๐ก๏ธ ็ฝ็ปๅฎๅ จ ยท ๆธ้ๆต่ฏ ยท ๆป้ฒๅฏนๆ ยท ็บข่ๅฏนๆ ยท AI Agent Skills
๐ก๏ธ Cybersecurity ยท Penetration Testing ยท Red/Blue Team ยท AI Agent Skills
ไธญๆ | English
โโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโ โโโโโโโ โโโโโโโ โโโโโโโโโโโโโโโ โโโโโโโ โโโโโโโโ
โโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโ โโโโโโโโโโ โโโ โโโโโโโโโโโ โโโ โโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโโ
โโโ โโโโโโโโโ โโโ โโโโโโโโโโโ โโโ โโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโโ
โโโโโโโโโโโโโโโโโ โโโ โโโ โโโโโโโโโโโโ โโโ โโโโโโ โโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโ
โโโโโโโ โโโโโโโโ โโโ โโโ โโโ โโโโโโโ โโโ โโโโโโ โโโโโโโโโโโโโโ โโโ โโโโโโโ โโโโโโโโ
๐ ๆๆกฃ โข ๐ ๏ธ ๅ็ฑป โข ๐ ๅฟซ้ๅผๅง โข ๐ค ่ดก็ฎ โข ๐ ่ฎธๅฏ่ฏ
OpenClaw SecSkills ๆฏไธไธชไธ้จไธบ็ฝ็ปๅฎๅ จไปไธไบบๅใๆธ้ๆต่ฏๅทฅ็จๅธใ็บข่ๅฏนๆๅข้ๆด็็ AI Agent Skills ้ๅใ
ๆฌ้กน็ฎๅบไบ OpenClaw ๆกๆถ๏ผๅฐไผ ็ปๅฎๅ จๅทฅๅ ทไธ AI Agent ่ฝๅ็ธ็ปๅ๏ผ่ฎฉๅฎๅ จๆต่ฏๆดๆบ่ฝใๆด้ซๆใ
| ๐ฏ | ๐ค | ๐ง | ๐ฆ |
|---|---|---|---|
| ็ฒพๅๅ็ฑป | AI ้ฉฑๅจ | ๅทฅๅ ท้ๆ | ๆ็ปญๆดๆฐ |
| 8 ๅคงๅฎๅ จ้ขๅ | ๆบ่ฝ่ชๅจๅ | ้ๆไธปๆตๅทฅๅ ท | ๆฏๅจๆดๆฐ |
| 200+ Skills | ่ช็ถ่ฏญ่จไบคไบ | Nmap/Nuclei ็ญ | ็คพๅบ่ดก็ฎ |
2026ๅนดๆๆฐ ChatGPT Plus / Grok / Claude ๅฝๅ ๅ ๅผ็ปๆๆๅ
๐ฅ ๅฎๆตๆๆ | โก 3ๅ้ๅฐ่ดฆ | ๐ก๏ธ 30ๅคฉ่ดจไฟ | ๐ฐ ๅ จ็ฝๆไฝไปท๏ฟฅ149่ตท
| ๆ ธๅฟไผๅฟ | ่ฏดๆ |
|---|---|
| ๐ฏ ๅกๅฏๅผไปฃๅ | ๆ ้ไฟก็จๅก๏ผๅพฎไฟก/ๆฏไปๅฎ/USDT ็ดๆฅ่ดญไนฐ |
| โก ๆ้ๅฐ่ดฆ | ่ชๅจๅๅก๏ผ3ๅ้ๅ ๅฎๆๅ็บง |
| ๐ก๏ธ ๆญฃ่งๆธ ้ | iOS ๅบ็จๅ ่ดญ๏ผ้้ปๅก็ๅท๏ผๆ ๅฐๅท้ฃ้ฉ |
| ๐ฐ ไปทๆ ผๆไฝ | ๏ฟฅ149่ตท๏ผๆฏๅธ้ขๆๆไปฃๅ ้ฝไพฟๅฎ |
| ๐งพ ไผไธๅผ็ฅจ | ๆฏๆไผไธๅ็ฅจ๏ผๆฅ้ๆ ๅฟง |
๐ ็ซๅณๅๅพๅ ๅผ๏ผ https://gptget.top ๏ผๅบ้บ๏ผcatfk.com๏ผ
๐ ๆฅ็่ฏฆ็ปๆ็จ๏ผ GitHub ไปๅบ
| ๐ก๏ธ ScanDomain โ ๅ ่ดนๅจ็บฟๅญๅๅๆซๆ็ฅๅจ | ๐ KvioAI โ AI API ่ๅๅนณๅฐ๏ผไธไธช Key ่ฐ็จๆๆไธปๆตๆจกๅ | ๐ณ CatFK ไปฃๅ โ ChatGPT Plus/้ขๅบฆไปฃๅ ๏ผๅ จ็ฝๆไฝไปท |
| ไธ้ฎๅ็ฐ็ฝ็ซ้่่ตไบง ยท ๅญๅๅ็็ ด ยท ๆฅ็ฎกๆฃๆต ยท ๆ็บน่ฏๅซ | Claude / GPT / Gemini ไธ็ซๅผๆฅๅ ฅ ยท ๅฝๅ ็ด่ฟ ยท ไปทๆ ผๆดไผ | ็ปๅฏนๆญฃ่งๆธ ้ ยท 30ๅคฉ่ดจไฟ ยท ๆฏๅธ้ขๆๆไปฃๅ ้ฝไพฟๅฎ |
| ๐ ็ซๅณไฝฟ็จ | ๐ ็ซๅณๆณจๅ | ๐ ็ซๅณๅๅพ |
Details
็ฝ็ไปฃ็ ๅฎๅ จๅฎก่ฎก๏ผ่ฆ็ Java/PHP/Python/ๆบ่ฝๅ็บฆ็ญ
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| sast-skills | Scan codebases for security flaws with LLM agent skills โ turn AI assistants into SAST scanners | github |
| securecoder | Installable AI-agent skill bundle for OWASP-driven code scanning, fixing, secure-build supervision | github |
| security-audit-system-skill | Structured security audit system for Claude agents โ improve security practices on any repo | github |
| agent-skills | 100+ specialized AI agent skills โ development, security, design, FinOps, compliance, testing | github |
| agent-skills | Agent skills for AI coding agents โ Laravel, React, TypeScript, security, code quality, technical debt | github |
| nsauditor-ai-agent-skill | AI Agent Skill for NSAuditor AI โ MCP tools, schemas, plugins, security audit workflows | github |
| Skill-Sonar | Protect AI agents with lifecycle security for pre-install checks and runtime monitoring | github |
| skills-scanner | Security scanner for AI agent skills, MCP servers, and agent harness configs | github |
| honeybadger | Security scanner for AI agent skills โ detects secrets, CVEs, supply chain attacks, prompt injection in SKILL.md | github |
| skill-dfyx_code_security_review | ไบ้ถๆฎตๆ ๅๅๅฎก่ฎกๅ่ฎฎ๏ผ็ณป็ปๆงๅ็ฐๅฎๅ จๆผๆด | github |
| whisper-skills | Agent Skills for WhisperGraph MCP โ threat investigation, Cypher query authoring, brand-protection sweeps | github |
| security-hardening | Portable defensive application security skill โ OWASP, MCP security, prompt injection, threat modeling | github |
| claude-active-directory | Active Directory offensive security AI agent harness โ 8 skill domains, 13 slash commands, 7 agents | github |
| security-lab | AI-driven security testing toolkit: 37 skills, multi-agent pentesting, comparison framework for web apps and APIs | github |
| claude-security-skills | Defensive security skills for Claude Code โ web applications and generative AI systems | github |
| skills | Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows | github |
| SlowMist-Learning-Roadmap-for-Becoming-a-Smart-Contract-Auditor | Smart contract audit skills roadmap for beginners, auditors, engineers, etc. | github |
| solsec | A collection of resources to study Solana smart contract security, auditing, and exploits. | github |
| Smart-Contract-Security-Audits | Certified Smart Contract Audits for Ethereum, Solana, Near, Cardano, Aptos, Sui, Binance Smart Chain, Fantom, EOS, Tezos | github |
| Smart-Contract-Auditor-Tools-and-Techniques | This repo contains a comprehensive list of smart contract auditor tools and techniques that can be utilized by both smar | github |
| SmartContracts-audit-checklist | A checklist of things to look for when auditing Solidity smart contracts. | github |
| smart-contract-audits | ContractWolf audited smart contracts | github |
| QuillAudit_Smart_contract_Auditor_Roadmap | Smart Contract Auditor Roadmap | Learn Blockchain Security & Smart Contract Auditing |
| smart-contract-auditing-heuristics | Heuristics for smart contract auditors | github |
| java-audit-skills | ไธๆณจไบjavaไปฃ็ ๅฎก่ฎกskills | github |
| QuillAudit_smart_contract_audit_Reports | QuillAudits โ Smart Contract Audits for DeFi, RWA, DEXs, Tokens, DeAI & DApps | github |
| PHP-Code-Audit-Skill | PHP-Code-Audit-SkillๆฏไธไธชไธๆณจไบPHPไปฃ็ ๅฎก่ฎก็Skill | github |
| agentseal | Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks | github |
| wxmini-security-audit | ๅพฎไฟกๅฐ็จๅบๅ จ่ชๅจๅฎๅ จๅฎก่ฎก Skill๏ผๅบไบ Claude Code Agent Teamsใ7 Agent ๅไฝ๏ผ่ฆ็ๆๆไฟกๆฏใAPIๆฅๅฃใๅ ๅฏๅๆใๆผๆดๅๆๅๅคง็ปดๅบฆใ้็จ่ๆฌ+LLMๅๅฑๆถๆ๏ผ่ๆฌไฟ่ฏ่ฆ็็๏ผLLMไฟ่ฏๅ็กฎ็ใ | github |
| claude-security-audit | Skill Claude Code pour audit de sรฉcuritรฉ complet (OWASP Top 10, CWE/CVE, headers, auth, paywall, infra) | github |
| claude-cybersecurity | AI-powered cybersecurity code review skill for Claude Code. 8 specialist agents, OWASP 2025, CWE Top 25, MITRE ATT&CK, 1 | github |
| panguard-ai | Open-source security platform for AI agents -- audits skills before install, monitors 24/7, shares threat intelligence a | github |
| PHP_AUDIT_SKILLS | PHP้ๆ+ๅจๆ+AIไปฃ็ ๅฎก่ฎกskills | github |
| solidity-auditor-skills | github | |
| claude-security-research-skill | AI-powered security research assistant for Claude Code โ structured assessment workflows, tool orchestration, and profes | github |
| security-audit-skill | Agent Skill for PHP security audits - OWASP patterns, vulnerability detection | Claude Code compatible |
| java-audit-skillss | java-audit-skillss | github |
| claude-skills | UX/UI evaluation, AI governance, and AI security skills for AI coding assistants. Audit interfaces with Nielsen heuristi | github |
| marketplace | Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified. | github |
| supabase-pentest-skills | 24 AI Agent Skills for professional security auditing of Supabase applications. Detection, key extraction, RLS testing, | github |
| skill-dfyx_code_security_review | ไบ้ถๆฎตๆ ๅๅๅฎก่ฎกๅ่ฎฎ๏ผ็ณป็ปๆงๅ็ฐๅฎๅ จๆผๆด | github |
| Code Audit | ่ฆ็ 55+ ๆผๆด็ฑปๅ๏ผๅ่ฝจๅฎก่ฎกๆจกๅ๏ผๅค Agent ๆทฑๅบฆๅๆ | github |
| zh-audit-skills-hub | ไธญๆ็จๆทไปฃ็ ๅฎก่ฎก Agent Skills ไปๅบ | github |
| perseus | AI-powered security assessment SKILLS for codebase. Multi-language | github |
| full-stack-audit | 90-point full-stack audit skill for websites and web apps. Catches security holes, accessibility issues | github |
| sentinelai | Security scanner, cost tracker, and model router for the AI ecosystem | github |
| trivy-security-agent-skill | AI-powered Trivy security scanning skill for Claude Code | github |
| dependency-scanner | Claude Code skill that scans npm/pip dependencies for vulnerabilities | github |
่ชๅจๅๆธ้ๆต่ฏใๆผๆดๆๆใBug Bounty
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| iothackbot | IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting | github |
| Android-Pentesting-Checklist | Delve into a comprehensive checklist, your ultimate companion for Android app penetration testing. Identify vulnerabilit | github |
| labs-pentest | Free Labs to Train Your Pentest / CTF Skills | github |
| threat-modeling | AI-native automated software risk analysis skill. LLM-driven, Code-First approach for comprehensive security risk assess | github |
| communitytools | Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and s | github |
| awesome-claude-skills-security | Security testing toolkit for Claude Code: curated SecLists wordlists, injection payloads, and expert agents for authoriz | github |
| public-skills-builder | Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups โ 18 vuln classes, no private r | github |
| BugHunterMethodology | A comprehensive bug bounty methodology compiled from extensive research, covering web application reconnaissance, checkl | github |
| pentest-skills | ๐ฌ ๐ ๅๅซ็น็ๅฝไปค่ก๏ผ็จ่ช็ถ่ฏญ่จ้ฉฑๅจไธไธ็บงๆธ้ๆต่ฏใ โก ่ฎฉๅฎๅ จๆต่ฏไปๆชๅฆๆญค็ฎๅใ้ซๆใForget complex command lines. ๐ก๏ธ Professional penetration testing, powered | github |
| OneLinerBounty | OneLinerBounty is a collection of quick, actionable bug bounty tips in one-liner format. Perfect for bug hunters looking | github |
| SecToolkit | Welcome SecToolkit repository! This is a comprehensive collection of cybersecurity and bug bounty hunting topics. Here, | github |
| picocom-claude-skill | A Claude Code skill for using picocom to give access to a live UART shell for enumeration, pentesting, etc. | github |
| VulnBox | VulnBox is a container that is intentionally designed with vulnerabilities to allow security professionals to practice a | github |
| Active-Directory-Workbook | A comprehensive and hands-on workbook designed to sharpen your Active Directory penetration testing skills. Whether you' | github |
| pentester-skills | ๅคๅผ็ฝ็ปๅฎๅ จๅญฆไน ๆณ๏ผไธๅชๆฏๅญฆไน ่ทฏ็บฟ่ฟๆฏ็ฌ่ฎฐใ | github |
| KaliPAKU | KaliPAKU is a training tool for penetration testing using Kali Linux. It is designed to help security professionals and | github |
| secknowledge-skill | 88,636 ไธช็ๅฎๆผๆดๆกไพ + 5,600+ ็ฏๅฎๅ จ็ ็ฉถๆๆกฃ็ฅ่ฏๅบ | github |
| Security Auditor | OWASP ๅๅคงๅฎก่ฎกใCORS/CSP ้ ็ฝฎใSQL ๆณจๅ ฅ/XSS ้ฒๆค | github |
| Pentest Api Attacker | OWASP API ๅฎๅ จๅๅๅๆต่ฏ | github |
| Pentest Auth Bypass | ่บซไปฝ้ช่ฏ็ป่ฟๅ่ดฆๆทๆฅ็ฎกๆต่ฏ | github |
| claude-code-pentest | 6 skills that automate the entire pentest lifecycle. From recon to exploitation | github |
| Anthropic-Cybersecurity-Skills | 754 structured cybersecurity skills for AI agents, mapped to MITRE ATT&CK, NIST, OWASP | github |
| claude-forge | Supercharge Claude Code with 11 AI agents, 36 commands & 15 skills | github |
| pownie | Agent harness for offensive security. Plugin for Claude Code packed with skills, memory, rules | github |
| pentest-skills | ่ชๅจๅๆธ้ agent skills | github |
| pentestagent | AI agent framework for black-box security testing โ bug bounty, red-team, penetration testing | github |
| Zen-Ai-Pentest | AI-Powered Penetration Testing Framework โ automated vulnerability scanning, multi-agent system, compliance reporting | github |
| CyberStrike | AI-powered offensive security agent with 7,300+ actionable security skills โ MITRE ATT&CK, CIS Benchmarks, OWASP, NIST | github |
| ultraship | Claude Code plugin โ 39 skills including pentesting, safety guardrails, canary monitoring, code review | github |
| kali-pentest | Kali Linux penetration testing skill for AI agents โ 200+ CLI tools, 15 scenario playbooks, attack path planning | github |
| Threatswarm | 27 scope-enforced AI agents running full pentest kill-chain (reconโexploitโpost-exโDFIRโreport), 754 MITRE-m |
... [OUTPUT TRUNCATED - 3188 chars omitted out of 53188 total] ...
/ctf-skills) | | reverse-skills | Reverse engineering skills for Claude Code | ้ๅๅทฅ็จ Claude Code Skills ๆไปถ | github | | Incident-Response-Projects-for-Beginners | Hands-on cybersecurity projects to enhance skills in phishing investigation, malware analysis, network intrusion detecti | github | | jshook-skill | AI-powered JS reverse engineering: deobfuscation, crypto detection, CDP debugging, hook injection, anti-detection | | github | | Common-CTF-Challenges | Common CTF Challenges is a collection of tools and resources to help individuals improve their Capture the Flag (CTF) sk | github | | IDA-Skill | ไฝฟ็จskill่ฎฉ AI Agent ๅๅฎๅ จๅๆๅธไธๆ ทๅๆๆถๆๆ ทๆฌ | AI Agent skill for automated malware analysis using IDA Pro | github | | spider-king-skill | Protocol-first reverse engineering skill for turning hostile web clients into pure-protocol Python collectors. | github | | ghidra-re-skill | Codex Ghidra reverse engineering skill with headless workflows, bug-hunting bundles, and a live bridge for Apple Mach-O | github | | CrackMaster | CCrackMaster is an educational CrackMe project written in C, designed to enhance skills in reverse engineering, code ana | github | | malware-analysis-claude-skills | Complete Claude skills toolkit for professional malware analysis. 5 specialized skills covering triage, dynamic analysis | github | | DeepExtractRuntime | AI-driven agent runtime for Windows PE binary analysis. Turns IDA Pro decompiled code and SQLite databases produced by D | github | | my-claude-skills | Binary analysis plugins for Claude Code: angr (static analysis, symbolic execution) and Frida (dynamic instrumentation) | github | | BloodCodeCTF | Blood Code CTF challenge repository! This repository contains all the challenges and their source files from the Capture | github | | TimeCod | KotlinCrackMaster is an educational CrackMe project written in Kotlin, designed to enhance skills in reverse engineering | github | | hello_js_reverse_skill | JS ้ๅไธ็ฌ่ซๅฏนๆ๏ผCamoufox ๅๆฃๆตๆต่งๅจ | github | | JS Reverse MCP | JavaScript ้ๅๅทฅ็จ MCP ๆๅกๅจ | github | | FlowDroidSkill | APK ้ๆๆฑก็นๅๆ๏ผๆฃๆตๆฐๆฎๆณ้ฒ่ทฏๅพ | github | | re-skill | Claude Code skill for reverse engineering retro games โ disassemble, annotate, explore | github | | epistemic-deconstructor | Claude skill for reverse engineering systems | github | | android-reverse-engineering-claude-skill | Decompile Android APK, XAPK, AAB, DEX, JAR using jadx | github | | apple-silicon-internals | Reverse engineering toolkit for Apple Silicon private APIs. 55+ frameworks | github | | iOS-reverse-engineering-claude-skill | Claude Code skill for extracting, analyzing, reverse engineering iOS apps | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| ใ้ๅ่ตๆบๅบใ - ๅพ็ฑ็ ด่งฃ - 52pojie.cn | 1 ๅคฉๅโยทโใ้ๅ่ตๆบๅบใ ๆถๅฝไบๅจ้ๅ่ฟ็จไธญไผไฝฟ็จ็็ปๅคงๅคๆฐๅทฅๅ ท๏ผๅทฅๆฌฒๅๅ ถไบๅฟ ๅ ๅฉๅ ถๅจ๏ผๅฅฝ็ๅทฅๅ ทๅจ้ๅ็ ด่งฃๅทฅ็จไธญ่ตทๅฐไบๅๅๅ็ไฝ็จใ ๆฌๅบๆ นๆฎๅทฅๅ ท็ไฝ็จๅๆไปฅไธๅ ็ฑป๏ผๅๅซๅไปฅไธญๆ่งฃ้่ฏด โฆ | ๅพ็ฑ็ ด่งฃ |
CTF ่งฃ้ขๆๅทงใๅทฅๅ ทไฝฟ็จใๆผๆดๆๆ
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| ctf-practice | Practice your hacking skills with these CTFs | github |
| linux-ctfs | A collection of Linux CTFs to practice your CLI skills | github |
| SecSkills | ๆถ้ๆด็ๆธ้ๆต่ฏใๆผๆดๆซๆใไปฃ็ ๅฎก่ฎกใCTFใ้ๅใๅฎๅ จ็ ็ฉถ ็ญ็ฝ็ปๅฎๅ จ็ธๅ ณ็ SkillsๅMCP | github |
| Walkthrough-and-Writeup | Welcome to my Capture The Flag (CTF) Walkthroughs & Writeups Repository. This repository contains educational, step-by-s | github |
| android-h1 | ๅบไบ HackerOne ็ๅฎๆฅๅ็็งปๅจๅฎๅ จๆผๆดๆๆ | github |
| BugBounty-Hunting | ๆผๆด่ต้็ไบบ่ตๆบ้ๅ | github |
ๅฎๅ จ้ฃ้ฉ่ฏไผฐใๅจ่ๅๆใๅ่งๆฃๆฅ
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| ThreatHunt | ThreatHunt is a PowerShell repository that allows you to train your threat hunting skills. | github |
| SOC-Analyst-Notes | Comprehensive SOC Analyst notes covering incident response, threat hunting, SOC workflows, and cybersecurity conceptsโpe | github |
| SkillWard | Security scanner for Agent Skills โ uncover hidden threats before deployment. | github |
| cti-expert | CTI Expert โ Cyber Threat Intelligence & OSINT analysis skill for Claude Code. 67+ commands, 35 techniques, no API keys | github |
| 30-Day-SOC-Analyst-Challenge | A 30-day hands-on SOC Analyst project simulating real-world cyber attacks using ELK Stack, Mythic C2, osTicket & Elastic | github |
| Offensive-Security-Forensics-Portfolio | A portfolio demonstrating advanced blue and red team skills, including: SSH MFA implementation, Volatility-based memory | github |
| ghsa-skill-builder | ่ชๅจๅฐ GitHub ๆผๆดๅบๅ HackerOne ๆฅๅ่ฝฌๅไธบ Skills | github |
Android/iOS ๅฎๅ จๅๆใๆผๆดๆๆ
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| Damn-Vulnerable-Bank | Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to as | github |
| Skill-Android-Security-Agent | ๆๅปบๅบไบ Skill ็ Android ๆบ่ฝๅฎก่ฎก Agent | github |
| mobile-security-learning-resources | This repository contains list of mobile security related resources that you can use to learn new skills and test existin | github |
| mobile-challenges | This repository houses diverse files and challenges centered around Just Mobile Security. With practical exercises and r | github |
| android-reversing-challenges | there are some CTF challenges or some other things helping improving android reversing skills. | github |
ๅฎๅ จไบไปถๅๅบใๅ่ฏๅๆใๆฅๅฟๅๆ
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| aguara | Security scanner for AI agent skills and MCP servers. Static analysis, incident response, no LLM. One binary. Detectio | github |
| repo-forensics | Automated Security scanner for GitHub repos, Agent Skills, Plugins, and MCP servers. 18 scanners. Zero dependencies. Kee | github |
| Digital-Crime-Scene-Challenge | The object of the Digital Crime Scene Challenge is for participants to use their forensic and investigative skills to fo | github |
| mini-hids | ่ฝป้็บงไธปๆบๅ ฅไพตๆฃๆตไธๆฅๅฟๅๆ็ณป็ป๏ผๆฏๆๅฐ่ฃ ไธบAI Agent Skillใ/ A lightweight HIDS for Linux, featuring AI-powered log analysis and automated def | github |
| backdoorsandbreaches-socinvader | ๐ฎ AI-powered solo mode for Backdoors & Breaches. Train incident response skills anytime with an LLM Incident Master. Arc | github |
| Digital-Forensic-Training | The Chupacabra case study was created by the ADEO dfir team due to the lack of resources and applications in the digital | github |
| DevOps-Security-Agent-Skills | Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform | github |
| agent-infra-security | Security skills for AI coding agents โ incident response for supply chain attacks, credential rotation, IOC detection. W | github |
| LinuxGun-skill | Linux ๅฎๅ จๅบๆฅๅๅบ AI ๆฃๆฅ | github |
| Email-OSINT | ่ชๅจๅ็ตๅญ้ฎไปถ OSINT ๅทฅๅ ท | github |
| incident-report-skill | Taiwan cybersecurity incident report generator | github |
| SecOpsAgentKit | Security operations toolkit for AI coding agents. 25+ skills for CVE research, exploit dev, threat intel | github |
| dfir-skills | DFIR/SOC skillset for Claude Code โ memory forensics, log analysis, network forensics | github |
ๆซๆๅจใๆผๆดๅฉ็จใ็บข่ๅฏนๆๅทฅๅ ทใAI ๅฎๅ จ
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| raptor | Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating r | github |
| slowmist-agent-security | SlowMist Agent Security Skill: A comprehensive security review framework for AI agents operating in adversarial environm | github |
| secureclaw | SecureClaw - Security Plugin and Skill for OpenClaw OWASP-Aligned | github |
| SecurityClaw | A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, bu | github |
| faillapop | Vulnerable-by-design solidity protocol to help Web3 security enthusiasts practice their skills in an environment closer | github |
| claude-code-owasp | Claude Code skill for OWASP security best practices (2025-2026). Includes Top 10:2025, ASVS 5.0, Agentic AI security, an | github |
| www-project-agentic-skills-top-10 | OWASP Foundation web repository | github |
| web3-bug-bounty-hunting-ai-skills | 18 Claude Code skill files for smart contract security โ built from 2,749 Immunefi reports, 681 DeFiHack reproductions, | github |
| kernel-vuln-analyzer | Claude Code skill for Linux kernel vulnerability analysis โ from crash log triage to patch verification | github |
| CEH-Assessments | A structured portfolio of weekly CEH v13 assessments, vulnerability labs, and ethical hacking documentation to demonstra | github |
| MalwareAnalysis | This central repository is crafted for cybersecurity enthusiasts, researchers, and professionals aiming to advance their | github |
| red-team-blue-team-agent-fabric | 466 security tests for AI agent systems โ MCP, A2A, x402/L402, decision governance, benchmark integrity, skill supply ch | github |
| mobile-security-skills | A collection of Claude Code and OpenAI Codex Agent Skills for mobile application security testing | github |
| htb-writeups | The most comprehensive Hack The Box writeup collection - 500+ machines, 400+ challenges, interactive knowledge graph, sk | github |
| tirith | Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated pay | github |
| agentguard | Security guard for AI agents โ blocks malicious skills, prevents data leaks, protects secrets. 24 detection rules, runti | github |
| SOC-Ressources | Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to i | github |
| security-skills | A collection of Claude Code skills that help security teams stay secure | github |
| cybersecurity-skills | Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex) | github |
| AI-agent-master-cyber-skills-list | Comprehensive cybersecurity skill pack for AI coding agents โ 741 skills | github |
| awesome-ai-agent-skills | 70+ ready-to-use, platform-agnostic AI agent skills | github |
| Awesome-OpenClaw | A carefully curated list of awesome OpenClaw resources | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| ANYDESK-BACKDOOR | You should never use malware to infiltrate a target system. With the skill of writing and exploiting technical codes, yo | github |
| PayloadsAllTheThings | Web ๅฎๅ จ payload ๅ็ป่ฟๅ่กจ | github |
| BugBountyGuide | ๆผๆด่ต้็ป่ฟๆๅทงๅ payload | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| Red-Team-Roadmap | Red Team Roadmap [defination, job positions, skills, tools] | github |
| eJPT | eJPT is a hands-on, entry-level Red Team certification that simulates skills utilized during real-world engagements. | github |
| Red-Team | ็บข้/ๆธ้ๆต่ฏๅทฅๅ ท้ๅ | github |
| Windows-Exploits | Windows ๆๆๆผๆด้ๅ | github |
| AD-Attack | Active Directory ๆปๅป่ทฏๅพ | github |
| Pentest Active Directory | AD ่บซไปฝๆปๅป่ทฏๅพ่ฏไผฐ | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| pydantic-ai-shields | Guardrail capabilities for Pydantic AI โ cost tracking, prompt injection detection, PII filtering, secret redaction | github |
| AgentForensics | Monitors LLM agent sessions in real time โ detects prompt injection across tool outputs, web pages, documents | github |
| immunity-agent | Security for AI agents โ block dangerous commands, prevent secret leaks, enforce runtime policies across all major agents | github |
| agentshield | AI agent security scanner โ detects vulnerabilities in agent configs, MCP servers, tool permissions. CLI + GitHub Action | github |
| hol-guard | AI antivirus for developer agents โ protect Codex, Claude Code, Cursor, plugins, skills, MCP servers before tools run | github |
| sandboxed.sh | Safe runtime for autonomous on-chain AI agents โ isolated sandboxes, encrypted secrets, OKX read-only security checks | github |
| kontext-cli | Runtime Security for tool-using AI agents โ permissions, credentials, policy enforcement, audit trails | github |
| skillguard | Security scanner for AI agent skills โ detects prompt injection, data exfiltration, malicious payloads | github |
| agent-bom | Open security scanner for AI supply chain โ agents, MCP, containers, cloud, GPU, runtime with blast-radius analysis | github |
| lang-guardx | Adaptive security for LangChain apps โ blocks prompt injection, validates tool calls, filters malicious outputs | github |
| ai-security-lab | AI/LLM Security Testing Framework โ 50+ jailbreak techniques, prompt injection tools, automated vulnerability scanners | github |
| skillscan-security | Security scanner for AI agent skills and MCP โ prompt injection, IOC matching, malware detection, ML classifier | github |
| ai-shield | LLM security toolkit โ prompt injection detection, PII masking, cost tracking, tool policies. <25ms scans | github |
| llm-audit | OWASP LLM Top 10 vulnerability scanner CLI โ prompt injection, jailbreaks, data leakage, with fix recommendations | github |
| lochbot.com | Prompt Injection Vulnerability Checker โ 31 attack patterns across 7 categories, security scoring | github |
| yula | Production-ready CLI for adversarial red-teaming of AI systems โ prompt injection, jailbreaks, evasion techniques | github |
| llm-red-teamer | Automated prompt injection & jailbreak testing โ OWASP LLM Top 10, 43 real-world payloads, risk scoring | github |
| openclaw-skill-vetter-mcp | MCP server for security-vetting AI agent extensions โ 41 detection rules, 0-100 risk score | github |
| llm-security-test | LLM Security Test โ AI Safety Evaluation Tool for Jailbreak, Prompt Injection, Harmful Content Detection | github |
| ai-security-toolkit | LLM security research toolkit โ jailbreak detection, prompt injection testing, adversarial text generation, API fuzzing | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| ramibot | RamiBot v3.8.0 is a local-first AI security operations platform integrating multi-LLM support, a dynamic red/blue team s | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| CLS-Certify | Skill ๅฎๅ จๆฃๆฅๅทฅๅ ท | github |
| SkillGuard | OpenClaw Skill ๅฎๅ จๆฃๆฅ | github |
| skill-audit | ๅฎก่ฎก Skill ๅฎไน็ๅฎๅ จๆงใๅฎๆดๆง | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| agent-scan | Security scanner for AI agents, MCP servers and agent skills. | github |
| skill-scanner | Security Scanner for Agent Skills | github |
| nova-proximity | Nova-Proximity is a MCP and Agent Skills security scanner powered with NOVA | github |
| llm-sast-scanner | A SAST skill that gives AI coding agents structured vulnerability detection across 34 vulnerability classes. | github |
| claude-skill-antivirus | Security scanner for Claude Code Skills โ 9 engines detect malicious patterns, data exfiltration, dangerous ops across 7 | github |
| skillsentry | AI Skill Security Scanner | github |
| skillcheck | Security scanner for Claude SKILL.md files. Detects vulnerabilities before they reach production. | github |
| SkillSemgrep | ๅบไบ Semgrep ็่ช็ถ่ฏญ่จๆผๆดๆซๆ | github |
| Nmap | ็ฝ็ปๅ็ฐๅๅฎๅ จๅฎก่ฎก | github |
| Nmap Pentest Scans | Nmap ไธปๆบๅ็ฐใ็ซฏๅฃๆไธพใNSE ๅๆ | github |
| Security Scanner | ้ๆ nmapใnuclei ็่ชๅจๅๆซๆ | github |
| Nuclei | ๅบไบๆจกๆฟ็ๅฟซ้ๆผๆดๆซๆๅจ | github |
| scv-scan | Claude Code skill that scans Solidity codebases for security vulnerabilities | github |
| redhound-arsenal | 76 AI-agent security skills for Kali Linux tools โ pentest, red team, forensics | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| reconFTW | ่ชๅจๅไพฆๅฏๅทฅๅ ท | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| AI-Infra-Guard | ๅ จๆ AI ็บข้ๆต่ฏๅนณๅฐ โ OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, LLM jailbreak ่ฏไผฐ | github |
| pentestagent | AI agent framework for black-box security testing โ bug bounty, red-team, penetration testing | github |
| Zen-Ai-Pentest | AI-Powered Penetration Testing Framework โ automated vulnerability scanning, multi-agent system | github |
| agentic_security | Agentic LLM Vulnerability Scanner / AI red teaming kit | github |
| agent-security-scanner-mcp | Security scanner MCP server for AI coding agents โ prompt injection firewall, 1000+ vulnerability rules, AST & taint analysis | github |
| LLMrecon | Enterprise-grade LLM security testing framework โ OWASP LLM Top 10, advanced prompt injection, jailbreak | github |
| WonderSuite-Ai-Bug-Bounty | AI-Powered Offensive Security Research Engine โ 90 tools, MITM proxy, stealth browser, autonomous AI agent | github |
| agent_asteroid | Agent responsible for detecting remote vulnerabilities, a robust scanner | github |
| DVAI | Damn Vulnerable AI โ hands-on AI security training across 12 categories, OWASP LLM Top 10, works 100% offline | github |
| CyberStrike | AI-powered offensive security agent with 7,300+ actionable security skills โ MITRE ATT&CK, CIS, OWASP, NIST | github |
| Threatswarm | 27 AI agents running full pentest kill-chain backed by 754 MITRE-mapped skills | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| supply-chain-defense-skills | Reusable Security Skills for AI Coding Agents โ protect against supply chain attacks in npm, PyPI, etc. | github |
| DevOps-Security-Agent-Skills | 80+ DevOps security skills โ Kubernetes, Terraform, AWS/Azure/GCP, container hardening, SOC2/ISO27001, incident response | github |
| Skill | ๆ่ฟฐ | ๆฅๆบ |
|---|---|---|
| Best-LwM2M-Agentic-Skills | Worlds most comprehensive OMA LwM2M (IoT) expert skill for Claude | github |
| Claude-Code-CyberSecurity-Skill | Comprehensive collection of 15 Claude Code Skills for cybersecurity | github |
็ฝ็ปๅฎๅ จๅญฆไน ่ตๆบใ็ปไน ๅนณๅฐใ็ฅ่ฏๆกๆถ
| Skill | ๆ่ฟฐ | ไปๅบ |
|---|---|---|
| 1earn | ffffffff0x ๅข้ๅฎๅ จ็ฅ่ฏๆกๆถ๏ผWeb/ๅทฅๆง/ๅ่ฏ/ๅบๆฅ/ๅๆธ้ | GitHub |
| Awesome-Infosec | ไฟกๆฏๅฎๅ จ่ฏพ็จๅๅน่ฎญ่ตๆบ็ฒพ้ | GitHub |
| HackTheBox | CTF ๅๆธ้ๆต่ฏ็ปไน ่ตๆบ | GitHub |
| ๅทฅๅ ท | ๆ่ฟฐ | ้พๆฅ |
|---|---|---|
| ScanDomain | ๐ฅ ๅ ่ดนๅจ็บฟๅญๅๅๆซๆ็ฅๅจ โ ไธ้ฎๅ็ฐ้่่ตไบงใๅญๅๅๆฅ็ฎกๆฃๆตใ็ฝ็ซๆ็บน่ฏๅซ๏ผๆธ้ๆต่ฏๅๅฟ ๅคไฟกๆฏๆถ้ๅทฅๅ ท | ็ซๅณไฝฟ็จ โ |
| KvioAI | ๐ AI API ่ๅๅนณๅฐ โ ไธไธช Key ๆฅๅ ฅ Claude/GPT/Gemini ็ญ 50+ ไธปๆตๆจกๅ๏ผๅฝๅ ็ด่ฟๆ ้็ฟปๅข๏ผไปทๆ ผๆฏๅฎๆนๆดไผ | ็ซๅณๆณจๅ โ |
| CatFK ไปฃๅ | ๐ณ ChatGPT Plus/้ขๅบฆไปฃๅ โ ็ปๅฏนๆญฃ่งๆธ ้๏ผ30ๅคฉ่ดจไฟ๏ผๆฏๅฝๅๅธ้ขๆๆไปฃๅ ้ฝไพฟๅฎ๏ผๅฎๅ จๆ ๅฟง | ็ซๅณๅๅพ โ |
ๆไปฌๆฌข่ฟๆๆ็ฝ็ปๅฎๅ จไปไธ่ ็่ดก็ฎ๏ผ
- Fork ๆฌไปๅบ
- ๅๅปบๆฐๅๆฏ (
git checkout -b feature/AmazingFeature) - ๆไบคๆดๆน (
git commit -m 'Add some AmazingFeature') - ๆจ้ๅฐๅๆฏ (
git push origin feature/AmazingFeature) - ๅผๅฏ Pull Request
่ฏทๅจ PR ไธญๆไปฅไธๆ ผๅผๆไพไฟกๆฏ๏ผ
## Skill ๅ็งฐ
- **ๆ่ฟฐ**: ไธๅฅ่ฏๆ่ฟฐๅ่ฝ
- **ไปๅบ้พๆฅ**: GitHub URL
- **ๅ็ฑป**: ไปฃ็ ๅฎก่ฎก/ๆธ้ๆต่ฏ/้ๅๅทฅ็จ/...
- **ๆ ็ญพ**: #java #audit #security