Search

Threat modeling

224 skills found, page 2.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

awarexone/Agentic-Bug-Hunter5.3k2 repos~6.4kAutomated safety check: WarnMITyesterday
50

Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark…

trailofbits/skills7.5k—~1.5kAutomated safety check: NotesCC-BY-SA-4.0yesterday
51

Attack-surface crawling with the crawl tool — BFS link/form/hidden-field collection, JS-bundle API route extraction, and auth boundary mapping through the scoped browser.

Ch1nfo/RiftX114—~718Automated safety check: PassMIT19 days ago
52

安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

ReJeCtAll/ExpertTeam-Codex113—~780Automated safety check: PassMIT3 mo ago
53

Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

sangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT1 mo ago
54

Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.

fabricioctelles/skills106—~2.8kAutomated safety check: PassApache-2.0today
55

A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.

ccashwell/evm-cortex131—~1.4kAutomated safety check: PassMIT11 days ago
56

Classify project-used dependency members and record taint sources as rule-authoring units.

seqra/opentaint163—~1.7kAutomated safety check: PassApache-2.0yesterday
57

Usar para sincronizar la documentación viva del proyecto después de una fase.

686f6c61/alfred-dev117—~382Automated safety check: PassMIT1 mo ago
58

安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust…

telagod/code-abyss244—~712Automated safety check: PassMIT2 mo ago
59

Conduct threat modeling using STRIDE methodology. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~4.3kAutomated safety check: PassMITyesterday
60

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

github/awesome-copilot40k1 repo~2.4kAutomated safety check: PassMIT2 days ago
61

Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.

trailofbits/skills7.5k—~996Automated safety check: PassCC-BY-SA-4.0yesterday
62

[omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds.

rlaope/oh-my-hermes3.2k—~2.6kAutomated safety check: PassMITyesterday
63

Analyze a codebase and produce a structured threat model at .turbo/threat-model.md covering assets, trust boundaries, attack surfaces with existing mitigations, attacker stories, and calibrated…

tobihagemann/turbo408—~2.5kAutomated safety check: PassMIT2 days ago
64
64.Pytm

Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification.

AgentSecOps/SecOpsAgentKit2202 repos~4.4kAutomated safety check: NotesUnknown5 mo ago
65
65.007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

sickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMIT2 days ago
66

Full STRIDE-A threat model analysis and incremental update skill for repositories and systems.

github/awesome-copilot40k1 repo~1.5kAutomated safety check: PassMIT2 days ago
67

Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

unxed/f42432 repos~3.6kAutomated safety check: PassMITyesterday
68

Generate or refresh a STRIDE-based threat model for the current repository using Bug Hunter-native artifacts.

codexstar69/bug-hunter520—~408Automated safety check: PassMIT1 mo ago
69

Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
70

Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: NotesApache-2.01 mo ago
71

Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
72

Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.01 mo ago
73

Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.01 mo ago
74

Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

trilwu/secskills157—~3.1kAutomated safety check: NotesMIT1 mo ago
75

A skill your agent uses when a B200/Blackwell kernel shows wrong results, uncoalesced global memory access, SMEM bank conflicts, a TMA swizzle that mismatches the Tensor Core read, or confused…

mirage-project/mirage2.5k—~1.8kAutomated safety check: PassApache-2.03 days ago
76

Threat-model and find vulnerabilities, with practical remediation.

antonbabenko/deliberation170—~1.1kAutomated safety check: PassMIT2 days ago
77

A skill your agent uses for security reviews of VoxBento code.

fossasia/eventyay-interpretation1.6k—~1.3kAutomated safety check: PassApache-2.05 days ago
78

Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

dzhalaevd/Donatello135—~5.1kAutomated safety check: NotesApache-2.07 days ago
79

Discover and inventory shadow API endpoints that operate outside documented OpenAPI/Swagger specs, using traffic analysis against API gateways (Kong, AWS API Gateway, Envoy), cloud configuration…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.01 mo ago
80

Configures Windows Group Policy Objects to block ransomware execution and lateral spread, covering AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
81

Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
82

Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.01 mo ago
83

Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
84

A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

hypnguyen1209/offensive-claude388—~2.2kAutomated safety check: PassMIT13 days ago
85

A skill your agent uses when an application or system — including one built quickly with AI coding agents — needs a security review with regulatory grounding: a STRIDE threat model, a LINDDUN…

davila7/claude-code-templates33k1 repo~6.4kAutomated safety check: NotesCC-BY-4.0yesterday
86

A skill your agent uses when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the…

alirezarezvani/claude-skills28k—~1.3kAutomated safety check: PassMIT1 mo ago
87

Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles.

ancoleman/ai-design-components525—~3.5kAutomated safety check: PassMIT10 mo ago
88

A skill your agent uses when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis.

sangrokjung/claude-forge852—~1kAutomated safety check: NotesMIT1 mo ago
89

Review Maple security across authentication, account isolation, local persistence, Tauri IPC and capabilities, OAuth and deep links, the Local OpenAI Proxy, Agent Mode tools and permissions, MCP…

MaplePrivacyLabs/Maple102—~7.1kAutomated safety check: PassMITyesterday
90

STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit.

withkynam/vibecode-pro-max-kit1.1k—~1.2kAutomated safety check: PassMIT3 mo ago
91

Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

trilwu/secskills157—~2.9kAutomated safety check: PassMIT1 mo ago
92

Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

forefy/.context152—~3.1kAutomated safety check: PassMIT6 days ago
93

NCAA cross country and track & field athlete data via TFRRS (tfrrs.org) and news via The Stride Report.

machina-sports/sports-skills243—~2kAutomated safety check: PassMIT5 days ago
94

Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
95

A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…

hypnguyen1209/offensive-claude388—~660Automated safety check: PassMIT13 days ago
96

Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface.

transilienceai/communitytools563—~1.4kAutomated safety check: PassMIT2 mo ago