Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
66 results
Skill

performing-penetration-testing

Orchestrate a penetration test by routing user intent to one or more of the 25 narrow skills in this pack. Confirms authorization + scope FIRST (cluster 5), runs the relevant scan skills (clusters 1-4

by jeremylongshoreskills.sh
Not rated yet
Free
Skill

probing-dangerous-http-methods

Probe a target for HTTP methods that should not be enabled in production — TRACE (XST attack), unrestricted PUT/DELETE, DEBUG/CONNECT, WebDAV (PROPFIND/MKCOL/COPY/MOVE), and Allow header enumeration.

by jeremylongshoreskills.sh
Not rated yet
Free
Skill

recording-pentest-engagement

Package an engagement's findings, scan outputs, evidence, and signed ROE into a timestamped archive with a SHA-256 manifest covering every file. Establishes chain of custody so legal counsel, internal

by jeremylongshoreskills.sh
Not rated yet
Free
Skill

scanning-for-hardcoded-secrets

Scan a source-code tree for hardcoded credentials embedded in source files: AWS access keys, GitHub tokens, Stripe keys, Slack tokens, Anthropic API keys, OpenAI keys, JWT signing secrets, generic bas

by jeremylongshoreskills.sh
Not rated yet
Free
Skill

tracing-transitive-vulnerabilities

Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies. Identifies which direct-dep bump woul

by jeremylongshoreskills.sh
Not rated yet
Free
Skill

pentest-validation

Use when validating security findings from SAST/DAST scans, proving exploitability of reported vulnerabilities, eliminating false positives, or running the 4-phase pentest pipeline (recon, analysis, v

by proffesor-for-testingskills.sh
Not rated yet
Free
Skill

qe-pentest-validation

Orchestrate security finding validation through graduated exploitation. 4-phase pipeline: recon (SAST/DAST), analysis (code review), validation (exploit proof), report (No Exploit, No Report gate). El

by proffesor-for-testingskills.sh
Not rated yet
Free
Skill

pentest-metasploit

Penetration testing framework for exploit development, vulnerability validation, and authorized security assessments using Metasploit Framework. Use when: (1) Validating vulnerabilities in authorized

by aiskillstoreskills.sh
Not rated yet
Free
Skill

security-engineer

安全工程师 Agent — 覆盖渗透测试、安全架构评审、DevSecOps、漏洞管理、安全监控与应急响应、合规审计、代码安全审查等全领域安全工作。能动手执行扫描、分析、加固、报告,不只是出方案。

by aiskillstoreskills.sh
Not rated yet
Free
Skill

strix

Install, configure, and operate Strix for AI-driven application security testing. Use when you need to run authorized vulnerability scans against local codebases, GitHub repositories, staging URLs, do

by akillnessskills.sh
Not rated yet
Free
Skill

nuclei-scanner

Scan web applications and infrastructure for vulnerabilities with Nuclei — template-based security scanner. Use when someone asks to "scan for vulnerabilities", "security scan my website", "Nuclei sca

by terminalskillsskills.sh
Not rated yet
Free
Skill

r00-anthropics-skills--security

🔒 Security & Compliance skill suite derived from anthropics/skills. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for

by TeamArtisanThriveGitHub
Not rated yet
Free
Skill

r00-hesreallyhim-awesome-claude-code--security

🔒 Security & Compliance skill suite derived from hesreallyhim/awesome-claude-code. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialis

by sparkfinderovenGitHub
Not rated yet
Free
Skill

mastermind-workflow

Mastermind Bug Bounty workflow orchestrator. Drives the 6-phase bug bounty lifecycle with 6-Hook middleware. Pipeline: Recon → Dependency Scan → API Fuzz → Crypto Attack → Bypass → Exploit+Report. AI

by jinyimeng01GitHub
Not rated yet
Free
Skill

redmind

Red team mindset that shifts the agent to offensive security thinking across any target or engagement type. Trigger when the goal of the engagement is offensive (finding what can be broken, bypassed,

by RifteoGitHub
Not rated yet
Free
Skill

Exploit Development & Payload Engineering

Proof-of-concept development, payload crafting, shellcode analysis, and exploitation technique research for authorized security testing

by GhostPWNGitHub
Not rated yet
Free
Skill

pentest-lyan

授权 Web 渗透测试 Skill。模型自主威胁建模,JSON Schema 校验状态文件结构,输出按功能列出测了哪些威胁。 Use when user asks to perform authorized web penetration testing, vulnerability assessment on a web application, security testing with an

by HeaSecGitHub
Not rated yet
Free
Skill

Red Team Operations & Engagement Planning

Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting

by noirelabGitHub
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.