Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 307-357 of 1,735 AI skills

AI skills directory results

rmyndharis logo

Api Testing Observability Api Mock

rmyndharis
CommunityPopular

You are an API mocking expert specializing in realistic mock services for development, testing, and demos. Design mocks that simulate real API behavior and enable parallel development.

264
1.6K
1 files
View
Dataojitori logo

Memory Audit

Dataojitori
CommunityPopular

记忆审计入口。当我主动决定审视记忆质量时,先读此文件判断应使用哪个子技能。

167
1.4K
Instructions
View
first-fluke logo

Oma Db

first-fluke
OrganizationPopular

Design schemas and migrations, tune queries, or plan vector retrieval and database operations. Application API implementation uses oma-backend.

149
1.3K
10 files
View
uphiago logo

Cross Wave Delta Analysis

uphiago
CommunityPopular

Compare recon waves to find NEW, REGRESSED, PERSISTENT findings.

213
1.3K
Instructions
View
TencentCloudBase logo

Auth Nodejs Cloudbase

TencentCloudBase
OrganizationPopular

CloudBase Node SDK auth guide for server-side identity, user lookup, and custom login tickets. This skill should be used when Node.js code must read caller identity, inspect end users, or bridge an…

141
1.1K
Instructions
View
jezweb logo

Hono Api Scaffolder

jezweb
CommunityPopular

Scaffold Hono API routes for Cloudflare Workers. Produces route files, middleware, typed bindings, Zod validation, error handling, and API_ENDPOINTS.md documentation. Use after a project is set up…

102
1K
5 files
View
mhattingpete logo

Feature Planning

mhattingpete
Community

Break down feature requests into detailed, implementable plans with clear tasks. Use when user requests a new feature, enhancement, or complex change.

96
675
1 files
View
analogjs logo

Angular Routing

analogjs
Organization

DEPRECATED - this skill is unmaintained. Use the official Angular skills at https://github.com/angular/skills instead. Implement routing in Angular v20+ applications with lazy loading, functional…

68
591
Instructions
View
blacklanternsecurity logo

Adcs Persistence

blacklanternsecurity
Organization

Establishes persistence and exploits weak certificate mapping in AD CS. Covers ESC9 (no security extension), ESC10 (weak certificate mapping), ESC12-15 (YubiHSM, issuance policy, altSecIdentities,…

39
276
Instructions
View
jpicklyk logo

Manage Schemas

jpicklyk
Community

Creates, views, edits, deletes, and validates note schemas for the MCP Task Orchestrator in .taskorchestrator/config.yaml — the templates that define which notes agents must fill at each workflow…

22
204
18 files
View
seb1n logo

Tool Schema Design

seb1n
Community

Design and validate model-facing tool definitions with clear names, action-oriented descriptions, bounded JSON Schema parameters, explicit side effects, safe defaults, idempotency, errors, and…

35
188
3 files
View
bitwarden logo

Classifying Review Findings

bitwarden
Organization

Use this skill when categorizing code review findings into severity levels. Apply when determining which emoji and label to use for PR comments, deciding if an issue should be flagged at all, or…

19
149
Instructions
View
trilwu logo

Analyzing Macos Binaries

trilwu
Community

Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…

15
144
Instructions
View
686f6c61 logo

Sbom Generate

686f6c61
Community

Usar para generar Software Bill of Materials para cumplimiento del CRA. También: Software Bill of Materials, inventario de componentes, CycloneDX, SPDX, cadena de suministro.

7
115
Instructions
View
apollographql logo

Apollo Mcp Server

apollographql
Organization

Guide for using Apollo MCP Server to connect AI agents with GraphQL APIs. Use this skill when: (1) setting up or configuring Apollo MCP Server, (2) defining MCP tools from GraphQL operations, (3)…

12
112
3 files
View
JinFanZheng logo

Email

JinFanZheng
Community

Email operations via IMAP/SMTP. Trigger for inbox checking, reading, drafting, or sending emails. Requires `.config/email.json` setup.

30
80
Instructions
View
simota logo

Beacon

simota
Community

Engineering observability and reliability: SLO/SLI design, distributed tracing, alerting, dashboards, capacity planning, toil automation, reliability review. Use for instrumentation or SLO definition.

14
80
17 files
View
vm0-ai logo

Cloudflare Tunnel

vm0-ai
Organization

Cloudflare Tunnel API for secure tunnels. Use when user mentions "Cloudflare tunnel", "argo tunnel", or secure connectivity.

18
76
Instructions
View
kaivyy logo

Perseus Api

kaivyy
Community

Deep-dive API security analysis (REST, GraphQL, WebSocket, gRPC, OAuth, Cache)

14
68
Instructions
View
usestrix logo

Owasp Top 10 Testing

usestrix
OrganizationPopular

Test an application against the OWASP Top 10 with Strix — autonomous AI agents that attempt real exploits for each category of the current OWASP Top 10:2025 (broken access control including SSRF,…

6.9K
63.3K
Instructions
View
CherryHQ logo

Code Mate Hermes

CherryHQ
OrganizationPopular

Runs Hermes Agent in one-shot mode for bounded local tasks. Use when the user explicitly asks to delegate work to Hermes and accepts its automatic tool approval behavior.

5K
51.9K
Instructions
View
google logo

Secops Detection Engineering

google
OrganizationPopular

Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps. Use when writing new detection rules, tuning existing rules, validating…

1.6K
20.1K
Instructions
View
prowler-cloud logo

Nextjs 16

prowler-cloud
OrganizationPopular

Next.js 16 App Router patterns. Trigger: When working in Next.js App Router (app/), Server Components vs Client Components, Server Actions, Route Handlers, proxy.ts, caching/revalidation, Cache…

2.4K
14.8K
Instructions
View
android logo

Verified Email

android
OrganizationPopular

Provides a complete workflow for implementing verified email retrieval on Android Credential Manager API. Use this skill to integrate a secure, OTP-less email verification flow into an Android app.…

484
7.4K
7 files
View
trailofbits logo

Cosmos Vulnerability Scanner

trailofbits
OrganizationPopular

Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence. 25 core + 16 IBC + 10 EVM + 3 CosmWasm patterns. Use when…

611
7.1K
10 files
View
Tencent logo

Human Agent Trust Exploit Detection

Tencent
OrganizationPopular

Detect social engineering, deceptive responses, false assurances, or prompts that induce unsafe user actions.

594
6.4K
Instructions
View
fengshao1227 logo

Ccg Skills

fengshao1227
CommunityPopular

CCG Skills - Quality gates, documentation generator, and multi-agent orchestration. Auto-installed by CCG workflow system.

446
5.9K
85 files
View
zebbern logo

Aws Penetration Testing

zebbern
CommunityPopular

This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF",…

464
4.6K
1 files
View
Netw0rkNoob logo

Ctf Web

Netw0rkNoob
OrganizationPopular

CTF Web攻击知识库 — PHP弱比较绕过、命令注入空格绕过、eval回显技巧、SSTI注入链、反序列化利用链、PHP代码审计checklist、常见flag位置

454
3.4K
8 files
View
ljagiello logo

Ctf Pwn

ljagiello
CommunityPopular

Provides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory corruption or low-level primitives into code…

380
3.3K
23 files
View
FreedomIntelligence logo

Benchling Integration

FreedomIntelligence
OrganizationPopular

Benchling R&D platform integration. Access registry (DNA, proteins), inventory, ELN entries, workflows via API, build Benchling Apps, query Data Warehouse, for lab data management automation.

410
3K
3 files
View
rlaope logo

Omh Application Threat Model

rlaope
CommunityPopular

[omh] Application threat model workflow: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds. Use…

194
2.7K
1 files
View
aws logo

Remediating With Aws Security Agent

aws
OrganizationPopular

Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. Use this whenever the user mentions Security Agent, security findings, pentest or penetration test results,…

311
2.7K
Instructions
View
sergebulaev logo

Linkedin Humanizer

sergebulaev
CommunityPopular

Remove the AI tells human readers and LinkedIn's AI-slop filter react to in a post or comment: 2026 vocabulary by paragraph density, reveal bridges, staccato fragments, stacked triads, performed…

456
2.6K
18 files
View
cisco-ai-defense logo

Embedded Payment Key

cisco-ai-defense
OrganizationPopular

Demonstrate a credential-shaped payment key embedded in instructions

321
2.5K
1 files
View
tsingyuai logo

Media Crawler

tsingyuai
OrganizationPopular

Install, authenticate, configure, operate, and troubleshoot the external MediaCrawler client shared by Douyin, Kuaishou, Bilibili, Weibo, Tieba, and Zhihu collectors. Xiaohongshu uses the separate…

170
2K
2 files
View
wgpsec logo

Prompt Injection

wgpsec
OrganizationPopular

AI/LLM 间接 Prompt 注入攻击。当目标 AI 系统会处理外部数据源(网页、文档、邮件、数据库、API 返回)时使用。覆盖间接注入、工具链劫持、RAG 投毒、数据外泄等技术。OWASP LLM Top 10 #1 漏洞类别

242
1.7K
1 files
View
ananddtyagi logo

Plugin Creator

ananddtyagi
Community

Create, validate, and publish Claude Code plugins and marketplaces. Use this skill when building plugins with commands, agents, hooks, MCP servers, or skills.

85
689
Instructions
View
secondsky logo

Sap Btp Best Practices

secondsky
Community

SAP BTP best practices for enterprise architecture, account management, security, and operations, with verification evidence tracked in the repository ledger. Use when planning BTP implementations,…

117
445
9 files
View
mizchi logo

Aws Vault Mfa Iam

mizchi
Community

Use when AWS account の IAM API が MFA 必須 policy で弾かれて、 `sts:GetCallerIdentity` は通るのに `iam:*` が `InvalidClientTokenId` で拒否されるとき、 または FIDO2 passkey で MFA が CLI から使えないとき。 aws-vault / aws-cli / MFA /…

4
333
Instructions
View
blacklanternsecurity logo

Adcs Template Abuse

blacklanternsecurity
Organization

Exploits misconfigured AD CS certificate templates to impersonate any domain user via SAN manipulation or enrollment agent abuse. Covers ESC1 (enrollee supplies subject), ESC2 (any-purpose/no EKU),…

39
276
Instructions
View
ed3dai logo

Prompt Security Hardening

ed3dai
Organization

Use when writing skills, CLAUDE.md files, agent prompts, or any directives that involve shell commands, environment variables, API credentials, file creation, or git operations - prevents secrets…

33
249
Instructions
View
ProgrammerAnthony logo

Code Security Audit

ProgrammerAnthony
Community

Use when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

77
236
32 files
View
asgard-ai-platform logo

Algo Blockchain Smart Contract

asgard-ai-platform
Organization

Design and implement smart contracts as self-executing programmatic agreements on blockchain. Use this skill when the user needs to build automated on-chain logic, evaluate smart contract security, or…

29
236
3 files
View
xenitV1 logo

Frontend Design

xenitV1
Community

Elite Tier Web UI standards, including pixel-perfect retro aesthetics, immersive layouts, and UX psychology protocols.

34
231
5 files
View
dev-toolings logo

Api Platform Tests

dev-toolings
Organization

Test API Platform resources with ApiTestCase; assert collections, items, filters, JSON schema, and authentication

24
213
1 files
View
jamesrochabrun logo

Engineer Expertise Extractor

jamesrochabrun
Community

Research and extract an engineer's coding style, patterns, and best practices from their GitHub contributions. Creates structured knowledge base for replicating their expertise.

25
209
1 files
View
seb1n logo

Agent Red Teaming

seb1n
Community

Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.…

35
188
5 files
View
bitwarden logo

Performing Multi Agent Code Review

bitwarden
Organization

Perform a rigorous, multi-agent code review with architecture-compliance, parallel quality/security analysis, finding validation, and severity audit. Use when the user asks for a structured, deep,…

19
149
7 files
View
trilwu logo

Analyzing Rust Binaries

trilwu
Community

Reverse engineer Rust binaries — demangling legacy and v0 symbol schemes, recognizing monomorphized generics, Result and Option control flow, trait object vtable dispatch, and panic-site strings that…

15
144
Instructions
View
Houseofmvps logo

Cost

Houseofmvps
Community

AI Build Cost Tracker — track how much AI is costing you per feature. Use when user wants to track AI spending, understand cost per feature, optimize AI usage, or budget their Claude/GPT costs.

14
122
Instructions
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇