Security Skills Guide
Scope
Use this skill when:
- Finding or adding security-related skills
- Understanding cybersecurity skill categories
- Organizing security skills in README.md
Security Skill Categories
Penetration Testing
| Category | Skills | |----------|--------| | Web Application | Burp Suite, FFUF fuzzing, SQL injection, XSS testing | | Network | Nmap, Wireshark, SMTP/SSH testing | | Cloud | AWS/Azure/GCP penetration testing | | Active Directory | Kerberoasting, DCSync, pass-the-hash |
Code Auditing
| Category | Skills | |----------|--------| | Static Analysis | CodeQL, Semgrep, Slither | | Smart Contracts | Solidity security, Move auditing | | Variant Analysis | Finding similar vulnerabilities |
Threat Hunting
| Category | Skills | |----------|--------| | Detection Rules | Sigma rules, YARA | | Forensics | File metadata, memory analysis | | Incident Response | Triage, investigation |
Key Security Skill Repositories
Trail of Bits Security Team
trailofbits/skills- Static analysis, code auditing, smart contracts
Antigravity Collection
sickn33/antigravity-awesome-skills- 50+ cybersecurity skills
Community Skills
mhattingpete/claude-skills-marketplace- Computer forensics skills
Where to Add Security Skills in README
- Penetration testing tools:
Cybersecurity & Penetration Testing - Code analysis tools:
Security & SystemsorDevelopment & Code Tools - Threat hunting:
Security & Systems - Smart contract security:
Development & Code Tools(if dev-focused)
Security Skill Best Practices
- Clear scope: Define what the skill does and doesn't do
- Legal warnings: Include responsible use disclaimers
- Tool requirements: List required external tools
- Safe defaults: Use non-destructive operations by default
- Logging: Include audit trail capabilities
Example Security Skill Structure
threat-hunting/
├── SKILL.md # Main instructions
├── scripts/
│ ├── sigma-search.py
│ └── log-parser.sh
├── references/
│ └── sigma-rules.md
└── templates/
└── report.md
Scan to join WeChat group