Skill collection
hardw00t/ai-security-arsenal agent skills
- skills
- 7
- GitHub stars
- 105
GitHub description: “A collection of skills, agents, commands, and workflows for security researchers. Compatible with Claude Code, Claude Desktop, OpenCode, and other AI coding tools.”
- Stars
- 105 (15 forks)
- Licence
- No licence
- Last push
- Apr 2026
- Created
- Jan 2026
Install all skills
npx skills add hardw00t/ai-security-arsenalAdd --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).
Skills in hardw00t/ai-security-arsenal, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. | hardw00t/ | 105 | — | ~2.2k | Automated safety check: Pass | No licence | 5 mo ago |
| 2 | Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by… | hardw00t/ | 105 | — | ~2.7k | Automated safety check: Pass | No licence | 5 mo ago |
| 3 | Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and… | hardw00t/ | 105 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 4 | Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. | hardw00t/ | 105 | — | ~2.4k | Automated safety check: Pass | No licence | 5 mo ago |
| 5 | LLM and AI application security testing skill for prompt injection (direct, indirect, multimodal), system-prompt extraction, RAG poisoning, memory poisoning, MCP server injection, skill-file… | hardw00t/ | 105 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 6 | Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to… | hardw00t/ | 105 | — | ~3k | Automated safety check: Pass | No licence | 5 mo ago |
| 7 | Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. | hardw00t/ | 105 | — | ~2.6k | Automated safety check: Pass | No licence | 5 mo ago |
Questions, answered from the data.
What is the best skill in hardw00t/ai-security-arsenal?
Dast Automation from hardw00t/ai-security-arsenal ranks first of the 7 skills in hardw00t/ai-security-arsenal listed here, with the highest score: its repository has 105 GitHub stars, its SKILL.md loads about 2.2k tokens and it passes the automated safety check with no findings. Next come Sast Orchestration and Container Security.
Are the skills in hardw00t/ai-security-arsenal official?
None yet. All 7 skills in hardw00t/ai-security-arsenal listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How do I install all skills from hardw00t/ai-security-arsenal?
Run npx skills add hardw00t/ai-security-arsenal in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.