Full Leaderboard·Data through 9 October 2026·Updated daily

Security Skill Leaderboard

Ranked repositories whose primary or secondary category is Security. Ordered by their overall Skill Leaderboard rank.
36.8kSkills tracked
426kStars gained / last 30 days
9.9kCommits / last 30 days
8.1MSKILL.md lines analyzed
RankRepositoryStars7 days30 days
24
zhaoxuya520/reverse-skill

Security workflows for AI agent prompt injection, APK hooking, and Active Directory certificate abuse within sandbox environments.

Stars40.4k
7 days+1.1k stars+2.7%
30 days+5.1k stars+14.5%
27
mukul975/Anthropic-Cybersecurity-Skills

A library of 818 structured cybersecurity skills for AI agents, covering red-teaming tasks such as DPAPI decryption and Active Directory privilege escalation.

Stars34k
7 days+302 stars+0.9%
30 days+1.5k stars+4.7%
35
cloudflare/security-audit-skill

Conducts security audits and vulnerability research across codebases, APIs, services, and CLI tools.

Stars26.8k
7 days+3.1k stars+12.9%
30 days+23.5k stars+722.5%
39
google/skills

A set of DevOps skills for Google Cloud, covering authentication, onboarding, and gcloud CLI operations.

Stars21.1k
7 days+480 stars+2.3%
30 days+1.4k stars+7.0%
52
Jeffallan/claude-skills

A collection of engineering skills for full-stack development, including Angular 17+ architecture, .NET Core expertise, and system design documentation.

Stars11.8k
7 days+89 stars+0.8%
30 days+409 stars+3.6%
64
SimoneAvogadro/android-reverse-engineering-skill

Decompiles APK, XAPK, JAR, and AAR files to trace Android architecture, API endpoints, and network call flows.

Stars8k
7 days+66 stars+0.8%
30 days+272 stars+3.5%
69
trailofbits/skills

Security auditing skills for vulnerability hunting, threat modeling, and detecting prompt injection risks in AI-integrated CI/CD pipelines.

Stars7.4k
7 days+104 stars+1.4%
30 days+420 stars+6.0%
72
SnailSploit/Claude-Red

Red team methodology for Active Directory attacks, covering reconnaissance, privilege escalation, persistence, and ADCS exploitation.

Stars7.4k
7 days+180 stars+2.5%
30 days+4.3k stars+141.3%
88
rehan-remade/universal-modder

Processes art into game-ready files via sprite cutout, palette pixelation, seamless texture generation, and 3D model rendering into isometric or top-down sprite frames.

Stars5.8k
7 days+4k stars+227.1%
30 days+5.8k starsCreated 9 days ago
102
elementalsouls/Claude-BugHunter

An Android red-team pipeline that automates APK acquisition, jadx decompilation, secret grepping, and Frida instrumentation.

Stars4.8k
7 days+77 stars+1.6%
30 days+421 stars+9.6%
134
ljagiello/ctf-skills

Provides AI and machine learning attack techniques for CTF challenges, including adversarial examples, model extraction, and LLM jailbreaking.

Stars3.4k
7 days+36 stars+1.1%
30 days+196 stars+6.1%
149
cloudflare/skills

Technical skills for building with the Cloudflare Agents SDK, managing Basin analytics workflows, and configuring Zero Trust SASE deployments.

Stars3k
7 days+49 stars+1.6%
30 days+211 stars+7.5%
152
Tiger3807861189/J-Space-Cognition-Suite

A workspace management skill for maintaining durable state, evidence, and consistency during long-horizon AI reasoning and repository engineering.

Stars3k
7 days0 stars-0.1%
30 days0 stars-0.6%
163
elementalsouls/Claude-OSINT

Automates external OSINT reconnaissance pipelines, including secret scanning and multi-stage discovery for authorized security engagements.

Stars2.8k
7 days+73 stars+2.7%
30 days+210 stars+8.1%
183
yaklang/hack-skills

Expert attack playbooks covering Active Directory exploitation, API security bypasses, and advanced penetration testing techniques.

Stars2.4k
7 days+62 stars+2.6%
30 days+268 stars+12.5%
185
google/mantis

A security review toolkit for AI agents featuring skills for vulnerability chaining, risk calibration, and automated remediation.

Stars2.4k
7 days+207 stars+9.5%
30 days+1.3k stars+112.9%
197
P4nda0s/reverse-skills

A set of skills for Android DEX dumping, iOS app decryption, Frida hook generation, IDAPython scripting, structure/symbol recovery, Unity IL2CPP symbol extraction, and Unicorn emulation.

Stars2.2k
7 days+30 stars+1.4%
30 days+132 stars+6.2%
206
Leanmcp/gateway-skills

Development style guides for the Claude Code codebase and diagnostic tools for tau2-bench evaluation analysis.

Stars2.1k
7 days—History unavailable
30 days—History unavailable
208
awesome-skills/code-review-skill

Provides multi-language code review guidance covering architecture, security audits, and performance analysis for pull requests.

Stars2.1k
7 days+38 stars+1.9%
30 days+156 stars+8.1%
273
utkusen/sast-skills

A skill collection that turns AI coding assistants into SAST scanners for 15+ vulnerability classes including injection, authentication, and business logic flaws.

Stars1.3k
7 days+5 stars+0.4%
30 days+25 stars+1.9%
276
yaojingang/yao-open-skills

A business-oriented skill set featuring professional code review services and domain knowledge graph construction tools.

Stars1.3k
7 days+2 stars+0.1%
30 days+11 stars+0.8%
278
BehiSecc/VibeSec-Skill

A secure coding guide for web application development and audit, covering major vulnerability classes with patterns, bypass prevention, and checklists.

Stars1.3k
7 days+10 stars+0.8%
30 days+47 stars+3.7%
279
uphiago/recon-skills

A security skill set covering SAML SSO attacks, Docker privilege escalation, and the construction of cross-attack chains.

Stars1.3k
7 days+6 stars+0.5%
30 days+42 stars+3.4%
296
pashov/skills

Generates Solidity fuzz suites for Echidna and Medusa from Foundry or Hardhat projects and converts natural language properties into Solidity assertions.

Stars1.2k
7 days+17 stars+1.4%
30 days+92 stars+8.1%
310
CharlesWiltgen/Axiom

Technical guidance for Apple platform development focusing on Apple Intelligence integration, CoreML, and WCAG accessibility compliance.

Stars1.2k
7 days+10 stars+0.8%
30 days+46 stars+4.0%
321
BagelHole/DevOps-Security-Agent-Skills

A library of agent-ready skills for automating DevOps security, infrastructure compliance, and centralized audit logging.

Stars1.1k
7 days+19 stars+1.7%
30 days+77 stars+7.2%
328
raroque/vibe-security-skill

Audits codebases for AI-introduced security issues: exposed secrets, broken access control, insecure payments, and authentication flaws in vibe-coded applications.

Stars1.1k
7 days+25 stars+2.3%
30 days+99 stars+9.9%
377
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Expert-level compliance skills for security frameworks and data privacy regulations including ISO 27001, SOC 2, NIST CSF, CCPA, and GDPR.

Stars944
7 days+13 stars+1.4%
30 days+55 stars+6.2%
407
BrownFineSecurity/iothackbot

A bundle of Claude Skills for IoT pentesting across mobile, hardware, firmware, and network layers—with APK decompilation, UART/JTAG probing, firmware threat scanning, and IoT traffic analysis.

Stars859
7 days+6 stars+0.7%
30 days+24 stars+2.9%
432
suleimanodetoro/skills

Guidelines for designing and implementing responsive product interfaces, visual hierarchies, and design system surfaces.

Stars788
7 days0 stars0.0%
30 days0 stars-6.3%
437
MicrosoftDocs/Agent-Skills

Expert knowledge for Azure Active Directory B2C development, covering custom policies, IdP configuration, API security, and deployment patterns.

Stars777
7 days+7 stars+0.9%
30 days+39 stars+5.3%
443
Archive228/loopkit

A library of coding agent skills featuring accessibility auditing and active memory management for consistent AI development workflows.

Stars755
7 days0 stars-0.3%
30 days+1 stars+0.1%
458
dmmulroy/cloudflare-skill

Technical guidance for Cloudflare Workers, Pages, storage (KV, D1, R2), AI tools, and infrastructure-as-code deployment.

Stars727
7 days0 stars0.0%
30 days0 stars-0.3%
465
LukasNiessen/terrashark

A failure-mode workflow for Terraform and OpenTofu that catches identity churn, secret exposure, blast radius issues, CI drift, and compliance gaps during generation, review, and delivery.

Stars715
7 days0 stars0.0%
30 days+397 stars+124.8%
510
7onez/cti-expert

An OSINT and CTI analysis toolkit for infrastructure pivoting, breach triage, digital footprint review, and structured threat reporting.

Stars607
7 days+2 stars+0.3%
30 days+18 stars+3.1%
538
aoyunyang/spider-king-skill

A web protocol reverse engineering skill that transforms browser-based interactions into Python collectors for handling tokens, fingerprints, and encrypted responses.

Stars509
7 days+4 stars+0.8%
30 days+30 stars+6.3%
565
LukasNiessen/kubernetes-skill

A failure-mode diagnostic workflow for Kubernetes manifests that identifies six categories of configuration risk and produces remediated YAML, Helm values, Kustomize overlays, and policy rules with validation steps.

Stars446
7 days+8 stars+1.8%
30 days+50 stars+12.6%
595
DragonJAR/Android-Pentesting-Skill

Performs Android APK security audits using static analysis, dynamic instrumentation with Frida and Objection, and IPC component abuse testing.

Stars395
7 days+16 stars+4.2%
30 days+36 stars+10.0%
596
currents-dev/playwright-best-practices-skill

Provides best practices for Playwright E2E and component testing, covering flaky test resolution, Page Object Model implementation, API mocking, and accessibility testing.

Stars394
7 days+8 stars+2.1%
30 days+21 stars+5.6%
609
agamm/claude-code-owasp

Automates security reviews and threat modeling using OWASP Top 10, ASVS 5.0, and specialized security standards for LLM and agentic applications.

Stars377
7 days+3 stars+0.8%
30 days+19 stars+5.3%
627
LumosLab-Innovation/OpenHunterAI

A security assessment tool for red-teaming web, API, and AI applications to validate vulnerabilities and implement fixes.

Stars330
7 days+1 stars+0.3%
30 days+328 stars+16400.0%
657
tanviet12/vbsec

Scans AI-generated code for 21 common security vulnerabilities with bilingual reporting, live CVE lookups, and automated patching.

Stars288
7 days+2 stars+0.7%
30 days+23 stars+8.7%
661
SunWeb3Sec/llm-sast-scanner

A general-purpose SAST skill for analyzing source code vulnerabilities across 34 classes using taint tracking and pattern matching.

Stars287
7 days0 stars0.0%
30 days+4 stars+1.4%
665
kitlangton/2password

A wrapper for 1Password that allows AI agents to find, save, and inject secrets, API keys, and credentials into commands or environment files.

Stars282
7 days—History unavailable
30 days—History unavailable
669
caido/skills

A Caido SDK integration for searching HTTP history with HTTPQL, managing replay sessions, and executing proxied curl requests.

Stars279
7 days+1 stars+0.4%
30 days+6 stars+2.2%
683
dinosn/raptor-loop-hunt

An autonomous security research loop that performs multi-altitude vulnerability hunting and verification across source code.

Stars264
7 days+33 stars+14.3%
30 days+47 stars+21.7%
699
sv-number/skills

Rents temporary private phone numbers via API to receive SMS verification codes for account signups and 2FA testing.

Stars200
7 days0 stars-0.5%
30 days0 stars-27.0%