Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 205-255 of 1,735 AI skills

AI skills directory results

eigent-ai logo

Skill Security Auditor

eigent-ai
OrganizationPopular

Security auditing for code, configs, and infrastructure. Use when the user wants to audit or improve security: scan for vulnerabilities (SQL injection, XSS, command injection, path traversal), detect…

1.8K
15.3K
4 files
View
prowler-cloud logo

Django Migration Psql

prowler-cloud
OrganizationPopular

Reviews Django migration files for PostgreSQL best practices specific to Prowler. Trigger: When creating migrations, running makemigrations/pgmakemigrations, reviewing migration PRs, adding indexes or…

2.4K
14.8K
Instructions
View
Jeffallan logo

Atlassian Mcp

Jeffallan
CommunityPopular

Integrates with Atlassian products to manage project tracking and documentation via MCP protocol. Use when querying Jira issues with JQL filters, creating and updating tickets with custom fields,…

1.1K
11.5K
5 files
View
Tencent logo

Direct Injection Detection

Tencent
OrganizationPopular

Detect direct prompt injection or instruction override via user message (no external content). Focuses on system/role override attempts.

594
6.4K
Instructions
View
SnailSploit logo

Offensive Jwt

SnailSploit
CommunityPopular

JWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256→HS256), weak HMAC secret brute force, kid parameter injection (SQLi, path traversal), jku/x5u/jwk header…

775
6K
Instructions
View
awarexone logo

Bug Bounty

awarexone
OrganizationPopular

Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling,…

868
4.9K
Instructions
View
spinabot logo

Bear Notes

spinabot
OrganizationPopular

Create, search, and manage Bear notes via grizzly CLI.

50
4.4K
Instructions
View
glitternetwork logo

Pinme R2

glitternetwork
OrganizationPopular

Use when a PinMe Cloudflare Worker needs R2 object storage, including secure file or image upload, streaming download, metadata lookup, deletion, listing, Range requests, or R2+D1 coordination. Guides…

276
3.7K
1 files
View
davepoon logo

Release Check

davepoon
CommunityPopular

Pre-release verification checklist. Validates features, tests, docs, security, and quality gates before shipping. Delegates to the Centinela (QA) agent.

509
3.5K
Instructions
View
ljagiello logo

Ctf Malware

ljagiello
CommunityPopular

Provides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, malicious packages, custom crypto protocols, C2 traffic, PE/.NET binaries, RC4/AES…

380
3.3K
3 files
View
aaron-he-zhu logo

Placement Exclusion Manager

aaron-he-zhu
CommunityPopular

Use when the user asks to "build my brand-safety exclusion lists", "set placement / topic / content exclusions before launch", "add network and audience exclusions", or "prep the A1 brand-safety…

361
2.8K
Instructions
View
cisco-ai-defense logo

Expression Compiler

cisco-ai-defense
OrganizationPopular

Compile a caller-provided expression into a Python code object

321
2.5K
2 files
View
Observal logo

Observal Ops

Observal
OrganizationPopular

Inspects Observal traces, sessions, rankings, feedback, telemetry health, logs, and Agent insight reports. Use when the user wants operational evidence, current activity, telemetry diagnosis, ratings,…

472
2.4K
2 files
View
yaklang logo

Active Directory Kerberos Attacks

yaklang
OrganizationPopular

Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.

292
2.2K
1 files
View
mvanhorn logo

Pp 3cx Xapi

mvanhorn
CommunityPopular

Every 3CX Configuration API (XAPI) object in one Go binary, with a local mirror of your whole PBX, offline search, config diffing, and cross-entity auditing no 3CX tool has. Trigger phrases: `audit my…

614
2K
Instructions
View
Eronred logo

App Clips

Eronred
CommunityPopular

When the user wants to implement, optimize, or use App Clips for app discovery and conversion. Use when the user mentions "App Clip", "app clip code", "mini app", "instant app", "App Clip card", "App…

116
1.9K
Instructions
View
wgpsec logo

Cot Injection

wgpsec
OrganizationPopular

思维链 (Chain-of-Thought) 注入攻击方法论。当目标系统使用 ReAct/CoT 框架进行多步推理、 Agent 依赖中间推理结果做决策、或需要测试思维链完整性时触发。 覆盖: 思维链干扰注入(伪造中间 Agent 结果)、思维链操纵注入(跳过验证步骤直接调度敏感操作)、 查询注入(在数据查询 Agent 中注入恶意查询语句)。

242
1.7K
Instructions
View
daymade logo

Cloudflare Troubleshooting

daymade
CommunityPopular

Investigate and resolve Cloudflare configuration issues using API-driven evidence gathering. Use when troubleshooting ERR_TOO_MANY_REDIRECTS, SSL errors, DNS issues, or any Cloudflare-related…

219
1.4K
6 files
View
Dataojitori logo

Memory Audit Node Decomposition

Dataojitori
CommunityPopular

节点分解。当一个节点体积过大、或塞了多个不相关概念导致disclosure无法覆盖时使用。

167
1.4K
Instructions
View
aklofas logo

Element14

aklofas
CommunityPopular

Search Newark, Farnell, and element14 for electronic components — find parts by MPN or distributor part number, check pricing/stock, download datasheets, analyze specifications. One unified API covers…

109
1.2K
2 files
View
ynulihao logo

Beads

ynulihao
Community

Tracks complex, multi-session work using the Beads issue tracker and dependency graphs, and provides persistent memory that survives conversation compaction. Use when work spans multiple sessions, has…

76
612
11 files
View
proffesor-for-testing logo

Api Testing Patterns

proffesor-for-testing
Community

Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing. Use when testing APIs or designing API test strategies.

92
480
5 files
View
smallnest logo

Code Review

smallnest
Community

Frontend-focused code review skill for React/TypeScript/Tailwind projects. Analyzes code quality, security vulnerabilities (XSS, CSRF), performance issues, accessibility (WCAG), React best practices,…

51
304
8 files
View
blacklanternsecurity logo

Ad Persistence

blacklanternsecurity
Organization

Establishes persistent access in Active Directory environments after domain compromise. Covers DCShadow (rogue DC attribute modification), Skeleton Key (LSASS master password), custom SSP injection…

39
276
Instructions
View
membranedev logo

15five

membranedev
Community

15Five integration. Manage Persons, Organizations. Use when the user wants to interact with 15Five data.

42
268
Instructions
View
ryoppippi logo

Council

ryoppippi
Community

Spawns parallel task agents to explore a codebase area. Use when researching unfamiliar code, auditing a subsystem, or gathering diverse perspectives before a design decision.

5
263
Instructions
View
ed3dai logo

Creating An Agent

ed3dai
Organization

Use when creating specialized subagents for Claude Code plugins or the Task tool - covers description writing for auto-delegation, tool selection, prompt structure, and testing agents

33
249
Instructions
View
xenitV1 logo

Browser Extension

xenitV1
Community

Master specialized skill for building 2025/2026-grade browser extensions. Deep expertise in Manifest v3, Service Worker persistence (Alarms, Offscreen API), Side Panel API, and Cross-Browser…

34
231
3 files
View
yezannnnn logo

Senior Architect

yezannnnn
Community

This skill should be used when the user asks to "design system architecture", "evaluate microservices vs monolith", "create architecture diagrams", "analyze dependencies", "choose a database", "plan…

49
149
6 files
View
trilwu logo

Analyzing Go Binaries

trilwu
Community

Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling convention,…

15
144
Instructions
View
686f6c61 logo

Memory

686f6c61
Community

This skill should be used when the user asks to record a design decision, search past project decisions, inspect the Alfred memory timeline, or work with the alfred-memory MCP server. Use it to call…

7
115
Instructions
View
aAAaqwq logo

Native Agent Swarms

aAAaqwq
Community

Coordinate small teams of specialized Codex agents with bounded parallelism, explicit ownership, native messaging, and evidence-based synthesis. Use when two or more independent investigations,…

23
98
4 files
View
nahisaho logo

Bug Hunter

nahisaho
Community

Copilot agent that assists with bug investigation, root cause analysis, and fix generation for efficient debugging and issue resolution Trigger terms: bug fix, debug, troubleshoot, root cause…

7
77
1 files
View
rknall logo

Python Backend Architecture Review

rknall
Community

Comprehensive design architecture review for Python backend applications. Use this skill when users ask you to review, analyze, or provide feedback on backend architecture designs, system design…

9
73
3 files
View
brucesongs logo

Ad Ldap Attack

brucesongs
Community

Active Directory is the backbone of enterprise identity and access management, making it a primary target during internal network penetration tests.

18
70
12 files
View
kaivyy logo

Perseus:Scan

kaivyy
Community

Use when starting a security assessment to map architecture, entry points, and attack surface (Phase 1 & 2)

14
68
Instructions
View
rejot-dev logo

Api Webhooks

rejot-dev
Organization

Configure inbound API webhooks end to end. Use when the user needs a webhook/callback URL, provides webhook auth or sample payloads, defines provider events, or routes webhook.received deliveries into…

6
62
Instructions
View
usestrix logo

Fix Security Vulnerabilities With Strix

usestrix
OrganizationPopular

Fix security vulnerabilities found by a Strix pentest (open-source CLI or app.strix.ai cloud) — triage by severity, patch the root cause rather than the symptom, and re-run Strix to prove each fix…

6.9K
63.3K
Instructions
View
mukul975 logo

Analyzing Active Directory Acl Abuse

mukul975
CommunityPopular

Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths

4K
32.9K
2 files
View
googleworkspace logo

Gws Chat Send

googleworkspace
OrganizationPopular

Google Chat: Send a message to a space.

1.8K
31K
Instructions
View
tradecatlabs logo

Web3 Grep Arsenal

tradecatlabs
CommunityPopular

Master grep command arsenal for Web3 smart contract auditing. Use when starting a new protocol scan, before deep code review, or when hunting specific vulnerability classes.

1.6K
16.3K
Instructions
View
prowler-cloud logo

Gh Aw

prowler-cloud
OrganizationPopular

Create and maintain GitHub Agentic Workflows (gh-aw) for Prowler. Trigger: When creating agentic workflows, modifying gh-aw frontmatter, configuring safe-outputs, setting up MCP servers in workflows,…

2.4K
14.8K
1 files
View
trailofbits logo

Cairo Vulnerability Scanner

trailofbits
OrganizationPopular

Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay. Use when auditing…

611
7.1K
3 files
View
Tencent logo

File Path Traversal Detection

Tencent
OrganizationPopular

Detect unsafe file handling and path traversal in upload/save/extract flows. Focuses on user-controlled paths or filenames, not data leakage.

594
6.4K
Instructions
View
awarexone logo

Cicd Security

awarexone
OrganizationPopular

CI/CD pipeline security hunting — GitHub Actions workflow injection, secret exfiltration, self-hosted runner poisoning, dependency confusion, OIDC token theft, and supply chain attacks. Covers…

868
4.9K
Instructions
View
zebbern logo

Audit Flow

zebbern
CommunityPopular

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature…

464
4.6K
5 files
View
ljagiello logo

Ctf Misc

ljagiello
CommunityPopular

Provides miscellaneous CTF challenge techniques for problems that do not cleanly fit the main categories. Use for encoding puzzles, pyjails, bash jails, RF/SDR, DNS oddities, unicode tricks, esoteric…

380
3.3K
12 files
View
WorldFlowAI logo

Security Review

WorldFlowAI
OrganizationPopular

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and…

484
3.1K
Instructions
View
cloudflare logo

Cloudflare One Migrations

cloudflare
OrganizationPopular

Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout.

277
2.8K
Instructions
View
cisco-ai-defense logo

Calendar Sync Helper

cisco-ai-defense
OrganizationPopular

Sync calendar events with an endpoint selected in configuration

321
2.5K
2 files
View
WordPress logo

Wp Abilities Verify

WordPress
OrganizationPopular

Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate…

318
2.1K
6 files
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇