Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 1,633-1,683 of 1,735 AI skills

AI skills directory results

oliver-kriska logo

Assigns

oliver-kriska
Community

Compatibility alias for the Elixir/Phoenix plugin's LiveView assigns audit. Invoke explicitly with /lv:assigns.

40
555
Instructions
View
davekilleen logo

Dex Doctor

davekilleen
Community

Whole-system checkup: verifies every Dex feature honestly (working/off/broken/couldn't-check), self-heals what's provably safe, guides the rest. Use when the user says 'is Dex healthy', 'something's…

130
481
Instructions
View
OneWave-AI logo

Customer Panel Of Experts

OneWave-AI
Organization

Build a panel of your real buyer personas (from a deep scan of any tools you allow it to connect to) and have them debate any decision you bring — a marketing launch, a price increase, a new product,…

49
293
Instructions
View
blacklanternsecurity logo

Nosql Injection

blacklanternsecurity
Organization

Guide NoSQL injection exploitation during authorized penetration testing.

39
276
Instructions
View
secondsky logo

Better Auth

secondsky
Community

Skill for integrating Better Auth - comprehensive TypeScript authentication framework for Cloudflare D1, Next.js, Nuxt, and 15+ frameworks. Use when adding auth, encountering D1 adapter errors, or…

31
219
36 files
View
proflead logo

Threat Modeling

proflead
Community

Perform threat modeling for a system or feature. Use when a senior developer needs security risk assessment.

31
147
Instructions
View
trilwu logo

Attacking Entra Id

trilwu
Community

Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse,…

15
144
Instructions
View
simota logo

Radar

simota
Community

Adding edge-case tests, repairing flaky tests, and improving coverage. Use when test gaps need filling or regressions need guarding. Supports JS/TS, Python, Go, Rust, and Java.

14
80
20 files
View
vm0-ai logo

Issue Triage

vm0-ai
Organization

Triage support issues by severity, duplicates, ownership, and first-response approach.

18
76
Instructions
View
brucesongs logo

Exa Search

brucesongs
Community

Semantic search using Exa API for security research queries. Unlike keyword-based search, Exa understands context and retrieves high-quality, relevant results for technical research.

18
70
12 files
View
sickn33 logo

Agents Md

sickn33
CommunityPopular

Create, revise, or audit AGENTS.md files from repository evidence, verified commands, and correctly scoped instructions without overwriting maintainer intent.

6.8K
46.5K
Instructions
View
zhaoxuya520 logo

Docs Generator

zhaoxuya520
CommunityPopular

Creates task-oriented technical documentation with progressive disclosure. Use when writing READMEs, API docs, architecture docs, or markdown documentation. Also use this skill at the END of any…

5K
36.3K
3 files
View
mukul975 logo

Analyzing Ransomware Leak Site Intelligence

mukul975
CommunityPopular

Safely monitor ransomware group Tor-hosted data leak sites (DLS) to collect and extract structured victim posting data, track group activity trends over time, and produce sector- and…

4K
32.9K
2 files
View
AgriciDaniel logo

Ads Landing

AgriciDaniel
CommunityPopular

Audit paid-ad landing pages for message match, mobile experience, performance, accessibility, trust, forms, consent, tracking, security, and conversion friction. Use for landing-page audit, post-click…

1.4K
9.4K
Instructions
View
wgpsec logo

Ctf Misc

wgpsec
OrganizationPopular

CTF 杂项挑战技术。当遇到编码谜题、Python/Bash 沙箱逃逸、RF/SDR 信号、游戏/VM 逆向、K8s RBAC、浮点数技巧、Z3 约束求解、博弈论等不属于 pwn/crypto/web/reverse/forensics/osint 的 CTF 挑战时使用。先排除其他分类后再使用本技能

242
1.7K
12 files
View
microsoft logo

Entra Agent Id

microsoft
OrganizationPopular

Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmi_path, OBO, cross-tenant)…

246
1.5K
6 files
View
vellum-ai logo

Notion

vellum-ai
OrganizationPopular

Read and write Notion pages and databases using the Notion API

186
1.3K
1 files
View
ancoleman logo

Securing Authentication

ancoleman
Community

Authentication, authorization, and API security implementation. Use when building user systems, protecting APIs, or implementing access control. Covers OAuth 2.1/OIDC, JWT patterns, sessions,…

73
523
11 files
View
Mathews-Tom logo

Pre Landing Review

Mathews-Tom
Community

Gate-oriented safety audit for code changes before landing, using a checklist with two-pass severity triage. Triggers on: "is this safe to land", "pre-landing review", "safety check before merge",…

47
318
2 files
View
blacklanternsecurity logo

Oauth Attacks

blacklanternsecurity
Organization

Exploit OAuth 2.0 and OpenID Connect vulnerabilities during authorized penetration testing.

39
276
Instructions
View
trilwu logo

Attacking Graphql

trilwu
Community

Test GraphQL APIs — introspection and schema recovery when introspection is disabled, field suggestion abuse, batching and alias-based rate limit bypass, query depth and complexity denial of service,…

15
144
Instructions
View
simota logo

Rally

simota
Community

Orchestrating multi-session parallel execution via Claude Code Agent Teams API and Codex CLI Subagents — launch, manage, coordinate concurrent tasks. Use when parallel work is needed.

14
80
12 files
View
brucesongs logo

Exploit Development

brucesongs
Community

Exploit development covers the full chain from vulnerability discovery through crash analysis to working exploit code, spanning buffer overflows, ROP chains, format string bugs, and shellcode…

18
70
12 files
View
Tibsfox logo

Code Review

Tibsfox
Community

Reviews code for bugs, style, and best practices. Use when reviewing PRs or checking code quality.

9
70
Instructions
View
mukul975 logo

Analyzing Ransomware Network Indicators

mukul975
CommunityPopular

Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and NetFlow…

4K
32.9K
2 files
View
Jeffallan logo

Terraform Engineer

Jeffallan
CommunityPopular

Use when implementing infrastructure as code with Terraform across AWS, Azure, or GCP. Invoke for module development (create reusable modules, manage module versioning), state management (migrate…

1.1K
11.5K
5 files
View
elementalsouls logo

Continuous Exposure Monitoring

elementalsouls
CommunityPopular

Turns one-shot external recon into a continuous monitoring program. Covers the scheduled re-scan-and-diff loop (baseline snapshot -> interval sleep -> re-scan -> asset/finding delta -> threshold-gated…

474
2.6K
Instructions
View
wgpsec logo

Ctf Osint

wgpsec
OrganizationPopular

CTF 开源情报(OSINT)技术。当挑战要求从公开信息中找线索——如给定用户名/邮箱追踪身份、给定照片进行地理定位、从历史网页快照中恢复数据时使用。覆盖社交媒体调查、Google Dorking、反向图片搜索、Wayback Machine、DNS 侦察、Tor 中继查询、元数据提取

242
1.7K
5 files
View
microsoft logo

Entra App Registration

microsoft
OrganizationPopular

Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API…

246
1.5K
16 files
View
daymade logo

Skill Reviewer

daymade
CommunityPopular

Reviews and improves Claude Code skills against official best practices. Supports three modes - self-review (validate your own skills), external review (evaluate others' skills), and auto-PR (fork,…

219
1.4K
4 files
View
ancoleman logo

Security Hardening

ancoleman
Community

Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles. Use when hardening production infrastructure, meeting compliance…

73
523
13 files
View
blacklanternsecurity logo

Password Reset Poisoning

blacklanternsecurity
Organization

Exploit password reset vulnerabilities during authorized penetration testing.

39
276
Instructions
View
Mindrally logo

Ethereum

Mindrally
Organization

Expert guidelines for Ethereum smart contract development with Solidity, OpenZeppelin, and Hardhat

41
259
Instructions
View
secondsky logo

Bun Cloudflare Workers

secondsky
Community

This skill should be used when the user asks about "Cloudflare Workers with Bun", "deploying Bun to Workers", "wrangler with Bun", "edge deployment", "Bun to Cloudflare", or building and deploying…

31
219
Instructions
View
team-telnyx logo

Telnyx Numbers Services Curl

team-telnyx
Organization

Configure voicemail, voice channels, and emergency (E911) services for your phone numbers. This skill provides REST API (curl) examples.

21
217
Instructions
View
trilwu logo

Attacking Grpc Protobuf

trilwu
Community

Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web…

15
144
Instructions
View
Hmbown logo

Identify

Hmbown
Community

Identify is static analysis for operational understanding. It answers "What is this?" by inspecting structure, naming, dependencies, and runtime touchpoints. It does NOT search for artifacts, debug…

10
106
Instructions
View
existential-birds logo

Elixir Security Review

existential-birds
Organization

Reviews Elixir code for security vulnerabilities including code injection, atom exhaustion, and secret handling. Use when reviewing code handling user input, external data, or sensitive configuration.

8
82
3 files
View
simota logo

Rank

simota
Community

Quantifying priority by scoring competing items with ICE/RICE/WSJF/MoSCoW/Cost of Delay/Kano. No code. Use to prioritize features/bugs/initiatives or arbitrate Must vs Should at MVP scoping.

14
80
6 files
View
brucesongs logo

File Inclusion

brucesongs
Community

Local File Inclusion (LFI) and Remote File Inclusion (RFI) attack techniques covering path traversal, PHP wrapper abuse, log poisoning, session file inclusion, and remote payload hosting for code…

18
70
12 files
View
ww-w-ai logo

Development Pipeline

ww-w-ai
Organization

9-phase Development Pipeline complete knowledge. Use when user doesn't know development order or starts a new project. Triggers: development pipeline, phase, development order, where to start, what to…

16
66
Instructions
View
elementalsouls logo

Email Domain Security

elementalsouls
CommunityPopular

Rigorous, defensible email-spoofability verdict and SPF supply-chain risk analysis computed from published DNS alone. Deepens the record-level SPF/DMARC/DKIM/BIMI/MTA-STS/DNSSEC fetch recipes in the…

474
2.6K
Instructions
View
ww-w-ai logo

Dynamic

ww-w-ai
Organization

Fullstack development skill using bkend.ai BaaS platform. Covers authentication, data storage, API integration for dynamic web apps. Project initialization with "init dynamic" or "dynamic init". Use…

16
66
Instructions
View
elementalsouls logo

Identity Provider Recon

elementalsouls
CommunityPopular

Organization-grade identity-fabric mapping: tenant/federation fingerprinting and the pre-auth user-ENUMERATION oracle methodology — enumeration and fingerprint only, never credential submission.…

474
2.6K
Instructions
View
luongnv89 logo

Website Cloner

luongnv89
Community

Build an improved website clone from a URL via 6-phase gated workflow (Vite/React/shadcn/Tailwind + GitHub Pages). Use for end-to-end site rebuilds. Don't use for single-phase work.

18
124
1 files
View
luongnv89 logo

Website Analyzer

luongnv89
Community

Analyze a website's UI/UX, category, style, performance, surface security, and SEO; emit structured JSON. Use for URL audits or website-cloner input. Don't use for penetration tests, full SEO audits,…

18
124
Instructions
View
anthropics logo

Customer Escalation

anthropics
OrganizationPopular

Package an escalation for engineering, product, or leadership with full context. Use when a bug needs engineering attention beyond normal support, multiple customers report the same issue, a customer…

3K
24.9K
Instructions
View
elementalsouls logo

Osint Methodology

elementalsouls
CommunityPopular

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 6-stage recon pipeline (seed → asset expansion → enrichment → exposure analysis →…

474
2.6K
Instructions
View
bobmatnyc logo

Linkedin

bobmatnyc
Community

LinkedIn automation via the Linked API CLI - fetch profiles, search people and companies, send messages, manage connections, create posts, react, comment, and run Sales Navigator and custom workflows.…

19
75
1 files
View
google logo

Mantis Advise

google
OrganizationPopular

Proactive security advisor and architectural remediation assistant for secure code development. Use to query threat models, historical vulnerability lineages, verified patch patterns, triaged false…

154
1.6K
Instructions
View
luongnv89 logo

Website Clone Report

luongnv89
Community

Generate a plain-language report from website-analyzer JSON and save it only after explicit approval. Use for non-technical summaries. Don't use for developer audits, raw SEO analysis, penetration…

18
124
1 files
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇