Topic · Security
Best network security skills for Claude Code, Codex and other agents.
- skills
- 66
- official
- 4
Network security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK. | kubeshark/ | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 2 | 2.Ohdear Manage Oh Dear website monitoring using the ohdear CLI. An agent skill from ohdearapp/ohdear-cli. | ohdearapp/ | 141 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 3 | Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs… | cyfung1031/ | 121 | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 4 | This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network… | zebbern/ | 4.7k | 8 repos | ~3k | Automated safety check: Pass | MIT | today |
| 5 | Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic. | AgentSecOps/ | 220 | 1 repo | ~4.8k | Automated safety check: Notes | Unknown | 5 mo ago |
| 6 | Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging. | wshobson/ | 40k | 9 repos | ~588 | Automated safety check: Pass | MIT | 3 days ago |
| 7 | 7.Iotnet IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications. | BrownFineSecurity/ | 858 | 1 repo | ~1k | Automated safety check: Notes | MIT | 4 mo ago |
| 8 | Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 9 | Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. | wshobson/ | 40k | 8 repos | ~3.2k | Automated safety check: Pass | MIT | 3 days ago |
| 10 | Configure iptables, nftables, and cloud firewalls. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.2k | Automated safety check: Notes | MIT | today |
| 11 | Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection. | arpitg1304/ | 368 | — | ~7.8k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 12 | Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations. | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Installs, configures, and tunes Snort 3 to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins. | mukul975/ | 34k | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 16 | Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC… | mukul975/ | 34k | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 17 | Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control… | mukul975/ | 34k | — | ~3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 18 | Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 19 | Conduct cybersecurity assessments of power grid infrastructure spanning generation, transmission substations, distribution, and EMS control centers, covering NERC CIP compliance verification, IEC… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 20 | Configure SSL/TLS break-and-inspect on next-generation firewalls and forward proxies to decrypt, inspect, and re-encrypt HTTPS traffic for malware and exfiltration detection, including deploying… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 21 | Guidance for Azure Firewall — managed cloud-native L3-L7 stateful network firewall for centralised egress, east-west, and ingress control. | vinayaklatthe/ | 175 | — | ~1.7k | Automated safety check: Pass | MIT | 3 mo ago |
| 22 | Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). | google/ | 21k | 1 repo | ~4.2k | Automated safety check: Pass | Apache-2.0 | today |
| 23 | Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 24 | Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS… | elastic/ | 592 | — | ~5.4k | Automated safety check: Pass | Apache-2.0 | today |
| 25 | Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. | mukul975/ | 34k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 26 | Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 27 | Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning… | mukul975/ | 34k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Configures AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring on Linux, covering baseline database creation, scheduled integrity checks via cron, change detection, and… | mukul975/ | 34k | — | ~642 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 31 | Automate network traffic analysis using tshark (Wireshark CLI) and pyshark to compute protocol distribution statistics, detect suspicious flows such as port scans and beaconing, extract IOCs (IPs… | mukul975/ | 34k | — | ~610 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 33 | Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall… | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 34 | This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. | mukul975/ | 34k | — | ~6.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | 35.Recon Perform structured reconnaissance and attack surface enumeration for authorized penetration tests, CTF challenges, and bug bounty programs. | briiirussell/ | 413 | — | ~1.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 36 | This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems including man-in-the-middle attacks on industrial protocols, unauthorized command… | mukul975/ | 34k | — | ~6.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Windows net diag: ping, traceroute, DNS, port scan (PowerShell) | taracodlabs/ | 851 | — | ~878 | Automated safety check: Pass | Apache-2.0 | 24 days ago |
| 38 | Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. | mukul975/ | 34k | — | ~593 | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 39 | A skill your agent uses whenever the user is learning computer networking, computer networks, TCP/IP, OSI, subnetting, routing, switching, DNS, HTTP, TCP, UDP, DHCP, TLS, NAT, congestion control… | mingchen666/ | 237 | — | ~1.1k | Automated safety check: Pass | No licence | 17 days ago |
| 40 | A skill your agent uses whenever the user asks about Wireshark, tcpdump, packet capture, pcap analysis, HTTP/DNS/TCP/DHCP/TLS capture interpretation, network lab reports, protocol fields observed in… | mingchen666/ | 237 | — | ~657 | Automated safety check: Pass | No licence | 17 days ago |
| 41 | Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.8k | Automated safety check: Notes | MIT | 25 days ago |
| 42 | Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. | Kilo-Org/ | 190 | 1 repo | ~1.9k | Automated safety check: Pass | MIT | 9 days ago |
| 43 | Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection… | trilwu/ | 156 | — | ~2.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 44 | Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables | Microck/ | 403 | 1 repo | ~2.7k | Automated safety check: Notes | Unknown | 1 mo ago |
| 45 | Network architecture, troubleshooting, and infrastructure patterns. | aiskillstore/ | 430 | 1 repo | ~1.4k | Automated safety check: Pass | No licence | today |
| 46 | Plan, deploy, operate, and troubleshoot Azure Local (formerly Azure Stack HCI): sizing and prerequisites, Arc registration, lifecycle updates, workloads (Azure Local VMs, AKS on Azure Local, images… | microsoft/ | 255 | — | ~854 | Automated safety check: Pass | MIT | today |
| 47 | Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection… | trilwu/ | 156 | — | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 48 | RBAC configuration, row policies, quotas, network security, audit logging, and access control best practices. | chmonitor/ | 299 | — | ~440 | Automated safety check: Pass | GPL-3.0 | 2 days ago |
Questions, answered from the data.
What is the best network security skill?
Kubernetes Network Security Audit from kubeshark/kubeshark ranks first of the 66 network security skills listed here, with the highest score: its repository has 12k GitHub stars, its SKILL.md loads about 7.3k tokens and it has informational notes only in the automated safety check. Next come Ohdear and Review Userscript Change.
Which network security skills are official?
4 of the 66 network security skills are official, published by the vendor's own GitHub organization: Google Cloud Waf Security, Cloud Provisioning, Azure Local and Azure Private Link.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38