Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 103-153 of 1,735 AI skills

AI skills directory results

ww-w-ai logo

Bkend Auth

ww-w-ai
Organization

bkend.ai authentication — email/social login, JWT tokens, RBAC, session management. Triggers: bkend auth, bkend login, bkend signup, bkend JWT, bkend RBAC

154
601
Instructions
View
aj-geddes logo

Access Control Rbac

aj-geddes
Community

Implement Role-Based Access Control (RBAC), permissions management, and authorization policies. Use when building secure access control systems with fine-grained permissions.

55
340
4 files
View
mizchi logo

Apm Usage

mizchi
Community

Reference for APM (Agent Package Manager) — apm.yml syntax, install / uninstall / update commands, target detection, lockfile workflow. Read when you need exact field names, but do NOT auto-invoke on…

4
333
3 files
View
Mathews-Tom logo

Agent Builder

Mathews-Tom
Community

Build AI agents and automate Claude Code programmatically via the Claude Agent SDK and headless CLI mode. Covers Python SDK, claude -p, SDK MCP servers, hooks, sessions. Triggers on: "build an agent",…

47
318
9 files
View
OneWave-AI logo

Agent Army

OneWave-AI
Organization

Deploy a 2-layer parallel agent hierarchy for large, parallelizable work — big refactors, multi-file migrations, codebase-wide audits, bulk generation. A top-tier commander (Fable or Opus)…

49
293
Instructions
View
blacklanternsecurity logo

Acl Abuse

blacklanternsecurity
Organization

Exploits misconfigured Active Directory ACLs for privilege escalation. Covers GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, targeted Kerberoasting via SPN manipulation, shadow…

39
276
Instructions
View
qf-studio logo

Backend Endpoint

qf-studio
Organization

Create REST/GraphQL API endpoint with validation, error handling, and tests. Auto-invoke when user says "add endpoint", "create API", "new route", or "add route".

12
232
9 files
View
LerianStudio logo

Ring:Auditing Production Readiness

LerianStudio
Organization

Auditing a service's production readiness against Ring engineering standards across base dimensions plus a conditional multi-tenant dimension, then emitting a scored report and an HTML dashboard. Use…

28
215
7 files
View
TheBushidoCollective logo

Architect

TheBushidoCollective
Organization

Design system architecture and high-level technical strategy

20
195
Instructions
View
oasm-platform logo

Vulnerability Analysis

oasm-platform
Organization

Perform deep analysis of CVEs and security vulnerabilities including CVSS scoring, affected versions, exploit maturity, and remediation steps. Use when the user needs detailed vulnerability…

30
192
Instructions
View
seb1n logo

Agent Observability

seb1n
Community

Design privacy-aware observability for AI agents using traces, spans, structured events, metrics, cost attribution, dashboards, alerts, and investigation workflows. Use when instrumenting an agent,…

35
188
3 files
View
datadog-labs logo

Agent Observability Auto Experiment

datadog-labs
Organization

Run an iterative code-improvement hill-climb against real Datadog LLM-Obs data, locally, with Claude Code as the agent. Establishes a baseline eval, makes one focused change, re-scores with the same…

28
172
3 files
View
payloadcms logo

Payload

payloadcms
Organization

Use when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries,…

4
156
11 files
View
GGPrompts logo

Integration

GGPrompts
Community

Integrate projects with TabzChrome terminals via Markdown links, HTML attributes, WebSocket, JS API, or Spawn API

10
147
6 files
View
trilwu logo

Analyzing Dotnet Assemblies

trilwu
Community

Reverse engineer .NET assemblies and executables with dnSpyEx, ILSpy, and de4dot — identifying and unwrapping obfuscators and packers, deobfuscating control flow and string encryption, handling…

15
144
Instructions
View
dandye logo

Full Investigation

dandye
Community

Complete Tier 2 investigation workflow. Orchestrates deep investigation of escalated cases: deep-dive-ioc, correlate-ioc, specialized triage (malware/login), pivot-on-ioc, and generate comprehensive…

34
126
Instructions
View
Houseofmvps logo

Architecture

Houseofmvps
Community

Living Architecture Map — auto-generate Mermaid diagrams of your codebase. Use when user wants to visualize architecture, understand code structure, generate diagrams, or document system design.

14
122
Instructions
View
686f6c61 logo

Evaluate Dependency

686f6c61
Community

Usar antes de aceptar una dependencia nueva. También: auditar paquete, licencia, CVEs, transitivas, bundle, npm install, pip, cargo add.

7
115
Instructions
View
neo4j-contrib logo

Neo4j Aura Agent Skill

neo4j-contrib
Organization

Manages Neo4j Aura Agents via the v2beta1 REST API — create, list, get, update, delete, and invoke Aura agents backed by an AuraDB instance. Use when configuring Aura Agent tools (CypherTemplate,…

38
112
7 files
View
TheBeardedBearSAS logo

Dynamic Workflows

TheBeardedBearSAS
Organization

Orchestrate dozens-to-hundreds of subagents from a script Claude writes (Claude Code Dynamic Workflows, trigger `ultracode`). Use when a task exceeds a single agent's context or needs more than ~4…

9
105
Instructions
View
korallis logo

Api Design

korallis
Community

Design clean, scalable, and maintainable REST and GraphQL APIs following industry best practices. Use when designing public or internal APIs, planning endpoint structures, defining request/response…

9
89
Instructions
View
henkisdabro logo

Fifteen Factor App

henkisdabro
Community

Cloud-native SaaS architecture methodology extending Twelve-Factor with three additional factors (API First, Telemetry, Security). Use when planning SaaS tools, product software architecture,…

12
88
4 files
View
zhaono1 logo

Api Documenter

zhaono1
Community

API documentation specialist for OpenAPI/Swagger specifications. Use when documenting REST or GraphQL APIs.

12
79
4 files
View
jiaxiaojunQAQ logo

Agentic Jujutsu

jiaxiaojunQAQ
Community

Quantum-resistant, self-learning version control for AI agents with ReasoningBank intelligence and multi-agent coordination

8
79
1 files
View
rknall logo

Docker Configuration Validator

rknall
Community

Comprehensive Docker and Docker Compose validation following best practices and security standards. Use this skill when users ask to validate Dockerfiles, review Docker configurations, check Docker…

9
73
2 files
View
tonone-ai logo

Apex Profile

tonone-ai
Organization

Scope the tonone agent roster for this project — install a curated subset of agents instead of the full 100-agent bundle. Use when "cut down the agent list", "profile for this project", "too many…

9
73
Instructions
View
wpacademy logo

Wp Plugin Review

wpacademy
Community

Comprehensive WordPress plugin review covering security vulnerabilities, WordPress Coding Standards (WPCS) compliance, plugin repository guidelines, unit test coverage, and accessibility. Runs…

18
70
4 files
View
SamarthaKV29 logo

Antigravity Workflows

SamarthaKV29
Community

Orchestrate multiple Antigravity skills through guided workflows for SaaS MVP delivery, security audits, AI agent builds, and browser QA.

16
69
1 files
View
inertia-rails logo

Inertia Rails Architecture

inertia-rails
Organization

Server-driven architecture patterns for Inertia Rails + React. Load this FIRST when building any Inertia page or feature — it routes to the right skill. Decision matrix for data loading, forms,…

2
68
2 files
View
kaivyy logo

Perseus:Exploit

kaivyy
Community

Use when verifying vulnerabilities with Dynamic Exploit Generation (Phase 3)

14
68
Instructions
View
rejot-dev logo

Slack Setup

rejot-dev
Organization

Set up or verify Slack in Backoffice for bot-token API calls, sending messages, Events API webhooks, app mentions, URL verification, signing-secret validation, or checking whether a Slack event…

6
62
Instructions
View
Shubhamsaboo logo

Dependency Doctor

Shubhamsaboo
CommunityPopular

Checks requirements.txt, pyproject.toml, and package.json dependency manifests for surface-level direct-dependency footguns: standard-library shadowing pins, abandoned backports, unpinned…

20.4K
138.7K
2 files
View
usestrix logo

Ci Security Scanning With Strix

usestrix
OrganizationPopular

Add security scanning to CI/CD with Strix — GitHub Actions, GitLab CI, or any pipeline — so every pull request gets a diff-scoped AI pentest that blocks vulnerable code before it merges, with results…

6.9K
63.3K
Instructions
View
wshobson logo

Multi Reviewer Patterns

wshobson
CommunityPopular

Coordinate parallel code reviews across multiple quality dimensions with finding deduplication, severity calibration, and consolidated reporting. Use this skill when organizing multi-reviewer code…

4.2K
39.8K
1 files
View
mukul975 logo

Achieving Cmmc Level 2 Compliance

mukul975
CommunityPopular

Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score…

4K
32.9K
3 files
View
phuryn logo

Shipping Artifacts

phuryn
CommunityPopular

The durable documentation set that makes an AI-built (vibe-coded) app reviewable before shipping. A small core every app needs — architecture, user/permission flows, permissions, variables/secrets,…

2.8K
26.4K
Instructions
View
google logo

Google Cloud Recipe Auth

google
OrganizationPopular

Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (ADC), and best practices for…

1.6K
20.1K
Instructions
View
prowler-cloud logo

Django Drf

prowler-cloud
OrganizationPopular

Django REST Framework patterns. Trigger: When implementing generic DRF APIs (ViewSets, serializers, routers, permissions, filtersets). For Prowler API specifics (RLS/RBAC/Providers), also use…

2.4K
14.8K
3 files
View
trailofbits logo

Algorand Vulnerability Scanner

trailofbits
OrganizationPopular

Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand…

611
7.1K
3 files
View
AIPentest logo

Attack Surface Recon

AIPentest
OrganizationPopular

侦察/攻击面测绘:被动whois/amass/crt.sh/FOFA/Shodan,主动subfinder/httpx/naabu/katana/nuclei,DNS地域/CDN/Nginx catch-all/宝塔/UniApp指纹。开局第一动作,认知写入项目黑板。Use when starting recon, asset mapping, fingerprinting, or CDN/DNS…

1.2K
6.9K
Instructions
View
Tencent logo

Data Leakage Detection

Tencent
OrganizationPopular

Detect sensitive information disclosure via escalating dialogue probes. Covers system prompt extraction, credential/API key leakage, PII, and internal configuration exposure.

594
6.4K
Instructions
View
ThinkInAIXYZ logo

Code Review

ThinkInAIXYZ
OrganizationPopular

Comprehensive code review assistant that analyzes code quality, security, and best practices

734
6.3K
Instructions
View
SnailSploit logo

Offensive Api Security

SnailSploit
CommunityPopular

Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication,…

775
6K
Instructions
View
epoko77-ai logo

Humanize Redo

epoko77-ai
CommunityPopular

가장 최근 윤문 결과를 2차로 다시 다듬는다 — 특정 카테고리·문단·강도 조정도 가능. humanize-korean strict 윤문(Phase B)을 기존 run_id에 재실행해 잔존 finding을 처리한다. 트리거 — "/humanize-redo".

605
5.6K
Instructions
View
awarexone logo

Bb Methodology

awarexone
OrganizationPopular

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with…

868
4.9K
Instructions
View
zebbern logo

Api Fuzzing Bug Bounty

zebbern
CommunityPopular

This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or…

464
4.6K
Instructions
View
elementalsouls logo

Bugcrowd Reporting

elementalsouls
CommunityPopular

Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact,…

678
4.5K
Instructions
View
letta-ai logo

Context Doctor

letta-ai
OrganizationPopular

Investigate agent behavior and audit memory structure, organization, and skills; make evidence-backed repairs.

411
3.4K
2 files
View
ljagiello logo

Ctf Forensics

ljagiello
CommunityPopular

Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography,…

380
3.3K
14 files
View
open-gitagent logo

Create Agent

open-gitagent
OrganizationPopular

Creates and configures agent.yaml files, writes SOUL.md personality definitions, and sets up agent directory structures with skills, tools, and knowledge. Use when the user wants to configure an…

348
2.9K
Instructions
View
aws logo

Coordinating Multi Space Devops Agent

aws
OrganizationPopular

Coordinate the AWS DevOps Agent across multiple AgentSpaces from one Claude Code session — route questions to the right space (prod vs staging vs knowledge), query several spaces in parallel and…

311
2.7K
Instructions
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇