网络安全 · 渗透测试 · 攻防对抗 · 红蓝对抗 · AI Agent Skills

🔐 OpenClaw SecSkills

🛡️ 网络安全 · 渗透测试 · 攻防对抗 · 红蓝对抗 · AI Agent Skills

AI Agent Skills

OpenClaw SecSkills 是一个专门为网络安全从业人员、渗透测试工程师、红蓝对抗团队整理的 AI Agent Skills 集合。

本项目基于 OpenClaw 框架,将传统安全工具与 AI Agent 能力相结合,让安全测试更智能、更高效。

✨ 项目特色

🎯🤖🔧📦
精准分类AI 驱动工具集成持续更新
8 大安全领域智能自动化集成主流工具每周更新
50+ Skills自然语言交互Nmap/Nuclei 等社区贡献

Agent Skills分类

🔒 代码审计

白盒代码安全审计,覆盖 Java/PHP/Python/智能合约等

Skill描述仓库
wxmini-security-audit微信小程序全自动安全审计 Skill,基于 Claude Code Agent Teams。7 Agent 协作,覆盖敏感信息、API接口、加密分析、漏洞分析四大维度。采用脚本+LLM双层架构,脚本保证覆盖率,LLM保证准确率。GitHub
claude-security-auditSkill Claude Code pour audit de sécurité complet (OWASP Top 10, CWE/CVE, headers, auth, paywall, infra)GitHub
panguard-aiOpen-source security platform for AI agents — audits skills before install, monitors 24/7, shares threat intelligence aGitHub
claude-skillsUX/UI evaluation, AI governance, and AI security skills for AI coding assistants. Audit interfaces with Nielsen heuristiGitHub
skillsTrail of Bits Claude Code skills for security research, vulnerability detection, and audit workflowsGitHub
SlowMist-Learning-Roadmap-for-Becoming-a-Smart-Contract-AuditorSmart contract audit skills roadmap for beginners, auditors, engineers, etc.GitHub
solsecA collection of resources to study Solana smart contract security, auditing, and exploits.GitHub
Smart-Contract-Security-AuditsCertified Smart Contract Audits for Ethereum, Solana, Near, Cardano, Aptos, Sui, Binance Smart Chain, Fantom, EOS, TezosGitHub
Smart-Contract-Auditor-Tools-and-TechniquesThis repo contains a comprehensive list of smart contract auditor tools and techniques that can be utilized by both smarGitHub
SmartContracts-audit-checklistA checklist of things to look for when auditing Solidity smart contracts.GitHub
smart-contract-auditsContractWolf audited smart contractsGitHub
QuillAudit_Smart_contract_Auditor_RoadmapSmart Contract Auditor RoadmapLearn Blockchain Security & Smart Contract Auditing
smart-contract-auditing-heuristicsHeuristics for smart contract auditorsGitHub
Smart-Contract-AuditsSmart Contract security audit reportsGitHub
QuillAudit_smart_contract_audit_ReportsQuillAudits — Smart Contract Audits for DeFi, RWA, DEXs, Tokens, DeAI & DAppsGitHub
marketplaceSecurity-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.GitHub
supabase-pentest-skills24 AI Agent Skills for professional security auditing of Supabase applications. Detection, key extraction, RLS testing,GitHub
solidity-auditor-skillsGitHub
ai-best-practices-skillsAI Best Practices Audit SkillsGitHub
java-audit-skillssjava-audit-skillssGitHub
security-audit-skillAgent Skill for PHP security audits – OWASP patterns, vulnerability detectionClaude Code compatible
java-audit-skills专注于 Java 代码审计,提供自动化源码分析、路由提取、参数映射GitHub
PHP-Code-Audit-SkillPHP Web 白盒审计全流程:路由枚举 → 鉴权建模 → 数据流追踪 → 漏洞审计GitHub
PHP_AUDIT_SKILLS多智能体协作框架,支持 21 种漏洞类型专家级审计GitHub
skill-dfyx_code_security_review五阶段标准化审计协议,系统性发现安全漏洞GitHub
Code Audit覆盖 55+ 漏洞类型,双轨审计模型,多 Agent 深度分析GitHub
zh-audit-skills-hub中文用户代码审计 Agent Skills 仓库GitHub

⚔️ 渗透测试

自动化渗透测试、漏洞挖掘、Bug Bounty

Skill描述仓库
iothackbotIoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentestingGitHub
labs-pentestFree Labs to Train Your Pentest / CTF SkillsGitHub
communitytoolsOpen-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and sGitHub
public-skills-builderGenerate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private rGitHub
BugHunterMethodologyA comprehensive bug bounty methodology compiled from extensive research, covering web application reconnaissance, checklGitHub
OneLinerBountyOneLinerBounty is a collection of quick, actionable bug bounty tips in one-liner format. Perfect for bug hunters lookingGitHub
SecToolkitWelcome SecToolkit repository! This is a comprehensive collection of cybersecurity and bug bounty hunting topics. Here,GitHub
picocom-claude-skillA Claude Code skill for using picocom to give access to a live UART shell for enumeration, pentesting, etc.GitHub
pentester-skills坤式网络安全学习法,不只是学习路线还是笔记。GitHub
KaliPAKUKaliPAKU is a training tool for penetration testing using Kali Linux. It is designed to help security professionals andGitHub
Active-Directory-WorkbookA comprehensive and hands-on workbook designed to sharpen your Active Directory penetration testing skills. Whether you’GitHub
Android-Pentesting-ChecklistDelve into a comprehensive checklist, your ultimate companion for Android app penetration testing. Identify vulnerabilitGitHub
Library-of-Cybersecurity-BooksA free, no-paywall cybersecurity self-study library covering foundations, pentesting, web security, exploit development,GitHub
pentest-skills自然语言驱动,自动选择工具、执行命令、分析结果GitHub
AutoSongshu Agent“半自动驾驶”渗透测试工作台,结合浏览器自动化GitHub
secknowledge-skill88,636 个真实漏洞案例 + 5,600+ 篇安全研究文档知识库GitHub
Security AuditorOWASP 十大审计、CORS/CSP 配置、SQL 注入/XSS 防护GitHub
Pentest Api AttackerOWASP API 安全前十名测试GitHub
Pentest Auth Bypass身份验证绕过和账户接管测试GitHub

🔍 逆向工程

二进制分析、恶意样本分析、JS 逆向

Skill描述仓库
DeepExtractRuntimeAI-driven agent runtime for Windows PE binary analysis. Turns IDA Pro decompiled code and SQLite databases produced by DGitHub
iOSAppReverseEngineeringThe world’s 1st book of very detailed iOS App reverse engineering skills 🙂GitHub
android-reverse-engineering-skillClaude Code skill to support Android app’s reverse engineeringGitHub
jshook-skillAI-powered JS reverse engineering: deobfuscation, crypto detection, CDP debugging, hook injection, anti-detection
re-skillClaude Code skill for reverse engineering retro games — disassemble, annotate, extract assets, web portGitHub
CrackMasterCCrackMaster is an educational CrackMe project written in C, designed to enhance skills in reverse engineering, code anaGitHub
TimeCodKotlinCrackMaster is an educational CrackMe project written in Kotlin, designed to enhance skills in reverse engineeringGitHub
skillsA growing collection of reverse engineering skills for AI coding agents.GitHub
Incident-Response-Projects-for-BeginnersHands-on cybersecurity projects to enhance skills in phishing investigation, malware analysis, network intrusion detectiGitHub
malware-analysis-claude-skillsComplete Claude skills toolkit for professional malware analysis. 5 specialized skills covering triage, dynamic analysisGitHub
my-claude-skillsBinary analysis plugins for Claude Code: angr (static analysis, symbolic execution) and Frida (dynamic instrumentation)GitHub
reverse-skills逆向工程插件市场,为 Claude Code 提供分析技能GitHub
IDA-Skill让 AI 像安全分析师一样分析恶意样本GitHub
hello_js_reverse_skillJS 逆向与爬虫对抗,Camoufox 反检测浏览器GitHub
JS Reverse MCPJavaScript 逆向工程 MCP 服务器GitHub
FlowDroidSkillAPK 静态污点分析,检测数据泄露路径GitHub

🏆 CTF 竞赛

CTF 解题技巧、工具使用、漏洞挖掘

Skill描述仓库
SecSkills收集整理渗透测试、代码审计、CTF 等网络安全相关的 SkillsGitHub
ctf-practicePractice your hacking skills with these CTFsGitHub
linux-ctfsA collection of Linux CTFs to practice your CLI skillsGitHub
Common-CTF-ChallengesCommon CTF Challenges is a collection of tools and resources to help individuals improve their Capture the Flag (CTF) skGitHub
Walkthrough-and-WriteupWelcome to my Capture The Flag (CTF) Walkthroughs & Writeups Repository. This repository contains educational, step-by-sGitHub
ctf-skillsWeb 漏洞利用、二进制破解、加密、逆向、取证、OSINTGitHub
android-h1基于 HackerOne 真实报告的移动安全漏洞挖掘GitHub
BugBounty-Hunting漏洞赏金猎人资源集合GitHub

🎯 威胁建模

安全风险评估、威胁分析、合规检查

Skill描述仓库
ThreatHuntThreatHunt is a PowerShell repository that allows you to train your threat hunting skills.GitHub
cti-expertCTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code. 67+ commands, 35 techniques, no API keysGitHub
threat-modelingAI-native automated software risk analysis skill. LLM-driven, Code-First approach for comprehensive security risk assessGitHub
SOC-Analyst-NotesComprehensive SOC Analyst notes covering incident response, threat hunting, SOC workflows, and cybersecurity concepts—peGitHub
SkillWardSecurity scanner for Agent Skills — uncover hidden threats before deployment.GitHub
threat-modelingLLM 驱动、代码优先的全面安全风险评估GitHub
ghsa-skill-builder自动将 GitHub 漏洞库和 HackerOne 报告转化为 SkillsGitHub

📱 移动安全

Android/iOS 安全分析、漏洞挖掘

Skill描述仓库
android-reversing-challengesthere are some CTF challenges or some other things helping improving android reversing skills.GitHub
Damn-Vulnerable-BankDamn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to asGitHub
Skill-Android-Security-Agent构建基于 Skill 的 Android 智能审计 AgentGitHub
mobile-security-learning-resourcesThis repository contains list of mobile security related resources that you can use to learn new skills and test existinGitHub
mobile-challengesThis repository houses diverse files and challenges centered around Just Mobile Security. With practical exercises and rGitHub
FlowDroidSkill基于 FlowDroid + Jadx 的 APK 静态分析GitHub
android-h1Android/iOS 应用漏洞挖掘手法分析GitHub
objection运行时移动探索工具GitHub

🚨 应急响应

安全事件响应、取证分析、日志分析

Skill描述仓库
Offensive-Security-Forensics-PortfolioA portfolio demonstrating advanced blue and red team skills, including: SSH MFA implementation, Volatility-based memoryGitHub
aguaraSecurity scanner for AI agent skills and MCP servers. Static analysis, incident response, no LLM. One binary. DetectioGitHub
repo-forensicsSecurity scanner for GitHub repos, Agent Skills, Plugins, and MCP servers. 18 scanners. Zero dependencies.GitHub
Digital-Crime-Scene-ChallengeThe object of the Digital Crime Scene Challenge is for participants to use their forensic and investigative skills to foGitHub
backdoorsandbreaches-socinvader🎮 AI-powered solo mode for Backdoors & Breaches. Train incident response skills anytime with an LLM Incident Master. ArcGitHub
Digital-Forensic-TrainingThe Chupacabra case study was created by the ADEO dfir team due to the lack of resources and applications in the digitalGitHub
spellbookPortable skill library for AI coding agents: debugging, PR workflows, design systems, incident response, and domain playGitHub
agent-infra-securitySecurity skills for AI coding agents — incident response for supply chain attacks, credential rotation, IOC detection. WGitHub
LinuxGun-skillLinux 安全应急响应 AI 检查GitHub
Blue-Team蓝队设施部署、取证分析资源GitHub
Email-OSINT自动化电子邮件 OSINT 工具GitHub

🛡️ 安全工具

扫描器、漏洞利用、红蓝对抗工具

Skill描述仓库
material-3-skillMaterial Design 3 skill for Claude Code — 30+ components, design tokens, theming, responsive layout, and MD3 complianceGitHub
htb-writeupsThe most comprehensive Hack The Box writeup collection – 500+ machines, 400+ challenges, interactive knowledge graph, skGitHub
DeepCameraOpen-Source AI Camera Skills Platform, AI NVR & CCTV Surveillance. Local VLM video analysis with Qwen, DeepSeek, SmolVLMGitHub
tirithTerminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payGitHub
raptorRaptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rGitHub
claude-forgeSupercharge Claude Code with 11 AI agents, 36 commands & 15 skills — the claude-code plugin framework inspired by oh-my-GitHub
TryHackMeRoadmapA list of 350+ free TryHackMe rooms💻 to kick off your cybersecurity learning, organized by topics for easy exploration aGitHub
agentguardSecurity guard for AI agents — blocks malicious skills, prevents data leaks, protects secrets. 24 detection rules, runtiGitHub
TryHackMeMaster cybersecurity skills with this TryHackMe free path, includes a collection of my write-ups, solutions and progressGitHub
secureclawSecureClaw – Security Plugin and Skill for OpenClaw OWASP-AlignedGitHub
TryHackMe-Learning-Path-From-Beginner-to-ExpertA comprehensive TryHackMe learning path with organized sections on Introductory Rooms, Linux Fundamentals, Networking, FGitHub
SecurityClawA modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, buGitHub
agentsealSecurity toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacksGitHub
orchestkitThe Complete AI Development Toolkit for Claude Code — 103 skills, 36 agents, 169 hooks. Production-ready patterns for fuGitHub
claude-code-owaspClaude Code skill for OWASP security best practices (2025-2026). Includes Top 10:2025, ASVS 5.0, Agentic AI security, anGitHub
ReferencesPoole, Mackworth & Goebel 1998, p. 1. Russell & Norvig 2003, p. 55. Definition of AI as the study of intelligent agenGitHub
AthenaTest your Security Skills, and Clean Code Development as a Pythonist, Hacker & Warrior 🥷🏻GitHub
www-project-agentic-skills-top-10OWASP Foundation web repositoryGitHub
don-cheli-sddDon Cheli — SDD Framework. The most comprehensive Specification-Driven Development framework for AI agents. 88+ commandsGitHub
Other-sourcesAsada, M.; Hosoda, K.; Kuniyoshi, Y.; Ishiguro, H.; Inui, T.; Yoshikawa, Y.; Ogino, M.; Yoshida, C. (2009). “Cognitive dGitHub
zephRust AI agent where every context token earns its place. Self-learning skills, temporal graph memory, cascade qualityGitHub
claude-code-skillsPlugin suite + bundled MCP servers for Claude Code. Full delivery lifecycle: Agile pipeline with multi-model AI review,GitHub
faillapopVulnerable-by-design solidity protocol to help Web3 security enthusiasts practice their skills in an environment closerGitHub
skillarchSkillArchGitHub
web3-bug-bounty-hunting-ai-skills18 Claude Code skill files for smart contract security — built from 2,749 Immunefi reports, 681 DeFiHack reproductions,GitHub
CEH-AssessmentsA structured portfolio of weekly CEH v13 assessments, vulnerability labs, and ethical hacking documentation to demonstraGitHub
Phase-1-Cybersecurity-Ethical-Hacking-Internship-LabsPhase 1 of the Cybersecurity Ethical Hacking Internship Labs offers hands-on training in essential skills. ParticipantsGitHub
claude-security-research-skillAI-powered security research assistant for Claude Code — structured assessment workflows, tool orchestration, and profesGitHub
VulnBoxVulnBox is a container that is intentionally designed with vulnerabilities to allow security professionals to practice aGitHub
open-source-handbook⭐️ Open source projects for all skill levelsGitHub
cybersecurity-roadmapSkills and career roadmap for various security roles like application security, cloud security, DevSecOps, security engiGitHub
Titanic-Machine-Learning-from-DisasterStart here if… You’re new to data science and machine learning, or looking for a simple intro to the Kaggle predictionGitHub
SOC-RessourcesRepository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to iGitHub
Python-Basic-programsWhat is Python? Executive Summary Python is an interpreted, object-oriented, high-level programming language with dynamiGitHub
EthicalHackingFromScratchWelcome to my comprehensive course on python programming and ethical hacking. The course assumes you have NO prior knowlGitHub
javascript-basic-programWhat is JavaScript and what does it do? Before you start learning something new, it’s important to understand exactlyGitHub
low-level-dev-skillsA curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, coveringGitHub
solana-claudeClaude Code configs for the expert Solana builder. CLAUDE.md, agents, commands, hooks, rules, skills and settings acrossGitHub
ClarityFinanceClarity is a financial analysis agent framework built on native Claude-skill architecture. Adopting a Planning-with-FileGitHub
30-Day-SOC-Analyst-ChallengeA 30-day hands-on SOC Analyst project simulating real-world cyber attacks using ELK Stack, Mythic C2, osTicket & ElasticGitHub
kernel-vuln-analyzerClaude Code skill for Linux kernel vulnerability analysis — from crash log triage to patch verificationGitHub
aws_deepracer_worksheetWorksheet and Utilities for AWS DeepRacer – one of the most exciting ways of building strong skills in reinforcement leaGitHub
MalwareAnalysisThis central repository is crafted for cybersecurity enthusiasts, researchers, and professionals aiming to advance theirGitHub
Machine-Learning-Interview-PreparationPrepare to Technical Skills Here are the essential skills that a Machine Learning Engineer needs, as mentioned Read me fGitHub
DevOps-Security-Agent-SkillsAgent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, TerraformGitHub
A-Online-Quiz-Site# Skill’s Breaker An online quiz system built on PHP, JS and HTML. It has inbuilt Timer support along with Admin PanelGitHub
Fuzzy-Logic-Based-Recommendation-System-for-Research-Topic-in-the-Final-yearMost University students are uncertain which research topic to choose for their final year research projects.The studentGitHub

漏洞利用

Skill描述仓库
awesome-claude-skills-securitySecurity testing toolkit for Claude Code: curated SecLists wordlists, injection payloads, and expert agents for authorizGitHub
ANYDESK-BACKDOORYou should never use malware to infiltrate a target system. With the skill of writing and exploiting technical codes, yoGitHub
PayloadsAllTheThingsWeb 安全 payload 和绕过列表GitHub
BugBountyGuide漏洞赏金绕过技巧和 payloadGitHub

红队工具

Skill描述仓库
Red-Team-RoadmapRed Team Roadmap [defination, job positions, skills, tools]GitHub
agile_v_skillsOfficial Agent Skills for the Agile V™ framework. Verifiable AI-augmented engineering with traceability, Red Team verifiGitHub
eJPTeJPT is a hands-on, entry-level Red Team certification that simulates skills utilized during real-world engagements.GitHub
Red-Team红队/渗透测试工具集合GitHub
Windows-ExploitsWindows 提权漏洞集合GitHub
AD-AttackActive Directory 攻击路径GitHub
Pentest Active DirectoryAD 身份攻击路径评估GitHub

蓝队防御

Skill描述仓库
ramibotRamiBot v3.8.0 is a local-first AI security operations platform integrating multi-LLM support, a dynamic red/blue team sGitHub
Default-Creds默认密码集合GitHub
Blue-Team蓝队防御资源GitHub

安全检查

Skill描述仓库
CLS-CertifySkill 安全检查工具GitHub
SkillGuardOpenClaw Skill 安全检查GitHub
skill-audit审计 Skill 定义的安全性、完整性GitHub

安全扫描

Skill描述仓库
llm-sast-scannerA SAST skill that gives AI coding agents structured vulnerability detection across 34 vulnerability classes.GitHub
agent-scanSecurity scanner for AI agents, MCP servers and agent skills.GitHub
skill-scannerSecurity Scanner for Agent SkillsGitHub
nova-proximityNova-Proximity is a MCP and Agent Skills security scanner powered with NOVAGitHub
claude-skill-antivirusSecurity scanner for Claude Code Skills — 9 engines detect malicious patterns, data exfiltration, dangerous ops across 7GitHub
skillsentryAI Skill Security ScannerGitHub
SkillSemgrep基于 Semgrep 的自然语言漏洞扫描GitHub
Nmap网络发现和安全审计GitHub
Nmap Pentest ScansNmap 主机发现、端口枚举、NSE 分析GitHub
Security Scanner集成 nmap、nuclei 的自动化扫描GitHub
Gobuster快速内容发现工具 (Rust)GitHub
Hydra网络登录破解器GitHub
Nuclei基于模板的快速漏洞扫描器GitHub

信息收集/OSINT

Skill描述仓库
Sherlock跨平台人员资料查找 (1000+ 网站)GitHub
reconFTW自动化侦察工具GitHub
BugBounty-Hunting漏洞赏金资源GitHub

🎓 学习与靶场

网络安全学习资源、练习平台、知识框架

Skill描述仓库
1earnffffffff0x 团队安全知识框架:Web/工控/取证/应急/后渗透GitHub
Awesome-Infosec信息安全课程和培训资源精选GitHub
HackTheBoxCTF 和渗透测试练习资源GitHub
TryHackMe网络安全学习路径GitHub

来源

https://github.com/Batman0506/openclaw-sec-skills/blob/main/README.md
© 版权声明
THE END
喜欢就支持一下吧
点赞6 分享
评论 抢沙发
头像
欢迎您留下宝贵的见解!
提交
头像

昵称

取消
昵称表情代码图片

    暂无评论内容