Security
7,261 rows, by stacks then stars
772 of these skill files have been read, by 666 distinct authors, and what they tell an agent counted. What Security authors agree on, and what they forbid
TheSethRose/Vulnerability-Scanning Skill
5★Local-first vulnerability and supply-chain scanning for agent runtimes.
olanokhin/agent-security-skill/skills/agent-security Skill
5★ repoNative Claude Code + Codex skills for AI security review. Also ships instruction files for Cursor, Copilot, and Windsurf. Checks 33 risks: OWASP LLM Top 10 2025 · applied RAG/MCP/agent checks · OWASP Agentic 2026.
eltociear/skill-audit-mcp/io.github.eltociear/skill-audit-mcp MCP server
no license5★ repoMCP server: static security scanner for MCP servers, agent skills & plugins. 68 attack patterns.
Philidor DeFi Vault Risk Analytics
Philidor-Labs/philidor-mcp/io.philidor/defi-vaults MCP server
5★ repoSearch 700+ DeFi vaults, compare risk scores, analyze protocols. No API key needed.
tinoimammp/vantage-security-agent/skills/vantage Skill
4★ repoAI-powered vulnerability scanner plugin for Claude Code with 28 agents statically scan web & mobile repos for OWASP Top 10 / Mobile Top 10 vulnerabilities, validate findings, and optionally auto-fix them. No live requests, ever.
akirtok/preflight-security-audit/plugins/preflight-security-audit/skills/preflight-security-audit Skill
4★ repoFor vibe coders who ship fast and don't want to get hacked. Preflight Security Audit plugin checks your app before its launch. One command finds the security, privacy, and payment vulnerabilities in your code and fixes them. 50+ security checks in 6 categories.
YangKuoshih/security-audit/skills/security-audit Skill
4★ repoUniversal security scanning skill for AI agents - finds hardcoded secrets, API keys, and vulnerabilities in any codebase. 44 patterns validated against GitLeaks, OWASP Top 10 mapping, Markdown/SARIF/JSON reports. Works across Claude Code, Cursor, Windsurf, and any agentic platform.
netresearch/enterprise-readiness-skill/skills/enterprise-readiness Skill
no license4★ repoAgent Skill for enterprise readiness assessment - security, quality, and automation | Claude Code compatible
n-shadloo/secure-code-auditor Skill
4★Backend security Agent Skill that helps AI audit code, detect vulnerabilities, and generate secure-by-default backend applications, with deep Django/DRF coverage and guidance for any backend stack.
imouiche/complete-mitre-attack-mcp-server/io.github.imouiche/mitre-attack-mcp-server MCP server
no license4★ repoMCP server providing 50+ tools for MITRE ATT&CK techniques, groups, and mitigations
pierre3/dotnet-zap-mcp/io.github.pierre3/zap-mcp MCP server
4★ repoMCP server for OWASP ZAP vulnerability scanning with Docker management
benderterminal/zkettle Skill
3★Self-hosted, zero-knowledge encrypted, self-destructing secrets
LeahyCC/claude-skills/skills/api-security Skill
3★ repoProduction-grade Claude Code skills verified against official specifications. Zero dependencies. Complete domain coverage.
leodisa/compliance-review-skill/plugins/compliance-review/skills/compliance-review Skill
3★ repoClaude skill on a repeatable, evidence-based gap analysis of a code repository against the EU AI Act, GDPR, and the NIS2 Directive (EU 2022/2555)
aliasunder/agent-skills/skills/obsidian-vault Skill
3★ repoAgent skills for AI coding agents — trip planner, Obsidian vault, and more
cyber-sorted/skills-pro/cybersorted Skill
no license3★ repoProfessional security and enterprise architecture advisory skills for Claude Code
acm-rgb/tutor-buddy Skill
3★A Claude Code skill that guides vibecoders and beginners from raw idea to a secured, GitHub-ready project, with real security checks, no false confidence, and no silent scope creep.
generalbusiness-ai/keep-hermes-skills/skills/github/github-vault-search Skill
3★ repoSkills repository for Hermes agent
hannsxpeter/arc-ready Skill
3★Stable Agent Skill that takes software projects from idea through launch: PRD, architecture, roadmap, stack, repo, app, deploy, observe, launch, and harden. Evolution of aihxp/ready-suite with aihxp/pillars task-routed agent memory.
belumume/solana-fuzz/solana-fuzz Skill
3★ repoClaude Code / Codex skill that writes Trident property and invariant fuzz tests for Solana programs (Anchor and native).
tjsdyy/clawheartv2/packages/clawheart-skill/clawheart-security Skill
no license3★ repoLocal-first AI security gateway for AI Agents. Intercept, audit and govern Claude Code · Codex · Cursor · OpenClaw traffic — 3 monitoring tiers × 8 defense layers, zero cloud.
Berektassuly/solana-audit-skill/skill Skill
3★ repoEvidence-backed Solana audit skill for Claude Code and Agent Skills: report-backed taxonomy, workflows, checklists, and public finding corpus for Anchor and native Solana security reviews.
danoszz/penthera/skills/penthera Skill
3★ repoLightweight website/app security scanner for vibecoded apps:: run it from your AI agent (Cursor/Claude Code) or the CLI. Black-box + white-box, OWASP-mapped, SARIF-ready. Authorized testing only.
leo-cheung-itlger/api-key-leak-checker-leop/skills/api-key-leak-checker-leop Skill
3★ repoA Codex skill and pre-publish gate for checking API key leaks before open-sourcing projects.
zantific/skill-security-review-lens Skill
3★Security review skill for Claude Code. Scans third-party agent skills against 35 detection rules and 7 semantic checks before you install them. Finds patterns worth looking at, flags what could go wrong. Does not pass or fail anything.
zw008/VMware-NSX-Security/skills/vmware-nsx-security Skill
no license3★ repoVMware NSX DFW microsegmentation and security: distributed firewall, security groups, tags, traceflow, IDPS — MCP tools for AI agents
alex-llm/attAck-mcp-server/ai.smithery/alex-llm-attack-mcp-server MCP server
no license3★ repoQuery and retrieve information about various adversarial tactics and techniques used in cyber atta…
MCPower-Security/mcpower-proxy/io.github.MCPower-Security/mcpower-proxy MCP server
3★ repoSecurity proxy that automatically wraps MCP servers with real-time monitoring and policy enforcement
Security antipatterns javascript
subhashdasyam/security-antipatterns-javascript Skill
no license2★Skill that teaches AI coding agents to write secure JavaScript. Catches SQL injection, XSS, prototype pollution, and OWASP Top 10 patterns in Express, Next.js, and Node.
graphlit/vault-sync/plugins/vault-sync/skills/vault-sync-setup Skill
2★ repoSync Vault Git repositories to local Markdown for Claude Code, Codex, OpenClaw, Cursor, and other file-aware AI agents.
Linmas cloud hardening architect
TanKimGwan/linmas/plugins/linmas/skills/linmas-cloud-hardening-architect Skill
no license2★ repoProof-carrying defensive security reviews for AI-assisted software, with deterministic policy, portable evidence, and human review required.
Mikacr1138/claude-bug-bounty Skill
2★Enable efficient bug bounty hunting across Web2 and Web3 with a tool that supports full recon to detailed reporting.
natuleadan/skills/skills/010101-package-security Skill
2★ repoMulti-domain agent skills collection for AI coding agents (Claude, Cursor, Copilot, OpenCode, and more). Covers programming, biology, cooking, and future domains. Installable via npx skills add.
dversoza/claude-skills/1password Skill
no license2★ repoReusable skills for extending coding assistants
Comoco235/saas-preflight Skill
2★Pre-ship audit skill for SaaS that takes money. Finds the billing and data-isolation holes generic scanners miss on Next.js + Supabase + Stripe.
Rootx202/appsec-skills/api-security Skill
no license2★ repoAppSec Skills — 15 plug-and-play Claude Code security skills that audit, harden, and fix any website or app before you ship it. OWASP Top 10, auth, API, database, frontend, backend, cloud, dependencies, secrets, and pentest-style checks — all defensive, all evidence-based.
ShreyasBh02/AI-Skills-Collection/a11y-security-generator Skill
no license2★ repoInstallable GitHub library of 5+ agentic skills for Claude Code, Cursor, Codex CLI, Gemini CLI, Antigravity, and more. Includes installer CLI, bundles, workflows, and official/community skill collections.
JckJhns/skill-check/skill-check Skill
2★ repoComprehensive testing and validation for Agent Skills. Quick, Standard, and Deep checks for structure, security, best practices, and more.
Calvin-LLC/claude-harden-plugin Skill
2★A codebase hardening plugin that audits your project for security vulnerabilities (OWASP Top 10:2025), debugging gaps, test coverage, robustness issues, and accessibility violations (WCAG 2.2). Works with any language. Compatible with both Claude Code and OpenCode.
uttej-badwane/secure-cloud-prompt-engineering/skills/iac-security-review Skill
2★ repoSecurity-focused prompt library and Claude Code skill for automated IaC security reviews. Covers Terraform, Kubernetes, Docker, Ansible, CloudFormation, and CI/CD pipelines. Compliance mapping to CIS, NIST 800-53, PCI-DSS, SOC2, HIPAA, and GDPR.
scalekit-inc/skills/skills/adding-api-key-auth Skill
no license2★ repo35 skills that teach AI coding agents to integrate Scalekit auth — agent auth, full-stack login, MCP OAuth 2.1, enterprise SSO, and SCIM. Works with Claude Code, Cursor, Windsurf, and 35+ other agents.
jabez007/johnny-decimal-zettelkasten/.agents/skills/librarian-vault-manager Skill
no license2★ repoThis project is a compounding knowledge system ("Second Brain") that manages multiple Obsidian vaults, combining Johnny Decimal for structural organization with Zettelkasten for emergent meaning, augmented by AI librarian agents for maintenance.
hackIDLE/skills/skills/iac-security-scanner Skill
2★ repoSecurity-focused agent skills for service mesh analysis, compliance reporting, and remediation
xAmirHamza77/PenKit51/assistant-skills/chatgpt/penkit51-ai Skill
no license2★ repoPenKit51 — Open-source AI penetration testing platform with 63 deep exploitation skills, multi-agent orchestration, PoC-validated findings, and native assistant skills for Claude, ChatGPT, and Grok. Authorized testing only.
Dread threat modeling framework
ivan-sincek/threat-modeling-agent-skills/json/dread-threat-modeling-framework Skill
2★ repoEasy-to-use, high-quality threat modeling agent skills.
1clawAI/1claw-mcp/io.github.1clawAI/1claw-mcp MCP server
2★ repoHSM-backed vault secrets for AI agents (JIT fetch) plus prompt-injection and threat scanning.
Bajuzjefe/Aikido-Security-Analysis-Platform/io.github.Bajuzjefe/aikido-mcp MCP server
2★ repoSecurity analysis for Aiken smart contracts on Cardano. 75 vulnerability detectors.
Skyrxin/sast-mcp-server/io.github.Skyrxin/sast-mcp-server MCP server
2★ repo11-scanner SAST/DAST MCP server with closed-loop remediation, SBOM/SARIF, and CI integrations
FastMCP server for surgical queries against a vault knowledge graph (NetworkX no
adelaidasofia/graph-query-mcp/io.github.adelaidasofia/graph-query-mcp MCP server
2★ repoFastMCP server for surgical queries against a vault knowledge graph (NetworkX node-link JSON).…
ako2345/android-security-analyzer/io.github.ako2345/android-security-analyzer MCP server
no license2★ repoMCP server for static security analysis of Android source code
MCPAmpel - MCP Security Scanner
MCPAmpel/mcpampel/io.github.diemoeve/mcpampel MCP server
2★ repoScan installed MCP servers for security vulnerabilities with 16 detection engines.
tidynest/raven-nest-mcp/io.github.tidynest/raven-nest-mcp MCP server
2★ repoAI-driven penetration testing - 22 security tools behind safety-hardened MCP endpoints
iwritec0de/dep-guard/skills/dep-guard Skill
1★ repoDependency security — intercepts package install commands to enforce latest versions and block vulnerable packages
scoobydont-666/shared-claude-skills/skills/ansible-hardening Skill
1★ repo10 production-tested Claude Code skills — model routing, security hardening, code quality, tax advisory, cost optimization. Install: clone to ~/.claude/skills/
subhashdasyam/security-antipatterns-java Skill
no license1★Claude Code or Codex Skill that teaches AI coding agents to write secure Java. Catches SQL injection, unsafe deserialization, exposed secrets in Spring Boot, Jakarta EE, and Hibernate code.
GabrielYMC/security-audit Skill
1★AI agent skill for pre-deploy security audits on vibe-coded web projects. 55 rules, 8 categories, evidence-based findings. Works with Claude Code / Claude.ai.
he8um/github-skills/github-skills Skill
1★ repoProduction-grade GitHub skill for AI agents to architect, audit, secure, automate, document, and maintain repositories, workflows, releases, pull requests, issues, and open-source governance.
seburbina/skillhub/base-skill/skillhub-identity Skill
no license1★ repoAgent Skill Depot — public skills social network for Claude agents. Publish, discover, install, and rank Claude skills by how much work they offloaded. Cloudflare Workers + Neon + pgvector + R2.
Consultora-AMDT/claude-github-security-audit/en/github-security-audit Skill
1★ repoAudit a GitHub repository for risk before integrating it into your stack. Seven-dimension framework with weighted scoring and ADOPT/EVALUATE/CAUTION/AVOID verdict.
kaposty/saop/skills/saop Skill
1★ repoSAOP (Sketch, Analyze, Optimize, Partition): a read-only planning skill for Claude Code. It sketches a solution, attacks it, optimizes the whole, and splits it into small checkable pieces before a single line is written. Errors surface in planning, where fixing them is cheap: a wrong assumption costs one small piece, not a whole block of work.