.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

home/subagents/security
home/subagents/security

Security Subagents

383 security subagents for Claude Code and AI agents, ranked by real installs from npm, PyPI and skills.sh.

#Type
  1. 1addyosmani avatarsecurity-auditorSecurity engineer focused on vulnerability detection, threat modeling, and secure coding practices. Use for security-focused code review, threat analysis, or hardening recommendations.SubagentsJul 2026—80k
  2. 2yeachan-heo avatarsecurity-reviewerSecurity vulnerability detection specialist (OWASP Top 10, secrets, unsafe patterns)SubagentsJul 2026—38k
  3. 3donchitos avatarsecurity-engineerThe Security Engineer protects the game from cheating, exploits, and data breaches. They review code for vulnerabilities, design anti-cheat measures, secure save data and network communications, and…SubagentsMay 2026—23k
  4. 4unoplatform avatarsecurityAudits code for vulnerabilities at the framework's real trust boundaries — XAML/data-binding of untrusted content, the DevServer/RemoteControl network host, source generators reading project inputs,…SubagentsJul 2026—10.0k
  5. 5mock-server avatarsecurity-auditorSecurity-focused code auditor for Java/Netty applications. Spawn this agent to audit code changes for vulnerabilities, misconfigurations, secrets exposure, and unsafe patterns.SubagentsJul 2026—4.9k
  6. 6nyldn avatarsecurity-auditorSecurity auditor for DevSecOps, OWASP compliance, vulnerability assessment, and threat modelingSubagentsJul 2026—3.9k
  7. 7gadievron avatarexploitability-validator-agentMulti-stage pipeline to validate vulnerability findings are real, reachable, and exploitableSubagentsJul 2026—3.4k
  8. 8gadievron avataroffsec-specialistUse this agent when the user needs to perform offensive security operations, security testing, or vulnerability research tasks. This includes:\n\n<example>\nContext: User wants to test a web…SubagentsJul 2026—3.4k
  9. 9gadievron avataross-evidence-verifier-agentVerify all collected evidence against original sourcesSubagentsJul 2026—3.4k
  10. 10gadievron avataross-hypothesis-checker-agentValidate hypothesis claims against verified evidenceSubagentsJul 2026—3.4k
  11. 11gadievron avataross-hypothesis-former-agentForm evidence-backed hypotheses for forensic investigationsSubagentsJul 2026—3.4k
  12. 12gadievron avataross-investigator-gh-archive-agentQuery GH Archive via BigQuery for tamper-proof forensic evidenceSubagentsJul 2026—3.4k
  13. 13gadievron avataross-investigator-github-agentQuery GitHub API for repository state, commits, and recovery of deleted commitsSubagentsJul 2026—3.4k
  14. 14gadievron avataross-investigator-ioc-extractor-agentExtract IOCs from vendor security reports as forensic evidenceSubagentsJul 2026—3.4k
  15. 15gadievron avataross-investigator-local-git-agentAnalyze cloned repositories for dangling commits and git forensicsSubagentsJul 2026—3.4k
  16. 16gadievron avataross-investigator-wayback-agentRecover deleted GitHub content via Wayback MachineSubagentsJul 2026—3.4k
  17. 17gadievron avataross-report-generator-agentGenerate final forensic report from confirmed hypothesis and evidenceSubagentsJul 2026—3.4k
  18. 18rohitg00 avatarpermission-analystAnalyze permission denial patterns and generate optimized alwaysAllow/alwaysDeny rules. Use when permission prompts slow down workflow.SubagentsJul 2026—2.7k
  19. 190xsteph avatar_scope-guardTurn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections,…SubagentsJun 2026—2.0k
  20. 200xsteph avatarad-attackerDelegates to this agent when the user wants to perform Active Directory attacks, run BloodHound analysis, use Impacket tools, execute Kerberos attacks, perform AD enumeration with CrackMapExec or…SubagentsJun 2026—2.0k
  21. 210xsteph avatarai-reconDelegates to this agent when the user wants to map the AI attack surface of an authorized web application before validation — discovering AI/LLM API endpoints (including OpenAI-compatible APIs),…SubagentsJun 2026—2.0k
  22. 220xsteph avatarapi-securityDelegates to this agent when the user asks about API security testing, REST API attacks, GraphQL exploitation, OAuth/OIDC vulnerabilities, JWT attacks, API enumeration, or web service penetration…SubagentsJun 2026—2.0k
  23. 230xsteph avatarattack-plannerDelegates to this agent when the user wants to correlate findings from multiple tools or agents, build multi-step attack chains, identify the optimal exploitation path through a network, prioritize…SubagentsJun 2026—2.0k
  24. 240xsteph avatarbizlogic-hunterDelegates to this agent when the user wants to test for business logic flaws, find workflow bypass vulnerabilities, detect price manipulation or payment tampering, identify race conditions in…SubagentsJun 2026—2.0k
  25. 250xsteph avatarbug-bountyDelegates to this agent when the user is working on bug bounty programs, submitting vulnerability reports to HackerOne or Bugcrowd, needs help with bug bounty methodology, wants to prioritize targets…SubagentsJun 2026—2.0k
  26. 260xsteph avatarc2-operatorDelegates to this agent when the user asks about command-and-control framework operations, Sliver/Mythic/Havoc/Cobalt Strike configuration, listener and beacon tuning, malleable C2 profiles, sleep…SubagentsJun 2026—2.0k
  27. 270xsteph avatarcloud-securityDelegates to this agent when the user asks about cloud security testing, AWS/Azure/GCP penetration testing, cloud misconfiguration analysis, IAM privilege escalation, container security, Kubernetes…SubagentsJun 2026—2.0k
  28. 280xsteph avatarcontainer-breakoutDelegates to this agent when the user asks about container escape, Docker breakout, Kubernetes pod escape, runc/containerd CVE exploitation, capability abuse, privileged container hunting, kubelet…SubagentsJun 2026—2.0k
  29. 290xsteph avatarcredential-testerDelegates to this agent when the user asks about password attacks, credential testing, hash cracking, brute force methodology, default credential checks, password spraying, or needs help with tools…SubagentsJun 2026—2.0k
  30. 300xsteph avatarcrypto-analyzerDelegates to this agent when the user wants to analyze cryptographic usage — weak algorithms or modes, key and IV/nonce management, TLS/certificate configuration, randomness quality, password…SubagentsJun 2026—2.0k
  31. 310xsteph avatarctf-solverDelegates to this agent when the user is working on CTF challenges, capture the flag competitions, HackTheBox machines, TryHackMe rooms, or needs help with CTF methodology including web exploitation,…SubagentsJun 2026—2.0k
  32. 320xsteph avatardata-exfiltratorDelegates to this agent when the user wants to test exfiltration and DLP/egress controls during an authorized engagement — DNS tunneling, HTTPS/cloud-storage exfil, ICMP, protocol abuse, and staging…SubagentsJun 2026—2.0k
  33. 330xsteph avatardetection-engineerDelegates to this agent when the user asks about detection rules, SIEM queries, threat hunting, indicator analysis, log analysis, blue team detection for specific attack techniques, or creating…SubagentsJun 2026—2.0k
  34. 340xsteph avatarevasion-specialistDelegates to this agent when the user wants to test defensive evasion during an authorized red team or EDR-validation engagement — AV/EDR evasion, AMSI and ETW bypass, payload obfuscation, in-memory…SubagentsJun 2026—2.0k
  35. 350xsteph avatarexploit-chainerDelegates to this agent when the user wants to automatically chain isolated vulnerabilities into multi-step attack paths, pivot through a system from a low-severity finding to full compromise,…SubagentsJun 2026—2.0k
  36. 360xsteph avatarforensics-analystDelegates to this agent when the user asks about digital forensics, incident response, evidence acquisition, memory forensics, disk forensics, network forensics, timeline analysis, or chain of custodySubagentsJun 2026—2.0k
  37. 370xsteph avatariot-pentesterDelegates to this agent when the user wants authorized security testing of IoT/embedded devices — firmware extraction and analysis, hardware interfaces (UART/JTAG/SPI), radio protocols…SubagentsJun 2026—2.0k
  38. 380xsteph avatarlateral-movementDelegates to this agent when the user wants post-foothold lateral-movement strategy on an authorized engagement — pass-the-hash/ticket, remote execution (PsExec/WMI/WinRM/DCOM/SSH), token…SubagentsJun 2026—2.0k
  39. 390xsteph avatarnetwork-attackerDelegates to this agent when the user wants layer-2/layer-3 offensive testing on an authorized internal network — LLMNR/NBT-NS/mDNS poisoning, ARP spoofing and MITM, NTLM relay, IPv6/mitm6 takeover,…SubagentsJun 2026—2.0k
  40. 400xsteph avataropsec-anonymizerDelegates to this agent when the user asks about operator-side identity hygiene, source IP separation, traffic anonymization for authorized red team work, Tor and proxy chains, burner infrastructure…SubagentsJun 2026—2.0k
  41. 410xsteph avatarosint-collectorDelegates to this agent when the user asks about OSINT, reconnaissance, information gathering, target profiling, email harvesting, subdomain enumeration, social media recon, breach data, open source…SubagentsJun 2026—2.0k
  42. 420xsteph avatarpassword-auditorDelegates to this agent when the user wants to audit password posture — policy review against NIST 800-63B, password-storage/hashing review, breach-exposure checks, and lockout-safe password-spray…SubagentsJun 2026—2.0k
  43. 430xsteph avatarpayload-crafterDelegates to this agent when the user asks about generating offensive payloads, building shellcode, working with msfvenom, packing or encoding payloads, building reverse shells, creating EDR-test…SubagentsJun 2026—2.0k
  44. 440xsteph avatarpersistence-plannerDelegates to this agent when the user wants to plan and document persistence during an authorized red team engagement — host persistence (Windows/Linux), Active Directory persistence (golden/silver…SubagentsJun 2026—2.0k
  45. 450xsteph avatarphishing-operatorDelegates to this agent when the user asks about setting up phishing infrastructure, configuring Evilginx3 or GoPhish, adversary-in-the-middle credential capture, MFA token relay, domain lookalike…SubagentsJun 2026—2.0k
  46. 460xsteph avatarpoc-validatorDelegates to this agent when the user wants to validate a vulnerability finding with a safe Proof of Concept, eliminate false positives from scan results, automatically generate and execute PoC…SubagentsJun 2026—2.0k
  47. 470xsteph avatarprivesc-advisorDelegates to this agent when the user asks about privilege escalation techniques, local enumeration, Linux or Windows privilege escalation, container escape, or needs help escalating access on a…SubagentsJun 2026—2.0k
  48. 480xsteph avatarrecon-advisorDelegates to this agent when the user pastes scan output (Nmap, Nessus, Nikto, masscan, etc.), asks about reconnaissance techniques, needs help with enumeration, wants to analyze an attack surface,…SubagentsJun 2026—2.0k
  49. 490xsteph avatarreport-generatorDelegates to this agent when the user needs to write a penetration test report, compile findings into a document, create an executive summary, format technical findings, or produce any security…SubagentsJun 2026—2.0k
  50. 500xsteph avatarrisk-scorerDelegates to this agent when the user wants to score and prioritize findings — build CVSS 3.1/4.0 vectors, enrich with EPSS and CISA KEV, adjust for business context and exploitability, and produce a…SubagentsJun 2026—2.0k
  51. 510xsteph avatarscada-attackerDelegates to this agent when the user wants authorized ICS/OT/SCADA security testing — Modbus/DNP3/S7comm/EtherNet-IP/OPC-UA protocol analysis, PLC/HMI/RTU enumeration, and Purdue-model attack-path…SubagentsJun 2026—2.0k
  52. 520xsteph avatarsocial-engineerDelegates to this agent when the user asks about social engineering, phishing campaigns, pretexting, vishing, physical social engineering, security awareness testing, or human-factor security…SubagentsJun 2026—2.0k
  53. 530xsteph avatarstig-analystDelegates to this agent when the user asks about STIG findings, security compliance, system hardening, GPO configurations, security baselines, or needs to document findings in STIG format including…SubagentsJun 2026—2.0k
  54. 540xsteph avatarthreat-modelerDelegates to this agent when the user asks about threat modeling, attack surface analysis, STRIDE, DREAD, attack trees, data flow diagrams, trust boundaries, or security architecture reviewSubagentsJun 2026—2.0k
  55. 550xsteph avatartraffic-analyzerDelegates to this agent when the user wants offline analysis of captured network traffic — dissecting pcaps, extracting credentials and artifacts, reconstructing sessions, identifying protocols and…SubagentsJun 2026—2.0k
  56. 560xsteph avatarvuln-scannerDelegates to this agent when the user wants to run vulnerability scans, identify CVEs in target systems, use tools like nuclei, nikto, or OpenVAS, parse vulnerability scan results, or prioritize…SubagentsJun 2026—2.0k
  57. 570xsteph avatarweb-hunterDelegates to this agent when the user wants to perform web application penetration testing, run directory brute forcing with ffuf or gobuster, test for SQL injection, discover hidden endpoints, fuzz…SubagentsJun 2026—2.0k
  58. 580xsteph avatarwireless-pentesterDelegates to this agent when the user asks about wireless security testing, WiFi pentesting, WPA/WPA2/WPA3 attacks, Bluetooth security, wireless reconnaissance, rogue access points, evil twin…SubagentsJun 2026—2.0k
  59. 59natively-ai-assistant avatarsecurity-reviewerUse for prompt-injection defense, untrusted content boundaries, browser/DOM/screen context, source capability boundaries, secret protection, and least-privilege reviews.SubagentsJul 2026—2.0k
  60. 60stacklok avataroauth-expertSpecialized in OAuth 2.0, OIDC, token exchange, and authentication flows for ToolHiveSubagentsJul 2026—2.0k
  61. 61stacklok avatarsecurity-advisorSecurity guidance for code reviews, architecture decisions, auth implementations, and threat modelingSubagentsJul 2026—2.0k
  62. 62xu-xiang avatarsecurity-reviewer安全漏洞检测与修复专家。在编写处理用户输入、身份认证、API 端点或敏感数据的代码后,应主动(PROACTIVELY)使用此智能体。它可以标记敏感信息(Secrets)、SSRF、注入(Injection)、不安全的加密以及 OWASP Top 10 漏洞。SubagentsMar 2026—1.8k
  63. 63cloudai-x avatarsecurity-auditorSecurity specialist for vulnerability detection, secure coding review, and security hardening. Use PROACTIVELY when handling authentication, authorization, encryption, secrets, credentials, OAuth,…SubagentsJul 2026—1.4k
  64. 64sceneview avatarsv-security-reviewerSecurity + secrets + supply-chain reviewer for a SceneView change. No committed keys, safe deserialization, sane permission scopes, no untrusted-input footguns. Read-only; ERROR = blocks merge.SubagentsJul 2026—1.3k
  65. 65huangjia2019 avatarauth-explorerExplore and analyze authentication-related code. Use when investigating auth flows, session management, or security.SubagentsJul 2026—1.0k
  66. 66go-kratos avatarsecurity-code-reviewerUse this agent when you need to review code for security vulnerabilities, input validation issues, or authentication/authorization flaws.SubagentsJul 2026—804
  67. 67sethgammon avatarpolicy-enforcerBlocking policy judge. Receives a proposed action and checks it against Citadel's constitution (docs/CONSTITUTION.md). Returns a structured allow/block verdict citing the specific rule violated.…SubagentsJul 2026—803
  68. 68sangrokjung avatarsecurity-reviewerOWASP Top 10 분석·시크릿 탐지·의존성 감사. severity × exploitability × blast radius 우선순위. Read-only 검토. Use proactively when 사용자 입력 처리, 인증/인가, API 엔드포인트, 민감 데이터를 다루는 코드 변경 시 — 특히 "보안 검토", "취약점", "auth 코드" 요청. 코드…SubagentsJul 2026—791
  69. 69h-mmer avatarauth-testerAuthentication and session management testing agent. Use for login bypass, session fixation, password reset flow abuse, MFA bypass, OAuth flaws, and privilege escalation testing. Provide the…SubagentsJun 2026—776
  70. 70h-mmer avatarbusiness-logicBusiness Logic vulnerability specialist (H1 #28, CWE-840/841/639/362). Use for testing workflow bypasses, price manipulation, coupon abuse, MFA/2FA bypass, password-reset bypass, free-trial abuse,…SubagentsJun 2026—776
  71. 71h-mmer avatarchain-builderDeep exploit chain builder. Given bug A, recursively walks the chain graph — each confirmed link becomes the new A. No depth limit. Supports 2-link to 10+ link chains. Use when you have any finding…SubagentsJun 2026—776
  72. 72h-mmer avatarconfig-auditorSecurity header and server configuration auditor. Use for HTTP security header analysis, CSP evaluation, CORS policy review, TLS configuration assessment, cookie security, and server hardening…SubagentsJun 2026—776
  73. 73h-mmer avatarcorrelatorFinding correlation engine. Use AFTER multiple agents have reported findings to discover attack chains. Combines individual findings into higher-impact chains (e.g., open redirect + CORS + SSRF =…SubagentsJun 2026—776
  74. 74h-mmer avatarcors-hunterCORS Misconfiguration specialist (H1 #58). Use for testing cross-origin resource sharing policies, origin reflection, null origin bypass, and credential-bearing cross-origin requests.SubagentsJun 2026—776
  75. 75h-mmer avatarcsrf-hunterCSRF specialist (H1 #57). Use for testing state-changing actions without proper token validation, SameSite cookie bypass, and CSRF in JSON/API endpoints.SubagentsJun 2026—776
  76. 76h-mmer avatarfile-uploadFile Upload vulnerability specialist (H1 #39). Use for testing upload restrictions, content-type bypass, extension filtering, path traversal in filenames, and web shell upload scenarios.SubagentsJun 2026—776
  77. 77h-mmer avataridor-hunterIDOR / BOLA specialist (H1 #55, OWASP API1:2023). Use for testing insecure direct object references and broken object level authorization across web apps, APIs, GraphQL endpoints, multi-tenant SaaS,…SubagentsJun 2026—776
  78. 78h-mmer avatarinfo-disclosureInformation Disclosure specialist (H1 #18, CWE-200/209/215/538/668/798). Use for finding exposed sensitive data: stack traces, debug endpoints, config files, environment variables, API keys,…SubagentsJun 2026—776
  79. 79h-mmer avatarnuclei-writerCustom nuclei template builder. Use when you've found a pattern that should be checked across multiple targets or when existing templates miss a specific vulnerability. Provide the vulnerability…SubagentsJun 2026—776
  80. 80h-mmer avataroauth-hunterOAuth 2.0 / 2.1, OpenID Connect (OIDC), SAML SSO, and JWT specialist. Dispatcher passes subtype — 'oauth', 'oidc', 'saml', or 'jwt' — in the task; falls back to inference.SubagentsJun 2026—776
  81. 81h-mmer avataropen-redirectOpen Redirect specialist (H1 #38). Use for testing URL redirect parameters, login/logout flows, OAuth callbacks, and any endpoint that redirects based on user input.SubagentsJun 2026—776
  82. 82h-mmer avatarpoc-builderBug bounty PoC and report builder. Use after confirming a vulnerability to create minimal reproduction steps, self-contained HTML demonstration pages, curl-based reproduction scripts, and…SubagentsJun 2026—776
  83. 83h-mmer avatarprivilege-escalationPrivilege Escalation specialist (H1 #26). Use for testing vertical and horizontal privilege escalation, role manipulation, admin endpoint access, and permission boundary violations.SubagentsJun 2026—776
  84. 84h-mmer avatarquality-checkReport quality scorer. Use BEFORE submitting any report to validate completeness, clarity, title strength, CVSS accuracy, PoC quality, and overall report grade. Provide the draft report path or…SubagentsJun 2026—776
  85. 85h-mmer avatarrace-conditionRace Condition specialist (H1 #29). Use for testing TOCTOU flaws, double-spend, parallel request abuse on balance operations, coupon redemption, and any non-idempotent state changes.SubagentsJun 2026—776
  86. 86h-mmer avatarrce-hunterRemote Code Execution specialist (H1 #70). Use for testing command injection, template injection (SSTI), deserialization, expression language injection, and any vector that achieves server-side code…SubagentsJun 2026—776
  87. 87h-mmer avatarreconReconnaissance agent for target enumeration. Use for subdomain discovery, port scanning, service fingerprinting, tech stack identification, and OSINT gathering.SubagentsJun 2026—776
  88. 88h-mmer avatarrecon-rankerAttack surface ranker. Takes recon output + brain data, produces P1/P2/Kill prioritized attack plan with concrete curl commands for each P1 target. Use after recon to decide what to test first.SubagentsJun 2026—776
  89. 89h-mmer avatarreport-writerSecurity report generation agent. Use for compiling findings into formal penetration test reports, executive summaries, technical write-ups, and bug bounty submissions. Provide the findings directory…SubagentsJun 2026—776
  90. 90h-mmer avatarsast-devils-advocateAdversarial validator for SAST findings. Your ONLY job is to DISPROVE the candidate. Find every reason it's not exploitable. If you can't disprove it, it survives. Use via /sast command.SubagentsJun 2026—776
  91. 91h-mmer avatarsast-exploit-builderBuilds working exploits from confirmed SAST findings. Takes a confirmed crash, develops it into a full exploit. Tier 1 (DoS) → Tier 5 (code execution). Use via /sast command after PoC confirmation.SubagentsJun 2026—776
  92. 92h-mmer avatarsast-file-rankerSource file attack surface ranker. Reads a repository, scores every source file 1-5 by exploitability. Outputs ranked JSON for per-file hunting. Use via /sast command.SubagentsJun 2026—776
  93. 93h-mmer avatarsast-hunterFocused PoC builder for SAST candidates. Receives a SPECIFIC candidate vulnerability that survived adversarial validation. Writes a PoC, compiles, runs with ASan, confirms or rejects. Use via /sast…SubagentsJun 2026—776
  94. 94h-mmer avatarscope-checkTarget scope validation agent. Use BEFORE any active testing to verify targets are in scope. Provide the target and the program name or scope file. Checks against .scope.txt, scope.yaml, and fetches…SubagentsJun 2026—776
  95. 95h-mmer avatarsqli-hunterSQL Injection specialist (H1 #67). Use for error-based, blind boolean, blind time-based, UNION-based, and out-of-band SQLi testing. Provide target endpoints with injectable parameters.SubagentsJun 2026—776
  96. 96h-mmer avatarssrf-hunterSSRF vulnerability hunting specialist. Use for testing URL-accepting parameters, webhook endpoints, file import features, and any server-side request functionality. Provide target endpoints with URL…SubagentsJun 2026—776
  97. 97h-mmer avatarssti-hunterServer-Side Template Injection specialist. Covers Jinja2 (H1 #74), Twig, Velocity, FreeMarker, ERB, Handlebars, Thymeleaf. Use for any rule-engine, comment/message rendering, PR automation, admin…SubagentsJun 2026—776
  98. 98h-mmer avatarsubdomain-takeoverSubdomain Takeover specialist (H1 #145). Use for finding dangling DNS records pointing to unclaimed cloud resources, expired services, or deprovisioned infrastructure.SubagentsJun 2026—776
  99. 99h-mmer avatarvalidatorFinding validator. Runs 7-Question Gate + 4-gate checklist. Kills weak/theoretical findings FAST before any report writing. Output: PASS, KILL, DOWNGRADE, or CHAIN REQUIRED.SubagentsJun 2026—776
  100. 100h-mmer avatarvuln-scannerAutomated vulnerability scanning agent. Use for running nuclei templates, nikto scans, SSL/TLS analysis, header checks, and known CVE detection against targets.SubagentsJun 2026—776

More subagents categories

Code Review & Refactor809Backend & APIs542Testing & QA507Product & Project Management497Agent Meta & Communication463Documentation & Knowledge418DevOps & CI/CD386AI Agents & MCP320Debugging290Research281All Subagents →