Threat modelling
737 rows, by stacks then stars
309 of these skill files have been read, by 325 distinct authors, and what they tell an agent counted. What Threat modelling authors agree on, and what they forbid
jsuvic/agent-profile/fixtures/advanced-review-enabled/expected/.claude/skills/security-review Skill
3★ repoConfigure Codex, Claude, and Tabnine to understand your project, follow its workflow, and respect its safety rules.
jsuvic/agent-profile/fixtures/tabnine-workflow-skills/expected/.agents/skills/security-review Skill
3★ repoConfigure Codex, Claude, and Tabnine to understand your project, follow its workflow, and respect its safety rules.
davccavalcante/supreme-coding-guidelines-skill.ah/skills/supreme-project-audit Skill
no license3★ repoThe .ah (Teleological Semantic Format) skill bundle for Claude Code, Cursor, Trae, Zed & Kiro by David C. Cavalcante. 9 gematria-checksummed skills: coding guidelines, project audit, problem-solving, AI engineering, NPM/Node, content craft, deliberation council & research-grade benchmarking. Token-efficient, always-on after one load.
agoradynamics/wick/.claude/skills/wick-security-review Skill
no license3★ repoDrop-in thinking-partner personality layer for Claude Code, Cursor, ChatGPT, and 20+ AI agent runtimes. MIT. Plaintext. Persistent memory. Framework-grounded. Calibration-disciplined.
bhaumikmaan/claude-code-master-skills/skills/security-review Skill
3★ repoAdvanced and deterministic skills built specifically for the Claude Code agent environment extending extends Claude's native capabilities to autonomously handle complex development tasks
yarlson/yarstack/plugins/yarstack/skills/security-review Skill
3★ repoEngineering workflows and standards for Codex and Claude Code: plan, implement, test, review, and deliver repository changes.
arthjean/skills/skills/security-review Skill
no license3★ repoPublic collection of Agent Skills for Codex, Claude Code, and compatible coding agents
JayRHa/AgentSkills/threat-modeler Skill
3★ repoThe largest community-driven library of Agent Skills (SKILL.md + scripts/references/examples) for Claude, Codex, Gemini CLI, Cursor and friends.
hollandkevint/data-product-operator/skills/ethical-risk-assessment Skill
3★ repoClaude Code skills for data product managers. Product thinking meets data engineering.
Muvon/octomind-tap/skills/ai-prompt-injection-defense Skill
3★ repoOctomind Agents Registry
rshade/agent-skills/skills/security-audit Skill
3★ repoPicks and Shovels for digging AI
jposluns/grc_library/dev-security/claude-rules/skills/publication-screening Skill
2★ repoA documentation library for governance, risk, compliance, cybersecurity, privacy, resilience, AI assurance, and operational control practices + a Claude Code rules-and-skills pack distilled from maintaining it.
exchanet/method_enterprise_builder_planning/agents/antigravity/.agent/skills/phase-3-risks Skill
2★ repo🏗️ Universal 8-phase methodology for planning and building enterprise-grade, mission-critical software with AI coding agents. Supports Cursor AI, Claude Code, Kimi Code, Windsurf & Google Antigravity. Includes ADR validator, microtask linter & CI/CD templates. ≥99% test coverage. MIT.
photostructure/coding-skills/plugins/security/skills/web-security-review Skill
2★ repoOpinionated Claude Code and Codex workflow skills: iterative planning, proof-based review, and clean Conventional Commits.
YousefNabil-SOC/claude-apex/skills/gs-cso Skill
2★ repoPublic mirror + teaching install of my Claude Code environment: 1,276 skills, 185 agents, 235 commands, 8 wired MCP servers, three-layer auto-routing (10 CARL domains). Curated original core + the open plugin/marketplace ecosystem, all credited. MIT.
multiplex-ai/muggle-ai-teams/skills/security-review Skill
2★ repoAI workflow for Claude Code — describe what you want, get production-grade results. Code, content, design, planning. Built by MuggleTest.
patrickserrano/lacquer/core/skills/security-review Skill
2★ repoGo CLI + profile templates that standardize how Claude Code works across every project
OpenSIN-AI/OpenSIN-Skills/engineering-team/senior-security Skill
no license2★ repoThe world's largest open-source AI agent skill library — 280+ skills across 9 knowledge domains + 46 operational actions. Built on alirezarezvani/claude-skills + OpenSIN-AI.
artherahq/skills/skills/risk-assessment Skill
2★ repoReusable Agent Skills for quantitative finance research, extracted from the Aria toolchain.
MarieLynneBlock/arcanum-artifex/skills/security/security-review Skill
no license2★ repoPrompts, skills, and agents that survive contact with real workflows. No vendor loyalty. Occasionally heretical. 🧙🏻♀️
MarieLynneBlock/arcanum-artifex/skills/security/threat-model-analyst Skill
no license2★ repoPrompts, skills, and agents that survive contact with real workflows. No vendor loyalty. Occasionally heretical. 🧙🏻♀️
saitarrun/sdlc-ai-workflow/skills/skill-threat-modeling Skill
no license2★ repoA comprehensive Claude Code plugin that automates the complete Software Development Lifecycle with 20 role-specific agents, 12 knowledge skills, and 8 commands, all guided by principles.
Ghosteken/agent-harness/archive/skills-community/cc-skill-security-review Skill
2★ repoProduction-grade engineering skills and specialist agent personas for AI coding assistants. Orchestrates the full SDLC, from spec to ship, with structured verification gates, anti-rationalization checks, and senior-level engineering discipline.
Ghosteken/agent-harness/archive/skills-community/stride-analysis-patterns Skill
2★ repoProduction-grade engineering skills and specialist agent personas for AI coding assistants. Orchestrates the full SDLC, from spec to ship, with structured verification gates, anti-rationalization checks, and senior-level engineering discipline.
Ghosteken/agent-harness/skills/gha-security-review Skill
2★ repoProduction-grade engineering skills and specialist agent personas for AI coding assistants. Orchestrates the full SDLC, from spec to ship, with structured verification gates, anti-rationalization checks, and senior-level engineering discipline.
Ghosteken/agent-harness/skills/threat-modeling-expert Skill
2★ repoProduction-grade engineering skills and specialist agent personas for AI coding assistants. Orchestrates the full SDLC, from spec to ship, with structured verification gates, anti-rationalization checks, and senior-level engineering discipline.
kinhluan/skills/.agent-skills/threat-modeling Skill
2★ repo🚀 Professional Multi-Agent Skills
ckorhonen/swe-skills/skills/security-audit Skill
2★ repoClaude Code skills for on-demand engineering work — PR risk review, repo introspection, audits, ownership maps. Published at cdd.dev/skills/swe.
The-AI-Directory-Company/agents-and-skills/skills/threat-model-writing Skill
2★ repo70+ AI agent templates and 55+ skill definitions for Claude Code, Cursor, Windsurf, and other AI coding tools. Community-maintained, MIT licensed. Follows the Agent Skills specification.
ClarentCinematics/Codex-Skills-for-Enterprise/skills/vendor-security-review Skill
2★ reposubhansh-dev/agent-maxxing/engineering/security-review Skill
2★ repo95+ agent skills, 19 UI components, 7 system prompts from Claude Fable 5, GPT-5.5, Gemini CLI & more. Self-fine-tune your agent: paste one prompt and it reads every skill, internalizes patterns, and becomes elite. Works with Claude Code, Codex, Cursor, OpenCode + 60 more agents.
IamK77/Skill/skills/engineering/aegis Skill
2★ repoAgent-era skill suites for Claude Code: engineering lifecycle + distributed systems, gated by the checklist CLI
FluxonLab/Skillry/plugins/security/skills/48-ai-security-review Skill
no license2★ repoInstallable, permission-bounded, multi-platform agent skills & subagents for Claude Code, Codex, Copilot & Gemini/Antigravity — 125 skills + 73 subagents across 18 departments, with a validation harness, native plugin marketplace, and full upstream attribution. by FluxonLab.
93 electron app security review
FluxonLab/Skillry/plugins/security/skills/93-electron-app-security-review Skill
no license2★ repoInstallable, permission-bounded, multi-platform agent skills & subagents for Claude Code, Codex, Copilot & Gemini/Antigravity — 125 skills + 73 subagents across 18 departments, with a validation harness, native plugin marketplace, and full upstream attribution. by FluxonLab.
jukrap/ai-agent-playbook/skills/security/security-review Skill
2★ repoReusable AI agent skills, project templates, and guardrails for safer software maintenance and delivery.
Truestack application security
adtn0810/truestack/skills/truestack-application-security Skill
2★ repoHonesty-first coding skill set for Claude Code — 21 skills behind an orchestrate router with an enforced governance gate, a code↔memory tally, and auto-research. Built for self-hosted work.
xAmirHamza77/PenKit51/skills/llm-prompt-injection-testing Skill
no license2★ repoPenKit51 — Open-source AI penetration testing platform with 63 deep exploitation skills, multi-agent orchestration, PoC-validated findings, and native assistant skills for Claude, ChatGPT, and Grok. Authorized testing only.
oscarqjh/super-agent-skills/plugins/super-agent-skills/skills/threat-modeling Skill
no license2★ repoFull-lifecycle engineering plugin for Claude Code — brainstorm → plan → build → review → ship, with production-grade standards at every step.
vignesh2027/AI-AGENT-SKILLS/skills/risk-assessment Skill
2★ repoTurn your ai agent into senior engineer..The result is fast code that fails slowly. AI Agent Skills solves this by giving agents the same disciplined workflows senior engineers use
m-binimran/finance-pack/skills/risk-assessment Skill
2★ repoClaude Code pack for financial analysts: data-integrity (citation), SEC/FINRA disclaimer, projection-labeling & MNPI/PII guardrails + skills for statement analysis, ratios, DCF/comps valuation, modeling, earnings, forecasting & FP&A, loops & review agents. Not investment advice.
angad-kandhari/deliberate/skills/pentest Skill
2★ repoEngineering discipline for AI harnesses. Drop-in skill library for LLM coding agents.
maxkle1nz/deviance-skills/claude/the3y3 Skill
2★ repoOperational doctrine as installable skills for Claude Code and Codex — the DEViance Intelligence method pack.
kimtth/agent-skill-100-lines-or-less/skills/security-review Skill
no license2★ repo🧿 Minimal but effective AI agent skill definitions in 100 lines or less.
kimtth/agent-skill-100-lines-or-less/skills/threat-modeling Skill
no license2★ repo🧿 Minimal but effective AI agent skill definitions in 100 lines or less.
Pyfagorass/bookofspells/skills/openai/security-threat-model Skill
no license2★ repo📖 The Book of Spells: a curated, enchanted index of real LLM tooling — and a pipeline that gathers SKILL.md skills from many houses into one searchable shelf.
Application security review desk
MadewellRD/skills-lab/dist/skills/security-command-desk/application-security-review-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/skills/security-command-desk/attack-surface-inventory-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/skills/security-command-desk/security-command-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/skills/security-command-desk/threat-modeling-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/skills/security-command-desk/vendor-security-review-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
Application security review desk
MadewellRD/skills-lab/dist/vendor/anthropic/security-command-desk/application-security-review-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/vendor/anthropic/security-command-desk/attack-surface-inventory-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/vendor/anthropic/security-command-desk/security-command-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/vendor/anthropic/security-command-desk/threat-modeling-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/vendor/anthropic/security-command-desk/vendor-security-review-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
Application security review desk
MadewellRD/skills-lab/dist/vendor/google/security-command-desk/application-security-review-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/vendor/google/security-command-desk/attack-surface-inventory-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/vendor/google/security-command-desk/security-command-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/vendor/google/security-command-desk/threat-modeling-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
MadewellRD/skills-lab/dist/vendor/google/security-command-desk/vendor-security-review-desk Skill
2★ repoVendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.