By sickn33
Run a full security engineering workflow: web app penetration testing with Burp Suite, cloud infrastructure assessment on AWS/GCP, Linux privilege escalation, DevSecOps auditing for Docker/Kubernetes, threat modeling with STRIDE/PASTA, and OWASP-based vulnerability analysis.
Execute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows.
Conduct comprehensive security assessments of cloud infrastructure across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
Master the complete penetration testing lifecycle from reconnaissance through reporting. This skill covers the five stages of ethical hacking methodology, essential tools, attack techniques, and professional reporting for authorized security assessments.
Execute systematic privilege escalation assessments on Linux systems to identify and exploit misconfigurations, vulnerable services, and security weaknesses that allow elevation from low-privilege user access to root-level control.
Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
A complete local skill catalog for coding agents—from project inspection and agent-owned selection to a reproducible, reviewable plan.
Current release: V15.1.0. This release includes AAS Core for complete local catalog search, agent-owned selection, manifest validation, planning, and diagnosis. Apply and recovery remain experimental and outside the supported preview path.
Codex or Claude inspects your project, enumerates its primary capabilities, searches and compares candidates across the complete local AAS catalog, and chooses the exact skills. Core imposes no semantic policy that favors a small stack; the manifest format has an explicit technical maximum of 128 skills. All 1,968 skills in the current catalog remain individually searchable, readable, and selectable. AAS Core does not rank or recommend skills. Its read-only compose_stack tool validates and returns the agent-owned manifest in memory; a client or the aas CLI persists the reviewed stack and its optional selection-evidence sidecar.
Read the AAS Core preview guide →
Project
-> inspected by Codex or Claude (not by AAS)
-> agent searches and reads the complete local catalog
-> AAS MCP (local stdio, read-only)
-> Codex or Claude chooses exact skill IDs
-> compose_stack validates the selection in memory (read-only)
-> client or AAS CLI persists aas-stack.json and optional evidence
-> AAS CLI validate + immutable plan preview
-> human review (optionally in Workbench)
The 1,967+ reusable SKILL.md playbooks, specialized plugins, bundles, workflows, and direct installers remain important. They are the content, curation, distribution, and compatibility layers around AAS Core—not competing primary products.
This is an independent community project. It is not affiliated with, sponsored by, endorsed by, or authorized by Google. Google, Antigravity, Gemini, and related product names are referenced only to describe compatibility and install targets. The GitHub repository is canonical; the hosted catalog and browser-local Workbench are companion discovery and review surfaces, not a hosted control plane.
The agent composes. You control. AAS keeps the stack reproducible.
AAS Core gives the repository one product model:
npx claudepluginhub sickn33/agentic-awesome-skills --plugin agentic-bundle-security-engineerPlugin-safe Claude Code distribution of Agentic Awesome Skills with 1,933 supported skills.
Editorial "AAS Security Engineer" bundle for Claude Code from Agentic Awesome Skills.
Plugin-safe Claude Code distribution of Agentic Awesome Skills with 1,916 supported skills.
Editorial "Web Designer" bundle for Claude Code from Agentic Awesome Skills.
Editorial "AAS QA & Test Automation" bundle for Claude Code from Agentic Awesome Skills.
Editorial "Security Engineer" bundle for Claude Code from Antigravity Awesome Skills.
Cybersecurity skills for AI agents — code audit, cloud, recon, IR, AI security, and more
Professional security tools for Claude Code: vulnerability scanning, compliance, cryptography audit, container & API security
Compliance and security skills for HIPAA, GDPR, SOC2, PCI-DSS audits, infrastructure hardening, incident planning, and secrets management.
82-skill bug-hunting & external red-team bundle for Claude Code — 57 hunt-* web/vuln-class + framework skills, enterprise platform attack chains (M365/Entra, Okta, SharePoint, vCenter, SSL-VPN, APK/iOS), recon/OSINT, reporting & validation gates, and Burp MCP integration. Skills auto-load by topic; 15 slash commands included.
SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and automated security hardening