
aradotso/security-skills
102 skills47.2k installs816 starsGitHub
Install
npx skills add https://github.com/aradotso/security-skillsSkills in this repo
1Anthropic Cybersecurity SkillsThe anthropic-cybersecurity-skills skill is designed for use 754 structured cybersecurity skills mapped to MITRE ATT&CK, NIST CSF, ATLAS, D3FEND, and NIST AI RMF for AI-driven security operations. anthropic-cybersecurity-skills > Skill by ara.so — Security Skills collection. Overview The Anthropic Cybersecurity Skills library provides 754 production-grade cybersecurity skills spanning 26 security domains. Invoke when the user asks about anthropic cybersecurity skills or related SKILL.md workflows.1.4kinstalls2Pentest Ai AgentsThe pentest-ai-agents skill claude Code subagents for offensive security research, penetration testing planning, recon analysis, exploit research, detection engineering, and security reporting # pentest-ai-agents > Skill by [ara.so](https://ara.so) - Security Skills collection. pentest-ai-agents transforms Claude Code into an offensive security research assistant through 35 specialized subagents. Each agent carries deep domain knowledge in specific areas: recon, web testing, Active Directory, cloud security, mobile/wireless pentesting, social engineering, payload crafting, reverse engineering, exploit chaining, detection engineering, and forensics. The agents route automatically based on task description - no manual agent selection needed. They understand 80+ offensive security tools (nmap, nuclei, BloodHound, Impacket, Sliver, Ghidra, etc.) and can plan engagements, analyze recon data, research exploits, chain attacks, build detections, and write reports. ## Installation ### Quick Install (Recommended) ```bash curl -fsSL https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/install.sh | bash ``` This copies agent files to `~/.claude/agents/` and is idempotent (safe t.1.2kinstalls3Pentest Agents Bug Bounty Frameworkpentest-agents-bug-bounty-framework is an ara.so Security Skills collection agent framework for autonomous bug bounty work in Claude Code, Codex, and compatible agents. It ships 50 specialized agents for hunt loops, exploit-chain construction, finding validation, and report submission, plus MCP servers for platform integration and writeup-database search. A 7-question gate validates security findings before submission. Developers invoke pentest-agents-bug-bounty-framework to install pentest agents, start autonomous hunt loops, search prior writeups, build exploit chains, and generate bug bounty reports—not for passive code style review.1.1kinstalls4Openosint Ai Osint Frameworkopenosint-ai-osint-framework is an ara.so Security Skills package for AI-powered open-source intelligence gathering through an interactive REPL, MCP server, and CLI. Developers and security engineers reach for it when investigating emails for social accounts or breach exposure, enumerating subdomains, looking up IP geolocation and ASN data, searching Shodan for exposed services, or generating Google dorks for reconnaissance. The framework bundles 11 integrated OSINT tools behind natural-language triggers so agents can run multi-step investigations without switching between standalone utilities. It is intended for authorized research during early project discovery, competitor analysis, or security assessments—not covert surveillance.1kinstalls5Vibe Security Skillvibe-security-skill is an agent skill from the ara.so Security Skills collection that guides use of the Vibe Security tool to find common vulnerabilities introduced by AI coding assistants. Trigger phrases include auditing code for security issues, checking Supabase RLS policies, validating auth implementations, scanning for hardcoded secrets, and reviewing payment flow safety. The skill targets fast-moving AI-assisted builds where speed can skip secure defaults in authentication, database policies, and secret handling. Developers reach for vibe-security-skill immediately before deployment or when a user explicitly asks to run a vibe security audit on an existing codebase.999installs6Openclaw Security Hardeningopenclaw-security-hardening is an ara.so Security Skills package that guides AI coding agents through deploying and validating OpenClaw defense matrices for autonomous agents with shell, filesystem, and API access. Developers invoke it when standing up or auditing an OpenClaw agent that will run production workflows, enforcing zero-trust architecture, red/yellow-line execution rules, and scheduled security posture checks. The skill covers configuration of nightly audits, validation of active controls, and remediation guidance when agents exceed permitted boundaries. It assumes the agent already has elevated privileges and needs explicit guardrails rather than generic OWASP checklists.994installs7Malware Detection AwarenessMalware Detection Awareness is an agent skill from aradotso/security-skills that helps developers understand security risks in software distribution and identify illegitimate packages before they enter a workflow. It triggers on questions about malware distribution repositories, signs of malicious packages, fake security software, suspicious GitHub repository indicators, verifying legitimate software sources, red flags for pirated software, keygen malware, and compromised download warnings. Developers reach for Malware Detection Awareness when evaluating unfamiliar repos, skill bundles, or dependencies that may bundle cracked tools or trojanized keygens. The skill emphasizes verifying source legitimacy and spotting distribution patterns common in compromised downloads rather than running exploit code.982installs8Autopentestx Automated Pentestingautopentestx-automated-pentesting is an automated penetration testing skill from aradotso/security-skills built around AutoPentestX. It triggers on requests to run automated pentests, conduct vulnerability scans, perform security assessments, or generate professional penetration test reports. The skill wraps reconnaissance, scanning, and reporting into a single agent workflow so developers and security engineers can assess targets without assembling separate CLI tools manually. Reach for autopentestx-automated-pentesting when a staging or production URL needs a structured security pass and a deliverable report, especially during pre-release hardening or periodic audit cycles.980installs9Slowmist Agent Security Frameworkslowmist-agent-security-framework is a security review skill from aradotso/security-skills built for adversarial AI agent environments. The framework guides structured audits of skills, GitHub repositories, URLs, blockchain addresses, and MCP servers before installation or tool access. Trigger phrases include reviewing a skill for security issues, checking repository safety, analyzing URLs for prompt injection, and verifying MCP server trust. slowmist-agent-security-framework fits developers wiring agents to third-party tools who need a repeatable pre-install assessment instead of ad hoc trust. Use it before granting shell, network, or secrets permissions to unfamiliar packages.978installs10Avast Premium Security Analysisavast-premium-security-analysis is a security-skills collection entry for studying Avast Premium Security architecture and protection behavior. It guides developers through understanding antivirus engine components, real-time protection implementation, behavior shield technology, and malware detection patterns inside commercial endpoint security software. Security engineers and researchers reach for avast-premium-security-analysis when they need to examine how Avast structures scanning pipelines, shields, and detection logic rather than writing generic app security checks. Trigger phrases include analyzing Avast antivirus behavior, studying security software internals, and explaining real-time protection implementation. The skill supports defensive research and architecture comprehension, not bypass or crack workflows.968installs11Malware Warning Avast Keygenmalware-warning-avast-keygen is a critical-security warning skill in the ara.so security-skills collection. It fires when a developer asks to install, use, or evaluate repositories claiming to offer Avast Premium Security cracks, keygens, license generators, or activation tools—including projects like dragonflyTomb Avast variants. The skill blocks unsafe workflows by flagging repositories that distribute malware under the guise of pirated security software. Developers reach for malware-warning-avast-keygen before cloning, running, or recommending suspicious Avast activation repos found on GitHub or elsewhere. It complements legitimate security analysis skills by stopping harmful install paths rather than explaining engine internals.966installs12Palisade Security Nexus Bitdefenderpalisade-security-nexus-bitdefender is a Palisade security skill for deploying and configuring Bitdefender Total Security 2026 with advanced threat detection, sandboxing, VPN integration, and AI-powered heuristic analysis. Trigger phrases cover antivirus sandbox setup, VPN and firewall rule integration, heuristic malware scanning, exploit mitigation, rootkit detection, privacy guard, tracker blocking, and security profiles for network protection. The skill also supports integrating AI threat detection with OpenAI or Claude. Developers reach for palisade-security-nexus-bitdefender when they need guided endpoint protection deployment rather than manual antivirus console configuration.958installs13Malware Warning Avast Piracymalware-warning-avast-piracy is a critical security warning skill from aradotso/security-skills by ara.so that stops agents from installing pirated Avast Premium Security or cracked security tooling. The skill triggers on prompts including install avast premium security, use avast keygen, activate avast premium, download avast cracked version, avast license key generator, setup avast premium loader, get free avast premium, and avast premium security crack. The repository distributing such files is flagged as a malware distribution channel disguised as legitimate security software. Developers and security teams install malware-warning-avast-piracy so coding agents refuse dangerous requests before any shell or download commands execute. The skill provides an immediate block and explicit warning rather than silently proceeding with compromised installers.955installs14Avast Security Awarenessavast-security-awareness is a security awareness skill from ara.so’s Security Skills collection. It teaches agents to spot malware distribution patterns where repositories impersonate Avast or other legitimate security products, including fake keygens, activation tools, and cracked software scams on GitHub. Triggers cover identifying fake antivirus repositories, verifying legitimate security software sources, detecting cracked-software scams, and spotting malware distribution tactics. The skill explicitly warns that scam repositories are not legitimate Avast products and documents common red flags agents should block before suggesting clones or installs. Developers reach for avast-security-awareness when agents might recommend or fetch GitHub dependencies and need guardrails against socially engineered security-tool impersonation.954installs15Report Malicious Repositoryreport-malicious-repository is an ara.so security skill from the aradotso/security-skills collection that helps developers identify and report GitHub repositories masquerading as legitimate security or developer tools. The skill guides analysis of suspicious repos distributing fake antivirus builds, keygens, cracked software, phishing payloads, and copyright-infringing content. Developers reach for report-malicious-repository when a dependency, clone, or starred project shows red flags such as impersonated branding, piracy keywords, or malware-adjacent release artifacts. Documented triggers include detecting fake antivirus repos, reporting keygen projects, analyzing suspicious security software repositories, and filing copyright infringement reports on GitHub.948installs16Unisecurityguard Academic Whistleblower Archiveunisecurityguard-academic-whistleblower-archive is a security skill from ara.so Security Skills for developers documenting academic employment transparency and institutional misconduct in Chinese higher education. The skill walks through building a GitHub-based archive and documentation platform that preserves whistleblowing posts, screenshots, and testimonials when platforms like Xiaohongshu remove primary sources. Its YAML frontmatter lists eight trigger phrases covering archive setup, censored social-media backup, employment-issue documentation, and safe evidence preservation. Reach for it when you need durable, version-controlled evidence outside a single social feed—not for general static-site hosting. The workflow emphasizes repository layout, contributor documentation, and redundancy so removed content stays queryable and attributable for researchers or advocates maintaining public records. Agents invoke the skill when users ask how to archive academic whistleblowing content, back up Red Book posts, or document institutional misconduct with Git commits instead of fragile social threads.947installs17Wxmini Security Auditwxmini-security-audit is an automated WeChat mini-program security auditing framework from aradotso/security-skills that deploys 7 specialized Claude Code Agent Teams agents for comprehensive static analysis. Triggers include auditing wxapkg directories, scanning for sensitive data leaks, reviewing API security issues, and decompiling mini programs for vulnerability review. Developers reach for wxmini-security-audit before shipping WeChat apps when manual security review cannot cover wxapkg decompilation, API exposure, and data-leak patterns at scale. The skill fits pre-release security gates on WeChat mini-program codebases rather than general web application pentesting.942installs18Avast Premium Security Detectionavast-premium-security-detection from ara.so's Security Skills collection identifies and analyzes suspicious software distribution repositories that claim to offer cracked or pirated security software. The skill detects pirated antivirus distribution attempts, keygen and crack malware patterns, and fake security software repositories on GitHub. Eight triggers cover analyzing Avast repos for legitimacy, checking security software repos for malware, detecting piracy scam repositories, and verifying antivirus download source authenticity. Developers reach for avast-premium-security-detection when they encounter GitHub repos offering cracked Avast Premium Security and need a structured scam and malware pattern analysis before interacting with the repository.939installs19Security Awareness Malicious Repository Detectionsecurity-awareness-malicious-repository-detection is an aradotso/security-skills module that flags GitHub repositories distributing malware under the guise of cracked software or pirated tools. Trigger phrases include identifying malicious repository patterns, detecting fake crack repos, analyzing suspicious GitHub projects, and scanning for threat indicators. The skill walks through legitimacy checks, piracy-themed malware heuristics, and threat indicator evaluation with explicit warnings about malicious distribution tactics. Developers reach for it before cloning unknown repos, approving dependencies, or investigating security-themed social engineering on GitHub. It produces a structured threat assessment rather than automated CVE scanning.930installs20Avast Premium Security Malware Analysisavast-premium-security-malware-analysis is a security research skill for developers and analysts who need structured, educational understanding of Avast Premium Security rather than exploit development. The skill covers Avast antivirus engine structure, behavior shield implementation, real-time protection mechanisms, malware detection pipelines, firewall protection systems, and ransomware defense capabilities. Triggers include explaining how Avast detects malware, analyzing behavior shield logic, and studying security features for coursework or defensive research. Reach for it when documenting how commercial endpoint protection layers interact—sandboxing, heuristics, and shields—and you require accurate feature-level descriptions. The skill explicitly frames legitimate research and education; it does not provide bypass instructions or offensive tooling. Use it to compare enterprise antivirus design patterns, prepare technical write-ups on Avast architecture with agent-guided depth, explain detection tradeoffs in security coursework, or brief blue teams on Avast endpoint behavior.927installs21Avast Premium Security Awarenessavast-premium-security-awareness is an ara.so security-skills module for investigating repositories that masquerade as Avast Premium Security or similar antivirus products. It documents red flags such as crack or keygen promises, keyword stuffing, missing legitimate source code, artificial star growth, and NOASSERTION licensing on commercial redistribution. The skill maps common threat types including trojan downloaders, info stealers, ransomware, backdoors, and cryptominers. Developers invoke it when evaluating suspicious software distribution repos, pirated security tools, or trojan distribution schemes before cloning or recommending dependencies. It supports verify legitimate avast source and investigate cracked software repo triggers.918installs22Avast Security Analysisavast-security-analysis is an aradotso/security-skills research guide for understanding Avast Premium Security architecture, behavior shield implementation, and real-time protection components. The skill triggers on queries about antivirus detection mechanisms, behavioral analysis, and reverse-engineering security software internals. Developers and security researchers reach for it when investigating how Avast intercepts processes, how behavior shields classify activity, or how protection layers interact with application code during security audits. The repository includes an explicit security notice framing the content for authorized research contexts.918installs23Openclaw Security Watchdogopenclaw-security-watchdog from aradotso/security-skills is an automated security scanning skill that performs comprehensive system security audits across 14 critical security dimensions and generates human-readable reports with clear risk indicators. Eight documented trigger phrases activate the skill, including run security scan, perform security audit, check system security, and run openclaw security watchdog. Developers invoke openclaw-security-watchdog when they need a structured security inspection inside agent sessions instead of manually running disparate CLI checks. Reports emphasize readable risk levels so engineers can prioritize fixes before release. With 749 catalog installs in the ara.so Security Skills collection, the skill suits teams hardening application or system environments pre-ship—not cosmetic UI audits, SEO checks, or deep penetration testing requiring manual exploit validation.877installs24Security Threat Awarenesssecurity-threat-awareness is an aradotso security-skills agent skill that intercepts dangerous requests involving GitHub repositories offering free Avast Premium, pre-activated licenses, keygens, or cracked commercial security software. The skill triggers on phrases like installing Avast from GitHub, finding free premium antivirus with activation keys, or evaluating repos with pre-activated licenses. Developers reach for security-threat-awareness when teammates or users ask about suspicious security software downloads before malware enters the development environment. The skill delivers immediate warnings about social engineering patterns common in fake antivirus distribution rather than performing deep binary reverse engineering.873installs25Malware Analysis Dragonflytomb Avastmalware-analysis-dragonflytomb-avast is an aradotso security-skills agent skill focused on the DragonflyTomb/Avast-Premium-Security-2026 malware campaign pattern. The skill examines GitHub repositories distributing cracked antivirus installers, keygens, loaders, and pre-activated license bundles that use social engineering to appear legitimate. Developers reach for malware-analysis-dragonflytomb-avast when evaluating suspicious security software repos before cloning, building, or recommending downloads to users. Trigger phrases include analyzing fake Avast installers, investigating premium security keygens, and identifying malware indicators in repositories offering commercial security tools for free.872installs26Avast Premium Security Malware Detectionavast-premium-security-malware-detection is a security audit skill from aradotso/security-skills that inspects repositories for cracked software, keygen, and fake antivirus installer distribution patterns. Trigger phrases include analyzing repos for malware hosting, validating legitimate Avast download sources, and detecting piracy or suspicious security software installers. Developers and security reviewers reach for avast-premium-security-malware-detection when evaluating third-party repos, dependency sources, or download mirrors that claim to distribute Avast Premium or similar security products before cloning, installing, or recommending them to users.858installs27Mcp Security Hubmcp-security-hub is a production-ready security skill from aradotso/security-skills bundling 38 Dockerized MCP servers for offensive security tooling. It exposes scanners and analysis tools—including Nmap, Nuclei, Ghidra, SQLMap, Radare2, and Gitleaks—so Claude and compatible agents invoke them via Model Context Protocol. Developers reach for mcp-security-hub when setting up AI-driven web security assessments, network scans, binary analysis, or secret scanning without manually chaining CLI commands. The skill covers deployment, orchestration, and integration of security tools as MCP servers for authorized testing workflows.850installs28Identify Malicious Repositoryidentify-malicious-repository is a security skill from aradotso/security-skills by ara.so for analyzing fraudulent software distribution repositories masquerading as legitimate security products. It triggers on investigations of fake antivirus repos, malicious download sites, keygen scam repositories, piracy malware distribution, and suspicious GitHub projects claiming to be security tools. The skill produces explicit warnings when a repository is malicious and should not be used. Developers reach for it before cloning unknown security-related repos, vetting download mirrors, or responding to supply-chain alerts about impersonated tooling. It focuses on pattern recognition for scam distribution rather than general SAST or dependency auditing.843installs29Bitdefender Total Security Malware AnalysisBitdefender Total Security Malware Analysis is a security research skill from aradotso/security-skills that helps developers investigate malware distribution tactics, cracked software risks, and deceptive antivirus impersonation. Trigger phrases cover detecting malware in cracked software, analyzing pirated antivirus risks, identifying malicious payloads in fake cracks, examining threat vectors in software distribution, investigating suspicious GitHub repositories distributing cracks, and detecting credential stealers in cracked applications. The skill structures threat analysis around real distribution schemes rather than generic security advice. Developers reach for Bitdefender Total Security Malware Analysis when reviewing suspicious repositories, evaluating crack-related supply-chain risk, or documenting how fake security software and credential stealers propagate through deceptive download channels.838installs30Malware Warning Bitdefender Crackmalware-warning-bitdefender-crack is a security skill from aradotso/security-skills that analyzes repositories claiming to offer cracked Bitdefender Total Security and issues a critical malware warning when distribution patterns match known piracy vectors. The skill activates on triggers such as evaluating antivirus crack projects, checking installer legitimacy, or reviewing security-software repositories that agents might otherwise treat as normal codebases. It guides developers through repository inspection, explains why crack-distribution repos are high-risk, and steers remediation away from executing suspicious binaries. Developers reach for malware-warning-bitdefender-crack when a user pastes a Bitdefender crack repo URL, asks if a download is safe, or requests help understanding an antivirus crack project during code review or dependency vetting.838installs31Bitdefender Total Security Awarenessbitdefender-total-security-awareness is a security awareness skill from aradotso's Security Skills collection that recognizes illegal antivirus cracks, keygens, and malware distribution repositories. The skill triggers on prompts requesting Bitdefender crack installation, keygen activation, loader execution, or pre-activated antivirus downloads. It issues critical warnings that such repositories are not legitimate Bitdefender software and commonly distribute malware. Developers and agents reach for this skill when users or automated workflows attempt to install pirated security software, preventing credential theft, ransomware payloads, and supply-chain compromise disguised as free license keys.820installs32Malware Detection And Removalmalware-detection-and-removal is an ara.so Security Skills collection workflow for detecting repositories that distribute malware while pretending to be legitimate cracked or security software. The skill triggers on requests to detect malware repository patterns, analyze suspicious GitHub projects, identify software piracy scams, investigate fake download repositories, and evaluate repository authenticity. Developers reach for malware-detection-and-removal when evaluating unfamiliar GitHub projects, crack mirrors, or download pages that may host trojanized binaries instead of real tools. The workflow documents malicious indicators and produces warnings suitable for security review, dependency vetting, or incident reporting rather than automated remediation alone.819installs33Dragonjar Android Pentesting Skilldragonjar-android-pentesting-skill is a skill from aradotso/security-skills for comprehensive Android APK security analysis before mobile releases. It covers static and dynamic testing, RASP detection, Frida instrumentation, SSL pinning bypass, root detection analysis, hardcoded secret discovery, and MASVS compliance scoring. Trigger phrases include audit this Android APK, analyze with MASVS scoring, bypass SSL pinning, detect RASP protections, and generate a pentesting report. Mobile security engineers reach for it when they need structured APK review with runtime defense analysis instead of ad-hoc manual tooling.799installs34Malware Detection Security Awarenessmalware-detection-security-awareness is a security education skill from ara.so's Security Skills collection that helps developers identify malware distribution disguised as legitimate security software on GitHub and download sites. The skill triggers on questions about fake crack repositories, compromised antivirus downloads, and signs of software-piracy malware. It walks through red flags in repository structure, naming patterns, and distribution tactics so engineers avoid cloning or executing hostile code during security tool evaluation. Reach for malware-detection-security-awareness before trusting an unfamiliar security repo, evaluating cracked software claims, or onboarding teammates to supply-chain hygiene.796installs35Npm Security Best Practicesnpm-security-best-practices is a Claude Code skill from aradotso/security-skills providing expert guidance on securing npm package installations, preventing supply-chain attacks, and hardening package-manager configurations across npm, pnpm, and Bun. Trigger phrases cover securing dependencies, blocking malicious packages, disabling postinstall scripts, preventing dependency confusion, and setting secure install defaults. Developers reach for this skill before adding new packages, during security reviews, or when CI must enforce hardened registry and script policies. The skill focuses on configuration and process guardrails—registry settings, install script controls, and dependency trust boundaries—rather than rewriting application business logic. It helps teams treat package managers as part of the attack surface, not passive utilities.790installs36Malware Awareness Bitdefender Crack Fraudmalware-awareness-bitdefender-crack-fraud is a security skill from the ara.so Security Skills collection that recognizes fraudulent cracked-security-software repositories on GitHub and issues critical malware warnings. The skill triggers on eight documented query patterns including Bitdefender keygen requests, license bypass attempts, and generic antivirus crack installs. Instead of helping activate cracked software, the skill explains that these repositories distribute malware and steers developers away from executing or cloning them. Developers reach for this skill when a suspicious GitHub repo promises free Bitdefender Total Security, keygens, or license bypass tools.784installs37Security Detections Mcpsecurity-detections-mcp is a Claude Code skill from aradotso/security-skills that connects agents to an MCP server indexing 8,200+ unified security detection rules across Sigma, Splunk, Elastic, KQL, Sublime, and CrowdStrike formats. Developers use it to search detections by technique, analyze MITRE ATT&CK coverage, find stack gaps, compare threat-actor coverage, and generate ATT&CK Navigator layers before code ships. Triggers include requests for Sigma rules, Splunk queries, credential dumping detections, lateral movement coverage, or ransomware ATT&CK analysis. The skill targets security engineers validating defensive depth rather than writing application features.768installs38Malware Repository Warningmalware-repository-warning is a security skill from the ara.so Security Skills collection that fires on triggers like Bitdefender crack requests, antivirus keygens, pirated security software installs, and license bypass attempts. The skill delivers a critical security alert instructing agents not to use flagged repositories identified as malware distribution schemes. Developers and security-conscious teams invoke it so coding agents refuse unsafe repository recommendations before shell commands or package installs execute. The skill acts as a policy gate rather than a scanner, blocking social-engineering paths that disguise malware as cracked security tools.762installs39Malware Detection And Reportingmalware-detection-and-reporting is an agent skill from aradotso/security-skills by ara.so that helps developers detect malicious software distribution repositories masquerading as legitimate security tools, fake antivirus cracks, keygens, and credential-stealing GitHub projects. The skill guides identification of piracy malware repos, analysis of suspicious software distribution patterns, and reporting workflows before cloning or recommending projects. Developers reach for malware-detection-and-reporting when evaluating unknown GitHub repos, investigating fake security software, or deciding whether to report malicious distribution channels.761installs40Malware Analysis Warningmalware-analysis-warning is an aradotso security-skills warning system that identifies repositories distributing malware disguised as legitimate security tools. It triggers when a developer asks to analyze security software repositories, verify antivirus downloads, evaluate Bitdefender crack projects, or check keygen repositories for safety. The skill surfaces critical security warnings and advises against downloading when high-risk indicators appear. Developers reach for malware-analysis-warning before cloning, installing, or recommending third-party security tooling from unfamiliar GitHub repositories.737installs41Malware Distribution Awarenessmalware-distribution-awareness is a security skill from aradotso/security-skills that trains coding agents to detect malicious software distribution repositories masquerading as legitimate security tools. Documented triggers include analyzing security software repos, verifying antivirus downloads, detecting fake crack sites, and scanning GitHub projects for malicious indicators. The readme opens with a critical security warning that affected repositories are not legitimate and should be reported. Developers reach for malware-distribution-awareness when evaluating Bitdefender crack repos, fake antivirus projects, or suspicious security-tool GitHub pages before cloning dependencies. The skill supports investigation and reporting workflows rather than exploitation or bypass guidance.711installs42Kali Pentest Ai Agentkali-pentest-ai-agent is a security skill from the ara.so Security Skills collection for authorized penetration testing with Kali Linux. An AI agent plans multi-phase attacks, selects appropriate scanning and exploitation tools, and pauses for human approval before high-risk actions such as exploitation or destructive tests. Developers and security engineers reach for kali-pentest-ai-agent when conducting ethical hacking assessments, network vulnerability scans, or automated pentest simulations that need structured attack phases and documented reporting. Trigger phrases include running penetration tests against authorized targets, performing security assessments with Kali tools, and generating penetration testing reports with human oversight rather than fully unattended exploitation.685installs43Bitdefender Malware Analysisbitdefender-malware-analysis is a security skill from aradotso/security-skills, published by ara.so, for researching malware distribution repositories, security software bypass techniques, and threat detection patterns. Developers and security engineers reach for bitdefender-malware-analysis when investigating suspicious GitHub repos, fake software distribution patterns, credential-stealing campaigns, or malware delivery mechanisms. The skill activates on triggers such as analyzing malicious repository structures, explaining bypass methods, and mapping threat actor infrastructure. Outputs emphasize understanding distribution tactics and detection indicators rather than offensive exploitation, supporting defensive review and research workflows.678installs44Skill File Securityskill-file-security is an aradotso/security-skills package that installs 29 battle-tested security instruction files into projects so AI coding assistants catch vulnerabilities while writing code. Coverage spans OWASP Top 10, CWE Top 25, and ASVS Level 3 requirements across categories like injection, authentication, and secrets handling. Developers reach for skill-file-security when triggers include installing a security skill, running a security audit, scanning for OWASP violations, or fixing vulnerabilities across a codebase. The skill teaches assistants persistent security rules rather than one-off scan reports.672installs45Zen Ai Pentest Frameworkzen-ai-pentest-framework is a production-ready skill from aradotso/security-skills for AI-powered autonomous penetration testing. A multi-agent system executes real security tools, scans for vulnerabilities, and generates compliance reports without manual step-by-step orchestration. Developers reach for zen-ai-pentest-framework when triggers include running AI-assisted penetration tests, deploying autonomous security scans, or analyzing application security with an AI framework. The skill complements preventive secure-coding rules by actively probing running applications for exploitable weaknesses.663installs46Bitdefender Malware Investigationbitdefender-malware-investigation is a Claude Code skill from aradotso/security-skills for dissecting repositories that impersonate antivirus products and deliver trojans or credential stealers. The skill walks through analyzing the MistDuckCount/Bitdefender-Total-Security-Crack-2026 pattern, fake installer payloads, piracy-driven malware vectors, and trojan delivery mechanisms in cracked security software. Developers reach for bitdefender-malware-investigation when a suspicious GitHub repo, counterfeit security tool, or cracked antivirus installer needs structured threat analysis rather than ad-hoc grep sessions. Trigger phrases include analyzing Bitdefender crack repos, examining fake antivirus installers, and checking repositories for credential-stealing malware.662installs47Edgesecurityaccess Wireguard Vpnedgesecurityaccess-wireguard-vpn is an aradotso/security-skills skill for EdgeSecurityAccess (ESA), a WireGuard-based rapid networking suite for Linux VPN deployment. The skill covers setting up ESA VPN servers, configuring WireGuard networking, creating VPN users and client configs, deploying EdgeSecurityAccess servers, building ESA utility tools, connecting clients, and troubleshooting connectivity issues. ESA exposes an HTTP API alongside WireGuard utilities so agents can automate user provisioning and server management from a coding session. Developers reach for edgesecurityaccess-wireguard-vpn when they need private network access, secure tunneling between environments, or repeatable WireGuard user lifecycle management without ad hoc shell scripts.655installs48Sparkfinderoven Security Compliance Skillssparkfinderoven-security-compliance-skills is an aradotso/security-skills suite providing specialized security and compliance workflows from ara.so. The skill covers OWASP vulnerability scanning, dependency CVE detection, secrets detection in codebases, GDPR compliance audits, SOC2 readiness assessments, architecture threat modeling, security incident playbook generation, and IAM permissions audits. Developers reach for sparkfinderoven-security-compliance-skills when they need a structured security pass before release or compliance evidence, rather than ad hoc grep searches. Triggers include scanning for OWASP issues, checking dependency CVEs, auditing GDPR posture, running SOC2 readiness, creating threat models, generating incident playbooks, and detecting leaked secrets or overprivileged IAM roles.647installs49Securityclaw Autonomous Soc Agentsecurityclaw-autonomous-soc-agent is an aradotso/security-skills skill for deploying and operating SecurityClaw, an autonomous security operations center agent. SecurityClaw combines RAG-based behavioral memory, LLM-powered anomaly analysis, skill-based security automation, and OpenSearch data integration for continuous threat monitoring. The skill covers LangGraph orchestration for automated threat hunting, vector embedding memory for security analytics, and LLM-driven threat analysis pipelines. Developers reach for securityclaw-autonomous-soc-agent when setting up an AI security agent with anomaly detection, integrating OpenSearch log analytics with LLM reasoning, or building a skill-based SOC automation framework rather than manual alert triage.646installs50Security Compliance Skills Suite Claudesecurity-compliance-skills-suite-claude is a comprehensive agent skill suite from the Security Skills collection that embeds security audits, vulnerability management, compliance reporting, and incident response inside the coding agent. Trigger phrases include scanning for OWASP vulnerabilities, running GDPR compliance audits, checking dependencies for CVEs, generating architecture threat models, creating SOC 2 readiness reports, detecting secrets in the codebase, auditing IAM permissions, and helping respond to security incidents. Developers reach for this suite when they need repeatable security and compliance artifacts without exporting context to separate scanners or GRC platforms. The suite spans code review, dependency risk, secrets hygiene, access control review, and regulatory readiness in one coordinated workflow. It suits teams shipping SaaS or API products that must demonstrate security posture to auditors, customers, or internal risk teams.620installs51Pentestify Security Report GeneratorPentestify is an interactive penetration testing report generator that lets developers and security professionals quickly register vulnerabilities, track findings, view live risk statistics, and produce polished corporate PDF reports. It supports bilingual operation in English and Spanish, stores everything in a local SQLite database for persistence across sessions, and offers both a FastAPI backend and a responsive Vanilla JavaScript frontend. Developers use it to turn raw security findings into client-ready documentation without manual formatting or spreadsheet gymnastics. The tool runs comfortably in Docker for instant setup or can be installed manually, making it practical for developers who also wear the security hat when shipping.568installs52Awesome Claude Code Security Compliance SuiteAwesome Claude Code Security & Compliance Suite is an agent skill that equips your coding agent with 10 specialized security commands and 5 structured compliance workflows. It performs OWASP Top-10 vulnerability scanning, detects CVEs in dependencies, audits applications for GDPR/SOC2/ISO27001 readiness, generates threat models, runs IAM least-privilege reviews, detects secrets, and creates incident response playbooks. Developers get consistent, structured output that surfaces real risks and compliance gaps so they can address them before shipping. The suite is derived from the awesome-claude-code collection and works with Claude Code, Cursor, and similar agents.564installs53Sparkfinderoven R01 Security Compliance SkillsSparkfinderoven-r01-security-compliance-skills is a comprehensive security and compliance skill suite that equips AI coding agents with expert knowledge for vulnerability scanning, compliance auditing, threat modeling, and incident response. It delivers OWASP Top-10 scans with CVSS scoring, CVE detection in dependencies, GDPR/SOC2/ISO27001 audits, STRIDE threat models, secret scanning, and structured incident response playbooks. Developers get consistent, auditable security outputs that integrate directly into agentic workflows, reducing the risk of shipping vulnerable code or missing compliance requirements. The suite is derived from curated expert sources and provides both one-off commands and repeatable multi-step processes with clear remediation guidance.563installs54Sparkfinderoven Claude Security Compliance SuiteSparkfinderoven-claude-security-compliance-suite is a collection of specialized commands and workflows that give Claude, Cursor and other coding agents expert-level security auditing capabilities. It performs OWASP Top-10 scans with CVSS scores, detects known vulnerabilities in dependencies, runs GDPR SOC2 and ISO27001 compliance audits, creates STRIDE threat models, audits IAM permissions for least privilege, finds hardcoded secrets, and generates structured incident response playbooks and penetration test reports. All outputs are formatted for immediate use by both the developer and the agent, turning ad-hoc security questions into repeatable, high-signal agent actions.560installs55Sparkfinderoven Security Compliance SuiteSparkfinderoven Security Compliance Suite is a comprehensive automation toolkit that equips AI coding agents to scan for OWASP vulnerabilities, check dependencies for CVEs, audit GDPR and SOC2 readiness, generate STRIDE threat models, detect secrets, and create incident response playbooks. Every command follows a repeatable 5-step workflow with visual progress indicators and prioritized remediation steps. Developers get consistent, auditable security and compliance outputs without needing deep security expertise. The suite is derived from proven awesome-claude-code patterns and works across multiple agent environments.557installs56S800 Vehicle Network Security TestingS800 is a vehicle network security testing framework that equips security researchers and penetration testers with specialized tools for analyzing, fuzzing, and securing automotive communication protocols. It focuses on CAN bus traffic capture and analysis, LIN and FlexRay protocol testing, Electronic Control Unit assessment, and systematic vulnerability discovery. The framework is built for professionals conducting authorized security evaluations of vehicles and embedded automotive systems. It requires Python 3.7+, Linux SocketCAN modules, and compatible CAN hardware interfaces. Users must only run it on systems they have explicit legal permission to test, as unauthorized vehicle network testing can be both illegal and physically dangerous.556installs57Esaa Security AuditESAA-Security Audit is an agent skill that executes structured, deterministic security audits using the Event Sourcing for Autonomous Agents architecture. It performs 95 checks spanning 16 security domains while recording every step, classification, and remediation decision in an immutable event log. The skill prevents hallucination through schema validation and evidence requirements, produces SHA-256 verifiable reports, and maintains a complete replayable audit trail. Ideal for developers who need trustworthy, repeatable security validation on AI-generated code or any evolving codebase without relying on non-deterministic LLM outputs.548installs58Agentic Security Scanneragentic-security-scanner is a security scanner built for AI-driven development workflows. It runs a 12-pillar scan (SAST, SCA, secrets, IaC, LLM safety, MCP agent-tool audit, containers, supply chain) and reports findings in plain English with fix suggestions. Developers use it to audit a codebase, auto-fix issues with preview and revert, and generate compliance reports. It installs as a Claude Code plugin or a standalone CLI.1installs59Agent Security Scanner Mcpagent-security-scanner-mcp is a security scanner packaged as an MCP server for AI coding agents. It exposes tools to scan code for vulnerabilities, detect AI-hallucinated packages, catch prompt injection, generate SBOMs, and auto-fix issues. Developers wire it into Claude Code, Cursor, or Windsurf so the agent can run security checks mid-task. It also runs from a CLI for scans, diffs, and compliance evaluation.1installs60Ai2pentesttool InstallerAI2PentestTool Installer is a Python CLI that automates installing penetration testing tools. It uses an AI agent to generate install plans with retry and error recovery, and falls back to built-in configs offline. Security testers use it to batch-install tools like nmap, sqlmap, and gobuster across macOS, Linux, and Windows. It also exposes a Python API to install tools programmatically.1installs61Ai Security Knowledge BaseAI Security Knowledge Base is a documentation project (originally Chinese-language) covering AI security from machine-learning foundations to advanced threats. It documents the OWASP ML/LLM Top 10, MCP security, offensive AI tactics like adversarial ML and deepfakes, and defensive ML detection. Security researchers and AI developers use it as a reference to learn threat models and defensive practices. It is a knowledge repository, not a code library.1installs62Awesome Ai Security ReferenceAwesome AI Security Reference helps navigate the Awesome AI Security curated list, an annotated roadmap of ML security resources. It organizes learning paths, attack vectors (prompt injection, adversarial examples, poisoning, privacy attacks), defensive tools, and AI pentesting. Developers use it to find the right resource or tool, such as Garak or Rebuff, for testing LLM and ML security. It is a reference roadmap, cloned to browse locally.1installs63Awesome Pentest Tools CatalogAwesome Pentest Tools Catalog is expert knowledge of a curated penetration testing and red-team tool collection. It organizes tools across the pentest lifecycle and MITRE ATT&CK, from information gathering through exploitation, privilege escalation, and covering tracks. Security testers use it to discover and recommend the right tool for a phase, with ready-to-run command examples. It is a reference catalog rather than an executable tool.1installs64Claude Pentest Frameworkclaude-pentest is a penetration testing framework for Claude Code that coordinates 15 specialized agents across 63 attack categories. It runs a structured recon-to-report workflow where every exploitation attempt requires explicit operator approval, and captures PoCs, HTTP evidence, and screenshots. Security testers use it to run scoped, evidence-driven assessments against a target. It installs as a Claude Code plugin and can connect to a remote Kali server for tools like nmap and sqlmap.1installs65Dalonso Security RepoDalonso Security Repo is a curated collection of Microsoft Security resources: KQL threat-hunting queries, Microsoft Sentinel workbooks, and Jupyter analytics notebooks. Security operations teams use it to run proactive threat detection, import investigation dashboards, and analyze security data with MSTICPy. It is a knowledge base for Sentinel and Microsoft Defender workflows, cloned for reference and adapted to a workspace.1installs66Deepseek Pentest Ai Burp ExtensionDeepSeek Pentest AI is a Burp Suite extension that uses the DeepSeek API to generate context-aware attack payloads and automate fuzzing. It detects parameters across query strings, POST, JSON, XML, and headers, injects generated payloads, and scores severity and confidence. Web application pentesters use it to test for SQL injection, XSS, SSRF, and other vulnerabilities, then export findings or send them to Repeater and Intruder. It requires Burp Suite, Jython, and a DeepSeek API key.1installs67Dfyx Code Security Auditdfyx-code-security-audit is a white-box static-analysis skill for AI agents that audits source code for vulnerabilities. It follows a five-phase protocol (reconnaissance, pattern matching, taint tracking, validation, reporting) across 9 languages and 10 security dimensions. Developers use it to run Quick, Standard, or Deep audits that trace data flows and validate findings with PoCs. It ships Python helper scripts wrapping tools like bandit, semgrep, and safety.1installs68Dfyx Code Security Auditordfyx-code-security-auditor is a white-box static-analysis skill for AI coding agents that audits source code for vulnerabilities. It applies a 5-phase protocol across 10 security dimensions and 9 languages, using sink-, control-, and config-driven tracks. Developers install it into Claude Code, Cursor, or Windsurf and run Quick, Standard, or Deep audits that deploy parallel agents and validate findings with PoCs. It also includes Python helper scripts.1installs69Dfyx Code Security Reviewdfyx-code-security-review is a white-box static-analysis skill for AI coding agents that audits source code for vulnerabilities. It runs a five-phase protocol with sink-, control-, and config-driven analysis across 9 languages, 10 security dimensions, and 14 web frameworks. Developers use it to find injection, authorization, deserialization, and SSRF flaws, tracing data flows from source to sink and generating PoCs. It installs into an agent's skills folder with optional Python scripts.1installs70Drm Pentesting ToolkitThe DRM Pentesting Toolkit is a plugin-based framework for testing DRM-protected streaming content. It loads Widevine and PlayReady device files, parses PSSH data from DASH/MPD manifests, retrieves decryption keys from license servers, and downloads content via N_m3u8DL-RE. A developer uses it to security-test DRM device credentials and license servers through a CustomTkinter GUI with chainable plugins.1installs71Eastsword Dfyx Code Security ReviewEastSword DFYX Code Security Review is a white-box static-analysis skill that audits source code for security vulnerabilities. It runs a five-phase protocol (reconnaissance, pattern matching, taint tracking, validation, reporting) using deep data-flow analysis to trace tainted input from sources to sinks. A developer uses it to find and validate injection, auth, deserialization and other flaws across 9 languages before shipping.1installs72Email Security Auditor CppEmail Security Auditor is a C++ utility for security-testing email accounts. It validates email credential combinations, tests SMTP and IMAP authentication, and manages email lists during authorized penetration testing. A developer uses it for bulk email account verification and credential-stuffing assessments, running multi-threaded checks and exporting valid, invalid, and report files.1installs73Foundry Security SpecFoundry Security Spec is a skill for implementing Cisco's Foundry, an open specification for building agentic AI security-evaluation systems. It defines a multi-agent architecture of 8 core roles plus extension roles, a finding lifecycle, coordination model, and governance rules. A developer uses it as a blueprint, driving a spec-kit workflow to scaffold their own security-evaluation agents rather than installing a ready-made tool.1installs74Gandalf Llm PentesterGandalf LLM Pentester is an automated red-team toolkit for stress-testing LLM defenses through the Lakera Gandalf challenge. It executes attack vectors against 7 progressive security levels and uses Claude to validate whether a password was extracted (direct text, Base64, NATO phonetic, or fragmented). A developer uses it to probe prompt-injection defenses and analyze where an LLM's guardrails fail.1installs75H Pentest Ai PlatformH-Pentest AI Platform is an AI-driven penetration-testing system built on a multi-agent architecture. Meta, Strategic, Worker, Payload, and Report agents coordinate to plan and run automated security testing using a 52+ document attack knowledge base, a Docker sandbox, and integrated tools like Nuclei. A developer uses it to configure pentest tasks, run AI-driven vulnerability scans, and monitor agent execution in real time.1installs76Iac Security Scan SkillsIaC Security Scanner Skills is an AI-driven security assessment for Infrastructure-as-Code. It runs a three-step pipeline (analysis, parallel domain scanning across IAM, network, storage, secrets, logging and serverless, then attack-chain correlation) to find privilege-escalation paths and composite attack chains in Terraform and CloudFormation. A developer uses it for full audits or fast PR checks, exporting HTML, CSV, and terminal reports.1installs77Jellyfin Security PluginJellyfin Security Plugin adds authentication and hardening to Jellyfin media servers (10.11+) through a server-side plugin. It provides TOTP, passkeys, email OTP, OIDC single sign-on, IP-based brute-force protection, TV device pairing, LAN bypass, and audit logging. A developer uses it to install and configure the plugin so security is enforced server-side across all Jellyfin clients and integrations.1installs78Linux Pentester Command ReferenceLinux Pentester Command Reference is a knowledge repository of practical Linux commands organized by penetration-testing phase. It covers reconnaissance, enumeration, exploitation, privilege escalation, and post-exploitation, plus quick-reference cheatsheets. A developer uses it during engagements or CTFs to recall battle-tested Linux commands like SUID-binary discovery and service enumeration.1installs79Linux Pentester CommandsLinux Pentester Commands is a practical Linux command reference for penetration testing, drawn from the Linux for a Pentester repository. It provides commands for reconnaissance, enumeration, exploitation, privilege escalation, and post-exploitation, including reverse-shell payloads and interactive-shell upgrades. A developer uses it to recall phase-appropriate Linux commands during security assessments and CTFs.1installs80Linux Pentester NotesLinux Pentester Notes is a curated collection of practical Linux commands and techniques organized by penetration-testing phase. It follows the standard methodology from general commands through recon, enumeration, exploitation, privilege escalation, and post-exploitation. A developer uses it as a quick reference during assessments, CTF challenges, or security research on Linux systems.1installs81Linux Pentester Practical CommandsLinux Pentester Practical Commands is a curated collection of practical penetration-testing commands organized by engagement phase. Structured around the pentest kill chain, it covers reconnaissance, enumeration, exploitation, privilege escalation, and post-exploitation, including reverse shells, file transfers, and SUID/GTFOBins escalation. A developer uses it to recall real-world Linux command-line operations during security assessments and CTFs.1installs82Linux Pentesting Command ReferenceA Linux command reference organized by penetration-testing phases: reconnaissance, enumeration, exploitation, privilege escalation, and post-exploitation. A developer or tester uses it to look up actionable shell commands during an engagement instead of theory. It bundles copy-ready one-liners for tasks like finding SUID binaries, spawning reverse shells, and upgrading TTYs.1installs83Linux Pentesting CommandsA skill that packages the Linux-for-a-Pentester repository as a phase-organized command knowledge base for penetration testing. A developer or tester uses it to pull recon, enumeration, exploitation, and privilege-escalation commands during a security test. It is near-identical in scope to the sibling linux-pentesting-command-reference skill.1installs84Malwarebytes Premium Security Cracked DistributionThis skill documents a project that distributes cracked Malwarebytes Premium and warns strongly against using it. It explains the legal, malware, and update risks of pirated security software and lists legitimate alternatives like Windows Defender and official trials. It provides no working functionality and exists mainly as a safety and legality warning.1installs85Microsoft Security Skills PluginA curated collection of 56 Microsoft Security expertise modules that give AI coding agents opinionated, decision-tree guidance grounded in Microsoft Learn. A developer installs it so an assistant can advise on Defender XDR, Sentinel, Entra ID, Conditional Access, Purview DLP, and Intune instead of generic security advice. It installs across GitHub Copilot, Claude Code, Cursor, Codex, and Gemini CLI.1installs86Oscp Pentestcheatsheet TerminalA single-file, offline HTML command reference for penetration testing that holds 580+ commands across 28 sections. A tester uses it during OSCP/OSEP prep or engagements to copy commands with placeholder variables like LHOST and RHOST auto-substituted. It also tracks target intel, notes, favorites, and command history locally in the browser.1installs87Pentest Ai Killer AutomationPentest AI Killer is an automation server that wraps 69+ security tools such as nmap, nuclei, and sqlmap behind a unified REST API and MCP interface. A developer runs it via Docker so an AI assistant like Claude Desktop or Cursor can execute reconnaissance, vulnerability assessment, and cloud security scans. It also ships an optional Go CLI (pentakill) that talks to the same API without MCP.1installs88Pentestcompanion WorkspacePentest Companion is a self-hosted workspace that consolidates penetration-testing engagement tracking, tool execution, finding management, and reporting in one interface. A tester uses it to run 90+ tools with live output, auto-import findings, score them with CVSS v3.1, and generate DOCX or PDF reports. All data stays on the user's own infrastructure with no cloud dependencies.1installs89Pentester Mcp Security ToolsPentester-MCP is a Model Context Protocol server that lets AI assistants run 200+ open-source penetration-testing tools like nmap, sqlmap, ffuf, and impacket. A developer runs it inside a Docker sandbox so an agent such as Claude Desktop or Cursor can execute security tools autonomously with timeout enforcement and output truncation. Each tool is wrapped with AI-optimized documentation and safe argument handling to prevent shell injection.1installs90Pentestops DashboardPentestOPS Dashboard is a penetration-testing operations platform for managing projects, tasks, findings, clients, and assets. A tester uses it for Kanban/table task tracking, CWE-linked finding management with CVSS scoring, rich-text pages, checklists, comments, and global search. It is a full-stack TypeScript app on Next.js, Express, and MongoDB that deploys as a single Docker container.1installs91Pentest R1 Autonomous Penetration TestingPentest-R1 is a two-stage reinforcement-learning framework for training large language models to perform autonomous penetration testing and CTF challenges. Stage 1 does offline RL on 500+ expert walkthroughs and Stage 2 does online RL inside interactive CTF Docker environments. A researcher uses it to fine-tune a model like Llama 3.1 8B with LoRA to develop attack-reasoning capabilities.1installs92Pentest Skills FrameworkPentest-Skills is a modular penetration-testing framework for AI CLI tools like Claude Code, Gemini CLI, and Cursor that runs security tests from plain-language commands. A tester describes a goal such as scanning ports or finding SQL injection, and the AI selects and runs the right tool. Each skill packages knowledge docs, automation scripts, reference docs, and resource files for tasks like subdomain enumeration and directory scanning.1installs93Pentest Toolkit Pro HtmlPenTest Toolkit Pro is a single-file HTML pentesting toolkit that runs offline in any browser without dependencies. A tester uses it to manage Rules of Engagement, work through OWASP WSTG checklists, track vulnerabilities with CVSS scoring, and generate printable reports. All data is stored locally in browser localStorage for privacy and offline use.1installs94Pypi Security Best PracticesA guidance skill for securing Python package installations from PyPI with uv and pip. It walks through binary-only installs, dependency cooldowns, cryptographic hash verification, deterministic lockfiles and preventing dependency confusion. A developer uses it when hardening a Python environment against supply-chain attacks. It matters because compromised PyPI packages can run arbitrary code during install.1installs95Security Investigator AutomationA framework that runs automated security investigations across the Microsoft security stack using GitHub Copilot Agent Skills, VS Code and MCP servers. It lets an analyst query Sentinel, Defender XDR and Graph API in natural language for user, incident, device and IoC investigations. A SOC analyst uses it to hunt threats and produce reports. It matters because it turns manual KQL hunting into guided agent workflows.1installs96Skill Security ScannerA command-line tool that statically scans Claude skills for malicious code, unauthorized network requests, sensitive-file access and command injection before installation. It assigns risk scores and produces HTML, JSON or console reports, and can auto-scan the .claude/skills directory. A developer runs it to vet third-party skills before trusting them. It matters because installed skills can execute arbitrary code.1installs97Solana Security StandardA Solana security standard of 37 SOL-0XX rules that scans Anchor and Rust programs for known on-chain vulnerability classes. It fires as you code across AI tools, editors, CLI, Semgrep and CI, and exits non-zero on findings to gate pull requests. A Solana developer uses it to catch exploit classes before deploying. It matters because Solana program bugs have caused hundreds of millions in losses.1installs98Supabase Pentest SkillsA toolkit of 24 AI agent skills for authorized security auditing of Supabase applications. It automates detection, credential extraction, Row Level Security testing, IDOR detection, storage and auth audits, evidence collection and reporting. A developer uses it to self-assess whether their own Supabase app leaks keys or misconfigures RLS. It matters because Supabase misconfigurations commonly expose data through the public API.1installs99Symfony Security AuditorAn AI-powered multi-agent security auditor for Symfony applications. It runs an ingestion, mapping and audit pipeline where an adversarial attacker agent finds issues and a skeptical reviewer agent eliminates false positives, catching business-logic flaws and broken access control that traditional SAST tools miss. A Symfony developer uses it before release. It matters because authorization and workflow bugs are hard to detect statically.1installs100Vibe Pentest Ai Security TestingAn AI-agent-based automated penetration testing tool that uses a multi-agent parallel architecture to run black-box security testing of web applications, APIs and admin backends. It fingerprints, crawls with Katana, distributes testing across six specialized agents and generates HTML/DOCX reports with remediation. A security tester uses it for authorized assessments. It matters because it automates broad web-app vulnerability testing including business logic.1installs101Websecurityacademy SolutionsA reference library of solutions and walkthroughs for PortSwigger Web Security Academy labs. It covers 30-plus vulnerability categories with step-by-step exploitation patterns and video tutorials, graded from Apprentice to Expert. A developer or learner uses it to practice web application penetration testing and understand attack patterns. It matters as a hands-on way to learn appsec beyond theory.1installs102Web Security Scanner ProA Python-based web security scanner with 49 modules for detecting web vulnerabilities such as XSS, SQL injection, LFI, XXE and SSTI. It fingerprints web servers and CMS platforms, evades WAFs with user-agent rotation and rate limiting, checks a built-in CVE database, and exposes a REST API for CI/CD. A security tester uses it for automated web-app scans. It matters because it consolidates many vulnerability checks in one tool.1installs