

84
565
Instructions
View
vercel logo

Next Forge

vercel
Organization

Expert assistance for next-forge — a production-grade Turborepo template for Next.js SaaS apps. Triggers on questions about next-forge installation, setup, architecture, packages, customization,…

56
286
4 files
View
blacklanternsecurity logo

Smb Enumeration

blacklanternsecurity
Organization

SMB share enumeration, access testing, password policy extraction, and content searching. Enumerates shares via null session, guest, and authenticated access. Covers share listing, per-share access…

39
276
Instructions
View
Mindrally logo

C Sharp

Mindrally
Organization

Guidelines for C# development including Blazor, Unity game development, and .NET backend best practices

41
259
Instructions
View
mattgierhart logo

Prd V07 Epic Scoping

mattgierhart
Community

Transform v0.6 specifications into context-window-sized work packages (EPICs) during PRD v0.7 Build Execution. Triggers on requests to create epics, scope work, break down implementation, or when user…

11
179
3 files
View
Kilo-Org logo

Azure Eventhub Py

Kilo-Org
Organization

Azure Event Hubs SDK for Python streaming. Use for high-throughput event ingestion, producers, consumers, and checkpointing. Triggers: "event hubs", "EventHubProducerClient", "EventHubConsumerClient",…

168
179
3 files
View
datadog-labs logo

Dd Audit Compliance Report

datadog-labs
Organization

Generate auditor-ready compliance evidence from Datadog Audit Trail for SOC 2 and PCI DSS. Maps framework controls to specific query patterns and produces formatted output.

28
172
1 files
View
Dynatrace logo

Dt Sec Insights

Dynatrace
Organization

Query and analyze Dynatrace security data in security.events with DQL: vulnerabilities, threat detections, compliance posture, and scan coverage. Covers Dynatrace-native Runtime Vulnerability…

30
156
15 files
View
TerminalSkills logo

Ai Pentesting

TerminalSkills
Organization

Run autonomous AI-driven penetration tests on web applications using tools like Shannon, PentAGI, and similar frameworks. Use when tasks involve setting up automated penetration testing pipelines,…

21
155
1 files
View
bitwarden logo

Action Remediate

bitwarden
Organization

Remediate GitHub Actions action findings identified by the action-audit skill. Applies the appropriate fix per action type — `@main` ref for internal `bitwarden/` actions, full SHA with inline version…

19
149
Instructions
View
diegosouzapw logo

Activecampaign Automation

diegosouzapw
Community

ActiveCampaign Automation via Rube MCP workflow skill. Use this skill when the user needs Automate ActiveCampaign tasks via Rube MCP (Composio): manage contacts, tags, list subscriptions, automation…

32
145
2 files
View
trilwu logo

Reviewing Cryptography

trilwu
Community

Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and JWT…

15
144
Instructions
View
dandye logo

Respond Malware

dandye
Community

Respond to a malware incident following PICERL methodology. Use when malware is detected on endpoints. Orchestrates triage, containment, eradication, and recovery. Works with triage-malware skill for…

34
126
Instructions
View
neo4j-contrib logo

Neo4j Spark Skill

neo4j-contrib
Organization

Use when reading from or writing to Neo4j with Apache Spark or Databricks using the Neo4j Connector for Apache Spark 6.0 (org.neo4j.connectors:spark) or 5.x (org.neo4j:neo4j-connector-apache-spark).…

38
112
2 files
View
dykyi-roman logo

Check Authentication

dykyi-roman
Community

Analyzes PHP code for authentication issues. Detects weak password handling, insecure sessions, missing auth checks, token vulnerabilities.

25
98
Instructions
View
wshaddix logo

Dotnet Agent Gotchas

wshaddix
Community

Generating or modifying .NET code. Common agent mistakes: async, NuGet, deprecated APIs, DI.

13
79
Instructions
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇