secskills
82 skills · 3 plugins · Claude Code

Security skills with the judgment built in.

Claude knows the commands. What these encode is the discipline — trace impact before you report it, preserve before you remediate, spot the honeypot before you touch it. Every skill fact-checked against primary sources.

✓ 82 / 82 verified· offense 37defense 22core 23
# add the marketplace $ /plugin marketplace add trilwu/secskills # offensive — red team / pentest $ /plugin install secskills-offense $ /plugin install secskills-core # defensive — DFIR / SOC / detection $ /plugin install secskills-defense $ /plugin install secskills-core
how it works

You describe the task — the skill does the rest

No commands to memorize, no manual invocation. This is what a skill changes versus asking Claude cold.

01
You describe the task in plain language.

Say audit this repo for auth bugs or a host is beaconing — where do I start?. Claude Code matches the right skill from its description; you never type a skill name.

02
It loads only when it applies.

Only each skill's one-line description sits in context. The full methodology loads when your task triggers it — 82 skills cost nothing until one is relevant. Procedure skills wait for their evidence (a libflutter.so, a SAMLResponse, an .E01 image).

03
It shapes the approach, then hands off.

The skill enforces a methodology — sequence, scope, the verification gate — and names the sibling skill to switch to as the task moves. That is how the collection composes instead of dumping commands.

04
It refuses the shortcut.

Each skill's Rationalizations to Reject blocks the plausible-but-wrong call — grep was clean, so the tree is clean, the tool rated it critical, so escalate.

prompt by use case

What to actually type

You don't need the jargon. Describe the situation — here are good starting prompts, and where each lands.

Builders
Micro-SaaS founder · pre-launch
"Before I launch, audit this codebase for anything that could leak a customer's data — focus on authentication, access control, and the billing flow."
Indie hacker · cloud check
"Review my AWS setup for anything public that shouldn't be, and flag any over-broad IAM roles."
AI / agent builder
"Review this LLM agent for prompt injection and tool misuse before I ship it."
securing-ai-systems
AI / agent builder · MCP
"Audit this MCP server I built — tool definitions, authorization, and what a caller can reach."
auditing-mcp-servers
Security professionals
AppSec · code review
"Audit the authentication and billing code in this repo for vulnerabilities."
Red team · internal engagement
"I'm on an internal pentest with a low-priv AD user — where do I look for escalation?"
DFIR · incident responder
"A host is beaconing to an unfamiliar domain. What do I preserve, and where do I start?"
SOC · analyst
"Triage this EDR alert for me — is it worth escalating, and why?"
who it's for

Install your side, get a coherent toolkit

Cloud and Kubernetes are covered from both sides, so purple-team work stays in one vocabulary.

red team · pentest

Offensive operations

offense + core

AD & Entra, AD CS ESC1–16, cloud, managed k8s, mobile, wireless, web/auth — plus recognizing-deception and maintaining-engagement-state.

appsec · code review

Find & fix in code

core (+ offense to prove impact)

Source audit with a verification gate, PR review that reads deleted lines, crypto & supply-chain, AI/MCP, PHP depth, backdoor hunting.

dfir · incident response

Investigate & respond

defense + core

Preserve-first forensics and cross-cloud IR for AWS, Azure, GCP, M365/Entra, built on the audit-log defaults that decide what's answerable.

soc · detection eng

Triage & detect

defense + core

Base-rate alert triage, detection-as-code with real FP analysis, threat hunting, KEV+EPSS vuln management, finished intel.

the catalog

All 82 skills

Search by name or technique; filter by plugin. Click any skill for the full methodology.

verification

Every skill checked against primary sources

The differentiator, and the honest version of it — not confidently-wrong output.

82/82
source-verified
2.6
errors / skill found
143
ATT&CK techniques

verified: is dated, not eternal — trust the methodology and re-confirm any specific before it lands in a deliverable. CI checks form, not truth; the dates are the accuracy signal.