Security Skill Leaderboard
Security workflows for AI agent prompt injection, APK hooking, and Active Directory certificate abuse within sandbox environments.
A library of 818 structured cybersecurity skills for AI agents, covering red-teaming tasks such as DPAPI decryption and Active Directory privilege escalation.
Conducts security audits and vulnerability research across codebases, APIs, services, and CLI tools.
A set of DevOps skills for Google Cloud, covering authentication, onboarding, and gcloud CLI operations.
A collection of engineering skills for full-stack development, including Angular 17+ architecture, .NET Core expertise, and system design documentation.
Decompiles APK, XAPK, JAR, and AAR files to trace Android architecture, API endpoints, and network call flows.
Security auditing skills for vulnerability hunting, threat modeling, and detecting prompt injection risks in AI-integrated CI/CD pipelines.
Red team methodology for Active Directory attacks, covering reconnaissance, privilege escalation, persistence, and ADCS exploitation.
Processes art into game-ready files via sprite cutout, palette pixelation, seamless texture generation, and 3D model rendering into isometric or top-down sprite frames.
An Android red-team pipeline that automates APK acquisition, jadx decompilation, secret grepping, and Frida instrumentation.
Provides AI and machine learning attack techniques for CTF challenges, including adversarial examples, model extraction, and LLM jailbreaking.
Technical skills for building with the Cloudflare Agents SDK, managing Basin analytics workflows, and configuring Zero Trust SASE deployments.
A workspace management skill for maintaining durable state, evidence, and consistency during long-horizon AI reasoning and repository engineering.
Automates external OSINT reconnaissance pipelines, including secret scanning and multi-stage discovery for authorized security engagements.
Expert attack playbooks covering Active Directory exploitation, API security bypasses, and advanced penetration testing techniques.
A security review toolkit for AI agents featuring skills for vulnerability chaining, risk calibration, and automated remediation.
A set of skills for Android DEX dumping, iOS app decryption, Frida hook generation, IDAPython scripting, structure/symbol recovery, Unity IL2CPP symbol extraction, and Unicorn emulation.
Development style guides for the Claude Code codebase and diagnostic tools for tau2-bench evaluation analysis.
Provides multi-language code review guidance covering architecture, security audits, and performance analysis for pull requests.
A skill collection that turns AI coding assistants into SAST scanners for 15+ vulnerability classes including injection, authentication, and business logic flaws.
A business-oriented skill set featuring professional code review services and domain knowledge graph construction tools.
A secure coding guide for web application development and audit, covering major vulnerability classes with patterns, bypass prevention, and checklists.
A security skill set covering SAML SSO attacks, Docker privilege escalation, and the construction of cross-attack chains.
Generates Solidity fuzz suites for Echidna and Medusa from Foundry or Hardhat projects and converts natural language properties into Solidity assertions.
Technical guidance for Apple platform development focusing on Apple Intelligence integration, CoreML, and WCAG accessibility compliance.
A library of agent-ready skills for automating DevOps security, infrastructure compliance, and centralized audit logging.
Audits codebases for AI-introduced security issues: exposed secrets, broken access control, insecure payments, and authentication flaws in vibe-coded applications.
Expert-level compliance skills for security frameworks and data privacy regulations including ISO 27001, SOC 2, NIST CSF, CCPA, and GDPR.
A bundle of Claude Skills for IoT pentesting across mobile, hardware, firmware, and network layers—with APK decompilation, UART/JTAG probing, firmware threat scanning, and IoT traffic analysis.
Guidelines for designing and implementing responsive product interfaces, visual hierarchies, and design system surfaces.
Expert knowledge for Azure Active Directory B2C development, covering custom policies, IdP configuration, API security, and deployment patterns.
A library of coding agent skills featuring accessibility auditing and active memory management for consistent AI development workflows.
Technical guidance for Cloudflare Workers, Pages, storage (KV, D1, R2), AI tools, and infrastructure-as-code deployment.
A failure-mode workflow for Terraform and OpenTofu that catches identity churn, secret exposure, blast radius issues, CI drift, and compliance gaps during generation, review, and delivery.
An OSINT and CTI analysis toolkit for infrastructure pivoting, breach triage, digital footprint review, and structured threat reporting.
A web protocol reverse engineering skill that transforms browser-based interactions into Python collectors for handling tokens, fingerprints, and encrypted responses.
A failure-mode diagnostic workflow for Kubernetes manifests that identifies six categories of configuration risk and produces remediated YAML, Helm values, Kustomize overlays, and policy rules with validation steps.
Performs Android APK security audits using static analysis, dynamic instrumentation with Frida and Objection, and IPC component abuse testing.
Provides best practices for Playwright E2E and component testing, covering flaky test resolution, Page Object Model implementation, API mocking, and accessibility testing.
Automates security reviews and threat modeling using OWASP Top 10, ASVS 5.0, and specialized security standards for LLM and agentic applications.
A security assessment tool for red-teaming web, API, and AI applications to validate vulnerabilities and implement fixes.
Scans AI-generated code for 21 common security vulnerabilities with bilingual reporting, live CVE lookups, and automated patching.
A general-purpose SAST skill for analyzing source code vulnerabilities across 34 classes using taint tracking and pattern matching.
A wrapper for 1Password that allows AI agents to find, save, and inject secrets, API keys, and credentials into commands or environment files.
A Caido SDK integration for searching HTTP history with HTTPQL, managing replay sessions, and executing proxied curl requests.
An autonomous security research loop that performs multi-altitude vulnerability hunting and verification across source code.
Rents temporary private phone numbers via API to receive SMS verification codes for account signups and 2FA testing.