Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 1,276-1,326 of 1,735 AI skills

AI skills directory results

brucesongs logo

Cps Attack

brucesongs
Community

Cyber-Physical Systems (CPS) attacks — PLCs (Siemens S7, Rockwell ControlLogix, Schneider Modicon, Mitsubishi MELSEC), ICS protocols (Modbus, DNP3, Profinet, EtherNet/IP, IEC 61850, OPC UA), HMIs,…

18
70
9 files
View
mukul975 logo

Analyzing Malware Behavior With Cuckoo Sandbox

mukul975
CommunityPopular

Detonate malware samples in Cuckoo Sandbox to observe runtime behavior — process creation, file system and registry changes, network communications, and API calls — and generate behavioral reports for…

4K
32.9K
2 files
View
googleworkspace logo

Gws Tasks

googleworkspace
OrganizationPopular

Google Tasks: Manage task lists and tasks.

1.8K
31K
Instructions
View
prowler-cloud logo

Vitest

prowler-cloud
OrganizationPopular

Vitest unit testing patterns with React Testing Library. Trigger: When writing unit tests for React components, hooks, or utilities.

2.4K
14.8K
Instructions
View
trailofbits logo

Post Patch Validation

trailofbits
OrganizationPopular

Validates security patches with reproducible baseline-versus-patched evidence, including original exploits, root-cause variants, behavior preservation, regressions, and newly introduced security…

611
7.1K
4 files
View
zebbern logo

Pentest Checklist

zebbern
CommunityPopular

This skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration testing", "define pentest scope", "follow security testing…

464
4.6K
Instructions
View
Netw0rkNoob logo

Redteam Postex Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized post-exploitation testing after initial access, including privilege escalation, persistence, lateral movement, data collection, and cleanup…

454
3.4K
1 files
View
wgpsec logo

Java Audit Pipeline

wgpsec
OrganizationPopular

Java 白盒源码安全审计总方法论。当需要对 Java 项目进行完整的源码安全审计、 或需要系统化的白盒漏洞挖掘流程时触发。 覆盖 5 阶段审计流水线: 路由映射→权限建模→数据流追踪→分类漏洞审计→利用链组装。 核心机制: 证据合约系统(EVID_*)防止 AI 幻觉误报,所有漏洞结论必须有数据流证据支撑。

242
1.7K
4 files
View
secondsky logo

Sap Sqlscript

secondsky
Community

This skill should be used when the user asks to "write a SQLScript procedure", "create HANA stored procedure", "implement AMDP method", "optimize SQLScript performance", "handle SQLScript exceptions",…

117
445
20 files
View
blacklanternsecurity logo

Windows Discovery

blacklanternsecurity
Organization

Windows local privilege escalation enumeration and attack surface mapping.

39
276
Instructions
View
bitwarden logo

Detecting Secrets

bitwarden
Organization

This skill should be used when the user asks to "find hardcoded secrets", "audit for credential leaks", "check for API keys in code", "review secret scanning alerts", "rotate a leaked secret", or…

19
149
Instructions
View
trilwu logo

Analyzing Shellcode

trilwu
Community

Analyze raw shellcode and position-independent code — extracting the bytes, guessing architecture, disassembling at the right base, decoding self-decoder stubs, resolving hashed Windows APIs,…

15
144
Instructions
View
einverne logo

Shell Scripting

einverne
Community

Specialized knowledge of Bash and Zsh scripting, shell automation, command-line tools, and scripting best practices. Use when the user needs to write, debug, or optimize shell scripts or work with…

24
121
Instructions
View
aAAaqwq logo

Audit Code

aAAaqwq
Community

Run a two-pass, multidisciplinary code audit led by a tie-breaker lead, combining security, performance, UX, DX, and edge-case analysis into one prioritized report with concrete fixes. Use when the…

23
98
4 files
View
dykyi-roman logo

Check Connection Pool

dykyi-roman
Community

Analyzes PHP code for connection pool issues. Detects connection leaks, improper pool sizing, missing connection release, timeout issues.

25
98
1 files
View
brucesongs logo

Crypto Attacks

brucesongs
Community

Cryptographic Attacks target implementation flaws and algorithm weaknesses in encryption systems, covering OWASP A04: Cryptographic Failures.

18
70
14 files
View
K-Dense-AI logo

Exploratory Data Analysis

K-Dense-AI
OrganizationPopular

Perform bounded, local exploratory analysis of explicitly supported scientific files. Use for redacted CSV/TSV/JSON profiles; optional NumPy, HDF5, FASTA/FASTQ, and basic image metadata inspection;…

4.1K
45.4K
20 files
View
mukul975 logo

Analyzing Malware Family Relationships With Malpedia

mukul975
CommunityPopular

Query the Malpedia API to look up malware family aliases and naming (platform.family_name), pull community/vendor YARA rules, link families to threat actors, and map family relationships such as…

4K
32.9K
2 files
View
prowler-cloud logo

Zod 4

prowler-cloud
OrganizationPopular

Zod 4 schema validation patterns. Trigger: When creating or updating Zod v4 schemas for validation/parsing (forms, request payloads, adapters), including v3 -> v4 migration patterns.

2.4K
14.8K
Instructions
View
zebbern logo

Pentest Commands

zebbern
CommunityPopular

This skill should be used when the user asks to "run pentest commands", "scan with nmap", "use metasploit exploits", "crack passwords with hydra or john", "scan web vulnerabilities with nikto",…

464
4.6K
Instructions
View
elementalsouls logo

Hunt Llm Ai

elementalsouls
CommunityPopular

Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct…

678
4.5K
Instructions
View
Netw0rkNoob logo

Redteam Recon Detail Pack

Netw0rkNoob
OrganizationPopular

Domain routing and boundary guidance for authorized reconnaissance and information gathering, including subdomain enumeration, port scanning, directory discovery, fingerprinting, and OSINT. Use when a…

454
3.4K
1 files
View
wgpsec logo

Java Auth Config Audit

wgpsec
OrganizationPopular

Java 源码认证与配置安全审计。当在 Java 白盒审计中需要检测认证绕过、权限缺陷或安全配置问题时触发。 覆盖 6 类风险: 认证绕过(Spring Security/Shiro Filter 链 URI 解析差异)、 越权(IDOR/水平越权/垂直越权)、JWT 安全(算法混淆/密钥泄露/Claims 验证)、…

242
1.7K
1 files
View
codewithmukesh logo

Scalar

codewithmukesh
Organization

Scalar API documentation UI for .NET 10 applications. Covers setup, themes, authentication prefill, multiple documents, layout options, and security. A modern replacement for Swagger UI. Load this…

170
721
Instructions
View
ancoleman logo

Implementing Service Mesh

ancoleman
Community

Implement production-ready service mesh deployments with Istio, Linkerd, or Cilium. Configure mTLS, authorization policies, traffic routing, and progressive delivery patterns for secure, observable…

73
523
13 files
View
majiayu000 logo

Dev Architecture Playbook

majiayu000
Community

Route full software-development architecture work from product intent through design, implementation, testing, release, and operations. Use when the user asks for a complete development architecture,…

26
280
1 files
View
blacklanternsecurity logo

Windows Kernel Exploits

blacklanternsecurity
Organization

Exploit Windows kernel vulnerabilities, vulnerable drivers, and privileged file operations for local privilege escalation to SYSTEM.

39
276
Instructions
View
TerminalSkills logo

Alert Optimizer

TerminalSkills
Organization

Restructure and optimize alert rules for monitoring platforms (Sentry, PagerDuty, Datadog, OpsGenie). Use when someone asks to "reduce alert noise", "fix alert fatigue", "create alert rules", "set up…

21
155
1 files
View
bitwarden logo

Perform Security Review

bitwarden
Organization

Performs a security-focused code review by launching multiple specialized agents and a verification agent to ensure comprehensive coverage and accurate findings. Use this skill when the user asks for…

19
149
3 files
View
trilwu logo

Defending Kubernetes

trilwu
Community

Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets…

15
144
Instructions
View
wshaddix logo

Dotnet Blazor Auth

wshaddix
Community

Adding auth to Blazor. AuthorizeView, CascadingAuthenticationState, Identity UI, per-model flows.

13
79
Instructions
View
JasonxzWen logo

Security Review

JasonxzWen
Community

Load when a task needs security-sensitive code, auth, user input, secrets, API endpoints, payments, injection risk, or unsafe IO reviewed; use code-review for broader review.

0
71
Instructions
View
ruvnet logo

Discover Plugins

ruvnet
CommunityPopular

Discover and recommend ruflo plugins based on your workflow, installed MCP tools, and current task

8.6K
72.7K
Instructions
View
mukul975 logo

Analyzing Malware Persistence With Autoruns

mukul975
CommunityPopular

Use Sysinternals Autoruns to systematically enumerate and analyze malware persistence mechanisms across Windows registry run keys, scheduled tasks, services, drivers, and startup locations. Use when…

4K
32.9K
5 files
View
alirezarezvani logo

Ciso Advisor

alirezarezvani
CommunityPopular

Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and…

3.7K
26.1K
5 files
View
prowler-cloud logo

Zustand 5

prowler-cloud
OrganizationPopular

Zustand 5 state management patterns. Trigger: When implementing client-side state with Zustand (stores, selectors, persist middleware, slices).

2.4K
14.8K
Instructions
View
trailofbits logo

Review Walkthrough

trailofbits
OrganizationPopular

Generates an interactive HTML walkthrough for reviewing code changes. Use only when explicitly called.

611
7.1K
4 files
View
Netw0rkNoob logo

Redteam Recon Intake

Netw0rkNoob
OrganizationPopular

Recon intake skill for first contact with a bare domain, URL, or IP address. Use to build an initial recon_profile and provide factual inputs for CVE lookup and attack-path routing.

454
3.4K
1 files
View
alsk1992 logo

Identity

alsk1992
CommunityPopular

User identity, OAuth connections, and device management

336
2.8K
1 files
View
yaklang logo

Ghost Bits Cast Attack

yaklang
OrganizationPopular

Java "Ghost Bits" / Cast Attack playbook (Black Hat Asia 2026). Use when attacking Java services where 16-bit char is silently narrowed to 8-bit byte to bypass WAF/IDS for SQL injection,…

292
2.2K
1 files
View
wgpsec logo

Java Exploit Chain

wgpsec
OrganizationPopular

Java 白盒审计漏洞利用链组装。当需要将 Java 审计中发现的多个漏洞组合为完整攻击路径、 或需要评估 Maven/Gradle 依赖中的已知 CVE 对项目的实际影响时触发。 核心: 单个中低危漏洞通过组合可升级为高危/Critical 利用链。 覆盖: 信息泄露→认证绕过→RCE 的典型链路、Gadget Chain 分析方法(ysoserial/marshalsec)、 Maven 依赖…

242
1.7K
1 files
View
codewithmukesh logo

Security Scan

codewithmukesh
Organization

Deep security scanning for .NET applications across 6 layers: vulnerable packages, secrets detection, OWASP code patterns, auth configuration, CORS policy, and data protection. Produces severity-rated…

170
721
1 files
View
ancoleman logo

Implementing Tls

ancoleman
Community

Configure TLS certificates and encryption for secure communications. Use when setting up HTTPS, securing service-to-service connections, implementing mutual TLS (mTLS), or debugging certificate…

73
523
12 files
View
giuseppe-trisciuoglio logo

Aws Sdk Java V2 Rds

giuseppe-trisciuoglio
Community

Provides AWS RDS (Relational Database Service) management patterns using AWS SDK for Java 2.x. Use when creating, modifying, monitoring, or managing Amazon RDS database instances, snapshots, parameter…

41
345
3 files
View
blacklanternsecurity logo

Windows Service Dll Abuse

blacklanternsecurity
Organization

Exploit Windows service misconfigurations and DLL hijacking for local privilege escalation.

39
276
Instructions
View
omer-metin logo

Backend

omer-metin
Community

World-class backend engineering - distributed systems, database architecture, API design, and the battle scars from scaling systems that handle millions of requestsUse when "backend, api, database,…

22
152
3 files
View
bitwarden logo

Reviewing Dependencies

bitwarden
Organization

This skill should be used when the user asks to "review Dependabot alerts", "check for vulnerable dependencies", "audit third-party packages", "assess supply chain risk", "run an Aikido scan", or…

19
149
Instructions
View
trilwu logo

Engineering Detections

trilwu
Community

Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices. Use when writing…

15
144
Instructions
View
jiaxiaojunQAQ logo

Lucid Dreamer

jiaxiaojunQAQ
Community

Nightly AI memory reasoning system. Lucid runs every night while you sleep — it reads your daily notes and memory files, detects stale facts, unresolved todos, recurring problems, and forgotten…

8
79
9 files
View
brucesongs logo

Darkweb Intel

brucesongs
Community

Dark web intelligence gathering — Tor/onion service reconnaissance, marketplace monitoring, breach data markets, threat actor profiling, with strict OPSEC for investigators.

18
70
14 files
View
zenobi-us logo

Code Comments

zenobi-us
Organization

Write clear, plain-spoken code comments and documentation that lives alongside the code. Use when writing or reviewing code that needs inline documentation—file headers, function docs, architectural…

6
67
1 files
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇