Search

Security · Threat modeling

208 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Hardens code against vulnerabilities. An agent skill from penpot/penpot.

penpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0yesterday
2

Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…

pashov/skills1.2k1 repo~10kAutomated safety check: PassMIT6 days ago
3

Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection.

open-edge-platform/anomalib6.2k—~1.4kAutomated safety check: PassApache-2.0yesterday
4

Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

alexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesUnknown14 days ago
5

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

ruvnet/ruflo74k1 repo~823Automated safety check: PassMITtoday
6

Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written.

OTRF/ThreatHunter-Playbook4.7k—~1.3kAutomated safety check: PassMIT9 mo ago
7

Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.

responsibleai/ASSERT330—~11kAutomated safety check: NotesMIT2 days ago
8

Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

cartography-cncf/cartography4.1k—~3kAutomated safety check: PassApache-2.0today
9
9.ReviewOfficial

Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the…

getsentry/sentry-react-native1.8k—~1.9kAutomated safety check: PassMIT2 days ago
10

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

elementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMITyesterday
11

Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

garrytan/gstack136k—~4.5kAutomated safety check: PassMITtoday
12

Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

addyosmani/agent-skills105k1 repo~4.4kAutomated safety check: NotesMITyesterday
13

Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

OTRF/ThreatHunter-Playbook4.7k—~819Automated safety check: PassMIT9 mo ago
14

Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…

samugit83/redamon3k—~2.2kAutomated safety check: PassMIT2 days ago
15

Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).

quillai-network/quillshield_skills130—~1.4kAutomated safety check: PassMIT6 mo ago
16
16.ReviewOfficial

Three-axis review of the branch diff — Standards (this repo's documented standards + public API surface), Spec (the originating Linear issue / PR), and Correctness (runtime bugs + the SDK threat…

getsentry/sentry-dart873—~1.3kAutomated safety check: PassMIT2 days ago
17

Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

codexstar69/bug-hunter520—~629Automated safety check: PassMIT1 mo ago
18

Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

AgriciDaniel/claude-cybersecurity228—~11kAutomated safety check: WarnMIT5 mo ago
19

Use before shipping to production. An agent skill from garagon/nanostack.

garagon/nanostack207—~3.7kAutomated safety check: NotesApache-2.01 mo ago
20

Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

trilwu/secskills157—~3.2kAutomated safety check: PassMIT1 mo ago
21

A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

ccashwell/evm-cortex131—~25kAutomated safety check: PassMIT11 days ago
22

Builds attack trees that map how an attacker could reach a goal, with AND and OR nodes and cost, time, skill and detection ratings, to find defense gaps.

wshobson/agents40k8 repos~623Automated safety check: PassMIT6 days ago
23

Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

wshobson/agents40k8 repos~742Automated safety check: PassMIT6 days ago
24

Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.

nordstjernen-web/northstar-browser128—~920Automated safety check: PassGPL-3.0today
25

Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks.

dralgorhythm/claude-agentic-framework125—~581Automated safety check: PassNo licence2 mo ago
26

Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.

xenitV1/Antigravity-Workflows1307 repos~1.8kAutomated safety check: NotesMIT8 mo ago
27

A skill your agent uses when stitching kernels into a multi-launch ELF and the AIE compiler rejects the merged module (BD exhaustion, channel routing, herd shape conflict, IR validation error, DMA…

Xilinx/mlir-air150—~1.8kAutomated safety check: PassMITyesterday
28

Apply STRIDE methodology to systematically identify threats.

sangrokjung/claude-forge8529 repos~5.3kAutomated safety check: PassMIT1 mo ago
29

Runs a parallel security audit with three vulnerability hunters and two proof-of-concept engineers, rating each finding by whether it is actually exploitable.

code-yeongyu/oh-my-openagent70k—~1.9kAutomated safety check: PassUnknowntoday
30

Deep behavioral code analysis agent for Bug Hunter. An agent skill from codexstar69/bug-hunter.

codexstar69/bug-hunter520—~2.6kAutomated safety check: PassMIT1 mo ago
31

Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

tsale/awesome-dfir-skills323—~1.4kAutomated safety check: PassApache-2.05 mo ago
32

Security audit skill. An agent skill from blueberrycongee/termcanvas.

blueberrycongee/termcanvas405—~966Automated safety check: NotesMIT4 mo ago
33
33.Cso

Chief Security Officer mode. An agent skill from no-session/pstack.

no-session/pstack136—~12kAutomated safety check: NotesMIT6 mo ago
34

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.

davila7/claude-code-templates33k2 repos~1.1kAutomated safety check: NotesMITtoday
35

Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation.

dariushoule/x64dbg-skills209—~3.9kAutomated safety check: NotesMIT7 mo ago
36

Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel…

utkusen/sast-skills1.3k—~5.3kAutomated safety check: PassMIT6 mo ago
37

Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive.

alpha-omega-security/scrutineer245—~2.9kAutomated safety check: NotesMITtoday
38

Analyzes Solidity contract entry points to map attack surface.

alt-research2/SolidityGuard104—~959Automated safety check: PassUnknown4 mo ago
39

MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness.

ruvnet/metaharness696—~637Automated safety check: NotesMITyesterday
40

Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots.

trailofbits/skills7.5k—~4.3kAutomated safety check: PassCC-BY-SA-4.0yesterday
41

Expert in threat modeling methodologies, security architecture review, and risk assessment.

davila7/claude-code-templates33k8 repos~529Automated safety check: PassMITtoday
42

Intelligent pattern selection for Fabric CLI. An agent skill from ynulihao/AgentSkillOS.

ynulihao/AgentSkillOS6181 repo~3.4kAutomated safety check: PassNo licence7 mo ago
43

Run a focused STRIDE-based security review using Bug Hunter-native artifacts.

codexstar69/bug-hunter520—~567Automated safety check: PassMIT1 mo ago
44

Analyze code changes for security vulnerabilities using LLM reasoning and threat model patterns.

Factory-AI/factory-plugins111—~2.3kAutomated safety check: PassNo licencetoday
45

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model.

trailofbits/skills-curated5139 repos~1.4kAutomated safety check: PassCC-BY-SA-4.02 mo ago
46

Classify game-cheat capabilities and their defensive implications across memory, injection, rendering, input, engines, kernels, DMA, and remote transports.

gmh5225/awesome-game-security3.6k—~356Automated safety check: PassMITtoday
47

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

awarexone/Agentic-Bug-Hunter5.3k2 repos~6.4kAutomated safety check: WarnMITyesterday
48

Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark…

trailofbits/skills7.5k—~1.5kAutomated safety check: NotesCC-BY-SA-4.0yesterday