Content
[](https://mseep.ai/app/daoyisec-secskills)
# Tool List
https://ai.daoyivip.com/ Register to get balance, low-cost model transit station
# SecSkills
Collect and organize skills related to network security such as penetration testing, vulnerability scanning, code auditing, CTF, reverse engineering, and security research, and MCP.
### 📌 Catalog (Total 54)
* [Code Audit 12](#Code-Audit)
* [Penetration Testing & Vulnerability Scanning 14](#Penetration-Testing-&-Vulnerability-Scanning)
* [JS Reverse 2](#JS-Reverse)
* [Skills Check 2](#Skills-Check)
* [Sample Analysis 1](#Sample-Analysis)
* [Incident Response 1](#Incident-Response)
* [Mobile Security 2](#Mobile-Security)
* [CTF 1](#CTF)
* [Red and Blue Confrontation 1](#Red-and-Blue-Confrontation)
* [Reverse Engineering 1](#Reverse-Engineering)
* [Report Writing 1](#Report-Writing)
* [Domain Penetration 1](#Domain-Penetration)
* [WeChat Mini Program Audit 1](#WeChat-Mini-Program-Audit)
* [MCP 1](#MCP)
* [Security Research 1](#Security-Research)
* [Entertainment 12](#Entertainment)
---
## Code Audit
| Name | Description | Link |
|------|------|------|
| java-audit-skills | A Claude Skills collection focusing on Java code auditing, providing automated source code analysis, routing extraction, parameter mapping, and more, to assist security researchers and developers in Java Web application security auditing. | [java-audit-skills](https://github.com/RuoJi6/java-audit-skills) |
| PHP Code Audit Skill | A white-box code security audit skill set for PHP Web, covering the entire process from routing enumeration to authentication modeling, data flow tracking, classification vulnerability auditing, evidence consistency verification, and report summarization. | [PHP-Code-Audit-Skill](https://github.com/0xShe/PHP-Code-Audit-Skill) |
| PHP_AUDIT_SKILLS | A multi-agent collaborative security audit framework based on Claude Code Agent Teams, covering environment construction, static reconnaissance, dynamic tracking, deep adversarial exploitation, post-penetration association analysis, and report closure, supporting expert-level auditing for 21 types of vulnerabilities. | [PHP_AUDIT_SKILLS](https://github.com/yunmengya/PHP_AUDIT_SKILLS) |
| java-audit-skill | A professional Java code audit skill. | [java-audit-skill](https://github.com/AuroraProudmoore/java-audit-skill) |
| zh-audit-skills-hub | An OpenClaw code audit Agent Skills repository organized and maintained for Chinese users. | [zh-audit-skills-hub](https://github.com/youki992/zh-audit-skills-hub) |
| skill-audit-skills | Claude Skills security audit tool - preventing supply chain poisoning risks. | [skill-audit-skills](https://github.com/LeeFeee/skill-audit-skills) |
| Code Audit | A professional white-box code security audit skill, covering 55+ vulnerability types, dual-track audit model, and multi-agent deep analysis. | [Code Audit](https://github.com/3stoneBrother/code-audit/blob/main/README_CN.md) |
| Security Auditor | Used to review code security vulnerabilities, implement authentication processes, audit OWASP Top 10, configure CORS/CSP headers, handle keys, input validation, SQL injection protection, XSS protection, or any security-related code review. | [Security Auditor](https://clawhub.ai/jgarrison929/security-auditor) |
| Security Audit Toolkit | Audit codebases and infrastructure for security issues. Used to scan dependency vulnerabilities, detect hard-coded secrets, check OWASP Top 10 issues, verify SSL/TLS, audit file permissions, or review code injection and authentication vulnerabilities. | [Security Audit Toolkit](https://clawhub.ai/gitgoodordietrying/security-audit-toolkit) |
| skill-dfyx_code_security_review | A professional code security audit skill designed for Claude Code, Trae, and other AI clients, adopting a white-box static analysis methodology, and systematically discovering and verifying security vulnerabilities in source code through a five-stage standardized audit protocol. | [skill-dfyx_code_security_review](https://github.com/EastSword/skill-dfyx_code_security_review) |
| skill-dfyx_code_security_review | A professional code security audit skill designed for Claude Code, Trae, and other AI clients, adopting a white-box static analysis methodology, and systematically discovering and verifying security vulnerabilities in source code through a five-stage standardized audit protocol. | [skill-dfyx_code_security_review](https://github.com/EastSword/dfyx_skills_lab/tree/main/skill-dfyx_code_security_review) |
| skill-dfyx_code_security_review | A professional code security audit skill designed for Claude Code, Trae, and other AI clients, adopting a white-box static analysis methodology, and systematically discovering and verifying security vulnerabilities in source code through a five-stage standardized audit protocol. | [skill-dfyx_code_security_review](https://github.com/EastSword/dfyx_skills_lab/tree/main/skill-dfyx_code_security_review) |
<br/>
## Penetration Testing & Vulnerability Scanning
| Name | Description | Link |
|------|------|------|
| HACK.SKILLS - Agent's Hacking Arsenal | A security skills knowledge base for agents, covering web security, API security, authentication and authorization, operating system privilege escalation (Linux/Windows/macOS), Active Directory attacks, mobile security, binary vulnerability exploitation (Pwn), reverse engineering, cryptographic attacks, blockchain and smart contract security, AI/ML and LLM security, network protocols and lateral movement, digital forensics - serving bug bounty, penetration testing, CTF competitions, and authorized security research. | [HACK.SKILLS - Agent's Hacking Arsenal](https://github.com/yaklang/hack-skills/blob/main/README_CN.md) |
| Sec-Skills | Large model skills related to network security. | [Sec-Skills](https://github.com/boqiqibo/Sec-Skills) |
| secknowledge-skill | A security testing expert skill (Skill) for Claude Code / Cursor, condensing 88,636 real vulnerability cases, 5,600+ security research documents, 150 AI security risks, OWASP LLM/ASI/WSTG, and 200+ commonly used security testing cases into an immediately callable penetration testing knowledge base. | [secknowledge-skill](https://github.com/Pa55w0rd/secknowledge-skill) |
| SkillSemgrep | Claude Code security scanning skill: say a few words in Chinese to scan vulnerabilities, powered by Semgrep. | [SkillSemgrep](https://github.com/KimYx0207/SkillSemgrep) |
| threat-modeling | Native AI automated software risk analysis skill. Adopting a large language model (LLM)-driven, code-first approach for comprehensive security risk assessment, threat modeling, security testing, penetration testing, and compliance checks. | [threat-modeling](https://github.com/fr33d3m0n/threat-modeling) |
| pentest-skills | Goodbye complex command lines, complete professional penetration testing with natural language. Just describe the test target, and Claude Code will automatically choose the appropriate tools, execute commands, and analyze results. | [pentest-skills](https://github.com/crazyMarky/pentest-skills) |
| AutoSongshu Agent (Automated Songshu) | AutoSongshu is an automated web penetration testing auxiliary agent. It aims to provide security engineers with a "semi-autonomous" penetration testing workstation by combining the reasoning capabilities of large language models (LLMs) with browser automation and security scanning tools. | [AutoSongshu Agent](https://github.com/Cian233/AutoSongshu) |
| ghsa-skill-builder | Let Claude automatically convert GitHub public vulnerability databases and HackerOne Bug Bounty reports into structured security skills (Skills) for code auditing/penetration testing. | [ghsa-skill-builder](https://github.com/yhy0/ghsa-skill-builder) |
| pentest-skills | Automated penetration testing agent skills. | [pentest-skills](https://github.com/Jumbo-WJB/pentest-skills) |
| Pentest Api Attacker | Test API security for OWASP API Top 10, including discovery, authentication abuse, and protocol-specific checks. | [Pentest Api Attacker](https://clawhub.ai/0x-professor/pentest-api-attacker) |
| Pentest Auth Bypass | Test authentication and session management controls for bypass and account takeover scenarios. | [Pentest Auth Bypass](https://clawhub.ai/0x-professor/pentest-auth-bypass) |
| Nmap Pentest Scans | Plan and coordinate authorized Nmap host discovery, port and service enumeration, NSE analysis, and reporting results for targets within the scope. | [Nmap Pentest Scans](https://clawhub.ai/0x-professor/nmap-pentest-scans) |
| Security Scanner | Provide automated security scanning and vulnerability detection for web applications, APIs, and infrastructure. When you need to scan target vulnerabilities, check SSL certificates, find open ports, detect configuration errors, or perform security audits, use this. Can integrate nmap, nuclei, and other security tools. | [Security Scanner](https://clawhub.ai/dmx64/security-scanner) |
| DeFiHackLabs-skill | Based on DeFiHackLabs' real attack cases and reproduction materials, precipitate reusable vulnerability analysis processes, classification methods, and defense points, making it convenient for security research, auditing, and rapid problem localization. | [DeFiHackLabs-skill](https://github.com/HToTH/DeFiHackLabs-skill) |
<br/>
## JS Reverse
| Name | Description | Link |
|------|------|------|
| hello_js_reverse_skill | A skill for reverse analysis and crawler confrontation scenarios, building a single workflow around camoufox-reverse MCP: first use Camoufox to detect browser network capture, source code positioning, Hook debugging, and anti-detection verification, and then land on Node.js or Python algorithm reduction and automated calling as needed. | [hello_js_reverse_skill](https://github.com/WhiteNightShadow/hello_js_reverse_skill) |
| JS Reverse MCP | A JavaScript reverse engineering MCP server, allowing your AI coding assistant (such as Claude, Cursor, Copilot) to debug and analyze JavaScript code in web pages. | [JS Reverse MCP](https://github.com/zhizhuodemao/js-reverse-mcp/tree/main) |
<br/>
## Skills Check
| Name | Description | Link |
|------|------|------|
| CLS-Certify | Possibly the best skill security check skill, produced by CocoLoop. | [cls-certify](https://github.com/CatREFuse/cls-certify) |
| SkillGuard | OpenClaw Skill security check tool. | [SkillGuard](https://github.com/Fangwenky/SkillGuard) |
<br/>
## Sample Analysis
| Name | Description | Link |
|------|------|------|
| IDA Skill for AI Agent | Let AI Agent analyze malicious samples like security analysts. | [IDA-Skill](https://github.com/miunasu/IDA-Skill) |
<br/>
## Incident Response
| Name | Description | Link |
|------|------|------|
| LinuxGun-skill | Linux security emergency response AI inspection skill. | [LinuxGun-skill](https://github.com/sun977/LinuxGun-skill) |
<br/>
## Mobile Security
| Name | Description | Link |
|------|------|------|
| android-h1 | A mobile security vulnerability mining expert skill, based on HackerOne's real reports, providing a knowledge base for mining vulnerabilities in Android and iOS applications, including vulnerability mining techniques, technical details, and code pattern analysis. | [android-h1](https://github.com/s7safe/android-h1) |
| FlowDroidSkill | An automated APK security analysis tool based on FlowDroid and Jadx. It performs static taint analysis on APKs, detects potential data leakage paths, and generates detailed security reports with real source code context. | [FlowDroidSkill](https://github.com/Tr0e/FlowDroidSkill) |
<br/>
## CTF
| Name | Description | Link |
|------|------|------|
| ctf-skills | Proxy skills for solving CTF challenges - web vulnerability exploitation, binary file cracking, encryption, reverse engineering, forensics, open-source intelligence (OSINT), etc. | [ctf-skills](https://github.com/ljagiello/ctf-skills) |
<br/>
## Red and Blue Confrontation
| Name | Description | Link |
|------|------|------|
| Anna Agent Skills | A professional skill set for AI programming assistants (Windsurf/Cursor), covering full-stack development, security confrontation, reverse engineering, and more. | [anna-agent-skills](https://github.com/crispvibe/anna-agent-skills) |
<br/>
## Reverse Engineering
| Name | Description | Link |
|------|------|------|
| reverse-skills | A reverse engineering skills set (Reverse Engineering Skills) for Claude Code, providing a plugin market for reverse engineering analysis skills. | [reverse-skills](https://github.com/P4nda0s/reverse-skills) |
<br/>
## Report Writing
| Name | Description | Link |
|------|------|------|
| dfyx_skills_lab | A security report writing assistant is an intelligent report generation tool focused on the cybersecurity field, capable of automatically generating industry-standard vulnerability analysis reports based on vulnerability numbers, names, or security scanning tool reports. | [dfyx_skills_lab](https://github.com/EastSword/dfyx_skills_lab/tree/main/security_reporter) |
<br/>
## Domain Penetration
| Name | Description | Link |
|------|------|------|
| Pentest Active Directory | Assess Active Directory identity attack paths, including baking, relaying, and delegation abuse. | [Pentest Active Directory](https://clawhub.ai/0x-professor/pentest-active-directory) |
<br/>
## WeChat Mini Program Audit
| Name | Description | Link |
|------|------|------|
| wxmini-security-audit | A fully automated security audit skill for WeChat mini programs, based on Claude Code Agent Teams. Seven agents collaborate to cover four dimensions: sensitive information, API interfaces, encryption analysis, and vulnerability analysis. Adopting a script + LLM dual-layer architecture, scripts ensure coverage, and LLM ensures accuracy. | [wxmini-security-audit](https://github.com/sssmmmwww/wxmini-security-audit) |
<br/>
## MCP
| Name | Description | Link |
|------|------|------|
| SO Analyzer MCP | A native library (SO file) analysis tool supporting Flutter application packet capture. A free and open-source alternative to IDA Pro! | [SO Analyzer MCP](https://github.com/1600822305/so-analyzer-mcp) |
<br/>
## Security Research
| Name | Description | Link |
|------|------|------|
| sec-skills | A security research skills repository, focusing on defensive security research tools. | [sec-skills](https://github.com/Rvn0xsy/sec-skills?tab=readme-ov-file) |
<br/>
## Entertainment
| Name | Description | Link |
|------|------|------|
| Colleague.skill | Transform cold farewells into warm skills. Welcome to Cyber Eternal Life! | [Colleague.skill](https://github.com/titanwings/colleague-skill) |
| Nuwa.skill | Nuwa helps you distill anyone's mindset, letting Jobs, Musk, Munger, and Feynman work for you. | [Nuwa.skill](https://github.com/alchaincyf/nuwa-skill) |
| X Mentor.skill | X Mentor.skill — The first "non-human" work of Nuwa. Distills 6 top X creators' methodologies + open-source algorithms and data, refining a complete guide for topic selection, writing, and growth operations. Made with Nuwa.skill | [X Mentor.skill](https://github.com/alchaincyf/x-mentor-skill) |
| Boss.skill | Boss.skills. Turn your boss into a token and liberate your own productivity. | [Boss.skill](https://github.com/vogtsw/boss-skills) |
| Ex.skill | Distill your ex into an AI skill, and have them talk to you in their own way. | [Ex.skill](https://github.com/therealXiaomanChu/ex-skill) |
| Yourself.skill | Instead of distilling others, distill yourself. Welcome to Digital Eternal Life! | [Yourself.skill](https://github.com/notdog1998/yourself-skill) |
| Blogger.skill | We seek emotional value, not specific individuals! | [Blogger.skill](https://github.com/YourongZhou/chat_with_me) |
| Anti-distill Skill | Anti-distill Skill: Clean your forced skill files, making them appear complete while keeping core knowledge to yourself. Anti-distillation for employee skills. | [Anti-distill Skill](https://github.com/leilei926524-tech/anti-distill) |
| Cyber Fortune Telling Skill | A BaZi (Eight Characters) and astrology analysis tool based on Claude Code. Collects birth information through interactive dialogue, arranges the four pillars of destiny, and provides professional analysis based on nine classical astrology texts. | [Cyber Fortune Telling Skill](https://github.com/jinchenma94/bazi-skill) |
| Moon Old Man · Fate Calculation Skills | Claude Code fate calculation skills — Cyber Moon Old Man uses traditional Chinese numerology to help you calculate your fate. | [Moon Old Man · Fate Calculation Skills](https://github.com/Ming-H/yinyuan-skills) |
| Numerologist Skills | This project aims to enable large language models (LLMs) to accurately understand and apply traditional Eastern numerology (such as Qimen Dunjia and Ziwei Doushu) through "engineering" means. | [Numerologist Skills](https://github.com/FANzR-arch/Numerologist_skills) |
| Master-skill | A generator of teaching roles for Chinese Buddhist patriarchs based on classical Buddhist literature. | [Master-skill](https://github.com/xr843/Master-skill) |
<br/>
## Follow Us
<div align="center">
**This project is created and maintained by Dao Yi Security**
<br>
Scan the QR code to follow our official account for more security information
<img src="gzh.png" width="2739" height="969" alt="Dao Yi Security Official Account">
</div>
Connection Info
You Might Also Like
everything-claude-code
Complete Claude Code configuration collection - agents, skills, hooks,...
markitdown
MarkItDown-MCP is a lightweight server for converting URIs to Markdown.
cc-switch
All-in-One Assistant for Claude Code, Codex & Gemini CLI across platforms.
codexia
Codexia is a powerful GUI toolkit for Codex CLI and Claude code with various...
glean
A self-hosted RSS reader and personal knowledge management tool.
xMCP
MCP server for the X API