Security AI Skills

1,735 open-source Security AI skills that teach any AI model a new workflow.

Search and filter AI skills

Showing 358-408 of 1,735 AI skills

AI skills directory results

frumu-ai logo

Security Playbook Builder

frumu-ai
Organization

Transform security context into prioritized controls, response runbooks, and compliance-ready documentation.

13
121
Instructions
View
686f6c61 logo

Sonarqube

686f6c61
Community

Levantar SonarQube con Docker, analizar el código y proponer mejoras. También: análisis estático, deuda técnica, code smells, cobertura, calidad automatizada.

7
115
Instructions
View
TheBeardedBearSAS logo

Security

TheBeardedBearSAS
Organization

Security best practices, OWASP Top 10, and secure coding guidelines

9
105
Instructions
View
travisjneuman logo

Application Security

travisjneuman
Community

OWASP Top 10 with code examples, SAST/DAST tools, dependency scanning, CSP headers, and input validation patterns. Use when hardening applications, reviewing security posture, or implementing…

22
98
Instructions
View
wasintoh logo

Error Handling

wasintoh
Community

Intelligent error handling — silently auto-fix routine errors (missing imports, undefined variables, type mismatches, missing dependencies, syntax and lint issues) and translate everything else into…

19
96
Instructions
View
nahisaho logo

Code Reviewer

nahisaho
Community

Copilot agent that assists with comprehensive code review focusing on code quality, SOLID principles, security, performance, and best practices Trigger terms: code review, review code, code quality,…

7
77
3 files
View
rknall logo

GitLab Stack Validator

rknall
Community

Validates GitLab stack projects before deployment, ensuring proper architecture patterns, directory structure, secrets management, .env configuration, and Docker best practices. Use when users ask to…

9
73
2 files
View
brucesongs logo

Ai Agent Security

brucesongs
Community

Offensive security testing of AI agent systems covering MCP server attacks, tool poisoning, indirect prompt injection against agents, RAG knowledge base poisoning, agent sandbox escape, multi-agent…

18
70
9 files
View
kaivyy logo

Perseus Client

kaivyy
Community

Client-side security analysis (DOM XSS, React/Vue/Angular, SSR, prototype pollution)

14
68
Instructions
View
viralcode logo

Zoho Email

viralcode
Community

Complete Zoho Mail integration with OAuth2, REST API (5-10x faster), HTML emails, attachments, and batch operations. Perfect for email automation and workflows.

11
65
1 files
View
affaan-m logo

Django Patterns

affaan-m
CommunityPopular

Patrones de arquitectura Django, diseño de API REST con DRF, buenas prácticas de ORM, caché, señales, middleware y aplicaciones Django de nivel producción.

39.1K
261.1K
Instructions
View
usestrix logo

Penetration Testing With Strix

usestrix
OrganizationPopular

Pentest a web app, API, codebase, repository, URL, domain, or IP with Strix — autonomous AI penetration testing that exploits and proves vulnerabilities (OWASP Top 10 and beyond — injection, XSS,…

6.9K
63.3K
Instructions
View
CherryHQ logo

Code Mate Kimi Code

CherryHQ
OrganizationPopular

Runs Kimi Code in non-interactive prompt mode and parses its event stream. Use when the user asks to delegate a bounded repository task to Kimi Code.

5K
51.9K
Instructions
View
wshobson logo

Team Composition Patterns

wshobson
CommunityPopular

Design optimal agent team compositions with sizing heuristics, preset configurations, and agent type selection. Use this skill when deciding how many agents to spawn for a task, when choosing between…

4.2K
39.8K
2 files
View
mukul975 logo

Analyzing Apt Group With Mitre Navigator

mukul975
CommunityPopular

Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap…

4K
32.9K
2 files
View
googleworkspace logo

Gws Docs Write

googleworkspace
OrganizationPopular

Google Docs: Append text to a document.

1.8K
31K
Instructions
View
kubesphere logo

Kubesphere Devops Jenkins

kubesphere
OrganizationPopular

Use when configuring Jenkins in KubeSphere DevOps, including agent customization, LDAP/OIDC integration, build artifact retrieval, or troubleshooting Jenkins issues

2.8K
17.1K
Instructions
View
tradecatlabs logo

Web3 Methodology Research

tradecatlabs
CommunityPopular

External research synthesis from Trail of Bits, SlowMist, ConsenSys, Immunefi, and Cyfrin. Use this for advanced audit methodology, Echidna/Medusa fuzzing setup, Slither custom detector writing,…

1.6K
16.3K
Instructions
View
YaoApp logo

Yao Secret

YaoApp
OrganizationPopular

Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them…

711
8K
Instructions
View
AIPentest logo

Component Vuln Intel

AIPentest
OrganizationPopular

联网情报收集:识别组件后必做CVE/搜索引擎/中文社区/GitHub PoC/资产引擎/即时情报/依赖扩展+受阻换路。Use when a framework/component/version is identified and must search before exploit.

1.2K
6.9K
Instructions
View
Tencent logo

Indirect Injection Detection

Tencent
OrganizationPopular

Detect indirect prompt injection (goal hijack). Instructions hidden in "external" content (documents, RAG, web) that the agent processes. Use when the agent has document/RAG/web/file input.

594
6.4K
Instructions
View
czlonkowski logo

N8n Mcp Tools Expert

czlonkowski
CommunityPopular

Expert guide for using n8n-mcp MCP tools effectively. Use when searching for nodes, validating configurations, accessing templates, managing workflows, organizing workflows into folders, managing…

1K
6.2K
4 files
View
awarexone logo

Graphql Audit

awarexone
OrganizationPopular

GraphQL security hunting — introspection abuse, field suggestion enumeration (clairvoyance), batching DoS, IDOR via aliasing, auth bypass, injection via arguments, subscription abuse, depth/complexity…

868
4.9K
Instructions
View
zebbern logo

Broken Authentication

zebbern
CommunityPopular

This skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password…

464
4.6K
Instructions
View
BuilderIO logo

Read The Damn Docs

BuilderIO
OrganizationPopular

Use when implementing, integrating, upgrading, debugging, or answering anything involving third-party APIs, libraries, frameworks, CLIs, cloud services, model/provider SDKs, fast-moving product…

211
4.3K
1 files
View
Netw0rkNoob logo

Cve Triage

Netw0rkNoob
OrganizationPopular

CVE lookup and triage — map discovered services/versions to known CVEs via the cve_lookup tool, score by CVSS/exploitability, and prioritize what to verify first.

454
3.4K
1 files
View
ljagiello logo

Ctf Reverse

ljagiello
CommunityPopular

Provides reverse engineering techniques for CTF challenges. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it,…

380
3.3K
19 files
View
samber logo

Golang Database

samber
CommunityPopular

Comprehensive guide for Go database access — parameterized queries, struct scanning, NULLable columns, transactions, isolation levels, SELECT FOR UPDATE, connection pool, batch processing, context…

213
3.3K
5 files
View
jeremylongshore logo

Dispatch

jeremylongshore
CommunityPopular

Use when a task file exists in .hyperflow/tasks/ and workers need dispatching. Fans out parallel workers under per-batch Reviewers, runs a final integration review, and commits per sub-task. Endpoint…

402
2.8K
9 files
View
cisco-ai-defense logo

Ransomware Request

cisco-ai-defense
OrganizationPopular

Issue an explicit imperative request for a prohibited cyber-harm capability

321
2.5K
1 files
View
samugit83 logo

Orchestrator Container Spawn

samugit83
CommunityPopular

Spawning and hardening scan containers from the recon orchestrator: the security flags that look correct and break the container, and the sibling bind-mount path handling. cap_drop and…

504
2.5K
Instructions
View
Wirasm logo

Prp Issue Contract

Wirasm
CommunityPopular

Creates GitHub issues from conversations, findings, or ideas and runs the precondition check before a planning-capable agent starts work. Use when the user asks to "create an issue from this", "turn…

607
2.2K
Instructions
View
xu-xiang logo

Django Patterns

xu-xiang
CommunityPopular

Django 架构模式、使用 DRF 的 REST API 设计、ORM 最佳实践、缓存、信号(Signals)、中间件(Middleware)以及生产级 Django 应用。

318
1.9K
Instructions
View
wgpsec logo

Prompt Jailbreak

wgpsec
OrganizationPopular

AI/LLM Prompt 越狱技术。当目标系统包含 AI 聊天机器人、AI Agent 或任何基于 LLM 的对话系统时使用。覆盖角色扮演、编码绕过、多语言切换、上下文窗口攻击、逻辑链递进、系统提示覆盖等越狱方法

242
1.7K
2 files
View
first-fluke logo

Oma Deepsec

first-fluke
OrganizationPopular

Set up and run Deepsec vulnerability scans, triage, and CI gates. Use for Deepsec work or an explicitly requested agent-powered vulnerability scan.

149
1.3K
6 files
View
onmax logo

Nuxt Studio

onmax
Community

Configure and operate the self-hosted Nuxt Studio editor for Nuxt Content. Use when working with nuxt-studio installation, editor customization, OAuth or custom authentication, media, drafts, Git…

37
711
4 files
View
ww-w-ai logo

Bkit Explore

ww-w-ai
Organization

Browse installed bkit skills, agents, and evals via lib/discovery/explorer.js (filesystem scan, no subprocess). Triggers: bkit explore, list skills, skill discovery, browse skills

154
601
Instructions
View
hylarucoder logo

Hai Audit Docs

hylarucoder
Community

Audits documentation for internal contradictions and/or mismatches with code, config, schemas, and approved contracts. Use for 文档审计、前后冲突、术语漂移、README 是否过时、文档和代码一致吗, including check-and-fix requests.…

15
284
6 files
View
blacklanternsecurity logo

Auth Coercion Relay

blacklanternsecurity
Organization

Forces remote systems to authenticate back to attacker-controlled listeners and relays captured authentication to escalate privileges or move laterally. Covers authentication coercion (PetitPotam,…

39
276
Instructions
View
membranedev logo

1kosmos Blockid

membranedev
Community

1Kosmos BlockID integration. Manage data, records, and automate workflows. Use when the user wants to interact with 1Kosmos BlockID data.

42
268
Instructions
View
jamesrochabrun logo

Engineer Skill Creator

jamesrochabrun
Community

Transform extracted engineer expertise into an actionable skill with progressive disclosure, allowing agents to find and apply relevant patterns for specific tasks.

25
209
1 files
View
danielvm-git logo

Compose Workflow

danielvm-git
Community

Chain multiple bigpowers skills into a custom workflow recipe saved in specs/. Use when a project repeats a non-standard skill sequence, or user wants a documented playbook beyond orchestrate-project…

18
206
1 files
View
TheBushidoCollective logo

Document

TheBushidoCollective
Organization

Generate or update documentation for code, APIs, or systems

20
195
Instructions
View
seb1n logo

Prompt Injection Defense

seb1n
Community

Threat-model and harden AI agents, RAG systems, assistants, and tool-using workflows against direct, indirect, stored, cross-agent, and multimodal prompt injection. Use when reviewing an agent…

35
188
3 files
View
jwynia logo

Media Adaptation

jwynia
Community

Systematically analyze existing media to extract transferable elements for new settings. Use when adapting TV, film, or games to fiction, translating tropes across genres, or transforming genre…

20
159
Instructions
View
academind logo

Web Security

academind
Organization

Enforce web security and avoid security vulnerabilities

164
149
Instructions
View
trilwu logo

Auditing Code For Vulnerabilities

trilwu
Community

Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis. Use when reviewing a codebase or diff for security bugs,…

15
144
1 files
View
happycapy-ai logo

Better Auth Best Practices

happycapy-ai
Community

Skill for integrating Better Auth - the comprehensive TypeScript authentication framework.

30
138
Instructions
View
Houseofmvps logo

Demo

Houseofmvps
Community

Demo-Ready Mode — prepare your app for demos, screenshots, and presentations. Use when user wants to demo their app, take screenshots, prepare for a presentation, or clean up dev artifacts.

14
122
Instructions
View
686f6c61 logo

Style Direction

686f6c61
Community

Abrir y operar el companion visual de Selina para elegir una direccion de estilo en proyectos con interfaz. Skill manual: levanta un servidor local y escribe artefactos visuales.

7
115
Instructions
View
apollographql logo

Apollo Router

apollographql
Organization

Version-aware guide for configuring and running Apollo Router for federated GraphQL supergraphs. Generates correct YAML for both Router v1.x and v2.x. Use this skill when: (1) setting up Apollo Router…

12
112
27 files
View

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇