Topic · Security
Best security operations skills for Claude Code, Codex and other agents.
- skills
- 248
- official
- 14
Security operations skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics. | OTRF/ | 4.7k | — | ~1.2k | Automated safety check: Pass | MIT | 8 mo ago |
| 2 | Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. | elastic/ | 592 | 1 repo | ~3.5k | Automated safety check: Notes | Apache-2.0 | 5 days ago |
| 3 | Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK. | kubeshark/ | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | 7 days ago |
| 4 | Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written. | OTRF/ | 4.7k | — | ~813 | Automated safety check: Pass | MIT | 8 mo ago |
| 5 | Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern. | OTRF/ | 4.7k | — | ~600 | Automated safety check: Pass | MIT | 8 mo ago |
| 6 | Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). | elastic/ | 592 | 1 repo | ~3.9k | Automated safety check: Notes | Apache-2.0 | 5 days ago |
| 7 | Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 8 | 8.Rsigma Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. | timescale/ | 157 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 9 | A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability… | chaitin/ | 114 | — | ~15k | Automated safety check: Notes | GPL-3.0 | 8 days ago |
| 10 | 10.Gates GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework. | Nebulock-Inc/ | 384 | — | ~12k | Automated safety check: Pass | MIT | 5 days ago |
| 11 | Creates structured agent definitions using the 7-component format grounded in persona science (the alignment-accuracy tradeoff), vocabulary routing, and the MAST failure taxonomy + Forge watchlist. | jdforsythe/ | 151 | — | ~4.5k | Automated safety check: Pass | MIT | 3 mo ago |
| 12 | Enable, configure, and query Elasticsearch security audit logs. | aspectrr/ | 405 | — | ~1.7k | Automated safety check: Pass | MIT | 5 mo ago |
| 13 | 13.Attack Flow Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports. | wiz-sec-public/ | 182 | — | ~3.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 14 | Independently implement and validate an alternative solution for an Astro pull request. | withastro/ | 63k | — | ~782 | Automated safety check: Pass | Unknown | today |
| 15 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 219 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 16 | Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas. | OTRF/ | 4.7k | — | ~819 | Automated safety check: Pass | MIT | 8 mo ago |
| 17 | Determines whether a security incident involves personal data, triggers regulatory breach-notification obligations (e.g. | ahmadvh/ | 375 | — | ~861 | Automated safety check: Pass | Unknown | 1 mo ago |
| 18 | Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills. | BagelHole/ | 1.1k | — | ~4.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 20 | 20.Dfir Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. | transilienceai/ | 559 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 21 | Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic. | AgentSecOps/ | 219 | 1 repo | ~4.8k | Automated safety check: Notes | Unknown | 5 mo ago |
| 22 | Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 23 | Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence. | zhaoxuya520/ | 40k | 1 repo | ~1k | Automated safety check: Pass | MIT | 15 days ago |
| 24 | Learn from public breach disclosures — extract the audit question each one implies and check your own stack. | briiirussell/ | 412 | — | ~3.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 25 | Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Check for existing SIEM alerts and case management entries related to IOCs. | dandye/ | 127 | — | ~624 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 27 | Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports. | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed. | FlorianBruniaux/ | 6.1k | — | ~680 | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 29 | 29.Audit Report Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools. | harness/ | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 30 | Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | A skill your agent uses for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation. | zhaoxuya520/ | 40k | 2 repos | ~344 | Automated safety check: Warn | MIT | 15 days ago |
| 32 | 32.Cis Controls Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection… | Sushegaad/ | 939 | 1 repo | ~4.2k | Automated safety check: Pass | MIT | 3 days ago |
| 33 | 33.Council Run a model-diverse subagent council to investigate the same problem from multiple perspectives, compare findings, and produce a final recommendation. | warpdotdev/ | 606 | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 7 days ago |
| 34 | 34.Enrich Ioc Enrich an IOC (IP, domain, hash, URL) with threat intelligence. | dandye/ | 127 | — | ~702 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA. | trailofbits/ | 7.4k | — | ~5.9k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 36 | Search for existing cases related to specific indicators or entities. | dandye/ | 127 | — | ~562 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Complete Tier 1 triage workflow. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 38 | 38.Msp Helpdesk A skill your agent uses for anything about how your MSP runs day-to-day support: setting or questioning a ticket's priority, response and resolution targets, "the client says everything is down"… | RTFM-IT-Services-LLC/ | 112 | — | ~3.3k | Automated safety check: Pass | Unknown | 5 days ago |
| 39 | 39.Blue Team A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing… | gaasher/ | 174 | — | ~3.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 40 | A skill your agent uses for your MSP's proactive, recurring operations: patching and update cycles, maintenance windows, backup monitoring and test restores, monitoring and alert triage, the on-call… | RTFM-IT-Services-LLC/ | 112 | — | ~2.6k | Automated safety check: Pass | Unknown | 5 days ago |
| 41 | Implement centralized audit logging and SIEM integration. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.5k | Automated safety check: Pass | MIT | yesterday |
| 42 | Automate security workflows and remediation. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~1k | Automated safety check: Pass | MIT | yesterday |
| 43 | Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e… | ohmyjahh/ | 276 | — | ~895 | Automated safety check: Pass | MIT | 8 days ago |
| 44 | Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved… | digoal/ | 8.6k | — | ~2.2k | Automated safety check: Pass | GPL-2.0 | 9 days ago |
| 45 | 45.Hunt Apt Hunt for a specific APT/threat actor in your environment. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 46 | 46.007 Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project. | sickn33/ | 47k | 2 repos | ~410 | Automated safety check: Pass | MIT | yesterday |
| 47 | A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU… | davila7/ | 32k | 1 repo | ~4.7k | Automated safety check: Pass | CC-BY-4.0 | today |
| 48 | Generic detection rule creation and management using Sigma, the universal SIEM rule format. | AgentSecOps/ | 219 | 1 repo | ~4k | Automated safety check: Pass | Unknown | 5 mo ago |
Questions, answered from the data.
What is the best security operations skill?
Threat Hunt Blueprint Assembly from OTRF/ThreatHunter-Playbook ranks first of the 248 security operations skills listed here, with the highest score: its repository has 4.7k GitHub stars, its SKILL.md loads about 1.2k tokens and it passes the automated safety check with no findings. Next come Security Alert Triage and Kubernetes Network Security Audit.
Which security operations skills are official?
14 of the 248 security operations skills are official, published by the vendor's own GitHub organization: Security Alert Triage, Security Detection Rule Management, Astro Adversary Blue, YARA-X Rule Authoring, Azure Smart City Iot Solution Builder and 9 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Supply chain security242
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34