SKILL.md packages that extend Claude Code, Cursor, Copilot, and other AI agents.
Tags

xianzhi-research
A structured vulnerability research framework distilled from 5600+ security docs, covering web injection, deserialization, binary exploitation, domain pentest,

claude-skill-registry
Security review and best-practice guidance for web apps and agentic AI systems covering OWASP Top 10:2025, ASVS 5.0, and agent security patterns.

claude-skills
Provides concrete guidance and code examples to implement authentication, authorization, input validation, and other defenses against OWASP Top 10 vulnerabiliti

claude-bughunter
Guided hunting methodology for server-side request forgery (SSRF): detection, OOB validation, payloads, bypass techniques, and escalation chains.

Anthropic Cybersecurity Skills
Guided workflow to identify, validate, and document reflected, stored, and DOM-based XSS using Burp Suite (scanner, repeater, intruder, DOM Invader).

bountyforge
Orchestrates parallelized bug-bounty audits across smart contracts and web/APIs, producing deduplicated, gate-evaluated, platform-ready vulnerability reports fo

comeonoliver
Auto-activating skill that generates and validates security HTTP headers and provides guidance for implementing secure header configurations.

kali-docker-pentesting
Provides a Kali Linux Docker container with 200+ penetration-testing tools and guidance for running scans, exploitation, and forensics via direct docker exec co

trezor-suite
Ensures generated code aligns with security headers and permissions policies, specifically for navigator object interactions.

claude-bughunter
Enumerate and assess on-prem Microsoft SharePoint servers for version disclosure, anonymous endpoints, legacy SOAP login abuse, ToolShell preconditions (CVE-202

Keygraph Shannon
Autonomous AI-driven pentesting tool for web apps and APIs. Performs real exploits to prove vulnerabilities with high success rates.

bb-huge
Advanced methodology for detecting Broken Object Level Authorization and Insecure Direct Object References in APIs.

vibe-pentest
A multi-agent parallel architecture for automated black-box web application penetration testing and vulnerability reporting.