Bounty Security Pattern Master Library — 399 Vulnerability Patterns
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
Skill of the Month: Award Winning Design by Aman Garg · View skill →
Skills for security audits, static analysis, vulnerability triage, threat modeling, and secrets hygiene. Ship safer software with fewer surprises.
435 live security skills for GitHub Copilot.
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
by Roy Yuen
Professional security audit skill for web apps and APIs with structured severity-based findings and remediation plans.
by Roy Yuen
Transform AI claims into verified, risk-assessed technical reports for production, DevOps, and enterprise governance.
by Roy Yuen
Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.
by Roy Yuen
Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.
by Roy Yuen
A high-performance wrapper to route security tasks directly to the Anthropic-Cybersecurity-Skills library.
Expert AI guidance for ISO-compliant cleanroom design, HVAC filtration setup, and controlled environment installation.
by Samuel Rose
Audit dependencies for security, licenses, and health while generating a phased, low-risk upgrade and migration plan.
by Roy Yuen
Automated security and compatibility firewall for installing AI agent skills and Codex/OpenClaw packages.
Scan AI agent skill definitions for malicious instructions, prompt injections, and security risks—locally.
by Shogun Labs
Pre-commit security hooks: secret detection, destructive command prevention
by Roy Yuen
A modular governance framework for AI policy, agent risk assessment, human-in-the-loop approvals, and audit trails.
by Roy Yuen
Automated governance and risk audit for AI agent tool permissions and authentication boundaries.
Accelerate your bounty hunting with smart program prioritization and vulnerability report triaging for DeFi protocols.
by LocoLoboZ
Professional CTI analysis skill for structured attribution using ACH, Diamond Model, and confidence scoring.
by Edric Vale
Safe dependency upgrade plans: changelog-aware risk scoring, test hints, and rollback paths.
by Shogun Labs
Project-specific Claude Code agent harness setup
by rayyer
Find accessibility barriers and WCAG 2.2 AA failures in web and mobile UI code — with file:line, the exact criterion, and a fix
by Tate Lyman
Automated launch-readiness auditor for x402 and agent-payment API surfaces.
by LocoLoboZ
Design and validate IEC 62443-compliant security zones and conduits for industrial (OT) networks.
Review Claude Code hooks, spot configuration gaps, and plan controlled checks with evidence you can inspect.
Automated security auditing and risk assessment for Model Context Protocol (MCP) servers.
by LocoLoboZ
Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.
by Timoranjes
Comprehensive security auditing for AI agents, covering prompt injection, tool permissions, and data leakage risks.
Each skill on this page is a SKILL.md file built for security work and confirmed to run in GitHub Copilot. Install one into .github/copilot/skills/ (repo) or VS Code workspace, start a new session, and GitHub Copilot follows the workflow the creator encoded instead of improvising from a short prompt.
Listings are ranked by installs, upvotes and reviews, so what surfaces first is what other GitHub Copilot users actually keep. Free and paid skills compete on the same page, and every listing shows its security scan result before you download anything.
Learn how it works: Best security auditing skills and How to use Copilot Agent mode skills.
These are the jobs creators are actually shipping skills for in this category. Each one encodes a full workflow, so GitHub Copilot follows the same method every time instead of improvising from a one-line prompt.
Start with the outcome, not the label. Open the listing and read the SKILL.md preview: a good security skill states exactly what it does, what it needs from you, and what it deliberately refuses to do. Vague descriptions usually mean vague output.
Then check three things: the install count and reviews (other GitHub Copilot users voting with their setup), whether the creator ships updates, and whether the skill is universal SKILL.md or agent-specific. Free skills are a fine way to test a creator's style before buying their paid work.
Related categories for GitHub Copilot: DevOps & Cloud, APIs & Backend and Code Quality & Review.
Every paid creator is verified before they can sell, so skills come from practitioners, not scraped prompt packs.
Each version is scanned for prompt injection, credential exfiltration and destructive commands before it goes live.
Some skills are free, but most are paid. Paid skills show the price upfront and include future updates from the creator.
Unzip into .github/copilot/skills/ (repo) or VS Code workspace and start a new session. No plugin store, no build step.
Questions, partnership ideas, or feedback on the platform? Tell us what's working and what isn't, we love to hear from you!
Founder & CEO of Agensi
Email UsBook a Callinfo@agensi.io
We typically respond within a few hours during business hours.