---
title: "hardw00t&#x2F;ai-security-arsenal skills · skilld"
canonical_url: "https://skilld.dev/gh/hardw00t/ai-security-arsenal"
meta:
  description: "A collection of skills, agents, commands, and workflows for security researchers. Compatible with Claude Code, Claude Desktop, OpenCode, and other AI coding tools."
  "og:description": "A collection of skills, agents, commands, and workflows for security researchers. Compatible with Claude Code, Claude Desktop, OpenCode, and other AI coding tools."
  "og:title": "hardw00t/ai-security-arsenal skills"
  "twitter:description": "A collection of skills, agents, commands, and workflows for security researchers. Compatible with Claude Code, Claude Desktop, OpenCode, and other AI coding tools."
  "twitter:title": "hardw00t/ai-security-arsenal skills"
---

`

[All skills](https://skilld.dev/skills)

[![hardw00t avatar](https://skilld.dev/_img/avatar?url=https%3A%2F%2Fgithub.com%2Fhardw00t.png)](https://skilld.dev/gh/hardw00t)

# **hardw00t/ai-security-arsenal**

A collection of skills, agents, commands, and workflows for security researchers. Compatible with Claude Code, Claude Desktop, OpenCode, and other AI coding tools.

main Updated 6 months ago [GitHub](https://github.com/hardw00t/ai-security-arsenal)

![README badge for hardw00t/ai-security-arsenal](https://skilld.dev/b/hardw00t/ai-security-arsenal?theme=light&label=0)

## Repository statistics

- Indexed skills

  **12**
- Skill groups

  **1**
- GitHub stars

  **104**
- Forks

  **15**

## Skills

12 total

Sort skills

[<h3>**/android-pentest**</h3>Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze APKs, bypass mobile security controls, or run MASVS/MASTG assessments. /android-pentest](https://skilld.dev/gh/hardw00t/ai-security-arsenal/android-pentest)

Updated 6 months ago

[<h3>**/api-security**</h3>Router skill for API penetration testing across REST, GraphQL, gRPC, and WebSocket. Covers OWASP API Top 10 (2023) including BOLA/BFLA/BOPLA, JWT attack chains, GraphQL introspection abuse, and mass assignment. Invoke when the user asks to pentest an API, analyze OpenAPI/Swagger, test auth/authorization, fuzz endpoints, or find API vulnerabilities. /api-security](https://skilld.dev/gh/hardw00t/ai-security-arsenal/api-security)

Updated 6 months ago

[<h3>**/cloud-security**</h3>Multi-cloud security assessment skill for AWS, Azure, and GCP. Use when performing cloud security audits, scanning for misconfigurations, testing IAM policies, auditing storage permissions, and identifying privilege escalation paths. Triggers on requests to audit cloud security, scan AWS/Azure/GCP, check cloud misconfigurations, or perform cloud penetration testing. Covers CIS benchmarks, CSPM, and cross-cloud identity federation. /cloud-security](https://skilld.dev/gh/hardw00t/ai-security-arsenal/cloud-security)

Updated 6 months ago

[<h3>**/container-security**</h3>Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and runtime monitoring (Falco/Tetragon). Use when scanning Docker/OCI images, auditing K8s clusters, reviewing Dockerfiles, diffing SBOMs across releases, analyzing RBAC, or assessing container runtime posture. Triggers on requests involving Trivy, Grype, Syft, Kubescape, kube-bench, Falco, container escapes, or CIS Docker/K8s benchmarks. /container-security](https://skilld.dev/gh/hardw00t/ai-security-arsenal/container-security)

Updated 6 months ago

[<h3>**/dast-automation**</h3>Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these URLs", "automated pentest", or "security-test the staging app". /dast-automation](https://skilld.dev/gh/hardw00t/ai-security-arsenal/dast-automation)

Updated 6 months ago

[<h3>**/iac-security**</h3>Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s security policies, checking cloud infrastructure compliance, or authoring custom policy-as-code (Rego). /iac-security](https://skilld.dev/gh/hardw00t/ai-security-arsenal/iac-security)

Updated 6 months ago

[<h3>**/ios-pentest**</h3>iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings. /ios-pentest](https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest)

Updated 6 months ago

[<h3>**/llm-security**</h3>LLM and AI application security testing skill for prompt injection (direct, indirect, multimodal), system-prompt extraction, RAG poisoning, memory poisoning, MCP server injection, skill-file injection, agentic tool misuse, computer-use UI injection, and excessive agency. Authorization required — this skill tests AI systems you are explicitly permitted to assess. Triggers on requests to test LLM / AI-agent / RAG / MCP / computer-use security, perform prompt injection, extract system prompts, poison RAG or memory, audit agent tool use, or evaluate AI guardrails. /llm-security](https://skilld.dev/gh/hardw00t/ai-security-arsenal/llm-security)

Updated 6 months ago

[<h3>**/network-pentest**</h3>Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges. /network-pentest](https://skilld.dev/gh/hardw00t/ai-security-arsenal/network-pentest)

Updated 6 months ago

[<h3>**/sast-orchestration**</h3>Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output, reduce false positives, or integrate SAST into CI/CD. Triggers on phrases like 'scan this code', 'write a Semgrep rule', 'triage these findings', 'SARIF', 'SAST in CI', or when a repo is handed over for a security review. /sast-orchestration](https://skilld.dev/gh/hardw00t/ai-security-arsenal/sast-orchestration)

Updated 6 months ago

[<h3>**/sca-security**</h3>Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems, Composer), reviewing PR lockfile diffs, generating SBOMs, auditing licenses, hunting malicious packages, or auditing the software supply chain. Triggers on requests to scan dependencies, check vulnerable packages, generate SBOM, license compliance, typosquat/dependency-confusion review, or reachability-based vuln triage. /sca-security](https://skilld.dev/gh/hardw00t/ai-security-arsenal/sca-security)

Updated 6 months ago

[<h3>**/threat-modeling**</h3>Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to NIST/CIS/OWASP ASVS controls, or producing a threat model report. Triggers on requests to threat model, analyze attack surface, create a DFD, apply STRIDE, or design security mitigations. /threat-modeling](https://skilld.dev/gh/hardw00t/ai-security-arsenal/threat-modeling)

Updated 6 months ago

## Add to your README

The badge links readers to this page. It shows the skilld mark and no counts, and it follows the reader's light or dark GitHub theme.

`<a href="https://skilld.dev/gh/hardw00t/ai-security-arsenal"> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://skilld.dev/b/hardw00t/ai-security-arsenal?theme=dark"> <source media="(prefers-color-scheme: light)" srcset="https://skilld.dev/b/hardw00t/ai-security-arsenal?theme=light"> <img alt="Skill repository on skilld.dev" src="https://skilld.dev/b/hardw00t/ai-security-arsenal?theme=light"> </picture> </a>`