Security
7,261 rows, by stacks then stars
772 of these skill files have been read, by 666 distinct authors, and what they tell an agent counted. What Security authors agree on, and what they forbid
AL-JANEF/janefskills/auth-hardening Skill
0★ repoDefensive security & production-grade engineering skills for Claude Code — auth, OWASP audit, threat modeling, secrets, logging.
0xkaizoku/launch-playbook Skill
0★Time-boxed pre-launch security playbook for MVPs and SaaS shipped fast.
hemant-datascientist/security-audit-skill Skill
0★116-check security, bug, and data-protection audit skill for Claude Code — with live threat intel, 0-100 scoring, and vibe-coding-specific patterns
tanav-ai/claude-plugin/skills/tanav-security-check Skill
0★ repoFree AI supply chain security checks for GitHub repos — right from a Claude conversation
jovd83/defensive-appsec-review-skill Skill
0★Authorized defensive AppSec review skill for repositories, APIs, CI/CD, IaC, and AI systems with findings-first output.
kpatryk/skills/skills/bandit Skill
0★ repoAI skills
Himess/fhevm-skill Skill
0★Production-ready Agent Skills that give any AI coding agent full FHEVM fluency for building confidential dApps on the Zama Protocol.
bensonmaxai/minis-security-skills/skills/agent-security-guard Skill
no license0★ repoSecurity skills for Minis on iOS: agent operational safety and prompt-injection defense.
Tyr0/agent-skills/plugins/credential-expert/skills/credential-storage Skill
0★ repoA collection of skills, plugins, and agents for AI workflows.
arpitexplores/super-security Skill
0★Portable Markdown skill for AI vibe coding with security: security audits, threat modelling, web security testing, application security, API security, and remediation workflows.
thericardoli/zama-dev-skills/skills/zama-fhevm-security-review Skill
0★ repoAgent skills for Zama FHEVM and protocol development.
sokratisg/trivy-security-scan/skills/trivy-security-scan Skill
0★ repoAgent-neutral Trivy security scanning skill for local vulnerability, misconfiguration, secret, and license scans.
zerostaff/server-security-skill/skills/server-security Skill
0★ repoAgent skill that audits and hardens basic security on a Debian/Ubuntu server over SSH with fail-safe rollback for sshd changes.
nanxiaoyao/network-huawei-skills/attack-defense Skill
0★ repoHuawei network device (USG firewall + S/CE switch) CLI skills pack for OpenClaw AI agent — also usable as a standalone cheatsheet.
alebeta06/cairo-audit-skill Skill
0★AI-assisted security auditing for Cairo smart contracts. An open-source Agent Skill for Claude Code.
sarfaraz-munir/Claude-Code-Cyber-agents/.claude/skills/ciso-ai-security Skill
0★ repoHierarchical CISO AI agent swarm for Claude Code — 10 specialist agents covering risk governance, compliance, threat intelligence, vulnerability management, incident response, and AI security (OWASP LLM Top 10 / MITRE ATLAS). Includes MCP tools, Claude Code skills etc.
K-Oxon/gh-security-audit-skill/skills/gh-security-audit Skill
0★ repoA read-only audit skill for GitHub repository security settings and Actions hardening.
esaldgut/ai-native-engineering-workspace/global-skills/android/android-security-checklist Skill
0★ repoAI-native engineering workspace — 42 Claude Code agent skills, platform-base workflow docs, and a freshness system that re-verifies each pattern against vendor docs.
Hermes skill local web security scan
web3blind/hermes-skill-local-web-security-scan Skill
no license0★Local Web Security Scan
vishnujchandran/.agents/skills/api-security-audit Skill
no license0★ repoA curated collection of reusable AI agent skills, playbooks, and prompts for security audits, engineering workflows, and automation.
LinLin00000000/aiops-vault-template Skill
0★Local-first, agent-friendly AIOps vault template with Markdown/JSONL truth sources and thin companion skills.
scchearn/loam/skills/loam-ground/loam-initializing-vault Skill
0★ repoWorkflow skills for AI coding agents: plan, execute, and maintain a persistent knowledge base across sessions.
alexbanda08/solana-auditor-skill/skill Skill
0★ repoPractical Solana/Anchor security audit workflow skill for the Solana AI Kit (static + manual + dynamic + report); fills the official seed. MIT.
jovd83/skill-vetting-reporter Skill
0★Security & trust vetting for AgentSkills: mandatory open-source scanner gate (Cisco, NVIDIA SkillSpector, Snyk, sentry), OWASP Top 10 for Agentic Applications mapping, and tiered review reports.
dvnc-labs/agent-config-audit Skill
0★Review agent setup files before you run them.
satishTheLegend/authz-architect Skill
0★Designs, implements, and adversarially verifies an application's authorization + tenant-isolation model — closing the IDOR/broken-access-control gaps that are the #1 web vuln.
Code performance optimizer skill
hireblackout/code-performance-optimizer-skill Skill
0★Code Performance Optimizer Skill helps developers improve backend and API performance with structured optimization, Big-O analysis, and security-first guardrails. It identifies bottlenecks, ranks improvement opportunities, and guides production-safe changes that preserve reliability, security posture, and scalability
yuelenghan/orbit/skills/api-pentest Skill
0★ repoAn open-source arsenal of reusable skills for AI agents — repo understanding, code review, delivery workflows, security pentests, and plug-and-play integrations with Jira, GitHub, GitLab, Jenkins & more. Drop into Claude Code, Codex, or any skill-aware host.
zakelfassi/skdd-commons/packs/2026-07-frontier/attack-the-plan Skill
0★ repoSkills that evolve in public — community agent-skill drops for SkDD
satishTheLegend/threat-model-studio Skill
0★Claude Code skill: a complete STRIDE/LINDDUN threat-modeling engagement — data-flow model, OWASP risk scoring, mitigations, gap loop, and a diffable remediation register. Enterprise AppSec rigor for solo builders.
satishTheLegend/risk-register-csf Skill
0★Claude Code skill: a solo security program as durable artifacts — a living risk register, NIST CSF 2.0 self-assessment, and a lightweight incident-response plan. The right-sized GRC slice, no SOC2 ceremony.
Hayatelin/devsecops-skills/skills/ci-security-gate Skill
0★ repoA security skills pack for Claude Code, Cursor, Codex and Gemini CLI: secrets pre-flight, dependency audit, secret rotation, STRIDE threat modeling, secure code review, Dockerfile hardening and env hygiene.
WIHATN/vault-crystallize Skill
no license0★Claude/agent skill for checkpointing progress into Handoff.md and distilling sources into a cited, confidence-rated evidence log inside an agent-managed knowledge vault.
satishTheLegend/ai-rmf-governor Skill
0★Claude Code skill: run NIST AI RMF (Govern/Map/Measure/Manage) on your LLM/ML feature — named failure modes, metric thresholds, an offline eval gate, and signed-off residual risk.
CaptainTimmeow/creator-vault-skill/.agents/skills/creator-vault Skill
0★ repoCopy-only local media ingest for creators using a Codex skill
kazani-351/system-upgrade Skill
0★Agent skill: run system-upgrade meta-prompts on your own setup. Adapted from Daniel Miessler's Fable prompts.
sjsylee/skills-hub/skills/codebase-security-audit Skill
0★ repo바이브 코딩에 규율을 입히는 에이전트 스킬 모음 · Agent skills that bring discipline to vibe coding. Install: npx skills add sjsylee/skills-hub
chang769/llm-wiki-vault-manager Skill
no license0★Agent skill for building source-backed LLM-wiki learning vaults for Codex and Claude Code
Incident reporting navigator skill
Ansvar-Systems/incident-reporting-navigator-skill Skill
no license0★Agent skill: one security incident mapped across EU reporting regimes (NIS2, GDPR, DORA, CRA) — duties, authorities, deadlines, cited live via the Ansvar Gateway MCP connector
MoonFuji/invariant-first-bug-bounty Skill
0★Evidence-gated Agent Skill for deep, invariant-first bug-bounty research, source-code auditing, duplicate analysis, and report readiness.
Ansvar-Systems/regulatory-threat-model-skill Skill
no license0★Agent skill: server-enforced STRIDE + LINDDUN threat modeling with cited EU security-obligations mapping via the Ansvar Gateway MCP connector
Nick-800/skills/skills/electron-development Skill
no license0★ repoCra vulnerability obligations skill
Ansvar-Systems/cra-vulnerability-obligations-skill Skill
no license0★Agent skill: EU Cyber Resilience Act vulnerability & reporting obligations, cited live via the Ansvar Gateway MCP connector
that-guy-jamie/legible-legitimacy/skills/legible-legitimacy Skill
0★ repoA portable workflow-governance skill for making high-consequence agent operations authorized, bounded, reversible, and auditable.
BWBlueVector/obsidian-vault-conventions Skill
0★Claude Code skill that keeps an AI's persistent memory correctly readable by both the AI and a human browsing it in Obsidian
Helixar-AI/helixar-mcp/ai.helixar/mcp MCP server
0★ repoSecurity tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
blackducksoftware/mcp-server/com.blackduck/mcp-server MCP server
0★ repoAI-powered security scanning using Black Duck Signal for vulnerability detection.
datakoot/security-intel-mcp/com.datakoot/security-intel-mcp MCP server
0★ repoCVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
nauta-ai/holster/com.nautaai/holster-mcp MCP server
0★ repoLocal-first secret scanning, rotation, vault, and audit-log tools for AI agents.
seanwinslow28/sw-mcp-vault-knowledge/com.seanwinslow/vault-knowledge MCP server
0★ repoRead-only MCP over a vault's typed knowledge graph: concept search, contradictions, article fetch.
GUCCI-atlasv/Skillssafe.com/com.skillssafe/scanner MCP server
0★ repoAI skill security scanner. Detects prompt injection, credential theft, ClawHavoc. Free, no signup.
AIWerk/mcp-server-vault/io.github.AIWerk/mcp-server-vault MCP server
0★ repoBitwarden/Vaultwarden for agents: list tagged items, TOTP codes, one-time Sends, save new secrets.
Agent prompt injection firewall mcp
CSOAI-ORG/agent-prompt-injection-firewall-mcp/io.github.CSOAI-ORG/agent-prompt-injection-firewall-mcp MCP server
0★ repoThe WAF for agents. Pattern-based + heuristic firewall scans prompts, RAG documents, tool argume...
CSOAI-ORG/owasp-agentic-mcp/io.github.CSOAI-ORG/owasp-agentic-mcp MCP server
0★ repoowasp-agentic-mcp MCP server by MEOK AI Labs
CSOAI-ORG/risk-assessment-ai-mcp/io.github.CSOAI-ORG/risk-assessment-ai-mcp MCP server
0★ repoRisk Assessment Ai MCP Server by MEOK AI Labs
CodingSelim/mcp-scan/io.github.CodingSelim/mcp-scan MCP server
0★ repoPassive security scanner: audits MCP servers against the OWASP MCP Top 10, graded A-F.
Compuute/compuute-scan-api/io.github.Compuute/compuute-scan-api MCP server
0★ repoScan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
DevInder1/supply-chain-scanner-public/io.github.DevInder1/tridentchain-security MCP server
0★ repoLocal supply-chain CVE scanner via OSV/NVD. Scans deps and IDE extensions. No upload.
Cybersecurity Threat Intelligence MCP
FoundryNet/cyber-intel-mcp/io.github.FoundryNet/cyber-intel-mcp MCP server
0★ repoCVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
H129hj/checkmcp/io.github.H129hj/checkmcp MCP server
0★ repoAudit any MCP server's security & quality — OWASP MCP Top 10 + explainable 0-100 MCP Score