.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

home/skills/security
home/skills/security

Security Skills

2954 security agent skills for Claude Code and AI agents, ranked by real installs from npm, PyPI and skills.sh. entra-app-registration leads with 484k installs a month.

#Type
  1. 1microsoft avatarentra-app-registrationGuides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.SkillsJul 2026484k1.3k
  2. 2microsoft avatarazure-complianceRun Azure compliance and security audits with azqr plus Key Vault expiration checks.SkillsJul 2026484k1.3k
  3. 3microsoft avatarentra-agent-idProvision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token…SkillsJul 2026207k1.3k
  4. 4firebase avatarfirebase-security-rules-auditorAudits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource…SkillsJul 202680k389
  5. 5samber avatargolang-securitySecurity best practices and vulnerability prevention for Golang.SkillsJul 202635k2.7k
  6. 6googleworkspace avatargws-modelarmorGoogle Model Armor: Filter user-generated content for safety.SkillsJul 202624k30k
  7. 7googleworkspace avatargws-modelarmor-create-templateGoogle Model Armor: Create a new Model Armor template.SkillsJul 202624k30k
  8. 8googleworkspace avatargws-modelarmor-sanitize-promptGoogle Model Armor: Sanitize a user prompt through a Model Armor template.SkillsJul 202624k30k
  9. 9googleworkspace avatargws-modelarmor-sanitize-responseGoogle Model Armor: Sanitize a model response through a Model Armor template.SkillsJul 202624k30k
  10. 10insforge avatarinsforge-integrationsUse when wiring an external auth provider (Clerk, Auth0, WorkOS, Kinde, Stytch, Better Auth) into InsForge for JWT-based RLS, or when adding the OKX x402…SkillsJul 202620k33
  11. 11cloudflare avatarturnstile-spinSet up Cloudflare Turnstile end-to-end in a project. Scan the codebase, create the widget via the Cloudflare API, embed it where user requests need bot…SkillsJul 202617k2.5k
  12. 12addyosmani avatarsecurity-and-hardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations.SkillsJul 202616k80k
  13. 13wshobson avatarsolidity-securityMaster smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns.SkillsJul 202613k38k
  14. 14affaan-m avatarsecurity-reviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.SkillsJul 202612k234k
  15. 15getsentry avatarsecurity-reviewSecurity code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP…SkillsJul 202612k892
  16. 16okx avatarokx-agentic-walletOKX Agentic Wallet — the single skill for the user's wallet and on-chain execution.SkillsJul 202612k315
  17. 17wshobson avatarsecrets-managementImplement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions.SkillsJul 202610k38k
  18. 18caffeinelabs avatarextension-email-verificationSupport for sending an email with a link the recipient can click to prove they own the email address.SkillsJul 20269.3k0
  19. 19caffeinelabs avatarextension-authorizationAuthorization system with role-based access control. Must-have for all apps that manage personal or access-restricted data.SkillsJul 20269.3k0
  20. 20wshobson avatarmtls-configurationConfigure mutual TLS (mTLS) for zero-trust service-to-service communication.SkillsJul 20268.0k38k
  21. 21ljagiello avatarctf-reverseProvides reverse engineering techniques for CTF challenges. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target…SkillsJul 20266.8k2.8k
  22. 22ljagiello avatarctf-webProvides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity…SkillsJul 20266.5k2.8k
  23. 23ljagiello avatarctf-pwnProvides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory corruption…SkillsJul 20266.3k2.8k
  24. 24ljagiello avatarctf-cryptoProvides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems…SkillsJul 20266.1k2.8k
  25. 25ljagiello avatarctf-osintProvides open source intelligence techniques for CTF challenges.SkillsJul 20266.1k2.8k
  26. 26ljagiello avatarctf-forensicsProvides digital forensics and signal analysis techniques for CTF challenges.SkillsJul 20266.0k2.8k
  27. 27openai avatarsecurity-best-practicesPerform language and framework specific security best-practice reviews and suggest improvements.SkillsJul 20265.9k24k
  28. 28ljagiello avatarsolve-challengeSolves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf-* skill.SkillsJul 20265.9k2.8k
  29. 29ljagiello avatarctf-miscProvides miscellaneous CTF challenge techniques for problems that do not cleanly fit the main categories.SkillsJul 20265.9k2.8k
  30. 30ljagiello avatarctf-malwareProvides malware analysis and network traffic techniques for CTF challenges.SkillsJul 20265.8k2.8k
  31. 31binance avatarquery-token-auditQuery token security audit to detect scams, honeypots, and malicious contracts before trading.SkillsJul 20265.6k942
  32. 32trailofbits avatarsecure-workflow-guideGuides through Trail of Bits' 5-step secure development workflow.SkillsJul 20265.6k6.3k
  33. 33trailofbits avatarfp-checkSystematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for…SkillsJul 20265.0k6.3k
  34. 34trailofbits avataragentic-actions-auditorAudits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI…SkillsJul 20264.9k6.3k
  35. 35trailofbits avataraudit-context-buildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.SkillsJul 20264.6k6.3k
  36. 36vercel avatarchat-sdkBuild multi-platform chat bots with Chat SDK (`chat` npm package).SkillsJul 20264.5k2.2k
  37. 37aws avataraws-iamVerified corrections for IAM behaviors that AI agents frequently get wrong — policy evaluation edge cases, trust policy gotchas, STS session limits,…SkillsJul 20264.5k2.1k
  38. 38trailofbits avatarproperty-based-testingProvides guidance for property-based testing across multiple languages and smart contracts.SkillsJul 20264.5k6.3k
  39. 39jeffallan avatarsecurity-reviewerIdentifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance.SkillsMay 20264.3k11k
  40. 40claude-office-skills avatarcontract-reviewAnalyze contracts for risks, check completeness, and provide actionable recommendations. Supports employment contracts, NDAs, service agreements, and more.SkillsJan 20264.3k339
  41. 41trailofbits avatarsolana-vulnerability-scannerScans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.SkillsJul 20264.2k6.3k
  42. 42trailofbits avataraudit-prep-assistantPrepares codebases for security review using Trail of Bits' checklist.SkillsJul 20264.1k6.3k
  43. 43jeffallan avatarfullstack-guardianBuilds security-focused full-stack web applications by implementing integrated frontend and backend components with layered security at every level.SkillsMay 20264.0k11k
  44. 44trailofbits avatarentry-point-analyzerAnalyzes smart contract codebases to identify state-changing entry points for security auditing.SkillsJul 20264.0k6.3k
  45. 45trailofbits avatarguidelines-advisorSmart contract development advisor based on Trail of Bits' best practices.SkillsJul 20263.9k6.3k
  46. 46trailofbits avatarcosmos-vulnerability-scannerScans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence.SkillsJul 20263.9k6.3k
  47. 47trailofbits avatarconstant-time-analysisDetects timing side-channel vulnerabilities in cryptographic code.SkillsJul 20263.9k6.3k
  48. 48trailofbits avataralgorand-vulnerability-scannerScans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access…SkillsJul 20263.8k6.3k
  49. 49trailofbits avatarton-vulnerability-scannerScans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without…SkillsJul 20263.8k6.3k
  50. 50trailofbits avatarcairo-vulnerability-scannerScans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems,…SkillsJul 20263.8k6.3k
  51. 51trailofbits avatarsubstrate-vulnerability-scannerScans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks.SkillsJul 20263.8k6.3k
  52. 52jeffallan avatarsecure-code-guardianUse when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations…SkillsMay 20263.7k11k
  53. 53trailofbits avatarburpsuite-project-parserSearches and explores Burp Suite project files (.burp) from the command line.SkillsJul 20263.6k6.3k
  54. 54openai avatarsecurity-threat-modelRepository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise…SkillsJul 20263.6k24k
  55. 55ghostsecurity avatarscan-codeGhost Security - SAST code scanner. Finds security vulnerabilities in source code by planning and executing targeted scans for issues like SQL injection, XSS,…SkillsMar 20263.3k400
  56. 56google avataragent-platform-inferenceConnects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama,…SkillsJul 20262.9k15k
  57. 57ghostsecurity avatarscan-secretsGhost Security - Secrets and credentials scanner. Scans codebase for leaked API keys, tokens, passwords, and sensitive data.SkillsMar 20262.9k400
  58. 58trailofbits avatardimensional-analysisAnnotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling.SkillsJul 20262.7k6.3k
  59. 59ghostsecurity avatarscan-depsGhost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings…SkillsMar 20262.7k400
  60. 60hoodini avatarowasp-securityImplement secure coding practices following OWASP Top 10. Use when preventing security vulnerabilities, implementing authentication, securing APIs, or…SkillsJul 20262.6k257
  61. 61dpearson2699 avatardevice-integrityVerify device legitimacy and app integrity using DeviceCheck (DCDevice per-device bits) and App Attest (DCAppAttestService key generation, attestation, and…SkillsJul 20262.6k933
  62. 62markdown-viewer avatarsecurityCreate security architecture diagrams using PlantUML syntax with identity, encryption, firewall, and compliance stencil icons.SkillsMay 20262.6k3.1k
  63. 63yaklang avatarhackEntry P0 primary router for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path…SkillsJun 20262.5k1.5k
  64. 64vercel-labs avataroauthConfigure OAuth providers (Google, Apple, Microsoft, Facebook, GitHub, etc.) to work with portless local dev URLs.SkillsJul 20262.5k10k
  65. 65cloudflare avatarsecurity-auditSecurity audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and more.SkillsJul 20262.4k2.7k
  66. 66raroque avatarvibe-securityAudits codebases for common security vulnerabilities that AI coding assistants introduce in "vibe-coded" applications.SkillsMar 20262.4k892
  67. 67ghostsecurity avatarvalidateThis skill should be used when the user asks to "validate a finding", "check if a vulnerability is real", "triage a security finding", "confirm a…SkillsMar 20262.4k400
  68. 68ghostsecurity avatarreportGhost Security — combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report…SkillsMar 20262.4k400
  69. 69yaklang avatarcode-obfuscation-deobfuscationCode obfuscation analysis and deobfuscation playbook. Use when reversing binaries protected by junk code, opaque predicates, self-modifying code, control flow…SkillsJun 20262.4k1.5k
  70. 70yaklang avatarapi-secEntry P1 category router for API security. Use when choosing between API recon, authorization, token abuse, and hidden-parameter workflows before any deeper…SkillsJun 20262.3k1.5k
  71. 71forcedotcom avatardx-code-analyzer-runRun Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations.SkillsJul 20262.3k765
  72. 72yaklang avatarbusiness-logic-vulnerabilitiesBusiness logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step…SkillsJun 20262.3k1.5k
  73. 73yaklang avatarjwt-oauth-token-attacksJWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding…SkillsJun 20262.3k1.5k
  74. 74yaklang avatarauthbypass-authentication-flawsAuthentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force…SkillsJun 20262.3k1.5k
  75. 75getsentry avatarskill-scannerScan agent skills for security issues. Use when asked to "scan a skill",SkillsJul 20262.2k892
  76. 76yaklang avataridor-broken-object-authorizationIDOR and broken object authorization testing playbook. Use when requests expose object identifiers, tenant boundaries, writable fields, or missing object-level…SkillsJun 20262.2k1.5k
  77. 77yaklang avatar401-403-bypass-techniques401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths.SkillsJun 20262.2k1.5k
  78. 78yaklang avatarauth-secEntry P1 category router for authentication and authorization.SkillsJun 20262.2k1.5k
  79. 79yaklang avatarinjection-checkingEntry P1 category router for injection testing. Use when routing between XSS, SQLi, SSRF, XXE, SSTI, command injection, and NoSQL injection workflows based on…SkillsJun 20262.2k1.5k
  80. 80openai avatarsecurity-ownership-mapAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for…SkillsJul 20262.2k24k
  81. 81yaklang avatarheap-exploitationHeap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging…SkillsJun 20262.2k1.5k
  82. 82yaklang avatarcsrf-cross-site-request-forgeryCSRF testing playbook. Use when reviewing state-changing web flows, anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, and OAuth state handling.SkillsJun 20262.2k1.5k
  83. 83yaklang avatarbusiness-logic-vulnEntry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than…SkillsJun 20262.2k1.5k
  84. 84yaklang avatarcors-cross-origin-misconfigurationCORS misconfiguration testing playbook. Use when analyzing cross-origin trust, credentialed browser reads, origin reflection, preflight policy bugs, and…SkillsJun 20262.2k1.5k
  85. 85yaklang avatarformat-string-exploitationFormat string exploitation playbook. Use when printf-family functions receive user-controlled format strings, enabling arbitrary stack reads (%p/%s), arbitrary…SkillsJun 20262.2k1.5k
  86. 86yaklang avatarcmdi-command-injectionCommand injection playbook. Use when user input may reach shell commands, process execution, converters, import pipelines, or blind out-of-band command sinks.SkillsJun 20262.2k1.5k
  87. 87yaklang avatarfile-access-vulnEntry P1 category router for file access and upload workflows.SkillsJun 20262.2k1.5k
  88. 88yaklang avatarbinary-protection-bypassBinary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET, and MTE protections in ELF…SkillsJun 20262.2k1.5k
  89. 89yaklang avatardeserialization-insecureInsecure deserialization playbook. Use when Java, PHP, or Python applications deserialize untrusted data via ObjectInputStream, unserialize, pickle, or similar…SkillsJun 20262.2k1.5k
  90. 90yaklang avatarbrowser-exploitation-v8Browser and V8 exploitation playbook. Use when exploiting JavaScript engine vulnerabilities including JIT type confusion, incorrect bounds elimination, and V8…SkillsJun 20262.2k1.5k
  91. 91yaklang avatarcrlf-injectionCRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values, or log files where carriage-return/line-feed…SkillsJun 20262.2k1.5k
  92. 92yaklang avatarinsecure-source-code-managementSource control and artifact exposure (.git, .svn, .hg, backups, .env).SkillsJun 20262.2k1.5k
  93. 93yaklang avatardependency-confusionSupply-chain testing via package-manager dependency confusion: when internal package names resolve to attacker-controlled public registries, leading to…SkillsJun 20262.2k1.5k
  94. 94yaklang avatarexpression-language-injectionExpression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in Spring, Struts2,…SkillsJun 20262.2k1.5k
  95. 95elastic avatarelasticsearch-auditEnable, configure, and query Elasticsearch security audit logs.SkillsJul 20262.2k542
  96. 96elastic avatarelasticsearch-authzManage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.SkillsJul 20262.1k542
  97. 97yaklang avataractive-directory-acl-abuseActive Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS…SkillsJun 20262.1k1.5k
  98. 98yaklang avatarcsp-bypass-advancedAdvanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy weaknesses, trusted…SkillsJun 20262.1k1.5k
  99. 99yaklang avatarcsv-formula-injectionCSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT*).SkillsJun 20262.1k1.5k
  100. 100forcedotcom avatarintegration-connectivity-connected-app-configureSalesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring.SkillsJul 20262.1k765

More skills categories

DevOps & CI/CD5519Productivity & Workflow5248Other4998Product & Project Management4964Documentation & Knowledge4545Code Review & Refactor4435Backend & APIs4325Agent Meta & Communication3318Research3084UX UI & Design2699All Skills →