Security Skills
Best Security skills, ranked by Evoa Score · 60 shown
Humane-Proxy
MCPApache-2.0Vishisht16/Humane-Proxy
Humane-Proxy is a lightweight AI safety middleware designed to intercept and filter user messages for self-harm ideation or criminal intent before they reach an upstream LLM. It combines heuristic keyword matching, semantic embeddings, and reasoning models to provide real-time risk evaluation, empathetic user care, and operator alerts.
autumn
Apache-2.0henryxm/autumn
This skill provides specialized development guidelines and conventions for the Autumn 2.x framework, focusing on JDK 8, Spring Boot 2.7, and MyBatis-Plus 2.x. It enforces strict architectural rules covering database design, authentication modes, field encryption, and code formatting.
agent-sandbox
MITmattolson/agent-sandbox
Agent Sandbox provides a secure local environment utilizing Docker containers and a sidecar proxy to safely run AI coding agents with restricted network and filesystem access.
agents-shipgate
MCPApache-2.0ThreeMoonsLab/agents-shipgate
Agents Shipgate is a deterministic merge gate for AI-generated agent capability changes, analyzing tool sources and configurations locally without agent execution or network calls.
ubon
MITluisfer/ubon
Ubon is a specialized security scanner designed to catch vulnerabilities commonly introduced by AI-generated applications, such as hardcoded API keys, unauthenticated server actions, and prompt-injection sinks.
skills-collection-1
Apache-2.0pinkpixel-dev/skills-collection-1
An expert security architecture skill that conducts comprehensive audits, threat modeling, and hardening for code, infrastructure, APIs, and AI agents.
AIHelms
MCPGPL-3.0beizhu-1209/AIHelms
AIHelms is an enterprise-grade AI resource management platform designed to help organizations control costs, track usage metrics, and securely manage AI assets and API access.
Awesome-Agentic-AI-Security
MITnatnew/Awesome-Agentic-AI-Security
This repository provides operating protocols, standards, and curated resources for securing agentic, multi-agent, and tool-using AI systems. It guides AI coding agents on how to maintain a comprehensive security field guide built around discovery, protection, and governance.
opensquat
GPL-3.0atenreiro/opensquat
openSquat is an OSINT security tool designed to detect brand protection threats such as typosquatting, phishing, and IDN homograph attacks through newly registered domain feeds and similarity detection.
dependency-risk-brief
MITpixelfox2033-vwict/dependency-risk-brief
Transforms raw dependency vulnerability alerts into structured, contextualized one-page risk cards with clear upgrade-versus-defer recommendations.
iac-security-scan-skills
MITsenaykt/iac-security-scan-skills
An AI-powered infrastructure-as-code security scanner that performs multi-pass assessments on Terraform and CloudFormation codebases. It detects privilege escalation, internet exposure, secret leaks, and multi-domain attack paths.
ar-go-tools
Apache-2.0awslabs/ar-go-tools
Argot is a suite of static analysis tools for Go that includes taint analysis, backtrace tracking, and reachability checks, exposed via an MCP server for AI assistants.
agent-bom
MCPApache-2.0msaad00/agent-bom
This repository provides engineering and operating guidelines for developing agent-bom, an open security scanner and self-hosted control plane for AI-era infrastructure.
arifOS
MCPAGPL-3.0ariffazil/arifOS
arifOS is a constitutional governance kernel and operating system substrate for autonomous intelligence that evaluates actions against 13 physical and epistemic floors.
obot
MCPMITobot-platform/obot
Obot is an open-source AI governance platform that provides centralized control, security, and distribution for Model Context Protocol (MCP) servers, agent skills, and LLM gateways.
gsd-browser
Apache-2.0gsd-build/gsd-browser
A native Rust browser automation CLI designed for AI agents and developers, providing deterministic control over Chrome/Chromium via Chrome DevTools Protocol (CDP).
prodsec-skills
Apache-2.0RedHatProductSecurity/prodsec-skills
A comprehensive library of tool-agnostic security skills designed to help AI coding assistants shift security left during development.
wassette
MCPMITmicrosoft/wassette
Wassette is an MCP server that executes tools as WebAssembly components within a secure Wasmtime sandbox.
cursor-handbook
MITgirijashankarj/cursor-handbook
An open-source configuration boilerplate and rules engine for Cursor IDE providing over 200 components to standardize AI behavior, enforce security policies, and optimize token usage.
skillpacks
CC-BY-SA-4.0tachyon-beep/skillpacks
An extensive marketplace and collection of over 50 professional skill packs and 200+ individual skills designed for Claude Code and compatible agents, covering AI/ML, engineering, security, and project management.
claude-skills
MITjezweb/claude-skills
This skill enables direct interaction with the Cloudflare REST API for bulk, automated, and fleet-wide operations that standard CLI tools and MCP servers cannot easily handle.
claude-plugins
MCPApache-2.0chainguard-demo/claude-plugins
Official Chainguard plugins for Claude Code that bring supply chain security, secure container generation, and documentation search into the development workflow.
claude-code-template
MITscotthavird/claude-code-template
An opinionated, comprehensive starter template and plugin for Claude Code featuring custom commands, subagents, auto-triggered skills, and security hooks.
claude-code-mastery
MITalissonlinneker/claude-code-mastery
A comprehensive configuration and memory system for Claude Code CLI that introduces perpetual memory banks, smart lifecycle hooks, and over 26 curated development skills.
unicorn-team
MITaj-geddes/unicorn-team
A comprehensive Claude Code plugin that encodes advanced software engineering expertise into a coordinated team of 6 specialized agents and 15 composable skills.
lc-ai
Apache-2.0refractionPOINT/lc-ai
An intelligent lifecycle assistant for managing, researching, validating, and deploying LimaCharlie adapters and cloud sensors.
ai-helpers
MITquay/ai-helpers
Automates CVE triage by gathering advisories from NVD, GHSA, and Go vuln DB, checking package manifests, classifying verdicts, and posting Jira updates.
adverse
MITaddyosmani/adverse
Multi-agent adversarial code review skill that spawns three distinct reviewer subagents (Auditor, Adversary, Pragmatist) in parallel, conducts a cross-examination phase, and deterministically synthesizes the results.
Pulse
No licenseRegncreative/Pulse
Pulse is a professional, read-only Windows diagnostics and observability platform that translates complex event logs into plain, human-readable language.
cursor-kit-for-ai
MCPMITkiurakku/cursor-kit-for-ai
Cursor Kit for AI provides a curated collection of plugins and production-grade agent skills designed to turn the Cursor AI editor into a role-specific specialist.
agent-skills
MITandreasasprou/agent-skills
A curated collection of plugins for Claude Code that provides advanced AI consultation, destructive command blocking, and dependency source code exploration.
downy
MITbensenescu/downy
Downy is a self-hosted multi-agent orchestration framework built on Cloudflare Durable Objects, allowing users to coordinate teams of specialized AI agents from any device. It supports flexible model backends including Workers AI, OpenRouter, and ChatGPT Plus/Pro subscriptions.
Proteus
GPL-3.0Vyntra-Research/Proteus
Proteus is an assistant-oriented runtime and multi-agent skill suite designed for continuous vulnerability research and offensive codebase exploration. It provides structured local SQLite memory, validation gates, and specialist coordination to map codebases and construct non-obvious exploit chains.
Awesome-Hacking
CC0-1.0Hack-with-Github/Awesome-Hacking
Awesome-Hacking is a curated directory of security, penetration testing, and hacking resources linking to specialized GitHub repositories.
megacode
MITmitkox/megacode
Execute privacy-preserving, tool-driven security audits on large .NET codebases using a local DSPy RLM workflow. It prevents context overflow by utilizing bounded file access and indexed manifests.
mcp-ip2location-io
MCPMITip2location/mcp-ip2location-io
This Model Context Protocol server connects AI assistants to the IP2Location.io API for detailed IP geolocation, network, and security analysis. It supports both single and bulk queries for IPv4 and IPv6 addresses.
oh-my-destructor
MITvyvhouse/oh-my-destructor
Agent-native uninstallers and cleanup scripts for removing 'oh-my' toolchains and side effects from local or remote environments.
identity
Apache-2.0agntcy/identity
AGNTCY Identity provides a secure and verifiable framework for assigning unique decentralized identities and verifiable credentials to software agents and MCP servers. It ensures trusted communication and interoperability across multi-agent systems using open standards like W3C DIDs and existing Identity Providers.
skills
MITseangeng/skills
This skill provides a server-side validation pattern to block disposable and throwaway email addresses during user registration.
aws-security-specialty-study-guide
MITRaduLupan/aws-security-specialty-study-guide
A comprehensive study guide and interactive quiz repository tailored for the AWS Certified Security - Specialty (SCS-C03) exam.
ultrasonic
MITruvnet/ultrasonic
Ultrasonic Agentics is a steganographic framework that embeds encrypted AI instructions into inaudible high-frequency audio bands (18-20 kHz). It provides command-and-control communication channels embedded inside ordinary media files.
awesome-ory
Apache-2.0ory/awesome-ory
A curated collection of resources, developer tools, blog posts, and code examples for the Ory identity and access management ecosystem.
claudecode-architecture-guide-skill
No licensechenluda/claudecode-architecture-guide-skill
Extracts and applies engineering and architectural patterns from Claude Code to new or existing systems.
ai-workspace-archive
MCPNo licenseHIDORAKAI002/ai-workspace-archive
A comprehensive self-hosted offline repository providing nearly 30,000 AI developer skills, prompts, IDE context rules, and MCP servers.
aster-mcp
No licensesatyajiit/aster-mcp
Aster provides an MCP server and Android application that allows AI assistants to interact with, control, and receive events from Android devices.
frona
No licensefronalabs/frona
Frona is a self-hosted personal AI assistant platform built in Rust that lets you create autonomous agents with sandboxed code execution, web browsing, and credential management.
CS292C
No licensefredfeng/CS292C
This repository contains course materials for a graduate seminar at UC Santa Barbara on formal methods for agentic programming and AI agent security.
brokencrystals
MITNeuraLegion/brokencrystals
Broken Crystals is a benchmark web application designed to evaluate security scanners and penetration testing tools against a wide range of common vulnerabilities.
rubric-evaluator
No licensehalfmoon-mind/rubric-evaluator
Assess and audit AI skill directories using a comprehensive 31-item, 6-section rubric that combines deterministic structural checks and semantic model analysis to assign a definitive S/A/B/C/F grade.
awesome-skill-md
CC0-1.0BadMenFinance/awesome-skill-md
A curated collection of SKILL.md resources, tools, and files designed to enhance AI coding agents with new capabilities.
aibeat
No licensetophant-ai/aibeat
Connects and configures AI coding agents like Codex, Claude Code, OpenCode, and OpenClaw as evaluation targets for Promptbeat security testing.
mitan
No licensekkbo8005/mitan
Mitan v2.0 is a comprehensive, project-based cybersecurity reconnaissance and penetration testing platform built with Rust and Tauri. It integrates over 50 capabilities including asset mapping, threat intelligence, vulnerability scanning, cloud security, and MCP server support for AI agents.
CyberSecurityRSS
No licensezer0yu/CyberSecurityRSS
A curated collection of cybersecurity and AI RSS feeds in OPML format designed to power automated threat intelligence and daily digest workflows.
mcp-nvd
MITmarcoeg/mcp-nvd
An MCP server that interfaces with the NIST National Vulnerability Database (NVD) API to retrieve CVE details and execute keyword searches for vulnerabilities.
guardian-cli
No licensezakirkun/guardian-cli
Guardian is an enterprise-grade, AI-powered penetration testing automation framework that orchestrates specialized AI agents and security tools through customizable YAML workflows.
java-bootcamp
No licenseWomen-Coding-Community/java-bootcamp
An automated git commit workflow helper that scans for sensitive data before generating detailed commit messages without co-author tags.
awesome-ai-agents-2026
No licenseSupersynergy/awesome-ai-agents-2026
A curated frontier index of AI agent frameworks, runtimes, protocols, memory systems, and security standards.
awesome-threat-modelling
CC0-1.0hysnsec/awesome-threat-modelling
A curated collection of learning materials, tools, and examples focused on cybersecurity threat modeling and risk analysis.
agent-shopping-safe-checkout
No licensepawel-cell/agent-shopping-safe-checkout
Drop-in safety instructions for AI agents that handle real-world web purchases and e-commerce checkouts.
cyberagents-exchange
MCPNo licensetenable/cyberagents-exchange
The content repository for the CyberAgents Exchange, a community-driven directory indexing open-source cybersecurity AI agents, skills, MCP servers, and playbooks.