Full Leaderboard·Data through 25 August 2026·Updated daily

Security Skill Leaderboard

Ranked repositories whose primary or secondary category is Security. Ordered by their overall Skill Leaderboard rank.
35kSkills tracked
325kStars gained / last 30 days
7.9kCommits / last 30 days
7.8MSKILL.md lines analyzed
RankRepositoryStars7 days30 days
17
mukul975/Anthropic-Cybersecurity-Skills

A library of 818 structured cybersecurity skills for AI agents, covering red-teaming tasks such as DPAPI decryption and Active Directory privilege escalation.

Stars31.1k
7 days+7.9%+2.3k stars
30 days+16.8%+4.5k stars
19
zhaoxuya520/reverse-skill

Security research skills for Android APK hooking, SSL bypass, and Active Directory Certificate Services abuse.

Stars29k
7 days+10.9%+2.9k stars
30 days+223.7%+20.1k stars
48
SimoneAvogadro/android-reverse-engineering-skill

A structured Android reverse engineering pipeline covering fingerprinting, decompilation with jadx and Fernflower, Kotlin name recovery, call flow tracing, and two-tier API endpoint documentation.

Stars7.3k
7 days+7.2%+490 stars
30 days+11.7%+768 stars
51
trailofbits/skills

Audits GitHub Actions workflows for security vulnerabilities and prompt injection risks in AI agent integrations.

Stars6.8k
7 days+3.0%+200 stars
30 days+9.1%+572 stars
76
elementalsouls/Claude-BugHunter

An Android red-team pipeline that automates APK acquisition, jadx decompilation, secret grepping, and Frida instrumentation.

Stars3.8k
7 days+3.2%+117 stars
30 days+23.5%+716 stars
91
ljagiello/ctf-skills

Eleven specialized skills for web, binary, crypto, reverse engineering, forensics, OSINT, AI/ML, and malware CTF categories, plus a dispatcher for automatic category routing.

Stars3.1k
7 days+1.8%+54 stars
30 days+8.8%+248 stars
94
cloudflare/security-audit-skill

Conducts thorough, multi-phase security audits of codebases, emphasizing exploitable vulnerabilities with real impact and machine-readable output for pipeline integration.

Stars3k
7 days+4.9%+142 stars
30 days+15.0%+398 stars
97
SnailSploit/Claude-Red

A curated library of offensive security skills for red teaming and penetration testing, covering AD, cloud, wireless, web, mobile, IoT, exploit development, and reporting.

Stars3k
7 days+0.9%+26 stars
30 days+6.3%+174 stars
116
elementalsouls/Claude-OSINT

Automates external OSINT reconnaissance pipelines, including secret scanning and multi-stage discovery for authorized security engagements.

Stars2.3k
7 days+1.3%+30 stars
30 days+17.6%+349 stars
126
P4nda0s/reverse-skills

A set of skills for Android DEX dumping, iOS app decryption, Frida hook generation, IDAPython scripting, structure/symbol recovery, Unity IL2CPP symbol extraction, and Unicorn emulation.

Stars2k
7 days+2.6%+51 stars
30 days+18.0%+310 stars
154
microsoft/azure-skills

A set of skills for generating IRQL pipelines and Kusto graph queries from natural language to support cybersecurity threat hunting and data visualization.

Stars1.4k
7 days+1.6%+22 stars
30 days+6.7%+88 stars
167
utkusen/sast-skills

A skill collection that turns AI coding assistants into SAST scanners for 15+ vulnerability classes including injection, authentication, and business logic flaws.

Stars1.3k
7 days+0.9%+11 stars
30 days+5.8%+71 stars
175
BehiSecc/VibeSec-Skill

A secure coding guide for web application development and audit, covering major vulnerability classes with patterns, bypass prevention, and checklists.

Stars1.2k
7 days+1.8%+21 stars
30 days+9.8%+109 stars
219
raroque/vibe-security-skill

Audits codebases for AI-introduced security issues: exposed secrets, broken access control, insecure payments, and authentication flaws in vibe-coded applications.

Stars972
7 days+1.6%+15 stars
30 days+9.8%+87 stars
242
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Governance, Risk, and Compliance skills for auditing against ISO 27001, SOC 2, NIST CSF, CMMC 2.0, and global data privacy laws.

Stars855
7 days+1.9%+16 stars
30 days+10.2%+79 stars
245
suleimanodetoro/skills

Guidelines for designing and implementing responsive product interfaces, visual hierarchies, and design system surfaces.

Stars839
7 days+2.8%+23 stars
30 daysPercentage change unavailable
253
BrownFineSecurity/iothackbot

A bundle of Claude Skills for IoT pentesting across mobile, hardware, firmware, and network layers—with APK decompilation, UART/JTAG probing, firmware threat scanning, and IoT traffic analysis.

Stars814
7 days+0.3%+2 stars
30 days+1.5%+12 stars
260
BagelHole/DevOps-Security-Agent-Skills

A library of agent-ready skills for automating DevOps security, infrastructure compliance, and centralized audit logging.

Stars785
7 daysPercentage change unavailable
30 daysPercentage change unavailable
264
google/mantis

A collection of security review skills for AI agents to autonomously identify, chain, and patch software vulnerabilities.

Stars774
7 days+2.3%+17 stars
30 daysPercentage change unavailable
329
7onez/cti-expert

A CTI and OSINT toolkit for web-infrastructure pivoting, breach data triage, and structured intelligence reporting.

Stars564
7 days+16.8%+81 stars
30 days+114.5%+301 stars
362
codexstar69/bug-hunter

An adversarial code audit tool for detecting security and logic defects using deterministic risk triage and a multi-role review process.

Stars490
7 days+0.6%+3 stars
30 days+24.7%+97 stars
366
transilienceai/communitytools

A security toolkit featuring vulnerability testing techniques for APIs and injection flaws, attack path mapping, and threat intelligence reporting formats.

Stars484
7 days+2.5%+12 stars
30 daysPercentage change unavailable
368
waybarrios/opencode-power-pack

A set of engineering skills for auditing AI agent security in GitHub Actions and optimizing project-rules for agent context.

Stars479
7 days+1.5%+7 stars
30 daysPercentage change unavailable
428
Gabson0x/bountyforge

A bug bounty workflow for mapping, testing, chaining, validating, triaging, and reporting vulnerabilities across applications, contracts, pipelines, and infrastructure.

Stars399
7 days+8.1%+30 stars
30 days+75.8%+172 stars
430
ghostsecurity/skills

Controls the reaper MITM proxy to capture, search, and replay HTTP/HTTPS traffic for security inspection.

Stars399
7 days+0.3%+1 stars
30 daysPercentage change unavailable
458
Eyadkelleh/awesome-skills-security

A security toolkit containing curated fuzzing payloads for vulnerability testing and adversarial prompts for LLM security evaluation.

Stars366
7 days+0.8%+3 stars
30 daysPercentage change unavailable
459
briiirussell/cybersecurity-skills

A cybersecurity practice library covering audits, penetration testing, SOC operations, threat hunting, incident response, and compliance against OWASP, NIST, PCI, HIPAA, and AI RMF.

Stars365
7 days+2.8%+10 stars
30 days+56.6%+132 stars
463
Masriyan/Claude-Code-CyberSecurity-Skill

Automates passive and active reconnaissance, binary reverse engineering, exploit development, and SOC incident playbook workflows.

Stars361
7 days+4.9%+17 stars
30 daysPercentage change unavailable
474
hypnguyen1209/offensive-claude

Provides skills for Active Directory exploitation, custom exploit development in Python and Rust, and red-teaming agentic AI applications.

Stars346
7 days+0.6%+2 stars
30 daysPercentage change unavailable
475
agamm/claude-code-owasp

A security review skill that applies OWASP Top 10:2025, ASVS 5.0, and AI-specific security standards to code analysis.

Stars345
7 days+2.4%+8 stars
30 days+13.5%+41 stars
533
superagents-lab/xcode27-skills

A set of engineering skills for auditing Xcode security settings, implementing C bounds-safety, and modernizing UIKit apps for SwiftUI and multi-window support.

Stars294
7 days+5.0%+14 stars
30 daysPercentage change unavailable
552
SunWeb3Sec/llm-sast-scanner

A general-purpose SAST skill for analyzing source code vulnerabilities across 34 classes using taint tracking and pattern matching.

Stars281
7 days+1.8%+5 stars
30 days+3.3%+9 stars
565
tanviet12/vbsec

A security scanner that detects common vulnerabilities in Go, PHP, Python, TypeScript, and .NET code with bilingual reporting.

Stars264
7 days0.0%0 stars
30 daysPercentage change unavailable
574
thoughtbot/rails-audit-thoughtbot

Analyzes Ruby on Rails applications for security, testing practices, and code design to produce a categorized audit report with severity levels.

Stars241
7 days+1.7%+4 stars
30 days+6.2%+14 stars
589
elvismdev/claude-wordpress-skills

Systematic performance code review for WordPress codebases, catching critical database, caching, and asset loading anti-patterns with severity levels.

Stars225
7 days+0.5%+1 stars
30 days+3.7%+8 stars
596
AgriciDaniel/claude-cybersecurity

Orchestrates eight parallel security agents for comprehensive code audit: OWASP, CWE, secrets, IaC, threat intelligence, AI code, and logic, with weighted scoring and compliance mapping.

Stars213
7 days+2.9%+6 stars
30 days+10.9%+21 stars
598
dinosn/raptor-loop-hunt

An autonomous security research agent that uses a looping methodology to perform deep-dive vulnerability hunts and exhaustive codebase audits.

Stars212
7 days+2.9%+6 stars
30 days+92.7%+102 stars
604
jthack/ffuf_claude_skill

Structured ffuf guidance for discovering hidden directories, subdomains, parameters, and vulnerabilities in web applications, including authenticated fuzzing and auto-calibration.

Stars209
7 days+1.5%+3 stars
30 days+5.6%+11 stars
622
Lelemon-studio/compliance-cl

Audits repositories to generate compliance documentation for Chilean laws 21.719 and 21.595, including privacy policies and data protection agreements.

Stars189
7 days+3.3%+6 stars
30 days+10.5%+18 stars
672
vikingmute/review-forge

Multi-model code review workflow: separate reviews per model, synthesized checklist, fix only checked items, regression tests, and independent verification.

Stars153
7 days0.0%0 stars
30 days+28.6%+34 stars
676
bjgreenberg/senior-engineering-partner

A senior engineering partner for Python, Bash, JS, and Swift that enforces a spec-to-verify workflow and security audits.

Stars148
7 days+1.4%+2 stars
30 days+8.0%+11 stars
695
Frankcastleauditor/safe-solana-builder

Produces Solana programs (Anchor, Native, or Pinocchio) with integrated security review, project scaffolding, test generation, and a vulnerability checklist from real audits.

Stars139
7 days+1.5%+2 stars
30 days+2.2%+3 stars