.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/briiirussell/cybersecurity-skills
home/skills/briiirussell/cybersecurity-skills
briiirussell avatar

briiirussell/cybersecurity-skills

29 skills · 3,798 total installs

View on GitHub
$npx skills add briiirussell/cybersecurity-skills
SkillInstalls
owasp-auditAudit application source code against the OWASP Top 10 (2021) vulnerability categories — broken access control, cryptographic failures, injection, insecure…171osint-reconGather and correlate open source intelligence from public sources for authorized investigations, threat intelligence, and attack surface assessment.161mobile-auditAudit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root…152dependency-auditAudit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.148web-pentestPerform black-box / grey-box web application penetration testing on an authorized target — auth bypass, IDOR, session handling, business-logic flaws, parameter…145reconPerform structured reconnaissance and attack surface enumeration for authorized penetration tests, CTF challenges, and bug bounty programs.143prompt-injectionAudit applications for AI prompt injection, agent security, and LLM permission boundary vulnerabilities.142api-auditAudit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).141disk-forensicsAnalyze disk images, file systems, and memory captures for digital evidence recovery in forensic investigations and CTF challenges.141incident-triageGuide rapid triage and initial response to security incidents following NIST SP 800-61 methodology.139cloud-auditAudit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.137secrets-auditFind leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.137finding-triageTriage a single security finding — from a scanner, audit, advisory, or report — to a defensible disposition with a mitigation plan, false-positive…127threat-modelingRun a structured threat-modeling session for a new feature, system, or architecture — STRIDE, attack trees, data flow diagrams, abuse cases.126privacy-engineeringImplement and audit privacy controls in product and infrastructure — GDPR, CCPA / CPRA, LGPD, PIPEDA.125crypto-auditAudit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and…124vuln-researchResearch a specific CVE or vulnerability disclosure end-to-end — what version is affected, is your code reachable, is there a public PoC, is there a patch,…124iam-auditAudit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google…123siem-detectionEngineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and…123red-team-engagementPlan, scope, and execute an authorized red-team engagement — distinct from a penetration test.120soc-operationsBuild, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow,…120threat-huntingConduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet.120breach-patternsLearn from public breach disclosures — extract the audit question each one implies and check your own stack.119container-auditAudit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.118pci-auditAudit applications and infrastructure handling payment card data against PCI DSS v4.0.116security-commsTranslate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal,…116csf-mappingMap your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover).115ai-risk-managementApply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation,…113hipaa-auditAudit applications and infrastructure handling Protected Health Information against HIPAA — Security Rule (administrative, physical, technical safeguards),…112