Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 1,531-1,581 of 1,735 AI skills

AI skills directory results

bobmatnyc logo

Security Scanning

bobmatnyc
Community

CI security scanning: secrets, deps, SAST, triage, expiring exceptions

34
152
6 files
View
trilwu logo

Writing Sigma Rules

trilwu
Community

Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with…

15
144
Instructions
View
brucesongs logo

Edge Computing Attack

brucesongs
Community

Attacks against edge computing platforms — Cloudflare Workers (V8 isolate), Fastly Compute@Edge (WASM/Wasmtime), AWS Lambda@Edge and CloudFront Functions, Akamai EdgeWorkers, Vercel Edge Functions,…

18
70
11 files
View
ww-w-ai logo

Bkend Security

ww-w-ai
Organization

bkend.ai security policies and encryption expert skill. Covers API key management (Public vs Secret), Row Level Security (RLS) with 4 roles (admin/user/guest/self), data encryption (Argon2id,…

16
66
Instructions
View
anthropics logo

Plugin Settings

anthropics
OrganizationPopular

This skill should be used when the user asks about "plugin settings", "store plugin configuration", "user-configurable plugin", ".local.md files", "plugin state files", "read YAML frontmatter",…

4.1K
36.4K
7 files
View
zhaoxuya520 logo

Case Review

zhaoxuya520
CommunityPopular

Reviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.

5K
36.3K
2 files
View
mukul975 logo

Analyzing Packed Malware With Upx Unpacker

mukul975
CommunityPopular

Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static…

4K
32.9K
2 files
View
Jeffallan logo

Security Reviewer

Jeffallan
CommunityPopular

Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance. Use when conducting security audits, reviewing code for…

1.1K
11.5K
6 files
View
elementalsouls logo

Hunt Shadow Api

elementalsouls
CommunityPopular

Hunt shadow / zombie / undocumented API surface (OWASP API9 Improper Inventory Management) — enumerate the full API version history (v1/v2/beta/legacy paths, header- and subdomain-based versioning),…

678
4.5K
Instructions
View
yaklang logo

Jwt Oauth Token Attacks

yaklang
OrganizationPopular

JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding weaknesses.

292
2.2K
Instructions
View
wgpsec logo

Php Serialization Audit

wgpsec
OrganizationPopular

PHP 源码序列化与模板类漏洞审计。当在 PHP 白盒审计中需要检测反序列化、XML 解析或模板注入漏洞时触发。 覆盖 3 类风险: PHP 反序列化(unserialize/phar 反序列化/POP 链构造)、 XXE(XML 外部实体注入/libxml 配置)、SSTI(模板注入/Twig/Blade/Smarty 引擎)。 需要 php-audit-pipeline 提供的数据流证据。

242
1.7K
1 files
View
uphiago logo

Bb Local Toolkit

uphiago
CommunityPopular

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning, vuln hunting (30+ classes), A-to-B chaining,…

213
1.3K
Instructions
View
aj-geddes logo

Cloud Security Configuration

aj-geddes
Community

Implement comprehensive cloud security across AWS, Azure, and GCP with IAM, encryption, network security, compliance, and threat detection.

55
340
6 files
View
blacklanternsecurity logo

Deserialization Php

blacklanternsecurity
Organization

Exploit PHP deserialization vulnerabilities during authorized penetration testing.

39
276
Instructions
View
Mindrally logo

Dotnet

Mindrally
Organization

Guidelines for .NET backend development with C#, ASP.NET Core, and Entity Framework Core

41
259
Instructions
View
secondsky logo

Api Security Hardening

secondsky
Community

REST API security hardening with authentication, rate limiting, input validation, security headers. Use for production APIs, security audits, defense-in-depth, or encountering vulnerabilities,…

31
219
1 files
View
danielvm-git logo

Request Review

danielvm-git
Community

Dispatch a fresh reviewer agent with a clean context to critique the code after audit-code passes. The reviewer has no shared state with the coding agent and gives a genuine second opinion. Use after…

18
206
Instructions
View
trilwu logo

Writing Yara Rules

trilwu
Community

Author durable YARA detection rules — meta/strings/condition anatomy, string types and modifiers, structural conditions with file magic and offsets, the PE/ELF/math/hash modules,…

15
144
Instructions
View
vasilyu1983 logo

Dev Dependency Management

vasilyu1983
Community

Guides dependency management across languages and ecosystems. Use when choosing package managers, lockfiles, update policy, security scanning, SBOMs, or monorepo patterns.

19
87
28 files
View
wshaddix logo

Dotnet Cryptography

wshaddix
Community

Choosing crypto algorithms, hashing, encryption, or key derivation. AES-GCM, RSA, ECDSA, PQC.

13
79
Instructions
View
brucesongs logo

Edge Computing Security

brucesongs
Community

Edge computing security testing covering CDN bypass, Cloudflare Workers abuse, AWS Lambda@Edge attacks, cache poisoning, origin IP discovery, WAF bypass, and edge function injection.

18
70
9 files
View
zhaoxuya520 logo

Cloud K8s

zhaoxuya520
CommunityPopular

Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.

5K
36.3K
1 files
View
mukul975 logo

Analyzing Pdf Malware With Pdfid

mukul975
CommunityPopular

Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector…

4K
32.9K
2 files
View
internet-court logo

Near Intents

internet-court
OrganizationPopular

Cross-chain token swap integration using NEAR Intents 1Click API. Use when building swap widgets, bridge interfaces, or multi-chain transfers across EVM, Solana, NEAR, TON, Stellar, and Tron.

106
5.8K
17 files
View
zebbern logo

Regulatory Audit Generator

zebbern
CommunityPopular

Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable…

464
4.6K
Instructions
View
elementalsouls logo

Hunt Sharepoint

elementalsouls
CommunityPopular

Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass (Authentication.asmx), ToolShell…

678
4.5K
Instructions
View
yaklang logo

Kernel Exploitation

yaklang
OrganizationPopular

Linux kernel exploitation playbook. Use when exploiting kernel vulnerabilities (UAF, OOB, race condition, type confusion) for privilege escalation via commit_creds, modprobe_path overwrite, or kernel…

292
2.2K
2 files
View
wgpsec logo

Ctf Ai Ml

wgpsec
OrganizationPopular

CTF AI/ML 攻击技术。当挑战涉及 AI 模型攻击、对抗样本生成、模型提取、Prompt 注入/越狱、LoRA 权重操纵、LLM Token 走私、成员推理攻击、训练数据投毒、神经网络分析时使用。覆盖 FGSM/PGD/C&W 对抗攻击、模型反演、模型权重扰动还原、LLM 工具链劫持、上下文窗口操纵等 AI 安全全链路攻防技术

242
1.7K
3 files
View
cbrock84 logo

Chief Information Officer

cbrock84
CommunityPopular

The CIO's remit — running the technology the company works on, service quality, IT spend, and the boundary with product engineering. Use this to set IT priorities, decide what IT owns versus…

237
1.6K
1 files
View
uphiago logo

Bug Bounty

uphiago
CommunityPopular

Master bug bounty orchestrator — full pipeline: recon, pre-hunt learning, vulnerability hunting (30+ classes), A-to-B chaining, AI/LLM testing (ASI01-ASI10), language-specific grep, bypass tables, and…

213
1.3K
Instructions
View
giuseppe-trisciuoglio logo

Spring Boot Actuator

giuseppe-trisciuoglio
Community

Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services. Use when setting up…

41
345
14 files
View
mizchi logo

Security Expert

mizchi
Community

Security specialist perspective for the weekly review. Focuses on XSS/CSRF, authorization boundaries, input validation, secrets handling, and dependency CVEs.

4
333
Instructions
View
blacklanternsecurity logo

File Upload Bypass

blacklanternsecurity
Organization

Guide file upload restriction bypass during authorized penetration testing.

39
276
Instructions
View
membranedev logo

Acunetix

membranedev
Community

Acunetix integration. Manage data, records, and automate workflows. Use when the user wants to interact with Acunetix data.

42
268
Instructions
View
LerianStudio logo

Ring:Using Lib Systemplane

LerianStudio
Organization

Using lib-systemplane, the hot-reload runtime-config plane (Postgres LISTEN/NOTIFY or MongoDB change streams), in two modes. Sweep Mode detects DIY config reload (SIGHUP, fsnotify, viper, pgx LISTEN),…

28
215
Instructions
View
bitwarden logo

Reviewing Agent Definitions

bitwarden
Organization

Reviews Claude Code agent definition files for tool-access security, triggering quality, and system prompt clarity. Use when reviewing changes to agents/<name>.md or agents/<name>/AGENT.md, whether…

19
149
Instructions
View
trilwu logo

Abusing Adcs

trilwu
Community

Enumerate and abuse Active Directory Certificate Services with Certipy and Certify — the ESC1 through ESC16 escalation paths, vulnerable template and CA configurations, NTLM relay to web enrollment,…

15
144
Instructions
View
simota logo

Probe

simota
Community

Integrating OWASP ZAP/Burp Suite/Nuclei, planning penetration tests, executing DAST, and scanning for vulnerabilities. For runtime vulnerability validation. Complements Sentinel static analysis.

14
80
15 files
View
zhaoxuya520 logo

Code Audit

zhaoxuya520
CommunityPopular

Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.

5K
36.3K
1 files
View
mukul975 logo

Analyzing Persistence Mechanisms In Linux

mukul975
CommunityPopular

Scan Linux systems for persistence mechanisms including crontab/systemd entries, LD_PRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorized_keys backdoors, then…

4K
32.9K
2 files
View
trailofbits logo

Constant Time Testing

trailofbits
OrganizationPopular

Measures timing side channels in cryptographic implementations by running them, using dudect for statistical analysis and Timecop over Valgrind for dynamic tracing. Covers the formal, symbolic,…

611
7.1K
2 files
View
zebbern logo

Repo Audit

zebbern
CommunityPopular

Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. Triggered when users ask about Git analysis, code hotspots,…

464
4.6K
3 files
View
yaklang logo

Kubernetes Pentesting

yaklang
OrganizationPopular

Kubernetes penetration testing playbook. Use when targeting Kubernetes clusters via API server, RBAC enumeration, service account abuse, etcd access, Kubelet API, pod escape, cloud-specific metadata,…

292
2.2K
Instructions
View
Besty0728 logo

Unity Project Scout

Besty0728
CommunityPopular

Advise on reconnoitering an existing Unity project

164
1.8K
Instructions
View
wgpsec logo

Ctf Crypto

wgpsec
OrganizationPopular

CTF 密码学攻击技术。用于 RSA/AES/ECC/格密码/PRNG/ZKP/古典密码等 CTF 加密类挑战。当遇到加密数据需要破解、密码学相关 CTF 题目、需要分析加密算法弱点、或识别到密文/公钥/密码学参数时使用。覆盖从古典替换密码到现代公钥密码、椭圆曲线、格攻击、零知识证明等全方位密码学攻防技术

242
1.7K
16 files
View
microsoft logo

Azure Resource Lookup

microsoft
OrganizationPopular

List, find, and show Azure resources across subscriptions or resource groups. Handles prompts like "list the websites in my subscription", "list my web apps", "show my app services", "list virtual…

246
1.5K
1 files
View
HoangNguyen0403 logo

Common Exploit Verification

HoangNguyen0403
Community

Enforce "No Exploit, No Report" policy with PoC construction standards, false-positive filtering, and evidence collection per vulnerability class across backend, frontend, and mobile. Use when…

164
569
3 files
View
blacklanternsecurity logo

Idor

blacklanternsecurity
Organization

Exploit Insecure Direct Object Reference (IDOR) and broken access control vulnerabilities during authorized penetration testing.

39
276
Instructions
View
bobmatnyc logo

Api Design Patterns

bobmatnyc
Community

Comprehensive API design patterns covering REST, GraphQL, gRPC, versioning, authentication, and modern API best practices

34
152
6 files
View
bitwarden logo

Reviewing Claude Config

bitwarden
Organization

Reviews Claude configuration files for security, structure, and prompt engineering quality. Use when reviewing changes to CLAUDE.md, agents, prompts, commands, hooks, or settings. Routes each file…

19
149
6 files
View
trilwu logo

Abusing Ci Cd Oidc

trilwu
Community

Exploit CI/CD pipeline misconfigurations and OIDC federation weaknesses across GitHub Actions, GitLab CI, and Jenkins -- poisoned workflows, secret exfiltration, runner compromise, overly broad OIDC…

15
144
Instructions
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇