Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By briiirussell
Conduct comprehensive security audits and incident response across cloud, API, mobile, and AI systems with pre-built skills for compliance, threat modeling, and red teaming.
npx claudepluginhub briiirussell/cybersecurity-skills --plugin cybersecurity-skillsApply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency, accountability, third-party model risk, monitoring for drift, and AI incident response. Broader than prompt-injection (which is the security slice). Use when the user mentions 'AI risk,' 'AI governance,' 'NIST AI RMF,' 'AI compliance,' 'ML governance,' 'model risk management,' 'AI fairness,' 'AI bias,' 'algorithmic accountability,' 'AI Bill of Rights,' 'EU AI Act,' 'AI transparency,' 'model card,' 'AI red team,' 'AI safety,' 'responsible AI,' 'model drift,' 'concept drift,' 'AI monitoring,' 'AI incident,' or needs to assess or govern an AI / ML system.
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023). Use when the user mentions 'API security,' 'API audit,' 'BOLA,' 'broken object level authorization,' 'BFLA,' 'function-level authorization,' 'mass assignment,' 'API rate limiting,' 'GraphQL security,' 'REST security,' 'API authentication,' 'API authorization,' 'excessive data exposure,' or needs to review API endpoints for security weaknesses.
Learn from public breach disclosures — extract the audit question each one implies and check your own stack. Capital One IMDS abuse, LastPass vault exfiltration, Okta Lapsus$, Snowflake credential reuse, MOVEit, SolarWinds, Equifax, Target POS, Codecov, Uber, Twilio — what would you check now if your boss said 'could that happen to us?' Use when the user mentions 'breach analysis,' 'lessons learned,' 'security postmortem,' 'breach patterns,' 'breach lessons,' 'has this happened to us,' 'apply breach lessons,' 'preempt breaches,' 'security retrospective,' 'real-world security incidents,' or wants to harden against known attacker playbooks.
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps. Use when the user mentions 'cloud security,' 'cloud audit,' 'AWS security,' 'GCP security,' 'Azure security,' 'IAM audit,' 'S3 bucket,' 'cloud misconfiguration,' 'cloud hardening,' or needs to review cloud infrastructure security.
Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation. Deeper than owasp-audit A02. Use when the user mentions 'crypto review,' 'cryptography audit,' 'encryption review,' 'KDF,' 'PBKDF2,' 'Argon2,' 'bcrypt cost,' 'IV reuse,' 'nonce reuse,' 'AES mode,' 'AES-GCM,' 'AES-ECB,' 'signature verification,' 'TLS configuration,' 'cipher suites,' 'key rotation,' 'libsodium,' 'BoringSSL,' or 'is this crypto right.'
Share bugs, ideas, or general feedback.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Editorial "Security Engineer" bundle for Claude Code from Antigravity Awesome Skills.
Professional security tools for Claude Code: vulnerability scanning, compliance, cryptography audit, container & API security
Security guidance skills for AI coding assistants. Covers cryptography, web security, supply chain, MCP servers, Kubernetes, API gateways, fuzzing, static analysis, audit workflows, and more.
753 cybersecurity skills covering web security, pentesting, DFIR, threat intelligence, cloud security, malware analysis, and more.
🛡️ Security Engineer — Security Engineer + Adversarial Security Specialist
AI-powered cybersecurity code review with 8 specialist agents, OWASP Top 10:2021, CWE Top 25:2024, MITRE ATT&CK v15, and framework-aware false-positive suppression
A collection of cybersecurity skills for AI coding agents. The AI does the heavy lifting; you bring the context about your stack and your priorities.
Built to be useful at every experience level:
You do not need to be a security expert to use these skills. The skills are written so the AI agent can run them end-to-end and explain the findings in language any technical reader can follow. If you can describe what you have and what you want to know about it, the agent can do the work.
Skills are authored as Claude Code SKILL.md files (the canonical format) and built into adapters for Cursor and Codex. Installable via npx skills or the Claude Code plugin marketplace.
Built by Bri Russell. I run real audits with these skills, then bring the gaps I find back into the skill itself — so each version is a little less opinion and a little more evidence.
Contributions welcome! Field feedback is the most valuable contribution — whether you're a security engineer who hit a gap during an audit, a developer whose AI agent missed something obvious, or a founder who used a skill and got an answer that wasn't quite right. Open a PR or open an issue — every level of expertise produces useful signal.
Not every skill is for every user on day one. A good starting point by context:
owasp-audit for the source-code sweep, then api-audit if you have API endpoints, then dependency-audit for the CVE passcloud-audit (AWS / GCP / Azure misconfig), then iam-audit if you manage identities, then container-audit if you run Docker / Kubernetesincident-triage for the immediate response, disk-forensics if you need to analyze a system afterward, security-comms to draft the stakeholder / customer communicationscsf-mapping for the governance frame, threat-modeling before new features, breach-patterns to learn from public incidentsprivacy-engineering for GDPR / CCPA / similar privacy laws, hipaa-audit for ePHI, pci-audit for payment cards, ai-risk-management for AI featuresfinding-triage for any single finding from any source — gives you a defensible disposition with the right ticket fieldssecurity-comms for board / exec / customer / engineering / sales-engineering deliverablesThe offensive skills (recon, osint-recon, web-pentest, red-team-engagement) require explicit authorization for the target and assume more security context. They open with an authorization check and will refuse anything ambiguous. red-team-engagement in particular carries the strongest refusal posture in the catalog and will refuse to plan anything against systems the user cannot demonstrate authorization for.
Skills are markdown files that give AI agents specialized knowledge and workflows for specific tasks. Drop them into your project and your agent recognizes when you're working on a security task and applies the right methodology — OWASP categories, NIST IR steps, MITRE ATT&CK references, the actual grep patterns that surface the bug.
The goal isn't to replace a security engineer — or to pretend you have one if you don't. It's to give the agent enough structure that the first pass is useful, the report format is consistent, and the obvious stuff stops slipping through. For teams without dedicated security headcount, that closes a real gap. For teams with security engineers, it lets them spend their time on the work the AI can't do.