Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 1,480-1,530 of 1,735 AI skills

AI skills directory results

sendaifun logo

Zz Code Recon

sendaifun
Organization

Deep architectural context building for security audits. Use when conducting security reviews, building codebase understanding, mapping trust boundaries, or preparing for vulnerability analysis.…

81
128
5 files
View
travisjneuman logo

Generic Fullstack Code Reviewer

travisjneuman
Community

Review full-stack code for bugs, security vulnerabilities, performance issues, accessibility gaps, and CLAUDE.md compliance. Enforces TypeScript strict mode, input validation, GPU-accelerated…

22
98
Instructions
View
korallis logo

Threat Hunting

korallis
Community

Proactively search for security threats, vulnerabilities, and suspicious patterns in applications and infrastructure before they cause damage. Use when conducting security audits, identifying…

9
89
Instructions
View
zoom logo

Zoom Websockets

zoom
Organization

Zoom WebSockets for real-time event notifications via persistent connection. Alternative to webhooks with lower latency, bidirectional communication, and enhanced security. Use when you need real-time…

16
78
5 files
View
ww-w-ai logo

Bkend Guides

ww-w-ai
Organization

bkend.ai operational guides, troubleshooting, and platform comparison. Covers migration guides, performance optimization, testing strategy, common error solutions, and FAQ. Triggers: migration,…

16
66
Instructions
View
wshobson logo

Auth Implementation Patterns

wshobson
CommunityPopular

Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing…

4.2K
39.8K
1 files
View
anthropics logo

Command Development

anthropics
OrganizationPopular

This skill should be used when the user asks to "create a slash command", "add a command", "write a custom command", "define command arguments", "use command frontmatter", "organize commands", "create…

4.1K
36.4K
9 files
View
mukul975 logo

Analyzing Network Traffic With Wireshark

mukul975
CommunityPopular

Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations…

4K
32.9K
2 files
View
googleworkspace logo

Persona It Admin

googleworkspace
OrganizationPopular

Administer IT — monitor security and configure Workspace.

1.8K
31K
Instructions
View
vercel-labs logo

Deepsec

vercel-labs
OrganizationPopular

Run deepsec, an AI-powered cyber-security vulnerability scanner. Activates when the user invokes /deepsec, asks to run deepsec, or wants to scan their repo, branch, or uncommitted changes for…

485
8K
386 files
View
trailofbits logo

Supply Chain Risk Auditor

trailofbits
OrganizationPopular

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and…

611
7.1K
12 files
View
rohitg00 logo

Mcp Audit

rohitg00
CommunityPopular

Audit connected MCP servers for token overhead, redundancy, and security. Use when sessions feel slow or before adding new MCPs.

286
2.9K
Instructions
View
wgpsec logo

Php Framework Audit

wgpsec
OrganizationPopular

PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。 覆盖 6 大框架: Laravel(Mass Assignment/Blade XSS/CSRF 例外)、 ThinkPHP(RCE 历史漏洞/路由注入/缓存写入)、WordPress(插件漏洞/权限钩子/nonce 验证)、 Symfony(Debug Bar/YAML…

242
1.7K
3 files
View
RefoundAI logo

Personal Brand Network

RefoundAI
OrganizationPopular

Help users build a strategic professional network and public audience by transitioning from passive learning to active, value-driven contribution.

170
1.3K
2 files
View
oliver-kriska logo

Security

oliver-kriska
Community

Enforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS, SQL injection, input validation, secrets. Use when editing auth files, login flows, RBAC, or API keys.

40
555
7 files
View
blacklanternsecurity logo

Csrf

blacklanternsecurity
Organization

Exploit Cross-Site Request Forgery (CSRF) vulnerabilities during authorized penetration testing.

39
276
Instructions
View
trilwu logo

Responding To Incidents

trilwu
Community

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…

15
144
Instructions
View
TheBeardedBearSAS logo

Security Symfony

TheBeardedBearSAS
Organization

Sicherheit & DSGVO - Atoll Tourisme. Use when reviewing security, implementing auth, or hardening code.

9
105
Instructions
View
simota logo

Pdm

simota
Community

Navigating delivery status read-only: reconciles planned scope (specs/roadmap/PRD) against implemented code for what's built vs left. Not for priority scoring (Rank) or AC conformance (Attest).

14
80
8 files
View
brucesongs logo

Dns Attacks

brucesongs
Community

DNS Attacks exploit the Domain Name System protocol for reconnaissance, spoofing, tunneling, and data exfiltration. DNS is a foundational infrastructure service that is frequently misconfigured,…

18
70
15 files
View
github logo

Azure Resource Visualizer

github
OrganizationPopular

Analyze Azure resource groups and generate detailed Mermaid architecture diagrams showing the relationships between individual resources. Use this skill when the user asks for a diagram of their Azure…

5K
39.1K
1 files
View
mukul975 logo

Analyzing Office365 Audit Logs For Compromise

mukul975
CommunityPopular

Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.

4K
32.9K
2 files
View
anbeime logo

Ontoly Software Graph

anbeime
CommunityPopular

Use Ontoly's deterministic Software Graph and MCP capabilities for architecture review, request tracing, dependency analysis, configuration lookup, and impact analysis before falling back to…

645
6.9K
1 files
View
steipete logo

Vm Lab

steipete
CommunityPopular

Parallels macOS VM lab: GUI automation, Peekaboo, TCC, Ghostty.

547
6.6K
3 files
View
Netw0rkNoob logo

Web Security Advanced

Netw0rkNoob
OrganizationPopular

Web高级安全测试 — 注入攻击族、协议安全、认证与逻辑漏洞、文件与部署安全、现代Web攻击面,含完整Playbook

454
3.4K
33 files
View
yaklang logo

Ios Pentesting Tricks

yaklang
OrganizationPopular

iOS pentesting playbook. Use when testing iOS applications for keychain extraction, URL scheme hijacking, Universal Links exploitation, runtime manipulation, binary protection analysis, data storage…

292
2.2K
1 files
View
wgpsec logo

Php Frontend Audit

wgpsec
OrganizationPopular

PHP 源码前端交互类漏洞审计。当在 PHP 白盒审计中需要检测前端安全相关漏洞时触发。 覆盖 5 类前端风险: XSS(反射/存储/DOM)、CSRF(Token 验证缺失)、 开放重定向(header Location 可控)、CRLF 注入(HTTP 响应拆分)、会话与 Cookie 安全(固定/劫持/属性)。 需要 php-audit-pipeline 提供的数据流证据。

242
1.7K
1 files
View
gooseworks-ai logo

Ad To Landing Page Auditor

gooseworks-ai
OrganizationPopular

Analyze the message match between your ads and landing pages. Checks if the promise in the ad copy carries through to the landing page headline, body, and CTA. Flags disconnects that kill conversion…

208
1.2K
1 files
View
jezweb logo

Shopify Setup

jezweb
CommunityPopular

Set up Shopify CLI auth and Admin API access for a store. Install CLI, authenticate, create custom app, store access token, verify. Use whenever the user wants to connect to a Shopify store, set up…

102
1K
1 files
View
HoangNguyen0403 logo

Common Dast Tooling

HoangNguyen0403
Community

Standardize dynamic application security testing for backend APIs, frontend web apps, and mobile clients. Covers ZAP, Nuclei, Nikto, sqlmap, ffuf, browser automation, mobile proxy interception, and…

164
569
2 files
View
blacklanternsecurity logo

Deserialization Dotnet

blacklanternsecurity
Organization

Exploit .NET deserialization vulnerabilities during authorized penetration testing.

39
276
Instructions
View
secondsky logo

Api Reference Documentation

secondsky
Community

Creates professional API documentation using OpenAPI specifications with endpoints, authentication, and interactive examples. Use when documenting REST APIs, creating SDK references, or building…

31
219
Instructions
View
LerianStudio logo

Ring:Using Lib Commons

LerianStudio
Organization

Using lib-commons v5, Lerian's shared Go library (non-observability surface), in two modes. Sweep Mode detects DIY code replaceable by lib-commons at file:line. Reference Mode catalogs lifecycle…

28
215
2 files
View
trilwu logo

Triaging Security Alerts

trilwu
Community

Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment by…

15
144
Instructions
View
dykyi-roman logo

Check Doc Links

dykyi-roman
Community

Validates documentation links. Detects broken relative links, missing anchor targets, malformed URLs, and orphaned documentation files.

25
98
Instructions
View
simota logo

Pixel

simota
Community

Generating pixel-accurate HTML/CSS code from image mockups (PNG/JPG/screenshots) and performing visual verification for faithful reproduction. Use when mockup-to-code generation is needed.

14
80
14 files
View
brucesongs logo

Docker Patterns

brucesongs
Community

Setting up a practice lab for penetration testing techniques - Creating isolated environments for exploit development and testing - Building vulnerable application targets for training - Testing tools…

18
70
12 files
View
ww-w-ai logo

Bkend Quickstart

ww-w-ai
Organization

bkend.ai platform onboarding and core concepts guide. Covers MCP setup, resource hierarchy (Org->Project->Environment), Tenant vs User model, and first project creation. Use proactively when user is…

16
66
Instructions
View
sickn33 logo

Rex

sickn33
CommunityPopular

Translates user intent into a precise, unambiguous specification and requirements.

6.8K
46.5K
Instructions
View
wshobson logo

Code Review Excellence

wshobson
CommunityPopular

Master effective code review practices to provide constructive feedback, catch bugs early, and foster knowledge sharing while maintaining team morale. Use when reviewing pull requests, establishing…

4.2K
39.8K
Instructions
View
Jeffallan logo

Secure Code Guardian

Jeffallan
CommunityPopular

Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as hashing passwords with…

1.1K
11.5K
5 files
View
AgriciDaniel logo

Ads Audit

AgriciDaniel
CommunityPopular

Run a source-grounded paid-advertising audit for one or more of Google, Meta, YouTube, LinkedIn, TikTok, Microsoft, Apple, Amazon, Reddit, Pinterest, Snapchat, and X. Use for full ad checks, account…

1.4K
9.4K
Instructions
View
zebbern logo

Red Team Tools

zebbern
CommunityPopular

This skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate subdomains", or needs…

464
4.6K
Instructions
View
elementalsouls logo

Hunt Session

elementalsouls
CommunityPopular

Hunt Session Management vulnerabilities — session fixation (no regeneration on login), insufficient invalidation on logout / password-change / email-change, predictable or low-entropy session IDs,…

678
4.5K
Instructions
View
yaklang logo

Jndi Injection

yaklang
OrganizationPopular

JNDI injection playbook. Use when Java applications perform JNDI lookups with attacker-controlled names, especially via Log4j2, Spring, or any code path reaching InitialContext.lookup().

292
2.2K
Instructions
View
mvanhorn logo

Pp Azure Functions Admin

mvanhorn
CommunityPopular

Inspect, audit, and right-size your Azure Functions from the terminal — cold-start trends, config drift Trigger phrases: `check my azure functions`, `are my functions cold-starting`, `should I move…

614
2K
Instructions
View
wgpsec logo

Php Injection Audit

wgpsec
OrganizationPopular

PHP 源码注入类漏洞审计。当在 PHP 白盒审计中需要检测注入类漏洞时触发。 覆盖 6 种注入: SQL 注入(PDO/MySQLi/ORM)、NoSQL 注入(MongoDB)、 命令注入(system/exec/passthru)、LDAP 注入、表达式注入(eval/preg_replace /e)、SSRF。 需要 php-audit-pipeline…

242
1.7K
1 files
View
uphiago logo

Zimbra Attack

uphiago
CommunityPopular

Zimbra SOAP user enum, CVE-2022-37042, SSRF when webmail.

213
1.3K
Instructions
View
blacklanternsecurity logo

Deserialization Java

blacklanternsecurity
Organization

Exploit Java deserialization vulnerabilities during authorized penetration testing.

39
276
Instructions
View
Mindrally logo

Docker

Mindrally
Organization

Docker containerization best practices for building, securing, and deploying containers.

41
259
Instructions
View
TerminalSkills logo

Apollo Client

TerminalSkills
Organization

You are an expert in Apollo Client, the comprehensive GraphQL client for React applications. You help developers fetch data with GraphQL queries and mutations, manage local and remote state with…

21
155
1 files
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇