Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 1,072-1,122 of 1,735 AI skills

AI skills directory results

tonone-ai logo

Blue Recon

tonone-ai
Organization

Audit existing security controls and detection coverage — find gaps against MITRE ATT&CK. Use when asked to "audit our detection coverage", "where are our security control gaps", or "check our MITRE…

9
73
Instructions
View
seaworld008 logo

Code Review And Quality

seaworld008
Community

Review code changes for correctness, maintainability, security, and validation evidence before integration or when a review is requested.

11
70
7 files
View
brucesongs logo

Cloud Security

brucesongs
Community

Cloud security covers security assessment for major cloud platforms including AWS, Azure, and GCP, with core focus on IAM misconfiguration detection, storage bucket exposure scanning, metadata service…

18
70
17 files
View
Tibsfox logo

Cloud Identity And Auth

Tibsfox
Community

Identity, authentication, authorization, and token management for cloud platforms. Covers Keystone-style scoped tokens, OAuth 2.0 flows, OpenID Connect, JWT structure and pitfalls, federation with…

9
70
Instructions
View
zenobi-us logo

Best Practices

zenobi-us
Organization

Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. Use when users mention Better Auth, betterauth, auth.ts, or need to…

6
67
Instructions
View
ComposioHQ logo

Ahrefs Automation

ComposioHQ
OrganizationPopular

Automate SEO research with Ahrefs -- analyze backlink profiles, research keywords, track domain metrics history, audit organic rankings, and perform batch URL analysis through the Composio Ahrefs…

8.7K
75.2K
Instructions
View
ruvnet logo

Browser Auth Flow

ruvnet
CommunityPopular

Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md

8.6K
72.7K
Instructions
View
mukul975 logo

Analyzing Kubernetes Audit Logs

mukul975
CommunityPopular

Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules from…

4K
32.9K
2 files
View
googleworkspace logo

Gws Modelarmor

googleworkspace
OrganizationPopular

Google Model Armor: Filter user-generated content for safety.

1.8K
31K
Instructions
View
RightNow-AI logo

Github

RightNow-AI
OrganizationPopular

GitHub operations expert for PRs, issues, code review, Actions, and gh CLI

2.3K
18.2K
Instructions
View
prowler-cloud logo

Prowler Ui

prowler-cloud
OrganizationPopular

Prowler UI-specific patterns. For generic patterns, see: typescript, react-19, nextjs-16, tailwind-4. Trigger: When working inside ui/ on Prowler-specific conventions (shadcn, folder placement,…

2.4K
14.8K
1 files
View
trailofbits logo

Fp Check

trailofbits
OrganizationPopular

Systematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each. Use when asked whether a specific…

611
7.1K
8 files
View
SnailSploit logo

Offensive Social Engineering

SnailSploit
CommunityPopular

Social engineering attack techniques beyond email phishing for authorized red team and physical penetration testing engagements. Covers pretexting methodology (persona creation, authority and urgency…

775
6K
Instructions
View
elementalsouls logo

Hunt Grpc

elementalsouls
CommunityPopular

Hunt gRPC vulnerabilities — server reflection enabled (enumerate all services/methods), missing authentication / metadata-stripping on internal endpoints, plaintext gRPC over HTTP/2, internal endpoint…

678
4.5K
Instructions
View
samber logo

Golang Safety

samber
CommunityPopular

Defensive Golang coding against accidental bugs — nil panics, typed-nil interfaces, `append` backing-array aliasing, silent int64-to-int32 truncation, float `==` comparison, `defer` inside loops,…

213
3.3K
3 files
View
aws logo

Aws Cloudformation

aws
OrganizationPopular

Authors, validates, and troubleshoots AWS CloudFormation templates. Covers template authoring with secure defaults, pre-deployment validation (cfn-lint, cfn-guard, change sets), CloudFormation Express…

311
2.7K
10 files
View
wgpsec logo

K8s Ingress Nightmare

wgpsec
OrganizationPopular

IngressNightmare (CVE-2025-1974) — Kubernetes Ingress-NGINX Admission Controller 未授权 RCE。当目标 K8s 集群使用 ingress-nginx、发现 443/8443 端口的 admission webhook、或通过 Pod 网络可达 admission controller…

242
1.7K
2 files
View
uphiago logo

Iot Camera Recon

uphiago
CommunityPopular

Attack cameras via RTSP, ONVIF, Axis config when 554 open.

213
1.3K
Instructions
View
ww-w-ai logo

Phase 2 Convention

ww-w-ai
Organization

Define coding rules, conventions, and standards for AI collaboration. Triggers: convention, coding style, lint, rules

154
601
Instructions
View
aiskillstore logo

Claude Code Hooks

aiskillstore
Organization

Claude Code hook system for pre/post tool execution. Triggers on: hooks, PreToolUse, PostToolUse, hook script, tool validation, audit logging.

45
427
4 files
View
mizchi logo

Frontend Review Security

mizchi
Community

Use when conducting a frontend security review — static analysis (risky HTML patterns, env var exposure), authentication/authorization audit (token storage, route guards, logout), and AI…

4
333
Instructions
View
blacklanternsecurity logo

Smb Exploitation

blacklanternsecurity
Organization

Exploit remote SMB vulnerabilities for unauthenticated code execution on Windows hosts.

39
276
Instructions
View
team-telnyx logo

Telnyx Messaging Profiles Curl

team-telnyx
Organization

Create and manage messaging profiles with number pools, sticky sender, and geomatch features. Configure short codes for high-volume messaging. This skill provides REST API (curl) examples.

21
217
Instructions
View
LerianStudio logo

Ring:Auditing Dependency Security

LerianStudio
Organization

Auditing a dependency for supply-chain risk before install (pip/npm/go/cargo): checks typosquatting, maintainer/age risk, vulnerability DBs (OSV, GHSA, Socket), and lockfile hash pinning, then emits a…

28
215
Instructions
View
NeverSight logo

Yellow Best Practices

NeverSight
Organization

Yellow Network and Nitrolite (ERC-7824) development best practices for building state channel applications. Use when building apps with Yellow SDK, implementing state channels, connecting to…

38
210
12 files
View
Kilo-Org logo

Azure Key Vault

Kilo-Org
Organization

Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. Covers…

168
179
Instructions
View
Dynatrace logo

Dt Sec Ioc Hunting

Dynatrace
Organization

Hunt threat-intelligence indicators of compromise (IoCs) across Dynatrace logs and spans and produce a 0-100 threat-exposure score. Extracts and normalizes IoCs — IPs, Domains (hostnames included),…

30
156
7 files
View
trilwu logo

Securing Ai Systems

trilwu
Community

Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP Top…

15
144
1 files
View
Houseofmvps logo

Ship Gate

Houseofmvps
Community

Turn the /ship scorecard into a blocking, config-as-code quality gate. Sets per-category score thresholds, hard-fails on leaked secrets or critical findings, and wires the gate into a pre-push hook…

14
122
Instructions
View
neo4j-contrib logo

Neo4j Spring Data Skill

neo4j-contrib
Organization

Use when building Spring Boot applications with Neo4j using Spring Data Neo4j (SDN 7.x/8.x) — @Node entity mapping, @Relationship, @RelationshipProperties, Neo4jRepository, ReactiveNeo4jRepository,…

38
112
1 files
View
cometchat logo

Cometchat Angular V5 Production

cometchat
Organization

Ship a CometChat Angular integration safely — server-minted auth tokens instead of the Auth Key, environment file replacement, key hygiene, build config and a pre-launch checklist. Triggers: 'is this…

2
109
Instructions
View
TheBeardedBearSAS logo

Security Paperclip

TheBeardedBearSAS
Organization

Paperclip-Sicherheit — Tenancy-Isolation, Secrets, Approval-Gates, harte Budgets, signierter Adapter-Channel. Verwenden Sie dies beim Auditing oder Härten von Paperclip.

9
105
Instructions
View
dykyi-roman logo

Check Authorization

dykyi-roman
Community

Analyzes PHP code for authorization issues. Detects missing access control, IDOR vulnerabilities, privilege escalation, role-based access gaps.

25
98
Instructions
View
simota logo

Gateway

simota
Community

Designing and reviewing APIs: OpenAPI spec generation, versioning strategy, breaking change detection, REST/GraphQL best practices. Use for API design or OpenAPI specs.

14
80
24 files
View
nahisaho logo

Traceability Auditor

nahisaho
Community

Validates complete requirements traceability across EARS requirements → design → tasks → code → tests. Trigger terms: traceability, requirements coverage, coverage matrix, traceability matrix,…

7
77
2 files
View
brucesongs logo

Cms Framework Attack

brucesongs
Community

Targeted security assessment of Content Management Systems (WordPress, Joomla, Drupal) using specialized scanners and exploit techniques.

18
70
10 files
View
zenobi-us logo

Better Auth Security Best Practices

zenobi-us
Organization

Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for…

6
67
Instructions
View
affaan-m logo

Quarkus Verification

affaan-m
CommunityPopular

Bucle de verificación para proyectos Quarkus: build, análisis estático, pruebas con cobertura, escaneos de seguridad, compilación nativa y revisión de diff antes del lanzamiento o PR.

39.1K
261.1K
Instructions
View
mukul975 logo

Analyzing Linux Audit Logs For Intrusion

mukul975
CommunityPopular

Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule…

4K
32.9K
2 files
View
prowler-cloud logo

Prowler

prowler-cloud
OrganizationPopular

Main entry point for Prowler development - quick reference for all components. Trigger: General Prowler development questions, project overview, component navigation (NOT PR CI gates or GitHub Actions…

2.4K
14.8K
1 files
View
dotnet logo

Exp Mock Usage Analysis

dotnet
OrganizationPopular

Audits .NET test mock usage by tracing each mock setup through the production code's execution path to find dead, unreachable, redundant, or replaceable mocks. Use when the user asks to audit mock…

416
5.4K
Instructions
View
zebbern logo

Idor Testing

zebbern
CommunityPopular

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

464
4.6K
Instructions
View
davepoon logo

Cal Com Automation

davepoon
CommunityPopular

Automate Cal.com tasks via Rube MCP (Composio): manage bookings, check availability, configure webhooks, and handle teams. Always search tools first for current schemas.

509
3.5K
Instructions
View
Netw0rkNoob logo

Redteam Evasion Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized defense evasion and bypass testing, including WAF bypass, AV/EDR evasion, logging considerations, and traffic obfuscation. Use when a task belongs…

454
3.4K
1 files
View
aaron-he-zhu logo

Deliverability Qa

aaron-he-zhu
CommunityPopular

Use when the user asks to "run a deliverability pre-flight before I send", "check my SPF/DKIM/DMARC/BIMI", "why am I landing in spam / promotions", or "score my sender reputation and list hygiene";…

361
2.8K
1 files
View
yaklang logo

Csv Formula Injection

yaklang
OrganizationPopular

CSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT*). Use when exports, imports, or user fields feed spreadsheets or reporting tools.

292
2.2K
Instructions
View
wgpsec logo

K8s Istio Bypass

wgpsec
OrganizationPopular

Istio Service Mesh 安全策略绕过。当目标 K8s 集群使用 Istio、请求被 AuthorizationPolicy 拒绝(403 RBAC denied)、或发现 Envoy sidecar 时使用。核心手法:UID 1337 绕过 Envoy。任何在 K8s 中遇到 Istio 策略阻拦、Service Mesh 限制、或 Envoy 相关安全控制的场景都应使用此技能

242
1.7K
Instructions
View
rshankras logo

Generators

rshankras
Community

Code generator skills that produce production-ready Swift code for common app components. Use when user wants to add logging, analytics, onboarding, review prompts, networking, authentication,…

70
744
150 files
View
thedivergentai logo

Godot Export Builds

thedivergentai
Community

Expert patterns for multi-platform exports including export templates (Windows/Linux/macOS/Android/iOS/Web), command-line exports (headless mode), platform-specific settings (codesign, notarization,…

43
727
16 files
View
Asymmetric-al logo

Inngest Middleware

Asymmetric-al
Organization

Use when adding cross-cutting concerns to durable functions — structured logging or tracing across all functions, error tracking with Sentry, payload encryption for sensitive data, dependency…

7
383
2 files
View
MadAppGang logo

Adr Documentation

MadAppGang
Organization

Architecture Decision Records (ADR) documentation practice. Use when documenting architectural decisions, recording technical trade-offs, creating decision logs, or establishing architectural…

26
281
Instructions
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇