Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 1,123-1,173 of 1,735 AI skills

AI skills directory results

blacklanternsecurity logo

Xmpp Enumeration

blacklanternsecurity
Organization

XMPP/Jabber service enumeration for Openfire, ejabberd, Prosody, and other XMPP servers. Trigger when ports 5222 (client), 5223 (legacy TLS), or 5269 (server-to-server) are found open. Covers…

39
276
Instructions
View
Kilo-Org logo

Azure Machine Learning

Kilo-Org
Organization

Expert knowledge for Azure Machine Learning development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration,…

168
179
2 files
View
trilwu logo

Unpacking Protected Binaries

trilwu
Community

Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping…

15
144
Instructions
View
dandye logo

Respond Ransomware

dandye
Community

Respond to a ransomware incident following PICERL methodology. Use when ransomware is detected or suspected. Orchestrates identification, containment, eradication, and recovery phases. Requires…

34
126
Instructions
View
Houseofmvps logo

Sprint

Houseofmvps
Community

Sprint workflow pipeline — chains plan → build → test → review → ship skills into a structured sprint. Use when starting a new feature or project iteration to follow the full lifecycle.

14
122
Instructions
View
aAAaqwq logo

Afrexai Compliance Audit

aAAaqwq
Community

Run internal compliance audits against major governance and security frameworks, highlighting gaps, risks, and remediation priorities.

23
98
1 files
View
simota logo

Gauge

simota
Community

Auditing SKILL.md normalization and compliance: scans the 21-item checklist, classifies violations, produces fix snippets. Use when auditing SKILL.md compliance or ecosystem health.

14
80
16 files
View
tonone-ai logo

Brace Kb

tonone-ai
Organization

Build or audit knowledge base -- article structure, coverage gaps, deflection rate, and maintenance process. Use when asked to "build a knowledge base", "what docs are missing", "improve our…

9
73
Instructions
View
brucesongs logo

Codebase Onboarding

brucesongs
Community

Rapidly acquire a mental model of any unfamiliar codebase — from a 500-line script to a 100M+ line monorepo. This skill transforms raw code into structured intelligence: architecture maps, entry…

18
70
14 files
View
code-yeongyu logo

Review Work

code-yeongyu
CommunityPopular

Post-implementation gate review: run manual QA on the real surface yourself, then launch ONE gate reviewer (never a panel) to audit goal, constraints, code quality, security, missed context, and QA…

5.7K
69.1K
Instructions
View
googleworkspace logo

Gws Script Push

googleworkspace
OrganizationPopular

Google Apps Script: Upload local files to an Apps Script project.

1.8K
31K
Instructions
View
AgriciDaniel logo

Seo Technical

AgriciDaniel
CommunityPopular

Technical SEO audit across 9 categories: crawlability, indexability, security, URL structure, mobile, Core Web Vitals, structured data, JavaScript rendering, and IndexNow protocol. Use when user says…

2.5K
17.1K
1 files
View
prowler-cloud logo

Pytest

prowler-cloud
OrganizationPopular

Pytest testing patterns for Python. Trigger: When writing or refactoring pytest tests (fixtures, mocking, parametrize, markers). For Prowler-specific API/SDK testing conventions, also use…

2.4K
14.8K
1 files
View
zebbern logo

Linux Privilege Escalation

zebbern
CommunityPopular

This skill should be used when the user asks to "escalate privileges on Linux", "find privesc vectors on Linux systems", "exploit sudo misconfigurations", "abuse SUID binaries", "exploit cron jobs for…

464
4.6K
Instructions
View
spinabot logo

Oauth Setup

spinabot
OrganizationPopular

Connect an OAuth 2.0 service (Gmail, Google APIs, etc.) using the built-in oauth_authorize tool — get a click-to-authorize link, auto-capture the code, and seal the tokens. Use whenever the operator…

50
4.4K
Instructions
View
Netw0rkNoob logo

Redteam File Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized file operation vulnerability testing, including path traversal, arbitrary file read/write/upload, and LFI/RFI. Use when a task belongs to the file…

454
3.4K
1 files
View
addyosmani logo

Seo

addyosmani
CommunityPopular

Optimize for search engine visibility and ranking. Use when asked to "improve SEO", "optimize for search", "fix meta tags", "add structured data", "sitemap optimization", or "search engine…

246
2.8K
1 files
View
wgpsec logo

K8s Network Recon

wgpsec
OrganizationPopular

Kubernetes 集群内网络侦察与服务发现。当已获得 Pod Shell、需要发现集群内其他服务、执行 K8s 内网扫描时使用。覆盖 DNS PTR 反查、SRV 记录枚举、AXFR 域传输、K8Spider 使用。任何在 Pod 中需要横向侦察、寻找隐藏服务、确定攻击目标的场景都应使用此技能,即使用户没有明确提到 DNS

242
1.7K
1 files
View
NeoLabHQ logo

Git Notes

NeoLabHQ
OrganizationPopular

Use when adding metadata to commits without changing history, tracking review status, test results, code quality annotations, or supplementing commit messages post-hoc - provides git notes commands…

159
1.7K
Instructions
View
Pluviobyte logo

Grok Build Cli

Pluviobyte
CommunityPopular

Invoke the locally installed Grok Build CLI from Codex and return Grok's response. Use whenever the user asks Codex to call, consult, run, or delegate a prompt to Grok or Grok Build, including Grok…

181
1.6K
1 files
View
first-fluke logo

Oma Tf Infra

first-fluke
OrganizationPopular

Create or review Terraform infrastructure and plans. Use for cloud resources, IAM, networking, state management, and infrastructure changes.

149
1.3K
8 files
View
codewithmukesh logo

Openapi

codewithmukesh
Organization

Built-in OpenAPI support for .NET 10 applications. Covers document generation, transformers, TypedResults metadata, security schemes, XML comments, build-time generation, and multiple document…

170
721
Instructions
View
ancoleman logo

Implementing Compliance

ancoleman
Community

Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection. Use when building systems requiring…

73
523
19 files
View
proffesor-for-testing logo

N8n Security Testing

proffesor-for-testing
Community

Credential exposure detection, OAuth flow validation, API key management testing, and data sanitization verification for n8n workflows. Use when validating n8n workflow security.

92
480
3 files
View
Microck logo

Better Auth

Microck
Community

Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth…

53
398
1 files
View
MadAppGang logo

Audit

MadAppGang
Organization

On-demand security and code quality audit. Use when checking for vulnerabilities, security issues, code smells, or compliance problems. Trigger keywords - "audit", "security check", "vulnerability…

26
281
Instructions
View
blacklanternsecurity logo

Credential Recovery

blacklanternsecurity
Organization

Offline credential and file recovery with hashcat and john. Use when any skill captures hashes (NTLM, Kerberos TGS/AS-REP, shadow, MSCACHE2) or encrypted files (ZIP, Office, PDF, KeePass, SSH key, 7z,…

39
276
Instructions
View
membranedev logo

Abuselpdb

membranedev
Community

AbuselPDB integration. Manage data, records, and automate workflows. Use when the user wants to interact with AbuselPDB data.

42
268
Instructions
View
LerianStudio logo

Ring:Creating Helm Charts

LerianStudio
Organization

Creating Helm charts to Lerian conventions via ring:helm: standardized chart structure, full env-var coverage from .env.example, security defaults (runAsNonRoot, readOnlyRootFilesystem),…

28
215
Instructions
View
datadog-labs logo

Dd Audit Security Investigation

datadog-labs
Organization

Answer "who did what" security questions from Audit Trail — deletions, config changes, login activity, permission changes, actions from a specific user or IP.

28
172
Instructions
View
trilwu logo

Vetting Agent Extensions

trilwu
Community

Decide whether an agent skill, plugin, or MCP server is safe to install into an AI coding agent, where its content is loaded into a model's context and its config can run on startup. Use when…

15
144
Instructions
View
Houseofmvps logo

Staying Current

Houseofmvps
Community

Use whenever answering anything version-sensitive — library/framework/SDK APIs, package versions, model IDs, pricing, CLI flags, config, or "latest/newest" anything. Verify against current sources…

14
122
Instructions
View
brucesongs logo

Command Injection Advanced

brucesongs
Community

Advanced injection attacks beyond SQL - covering OS command injection, LDAP injection, NoSQL injection, template injection (SSTI), XPath injection, and comprehensive filter bypass techniques.

18
70
13 files
View
zenobi-us logo

Email And Password

zenobi-us
Organization

Configure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication. Use when users need to set up…

6
67
Instructions
View
mukul975 logo

Analyzing Linux Kernel Rootkits

mukul975
CommunityPopular

Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify…

4K
32.9K
2 files
View
prowler-cloud logo

React 19

prowler-cloud
OrganizationPopular

React 19 patterns with React Compiler. Trigger: When writing React 19 components/hooks in .tsx (React Compiler rules, hook patterns, refs as props). If using Next.js App Router/Server Actions, also…

2.4K
14.8K
Instructions
View
trailofbits logo

Goal Prompt

trailofbits
OrganizationPopular

Drafts copy-paste-ready /goal commands for goal mode in Claude Code and Codex. Use when the user asks to create, write, rewrite, improve, compress, clean up, or prepare a goal prompt, goal condition,…

611
7.1K
3 files
View
SnailSploit logo

Offensive Reporting

SnailSploit
CommunityPopular

Penetration test and red team report writing methodology. Covers executive summary structuring (risk-led narrative for non-technical readers), technical finding format (title, severity, affected…

775
6K
Instructions
View
zebbern logo

Linux Shell Scripting

zebbern
CommunityPopular

This skill should be used when the user asks to "create bash scripts", "automate Linux tasks", "monitor system resources", "backup files", "manage users", or "write production shell scripts". It…

464
4.6K
Instructions
View
aaron-he-zhu logo

List Hygiene Monitor

aaron-he-zhu
CommunityPopular

Use when the user asks to "watch my list health over time", "flag decaying / unengaged subscribers on a schedule", "why is my open rate drifting down / bounces creeping up", or "build me a…

361
2.8K
1 files
View
wgpsec logo

K8s Sidecar Attack

wgpsec
OrganizationPopular

Kubernetes Sidecar 容器流量劫持与敏感信息窃取。当目标 Pod 存在 Istio/Envoy/Linkerd sidecar、题目提到'隐形旁观者'或'共享网络'、或需要从 Pod 内部嗅探流量时使用。覆盖 tcpdump 抓包、sidecar 明文流量捕获、共享网络命名空间利用。只要在 K8s Pod 中发现有 sidecar 或多容器共存的迹象,就应使用此技能

242
1.7K
Instructions
View
proffesor-for-testing logo

N8n Trigger Testing Strategies

proffesor-for-testing
Community

Webhook testing, schedule validation, event-driven triggers, and polling mechanism testing for n8n workflows. Use when testing how workflows are triggered.

92
480
3 files
View
aj-geddes logo

Aws Rds Database

aj-geddes
Community

Deploy and manage relational databases using RDS with Multi-AZ, read replicas, backups, and encryption. Use for PostgreSQL, MySQL, MariaDB, and Oracle.

55
340
5 files
View
mizchi logo

Frontend Review Triage

mizchi
Community

Use when starting a frontend review engagement or when the user asks for an initial assessment ("triage", "day 0", "what's the state of this repo"). Reads package.json, README, gh issues, and produces…

4
333
Instructions
View
blacklanternsecurity logo

Linux Cron Service Abuse

blacklanternsecurity
Organization

Exploit cron jobs, systemd timers/services, D-Bus services, and Unix sockets for privilege escalation.

39
276
Instructions
View
trilwu logo

Analyzing Disk Images

trilwu
Community

Perform dead-disk forensics on an acquired disk image using The Sleuth Kit, Plaso, and bulk_extractor — verify integrity and mount read-only, map partitions, recover deleted files, build a file-system…

15
144
Instructions
View
luongnv89 logo

Codebase Modernizer

luongnv89
Community

Audit a stale, inherited, or messy codebase — deps, bugs, security, tests, CI, docs, UI/UX — then emit a phased, testable modernization plan. Read-only: plans upgrades, never applies them. Not for…

18
124
15 files
View
Houseofmvps logo

Using Ultraship

Houseofmvps
Community

Use when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

14
122
2 files
View
olorehq logo

Olore Lucia Latest

olorehq
Organization

Local lucia documentation reference (latest). Lucia auth documentation. Use for session-based authentication, OAuth 2.0, password hashing, and framework-specific auth implementations.

6
103
24 files
View
simota logo

Grove

simota
Community

Designing and auditing repository structure for humans and LLM agents: layouts, monorepos, docs/tests/scripts, progressive disclosure, prompt-cache topology, and safe migrations.

14
80
24 files
View
wshaddix logo

Dotnet Api Security

wshaddix
Community

Implementing API auth. Identity, OAuth/OIDC, JWT bearer, passkeys (WebAuthn), CORS, rate limiting.

13
79
Instructions
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇