Security Skill Leaderboard
A library of 818 structured cybersecurity skills for AI agents, covering red-teaming tasks such as DPAPI decryption and Active Directory privilege escalation.
Security research skills for Android APK hooking, SSL bypass, and Active Directory Certificate Services abuse.
A structured Android reverse engineering pipeline covering fingerprinting, decompilation with jadx and Fernflower, Kotlin name recovery, call flow tracing, and two-tier API endpoint documentation.
Audits GitHub Actions workflows for security vulnerabilities and prompt injection risks in AI agent integrations.
An Android red-team pipeline that automates APK acquisition, jadx decompilation, secret grepping, and Frida instrumentation.
Eleven specialized skills for web, binary, crypto, reverse engineering, forensics, OSINT, AI/ML, and malware CTF categories, plus a dispatcher for automatic category routing.
Conducts thorough, multi-phase security audits of codebases, emphasizing exploitable vulnerabilities with real impact and machine-readable output for pipeline integration.
A curated library of offensive security skills for red teaming and penetration testing, covering AD, cloud, wireless, web, mobile, IoT, exploit development, and reporting.
Automates external OSINT reconnaissance pipelines, including secret scanning and multi-stage discovery for authorized security engagements.
A set of skills for Android DEX dumping, iOS app decryption, Frida hook generation, IDAPython scripting, structure/symbol recovery, Unity IL2CPP symbol extraction, and Unicorn emulation.
A set of skills for generating IRQL pipelines and Kusto graph queries from natural language to support cybersecurity threat hunting and data visualization.
A skill collection that turns AI coding assistants into SAST scanners for 15+ vulnerability classes including injection, authentication, and business logic flaws.
A secure coding guide for web application development and audit, covering major vulnerability classes with patterns, bypass prevention, and checklists.
Audits codebases for AI-introduced security issues: exposed secrets, broken access control, insecure payments, and authentication flaws in vibe-coded applications.
Governance, Risk, and Compliance skills for auditing against ISO 27001, SOC 2, NIST CSF, CMMC 2.0, and global data privacy laws.
Guidelines for designing and implementing responsive product interfaces, visual hierarchies, and design system surfaces.
A bundle of Claude Skills for IoT pentesting across mobile, hardware, firmware, and network layers—with APK decompilation, UART/JTAG probing, firmware threat scanning, and IoT traffic analysis.
A library of agent-ready skills for automating DevOps security, infrastructure compliance, and centralized audit logging.
A collection of security review skills for AI agents to autonomously identify, chain, and patch software vulnerabilities.
A CTI and OSINT toolkit for web-infrastructure pivoting, breach data triage, and structured intelligence reporting.
An adversarial code audit tool for detecting security and logic defects using deterministic risk triage and a multi-role review process.
A security toolkit featuring vulnerability testing techniques for APIs and injection flaws, attack path mapping, and threat intelligence reporting formats.
A set of engineering skills for auditing AI agent security in GitHub Actions and optimizing project-rules for agent context.
A bug bounty workflow for mapping, testing, chaining, validating, triaging, and reporting vulnerabilities across applications, contracts, pipelines, and infrastructure.
Controls the reaper MITM proxy to capture, search, and replay HTTP/HTTPS traffic for security inspection.
A security toolkit containing curated fuzzing payloads for vulnerability testing and adversarial prompts for LLM security evaluation.
A cybersecurity practice library covering audits, penetration testing, SOC operations, threat hunting, incident response, and compliance against OWASP, NIST, PCI, HIPAA, and AI RMF.
Automates passive and active reconnaissance, binary reverse engineering, exploit development, and SOC incident playbook workflows.
Provides skills for Active Directory exploitation, custom exploit development in Python and Rust, and red-teaming agentic AI applications.
A security review skill that applies OWASP Top 10:2025, ASVS 5.0, and AI-specific security standards to code analysis.
A set of engineering skills for auditing Xcode security settings, implementing C bounds-safety, and modernizing UIKit apps for SwiftUI and multi-window support.
A general-purpose SAST skill for analyzing source code vulnerabilities across 34 classes using taint tracking and pattern matching.
A security scanner that detects common vulnerabilities in Go, PHP, Python, TypeScript, and .NET code with bilingual reporting.
Analyzes Ruby on Rails applications for security, testing practices, and code design to produce a categorized audit report with severity levels.
Systematic performance code review for WordPress codebases, catching critical database, caching, and asset loading anti-patterns with severity levels.
Orchestrates eight parallel security agents for comprehensive code audit: OWASP, CWE, secrets, IaC, threat intelligence, AI code, and logic, with weighted scoring and compliance mapping.
An autonomous security research agent that uses a looping methodology to perform deep-dive vulnerability hunts and exhaustive codebase audits.
Structured ffuf guidance for discovering hidden directories, subdomains, parameters, and vulnerabilities in web applications, including authenticated fuzzing and auto-calibration.
Audits repositories to generate compliance documentation for Chilean laws 21.719 and 21.595, including privacy policies and data protection agreements.
Multi-model code review workflow: separate reviews per model, synthesized checklist, fix only checked items, regression tests, and independent verification.
A senior engineering partner for Python, Bash, JS, and Swift that enforces a spec-to-verify workflow and security audits.
Produces Solana programs (Anchor, Native, or Pinocchio) with integrated security review, project scaffolding, test generation, and a vulnerability checklist from real audits.