Threat modelling
737 rows, by stacks then stars
309 of these skill files have been read, by 325 distinct authors, and what they tell an agent counted. What Threat modelling authors agree on, and what they forbid
myclaude-sh/myclaude-creator-engine/.claude/skills/aegis Skill
24★ repoThe creation pipeline for Claude Code products — research, create, validate, publish. 13 types, 20 quality patterns, zero coding required.
alpha-omega-security/threat-model/skills/threat-model-authoring Skill
18★ repoAgent skill for producing threat models for open-source projects
screem500/prompt-injection-auditor Skill
13★Security audit skill for LLM agents - prompt injection scanner, attack catalog & defense checklist
cyber-sorted/skills-pro/cybersorted Skill
no license3★ repoProfessional security and enterprise architecture advisory skills for Claude Code
zantific/skill-security-review-lens Skill
3★Security review skill for Claude Code. Scans third-party agent skills against 35 detection rules and 7 semantic checks before you install them. Finds patterns worth looking at, flags what could go wrong. Does not pass or fail anything.
Mikacr1138/claude-bug-bounty Skill
2★Enable efficient bug bounty hunting across Web2 and Web3 with a tool that supports full recon to detailed reporting.
uttej-badwane/secure-cloud-prompt-engineering/skills/iac-security-review Skill
2★ repoSecurity-focused prompt library and Claude Code skill for automated IaC security reviews. Covers Terraform, Kubernetes, Docker, Ansible, CloudFormation, and CI/CD pipelines. Compliance mapping to CIS, NIST 800-53, PCI-DSS, SOC2, HIPAA, and GDPR.
Dread threat modeling framework
ivan-sincek/threat-modeling-agent-skills/json/dread-threat-modeling-framework Skill
2★ repoEasy-to-use, high-quality threat modeling agent skills.
Github actions security review
Fyzel/claude-skills/skills/github-actions-security-review Skill
1★ repoA collection of Claude skills.
kauaim/skills/prompt-injection-guard Skill
no license1★ repoFree, open-source skills for Claude Code and Claude Desktop — starting with a prompt-injection guard for safely ingesting untrusted documents.
anthalehq/anthale-agent-skills/skills/prompt-injection-hardening Skill
1★ repoAnthale's official AI agent security skills
P1tak4s/production-readiness-audit Skill
1★Claude Agent Skill: scan, review & harden codebases for production — security, reliability, testing, data/compliance, ops, accessibility. Includes a dependency-free scanner, deep checklists, and templates.
GeorgeMJZak/before-you-deploy/skills/pre-deploy-security-review-pl Skill
1★ repoA pre-deploy security review skill for any AI agent (Claude, Codex, Gemini). Runs the 'Before You Deploy Your Vibe-Coded App' 8-category review on your real code.
maherukhislam/postgres-auth-security-review/skills/postgres-auth-security-review Skill
1★ repoAn Agent Skill that reviews and writes PostgreSQL/Supabase authentication code against a researched set of common and uncommon security mistakes - before it ships.
cyanheads/attack-surface-mcp-server/io.github.cyanheads/attack-surface-mcp-server MCP server
1★ repoPassive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
siam-hossain9/secure-development-skill/plugins/secure-development/skills/secure-development Skill
0★ repoSecure Development — a Claude Code skill: 23 security reference domains + a phase-by-phase secure build lifecycle (secure-by-design).
bensonmaxai/minis-security-skills/skills/agent-security-guard Skill
no license0★ repoSecurity skills for Minis on iOS: agent operational safety and prompt-injection defense.
thericardoli/zama-dev-skills/skills/zama-fhevm-security-review Skill
0★ repoAgent skills for Zama FHEVM and protocol development.
alebeta06/cairo-audit-skill Skill
0★AI-assisted security auditing for Cairo smart contracts. An open-source Agent Skill for Claude Code.
alexbanda08/solana-auditor-skill/skill Skill
0★ repoPractical Solana/Anchor security audit workflow skill for the Solana AI Kit (static + manual + dynamic + report); fills the official seed. MIT.
satishTheLegend/threat-model-studio Skill
0★Claude Code skill: a complete STRIDE/LINDDUN threat-modeling engagement — data-flow model, OWASP risk scoring, mitigations, gap loop, and a diffable remediation register. Enterprise AppSec rigor for solo builders.
satishTheLegend/risk-register-csf Skill
0★Claude Code skill: a solo security program as durable artifacts — a living risk register, NIST CSF 2.0 self-assessment, and a lightweight incident-response plan. The right-sized GRC slice, no SOC2 ceremony.
satishTheLegend/ai-rmf-governor Skill
0★Claude Code skill: run NIST AI RMF (Govern/Map/Measure/Manage) on your LLM/ML feature — named failure modes, metric thresholds, an offline eval gate, and signed-off residual risk.
kazani-351/system-upgrade Skill
0★Agent skill: run system-upgrade meta-prompts on your own setup. Adapted from Daniel Miessler's Fable prompts.
Ansvar-Systems/regulatory-threat-model-skill Skill
no license0★Agent skill: server-enforced STRIDE + LINDDUN threat modeling with cited EU security-obligations mapping via the Ansvar Gateway MCP connector
Agent prompt injection firewall mcp
CSOAI-ORG/agent-prompt-injection-firewall-mcp/io.github.CSOAI-ORG/agent-prompt-injection-firewall-mcp MCP server
0★ repoThe WAF for agents. Pattern-based + heuristic firewall scans prompts, RAG documents, tool argume...
CSOAI-ORG/risk-assessment-ai-mcp/io.github.CSOAI-ORG/risk-assessment-ai-mcp MCP server
0★ repoRisk Assessment Ai MCP Server by MEOK AI Labs
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/007 Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
kklimuk/docx-cli/.claude/skills/security-review Skill
178★ repoCLI for AI agents (Claude, Codex) to read, edit, and comment on .docx files with full format fidelity.
Orizon-eu/claude-code-pentest/attack-path-architect Skill
22★ repo6 Claude Code skills that automate the entire pentest lifecycle. From recon to exploit chains to bug bounty reports — just give it a domain. 43 scripts, zero dependencies, pure Python.
alpha-omega-security/threat-model/skills/threat-model-backtest Skill
18★ repoAgent skill for producing threat models for open-source projects
kdr/overcast/skills/overcast-attack-surface Skill
12★ repoVideo OSINT agent: senses + OSINT reach for any agent.
pinkpixel-dev/skills-collection-1/SKILLS/007 Skill
7★ repoPart 1 of a large AI and agent skills collection featuring 900+ reusable skill folders, prompt workflows, references, scripts, and assets across engineering, cloud, security, research, writing, design, and automation.
CrashBytes/claude-role-skills/skills/infosec-engineer Skill
6★ repoClaude Code plugin with 7 role-based professional skills for software teams — Scrum Master, Product Owner, Product Manager, UX/UI Developer, InfoSec Engineer, DevOps Engineer, and Software Migration Engineer
ranbot-ai/awesome-skills/skills/007 Skill
no license6★ repoAwesome Claude Skills, Tools for Customizing Claude AI workflows
Mikacr1138/claude-bug-bounty/skills/bug-bounty Skill
2★ repoEnable efficient bug bounty hunting across Web2 and Web3 with a tool that supports full recon to detailed reporting.
Pasta threat modeling framework
ivan-sincek/threat-modeling-agent-skills/json/pasta-threat-modeling-framework Skill
2★ repoEasy-to-use, high-quality threat modeling agent skills.
newmindsgroup/ai-agent-skills-library/dist/skills/007 Skill
1★ repoShared library of AI agent skills — works across Claude Code, Cursor, Codex, Windsurf, OpenCode, and Google Antigravity via a single universal installer.
GeorgeMJZak/before-you-deploy/skills/pre-deploy-security-review Skill
1★ repoA pre-deploy security review skill for any AI agent (Claude, Codex, Gemini). Runs the 'Before You Deploy Your Vibe-Coded App' 8-category review on your real code.
cyber-sorted/skills-free/cybersorted-lite Skill
0★ repoFree Claude Code skills for cloud architecture diagrams and security advisory
bensonmaxai/minis-security-skills/skills/prompt-injection-defense Skill
no license0★ repoSecurity skills for Minis on iOS: agent operational safety and prompt-injection defense.
code-yeongyu/oh-my-openagent/.agents/skills/security-research Skill
no license67,917★ repoomo/lazycodex: The coding agent for tokenmaxxers;the one and only agent harness for complex codebases. For your Codex, for your OpenCode
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/cc-skill-security-review Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/gha-security-review Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/stride-analysis-patterns Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/threat-modeling-expert Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/007 Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/cc-skill-security-review Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/gha-security-review Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/stride-analysis-patterns Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/threat-modeling-expert Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-bundle-aas-privacy-compliance-engineering/skills/cc-skill-security-review Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-bundle-aas-secure-app-builder/skills/cc-skill-security-review Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-bundle-security-developer/skills/cc-skill-security-review Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-bundle-security-engineer/skills/threat-modeling-expert Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/007 Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/cc-skill-security-review Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/gha-security-review Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/stride-analysis-patterns Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/threat-modeling-expert Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.