Agent Security Workbench
Scan before you trust, then practice: scanners that vet agent skills, CTF drills for judgment, and authorized-testing libraries for red-team work.
7 skills
The workbench has two benches, and the first one is vetting: agent skills are instruction files and scripts that run with your credentials. nvidia/skillspector detects vulnerabilities, malicious patterns, prompt injection, data exfiltration, and supply-chain risks in skills before you install them. cisco-ai-defense/skill-scanner does what its name promises — a security scan for agent skills. prompt-security/clawsec guards the agent side of the house for OpenClaw-family agents with drift detection, live security recommendations, automated audits, and skill integrity verification.
The second bench is practice, for authorized work only. ljagiello/ctf-skills drills the fundamentals across web exploitation, binary pwn, crypto, reverse engineering, forensics, and OSINT. gadievron/raptor turns Claude Code into an offensive/defensive security agent with orchestrated security tooling. snailsploit/claude-red and elementalsouls/claude-osint are structured skill libraries for specific attack surfaces and external recon — the latter built for authorized red-team and bug-bounty engagements.
The recommended order: scan before you install anything, keep clawsec running against your own agent setup, and take the practice libraries to authorized targets only — CTF frames and in-scope engagements.
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
15,946Sep 1, 2026Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Stars: 15,946
Last Updated: Sep 1, 2026
Security Scanner for Agent Skills
Stars: 2,493
Last Updated: Sep 3, 2026
A complete security skill suite for OpenClaw, Hermes, PicoClaw and NanoClaw agents (and variants). Protect your SOUL.md (etc') with drift detection, live security recommendations, automated audits, and skill integrity verification. All from one installable suite.
1,097Sep 4, 2026A complete security skill suite for OpenClaw, Hermes, PicoClaw and NanoClaw agents (and variants). Protect your SOUL.md (etc') with drift detection, live security recommendations, automated audits, and skill integrity verification. All from one installable suite.
Stars: 1,097
Last Updated: Sep 4, 2026
Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more
3,168Aug 25, 2026Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more
Stars: 3,168
Last Updated: Aug 25, 2026
Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we configure the agent for adversarial thinking, and perform research or attack/defense operations.
3,707Sep 1, 2026Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we configure the agent for adversarial thinking, and perform research or attack/defense operations.
Stars: 3,707
Last Updated: Sep 1, 2026
claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
3,024Aug 30, 2026claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
Stars: 3,024
Last Updated: Aug 30, 2026
8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and bug-bounty engagements.
2,531Aug 30, 20268 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and bug-bounty engagements.
Stars: 2,531
Last Updated: Aug 30, 2026