SKILL.md packages that extend Claude Code, Cursor, Copilot, and other AI agents.
Tags

xianzhi-research
A structured vulnerability research framework distilled from 5600+ security docs, covering web injection, deserialization, binary exploitation, domain pentest,

Anthropic Cybersecurity Skills
Techniques and checks to find and exploit common JWT misconfigurations (alg none, alg confusion, kid/JKU injection, weak secrets).

saas-security
Comprehensive SaaS security audit skill: run domain-based audits, generate checklists, classify risks, and produce prioritized remediation reports.

anthropic-cybersecurity-skills
Structured workflow to test REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR), with techniques for discovery, exploitation checks, and rem

Anthropic Cybersecurity Skills
Guided workflow to identify, validate, and document reflected, stored, and DOM-based XSS using Burp Suite (scanner, repeater, intruder, DOM Invader).

antigravity-awesome-workspace-skill
A comprehensive security testing framework for REST and GraphQL APIs, covering auth, rate limiting, and input validation.

guardian-cli
An AI-driven, production-ready CLI that automates authorized penetration testing workflows, orchestrating planner, tool, analyst and reporter agents to produce

joshft
Goal-directed red team assessment skill for live systems with source-code access; enforces isolation and intensity gating before active testing.

vibe-security-skill
Audits AI-generated codebases for critical security flaws like exposed keys, broken RLS, and insecure payment flows.

joshft
Live adversarial red team assessment and goal-directed penetration testing.

claude-bughunter
Enumerate and assess on-prem Microsoft SharePoint servers for version disclosure, anonymous endpoints, legacy SOAP login abuse, ToolShell preconditions (CVE-202

Anthropic Cybersecurity Skills
Comprehensive guide for testing REST and GraphQL APIs for Broken Object Level Authorization (BOLA) and IDOR vulnerabilities.

Anthropic Cybersecurity Skills
Identify and exploit critical JWT vulnerabilities including algorithm confusion, 'none' bypass, and weak secret exploitation.

xalgorix
Comprehensive guide for enumerating and attacking FreeIPA domains, including LDAP leaks, Kerberos ticket abuse, and HBAC analysis.

awesome-omni-skill
Comprehensive guide for writing secure web apps, ensuring OWASP compliance and protection against XSS, CSRF, SSRF, and SQLi.