Topic · Security

Best security operations skills for Claude Code, Codex and other agents.

Skills that handle security alerts, threat hunting and breach response.
skills
248
official
14

Security operations skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Security operations skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.

OTRF/ThreatHunter-Playbook4.7k—~1.2kAutomated safety check: PassMIT8 mo ago
2

Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

elastic/agent-skills5921 repo~3.5kAutomated safety check: NotesApache-2.05 days ago
3

Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

kubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.07 days ago
4

Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written.

OTRF/ThreatHunter-Playbook4.7k—~813Automated safety check: PassMIT8 mo ago
5

Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.

OTRF/ThreatHunter-Playbook4.7k—~600Automated safety check: PassMIT8 mo ago
6

Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

elastic/agent-skills5921 repo~3.9kAutomated safety check: NotesApache-2.05 days ago
7

Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
8

Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve.

timescale/rsigma157—~1.2kAutomated safety check: PassMITyesterday
9

A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

chaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.08 days ago
10

GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

Nebulock-Inc/agentic-threat-hunting-framework384—~12kAutomated safety check: PassMIT5 days ago
11

Creates structured agent definitions using the 7-component format grounded in persona science (the alignment-accuracy tradeoff), vocabulary routing, and the MAST failure taxonomy + Forge watchlist.

jdforsythe/forge151—~4.5kAutomated safety check: PassMIT3 mo ago
12

Enable, configure, and query Elasticsearch security audit logs.

aspectrr/deer405—~1.7kAutomated safety check: PassMIT5 mo ago
13

Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports.

wiz-sec-public/SITF182—~3.1kAutomated safety check: PassUnknown2 mo ago
14

Independently implement and validate an alternative solution for an Astro pull request.

withastro/astro63k—~782Automated safety check: PassUnknowntoday
15

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit219—~2.3kAutomated safety check: PassUnknown5 mo ago
16

Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

OTRF/ThreatHunter-Playbook4.7k—~819Automated safety check: PassMIT8 mo ago
17

Determines whether a security incident involves personal data, triggers regulatory breach-notification obligations (e.g.

ahmadvh/octochains375—~861Automated safety check: PassUnknown1 mo ago
18

Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.01 mo ago
19

Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

BagelHole/DevOps-Security-Agent-Skills1.1k—~4.5kAutomated safety check: PassMIT4 mo ago
20
20.Dfir

Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

transilienceai/communitytools559—~1.5kAutomated safety check: PassMIT2 mo ago
21

Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

AgentSecOps/SecOpsAgentKit2191 repo~4.8kAutomated safety check: NotesUnknown5 mo ago
22

Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
23

Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence.

zhaoxuya520/reverse-skill40k1 repo~1kAutomated safety check: PassMIT15 days ago
24

Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

briiirussell/cybersecurity-skills412—~3.5kAutomated safety check: NotesMIT4 mo ago
25

Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
26

Check for existing SIEM alerts and case management entries related to IOCs.

dandye/ai-runbooks127—~624Automated safety check: PassApache-2.01 mo ago
27

Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
28

Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed.

FlorianBruniaux/claude-code-ultimate-guide6.1k—~680Automated safety check: PassCC-BY-SA-4.0yesterday
29

Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

harness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0yesterday
30

Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.1kAutomated safety check: PassApache-2.01 mo ago
31

A skill your agent uses for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.

zhaoxuya520/reverse-skill40k2 repos~344Automated safety check: WarnMIT15 days ago
32

Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repo~4.2kAutomated safety check: PassMIT3 days ago
33

Run a model-diverse subagent council to investigate the same problem from multiple perspectives, compare findings, and produce a final recommendation.

warpdotdev/common-skills6061 repo~1.8kAutomated safety check: PassMIT7 days ago
34

Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

dandye/ai-runbooks127—~702Automated safety check: PassApache-2.01 mo ago
35

Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA.

trailofbits/skills7.4k—~5.9kAutomated safety check: PassCC-BY-SA-4.05 days ago
36

Search for existing cases related to specific indicators or entities.

dandye/ai-runbooks127—~562Automated safety check: PassApache-2.01 mo ago
37

Complete Tier 1 triage workflow. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.8kAutomated safety check: PassApache-2.01 mo ago
38

A skill your agent uses for anything about how your MSP runs day-to-day support: setting or questioning a ticket's priority, response and resolution targets, "the client says everything is down"…

RTFM-IT-Services-LLC/msp-claude-skills112—~3.3kAutomated safety check: PassUnknown5 days ago
39

A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing…

gaasher/Agent-Loop-Skills174—~3.6kAutomated safety check: PassMIT3 mo ago
40

A skill your agent uses for your MSP's proactive, recurring operations: patching and update cycles, maintenance windows, backup monitoring and test restores, monitoring and alert triage, the on-call…

RTFM-IT-Services-LLC/msp-claude-skills112—~2.6kAutomated safety check: PassUnknown5 days ago
41

Implement centralized audit logging and SIEM integration. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~3.5kAutomated safety check: PassMITyesterday
42

Automate security workflows and remediation. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~1kAutomated safety check: PassMITyesterday
43

Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

ohmyjahh/xquads-squads276—~895Automated safety check: PassMIT8 days ago
44

Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved…

digoal/blog8.6k—~2.2kAutomated safety check: PassGPL-2.09 days ago
45

Hunt for a specific APT/threat actor in your environment. An agent skill from dandye/ai-runbooks.

dandye/ai-runbooks127—~1.1kAutomated safety check: PassApache-2.01 mo ago
46
46.007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

sickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMITyesterday
47

A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU…

davila7/claude-code-templates32k1 repo~4.7kAutomated safety check: PassCC-BY-4.0today
48

Generic detection rule creation and management using Sigma, the universal SIEM rule format.

AgentSecOps/SecOpsAgentKit2191 repo~4kAutomated safety check: PassUnknown5 mo ago

Questions, answered from the data.

What is the best security operations skill?

Threat Hunt Blueprint Assembly from OTRF/ThreatHunter-Playbook ranks first of the 248 security operations skills listed here, with the highest score: its repository has 4.7k GitHub stars, its SKILL.md loads about 1.2k tokens and it passes the automated safety check with no findings. Next come Security Alert Triage and Kubernetes Network Security Audit.

Which security operations skills are official?

14 of the 248 security operations skills are official, published by the vendor's own GitHub organization: Security Alert Triage, Security Detection Rule Management, Astro Adversary Blue, YARA-X Rule Authoring, Azure Smart City Iot Solution Builder and 9 more.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.