Skip to main content
Category ranking· 品类排行

The best AI skills for security & compliance做安全与合规最好用的

Scan vulnerabilities, audit dependencies and permissions before anything ships.扫漏洞、查依赖、审权限:让代码和 AI Agent 上线前过一遍安全关。

Task shortcuts按用途继续找

Open the matching picks in the full catalog.这些入口会带你去完整目录里看对应用途。

Editor's picks编辑精选榜单

2026-06-09 last re-ranked · 上次重排
#1Gold · 金

api-security-testing

Editor's Choice· 编辑首选
by Ed1s0nZ·updated 2mo ago

API安全测试的专业技能和方法论

API安全测试的专业技能和方法论

Claude CodeCodexMedium risk · 中风险$
rating · 评分
3.7k
stars · 星标
View看详情 →
#2Silver · 银

aig-scanner

Runner-up· 次选
by Tencent·updated 2mo ago

A.I.G Scanner — AI security scanning for infrastructure, AI tools / skills, AI Agents, and LLM jailbreak evaluation via

A.I.G Scanner — AI security scanning for infrastructure, AI tools / skills, AI Agents, and LLM jailbreak evaluation via Tencent Zhuque Lab AI-Infra-Guard. Uses built-in exec + Python script, no plugin required. Requires AIGBASEURL to be configured. Triggers on: scan AI service, AI vulnerability scan, scan AI infra, check CVE, audit AI service, scan MCP, scan skills, audit AI tools, scan agent, red-team LLM, jailbreak test, 扫描AI服务, 检查AI漏洞, 扫描AI工具, 检查MCP安全, 审计Agent, 越狱测试.

Claude CodeCodexMedium risk · 中风险$
rating · 评分
3.6k
stars · 星标
View看详情 →
#3Bronze · 铜

acquiring-disk-image-with-dd-and-dcfldd

Pair with #1· 推荐配套
by Mahipal·updated 2mo ago

Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash v

Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.

Claude CodeCodexMedium risk · 中风险$
rating · 评分
6.2k
stars · 星标
View看详情 →
#4

android-reverse-engineering

by SimoneAvogadro·updated 2mo ago

Decompile Android APK, XAPK, JAR, and AAR files using jadx or Fernflower/Vineflower. Reverse engineer Android apps, extr

Decompile Android APK, XAPK, JAR, and AAR files using jadx or Fernflower/Vineflower. Reverse engineer Android apps, extract HTTP API endpoints (Retrofit, OkHttp, Volley), and trace call flows from UI to network layer. Use when the user wants to decompile, analyze, or reverse engineer Android packages, find API endpoints, or follow call flows. 中文触发词:反编译APK、安卓逆向、提取API、分析安卓应用、反编译安卓、逆向工程、追踪调用链、提取接口

Claude CodeCodexMedium risk · 中风险$
rating · 评分
5.6k
stars · 星标
View看详情 →
#5

Active Directory Attacks

by zebbern·updated 2mo ago

This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pas

This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP roasting", "NTLM relay", or needs guidance on Windows domain penetration testing.

Claude CodeCodexMedium risk · 中风险$
rating · 评分
4.1k
stars · 星标
View看详情 →
#6

offensive-active-directory

by SnailSploit·updated 2mo ago

Active Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerV

Active Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trust attacks, ADCS abuse (ESC1-ESC15), and modern MDI/Defender for Identity evasion. Use when assessing on-prem AD, hybrid AD/Entra ID environments, or ADCS deployments.

Claude CodeCodexMedium risk · 中风险$
rating · 评分
1.2k
stars · 星标
View看详情 →
#7

offensive-iot

by SnailSploit·updated 2mo ago

IoT and embedded device security testing methodology. Covers hardware reconnaissance (UART, JTAG, SWD, SPI flash, I2C EE

IoT and embedded device security testing methodology. Covers hardware reconnaissance (UART, JTAG, SWD, SPI flash, I2C EEPROM, eMMC chip-off), firmware acquisition (vendor portals, OTA capture, flash dump, binwalk extraction), firmware analysis (filesystem mounting, binary triage, hardcoded secrets, default credential discovery), bootloader attacks (U-Boot console, secure-boot bypass, fault injection), runtime attacks on embedded Linux/RTOS (busybox CVEs, MTD writes, /dev/mem), wireless protocol attacks (Zigbee, BLE, Z-Wave, LoRaWAN, Thread/Matter, sub-GHz), MQTT/CoAP/Modbus/BACnet/OPC-UA exploitation, mobile companion app analysis, cloud-IoT API abuse, and side-channel/glitching basics. Use for IoT pentest, smart-home assessment, ICS/OT testing, or embedded vulnerability research.

Claude CodeCodexMedium risk · 中风险$
rating · 评分
1.2k
stars · 星标
View看详情 →

Why we didn't pick these为什么没选这些

Also common, but didn't make the picks同样常见,但未入精选
  • soc2 compliance

    Workflows that require stronger human review than this catalog entry documents.

    需要比当前目录条目更严格人工复核的工作流。

  • threat detection

    Workflows that require stronger human review than this catalog entry documents.

    需要比当前目录条目更严格人工复核的工作流。

  • soc2 compliance

    Workflows that require stronger human review than this catalog entry documents.

    需要比当前目录条目更严格人工复核的工作流。

Didn't find what you need?没看到合适的 skill?

Tell us your pain points and we'll go look.把你的痛点告诉我们,我们会去找。

Skill Market
Find the best AI skills for the job·按品类找最好用的 AI 技能
v0.4 · 1306 skills indexed · last review 2026-06-09