Topic · Security
Best prompt injection and agent security skills, page 3
Prompt injection and agent security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects. | romarayt/ | 149 | — | ~572 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 98 | Extract structured data via stored browser-templates or one-shot DOM queries, with mandatory AIDefence PII + prompt-injection gates before content reaches the model | ruvnet/ | 74k | — | ~888 | Automated safety check: Notes | MIT | today |
| 99 | Threat-model and harden AI agents, RAG systems, assistants, and tool-using workflows against direct, indirect, stored, cross-agent, and multimodal prompt injection. | seb1n/ | 206 | — | ~2.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 100 | Verify exact SillyTavern, Tavern Helper / JS-Slash-Runner, STScript, macro, prompt-injection, worldbook, EJS, MVU, and runtime-library capabilities before implementing or reviewing rolecard… | LiarMTTT/ | 154 | — | ~2.4k | Automated safety check: Pass | Unknown | 6 days ago |
| 101 | 101.Security Review Use before committing changes to auth, workspace scoping, channel webhooks, AI tools/MCP, permission settings, or anything handling untrusted channel content in ChatbotX. | ChatbotXIO/ | 885 | — | ~1.8k | Automated safety check: Notes | Unknown | yesterday |
| 102 | Defend AI systems against prompt injection and indirect prompt attacks using input controls, tool permissions, output validation, and isolation boundaries. | sickn33/ | 47k | 2 repos | ~4.2k | Automated safety check: Warn | MIT | yesterday |
| 103 | 103.Safety Scan Scan inputs for prompt injection, unsafe content, and adversarial attacks using AIDefence. | ruvnet/ | 74k | — | ~409 | Automated safety check: Notes | MIT | today |
| 104 | Screen fetched web pages, tool results, emails and file contents for instructions aimed at the agent before they enter context, using a keyless multi-label classifier over chunks. | mrmps/ | 424 | — | ~1.5k | Automated safety check: Pass | MIT | 3 days ago |
| 105 | [omh] Agent or automation safety risks: review prompt, tool, secret, dependency, destructive-action, and explicit local plugin risks before agent or code execution. | rlaope/ | 3.2k | — | ~2.3k | Automated safety check: Pass | MIT | today |
| 106 | AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and… | modu-ai/ | 1.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | today |
| 107 | 107.Moai Ref Secops DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning… | modu-ai/ | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | today |
| 108 | 108.Stack Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally… | guardana/ | 131 | — | ~568 | Automated safety check: Pass | Apache-2.0 | today |
| 109 | 109.LLM Security Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP… | sickn33/ | 47k | 1 repo | ~1.2k | Automated safety check: Warn | MIT | yesterday |
| 110 | Detects prompt injection using regex signature matching, heuristic scoring for structural anomalies, and DeBERTa-based transformer classification, flagging direct injections (system-prompt… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 111 | Detect and defend against indirect prompt injection hidden in web pages, documents, and images consumed by an agent, via content extraction (HTML/PDF/OCR), normalization, and scanning with LLM… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 112 | Runs NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 113 | Deploys Llama Guard 3 safety classification, NeMo Guardrails programmable dialogue rails, and LLM Guard input/output scanner pipelines as complementary runtime defenses that inspect and constrain… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 114 | 114.Runtime Sentinel Runtime security guardian for OpenClaw agents. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~1.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 115 | 115.AI Security This skill should be used when the user asks to "scan AI systems for security threats", "check for prompt injection vulnerabilities", "assess model security posture", "detect data poisoning risks"… | borghei/ | 891 | — | ~1.1k | Automated safety check: Pass | MIT | 3 days ago |
| 116 | 116.AI Security A skill your agent uses when assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, or agent tool abuse. | alirezarezvani/ | 28k | — | ~4.5k | Automated safety check: Warn | MIT | 1 mo ago |
| 117 | Consolidate brain memory and mine user sessions since the last consolidation checkpoint (sleep-cycle style). | mikeyobrien/ | 373 | — | ~1.3k | Automated safety check: Pass | MIT | 9 days ago |
| 118 | Binance Web3 official skill — security audit for token contracts, detecting honeypots, rug pulls, and malicious functions across BSC, Base, Solana, and Ethereum. | TermiX-official/ | 100 | — | ~695 | Automated safety check: Pass | MIT | 4 mo ago |
| 119 | Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. | aws/ | 2.8k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | today |
| 120 | 120.Polygraph Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills. | BankrBot/ | 1.2k | — | ~3.4k | Automated safety check: Pass | No licence | today |
| 121 | AI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范. An agent skill from ProgrammerAnthony/Expert-Coding-Harness. | ProgrammerAnthony/ | 235 | — | ~3k | Automated safety check: Pass | MIT | 5 mo ago |
| 122 | 122.Hunt LLM LLM / AI application attack hunting - prompt injection (direct + indirect), excessive agency, insecure output handling, system-prompt + data leakage. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 123 | 123.Hunt MCP MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. | Encod3d-Sec/ | 329 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 124 | Test LLM-integrated applications against known prompt injection techniques, evasion methods, and attack intents using the Arcanum PI Taxonomy. | OWASP/ | 188 | — | ~758 | Automated safety check: Pass | CC-BY-4.0 | 15 days ago |
| 125 | Audit an LLM application for indirect prompt injection - compose objective x technique payloads, deliver them through the channels the agent actually reads, and prove impact with an out-of-band… | forefy/ | 152 | — | ~2.3k | Automated safety check: Pass | MIT | 5 days ago |
| 126 | 126.Security Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries… | telagod/ | 244 | — | ~907 | Automated safety check: Pass | MIT | 2 mo ago |
| 127 | Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 128 | Test whether authorized direct or indirect untrusted content can alter an AI system's protected behavior, context use, memory, retrieval, output handling, or downstream capability. | cyberful/ | 135 | — | ~538 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 129 | Reconstruct how instructions, retrieved content, memory, identities, approvals, tool schemas, arguments, outputs, delegation, and fallbacks propagate through an AI system. | cyberful/ | 135 | — | ~517 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 130 | 130.Debug Systematic diagnosis of a red test, a rule that fires or stays silent wrongly, a scan or probe whose artifact looks wrong, a collector error, a red CI run or a gate that is green for the wrong reason. | guardana/ | 131 | — | ~933 | Automated safety check: Pass | Apache-2.0 | today |
| 131 | Implement content safety guardrails for Claude — input filtering, Use when working with policy-guardrails patterns. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 132 | Secure your Anthropic integration — API key management, input validation, Use when working with security-basics patterns. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Notes | MIT | today |
| 133 | Security and compliance review framework for Kling AI integrations. | jeremylongshore/ | 2.8k | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 134 | Audit a Claude/Agent SKILL.md (or any AI skill / system prompt) for safety before installing or merging it. | mohitagw15856/ | 1.4k | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 135 | 135.Prompt Injection AI/LLM 间接 Prompt 注入攻击。当目标 AI 系统会处理外部数据源(网页、文档、邮件、数据库、API 返回)时使用。覆盖间接注入、工具链劫持、RAG 投毒、数据外泄等技术。OWASP LLM Top 10 1 漏洞类别 | wgpsec/ | 1.8k | — | ~704 | Automated safety check: Notes | No licence | today |
| 136 | Adversarial defense layer for the mortgage plugin — protects against prompt injection, system prompt extraction, PII leakage, workflow bypass, and social engineering attacks. | davepoon/ | 3.6k | — | ~455 | Automated safety check: Pass | MIT | yesterday |
| 137 | 137.Security Audit 服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题. An agent skill from 312362115/claude. | 312362115/ | 107 | — | ~1.3k | Automated safety check: Pass | MIT | 4 mo ago |
| 138 | 138.Icml Submission A skill your agent uses when auditing an ICML main-track submission for OpenReview, LaTeX formatting, 8-page body, anonymity, supplementary material, impact statement, dual submission, concurrent… | franklee16/ | 223 | 1 repo | ~655 | Automated safety check: Pass | No licence | 22 days ago |
| 139 | Detects prompt injection hidden in documents from the other side (pleadings, skeletons, bundles, served evidence, opponents' emails and attachments) before an AI reads them, so the model is not… | lawve-ai/ | 847 | — | ~4.6k | Automated safety check: Pass | MIT | 7 days ago |
| 140 | Route broad AI-agent security reviews to focused Cyberful skills across risk, model supply chain, context and capabilities, prompt injection, tool authorization, and RAG isolation. | cyberful/ | 135 | — | ~723 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 141 | 141.Openart Guide an OpenART agent or contributor through planning, running, extending, and debugging the framework. | AI45Lab/ | 235 | — | ~918 | Automated safety check: Notes | AGPL-3.0 | 7 days ago |
| 142 | 142.Bagman Secure key management for AI agents. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~2.9k | Automated safety check: Notes | MIT | 2 mo ago |
| 143 | 143.Console Agent Build AI agents with console.agent() - the jQuery of AI Agents. | LeoYeAI/ | 2.2k | — | ~4.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 144 | 144.Mandate A skill your agent uses when enforcing spend limits on AI agent wallets, validating transactions before signing, configuring allowlists or approval workflows, detecting prompt injection in agent… | LeoYeAI/ | 2.2k | — | ~5k | Automated safety check: Notes | MIT | 2 mo ago |
Explore related skills
Category
More topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38