Awesome-omni-skill security-skills-guide

Guide for security-related Agent Skills including penetration testing, code auditing, threat hunting, and forensics skills.

install
source · Clone the upstream repo
git clone https://github.com/diegosouzapw/awesome-omni-skill
Claude Code · Install into ~/.claude/skills/
T=$(mktemp -d) && git clone --depth=1 https://github.com/diegosouzapw/awesome-omni-skill "$T" && mkdir -p ~/.claude/skills && cp -r "$T/skills/testing-security/security-skills-guide" ~/.claude/skills/diegosouzapw-awesome-omni-skill-security-skills-guide && rm -rf "$T"
manifest: skills/testing-security/security-skills-guide/SKILL.md
source content

Security Skills Guide

Scope

Use this skill when:

  • Finding or adding security-related skills
  • Understanding cybersecurity skill categories
  • Organizing security skills in README.md

Security Skill Categories

Penetration Testing

CategorySkills
Web ApplicationBurp Suite, FFUF fuzzing, SQL injection, XSS testing
NetworkNmap, Wireshark, SMTP/SSH testing
CloudAWS/Azure/GCP penetration testing
Active DirectoryKerberoasting, DCSync, pass-the-hash

Code Auditing

CategorySkills
Static AnalysisCodeQL, Semgrep, Slither
Smart ContractsSolidity security, Move auditing
Variant AnalysisFinding similar vulnerabilities

Threat Hunting

CategorySkills
Detection RulesSigma rules, YARA
ForensicsFile metadata, memory analysis
Incident ResponseTriage, investigation

Key Security Skill Repositories

Trail of Bits Security Team

  • trailofbits/skills
    - Static analysis, code auditing, smart contracts

Antigravity Collection

  • sickn33/antigravity-awesome-skills
    - 50+ cybersecurity skills

Community Skills

  • mhattingpete/claude-skills-marketplace
    - Computer forensics skills

Where to Add Security Skills in README

  • Penetration testing tools:
    Cybersecurity & Penetration Testing
  • Code analysis tools:
    Security & Systems
    or
    Development & Code Tools
  • Threat hunting:
    Security & Systems
  • Smart contract security:
    Development & Code Tools
    (if dev-focused)

Security Skill Best Practices

  1. Clear scope: Define what the skill does and doesn't do
  2. Legal warnings: Include responsible use disclaimers
  3. Tool requirements: List required external tools
  4. Safe defaults: Use non-destructive operations by default
  5. Logging: Include audit trail capabilities

Example Security Skill Structure

threat-hunting/
├── SKILL.md           # Main instructions
├── scripts/
│   ├── sigma-search.py
│   └── log-parser.sh
├── references/
│   └── sigma-rules.md
└── templates/
    └── report.md