rhysha

Claude Security Research Skill — Security skill for Claude Code

Security community

AI-powered security research assistant for Claude Code — structured assessment workflows, tool orchestration, and professional reporting across recon, enumeration, vulnerability scanning, and secrets.

How to install Claude Security Research Skill

This entry records only its repository, not the path inside it, so there is no exact command to give. Open rhysha/claude-security-research-skill and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Claude Security Research Skill does

AI-powered security research assistant for Claude Code — structured assessment workflows, tool orchestration, and professional reporting across recon, enumeration, vulnerability scanning, and secrets auditing. Built for security researchers and bug bounty hunters who want Claude as an analyst, not a command generator.

Alternatives in Security

  • Deepsec — Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents 7.8k ★
  • Skills — Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows 4k ★
  • Claude Code Security Review — An AI-powered security review GitHub Action using Claude to analyze code changes for security vulnerabilities 3.9k ★

README

🔐 Claude Security Research Skill

![Claude Code](https://img.shields.io/badge/Claude-Code-orange) ![License](https://img.shields.io/badge/license-MIT-blue) ![Security Research](https://img.shields.io/badge/use-security%20research-green)

**A full-spectrum security research skill for Claude** — structured, tool-driven security assessment workflows built directly into your AI assistant.

Drop this skill into [Claude Code](https://claude.ai/code) or any Claude MCP setup and get an AI that thinks like a security researcher: structured phases, proper tool chaining, scoped recon, and professional reporting — not ad-hoc command generation.

Claude's role in this skill is to **interpret tool output, suggest next steps, and document findings**. Tools perform the active testing. Claude does not generate payloads or exploit code.


See It In Action

Want to know what the output actually looks like before installing?

**[View sample assessment report →](examples/sample-report.md)**

A fictional but realistic security assessment report showing the exact format Claude produces — five findings across CRITICAL → INFO severities, with raw tool output, impact analysis, and a remediation priority table.


What It Does

The skill gives Claude a complete engagement workflow across 6 phases:

RECON → ENUMERATION → VULN SCANNING → VULNERABILITY VALIDATION → SECRETS AUDIT → REPORTING

Claude automatically routes based on your target type, loads the right reference, suggests tools in the right order, and hands off outputs between phases.

Supported Targets

Target Tools Used
Web server (Apache / Nginx / IIS) nmap, nikto, nuclei, testssl
REST API ffuf, sqlmap, dalfox
Web application nikto, nuclei, ZAP, ffuf
Network / IP range nmap, snmpwalk, enum4linux
Source code / repo trufflehog
Full engagement Everything, in phase order

Quick Start

0. Prerequisites

  • Claude Code installed and configured
  • A tar