Claude Security Research Skill — Security skill for Claude Code
AI-powered security research assistant for Claude Code — structured assessment workflows, tool orchestration, and professional reporting across recon, enumeration, vulnerability scanning, and secrets.
How to install Claude Security Research Skill
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open rhysha/claude-security-research-skill and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Claude Security Research Skill does
AI-powered security research assistant for Claude Code — structured assessment workflows, tool orchestration, and professional reporting across recon, enumeration, vulnerability scanning, and secrets auditing. Built for security researchers and bug bounty hunters who want Claude as an analyst, not a command generator.
Alternatives in Security
- Deepsec — Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents 7.8k ★
- Skills — Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows 4k ★
- Claude Code Security Review — An AI-powered security review GitHub Action using Claude to analyze code changes for security vulnerabilities 3.9k ★
README
🔐 Claude Security Research Skill
  
**A full-spectrum security research skill for Claude** — structured, tool-driven security assessment workflows built directly into your AI assistant.
Drop this skill into [Claude Code](https://claude.ai/code) or any Claude MCP setup and get an AI that thinks like a security researcher: structured phases, proper tool chaining, scoped recon, and professional reporting — not ad-hoc command generation.
Claude's role in this skill is to **interpret tool output, suggest next steps, and document findings**. Tools perform the active testing. Claude does not generate payloads or exploit code.
See It In Action
Want to know what the output actually looks like before installing?
**[View sample assessment report →](examples/sample-report.md)**
A fictional but realistic security assessment report showing the exact format Claude produces — five findings across CRITICAL → INFO severities, with raw tool output, impact analysis, and a remediation priority table.
What It Does
The skill gives Claude a complete engagement workflow across 6 phases:
RECON → ENUMERATION → VULN SCANNING → VULNERABILITY VALIDATION → SECRETS AUDIT → REPORTING
Claude automatically routes based on your target type, loads the right reference, suggests tools in the right order, and hands off outputs between phases.
Supported Targets
| Target | Tools Used |
|---|---|
| Web server (Apache / Nginx / IIS) | nmap, nikto, nuclei, testssl |
| REST API | ffuf, sqlmap, dalfox |
| Web application | nikto, nuclei, ZAP, ffuf |
| Network / IP range | nmap, snmpwalk, enum4linux |
| Source code / repo | trufflehog |
| Full engagement | Everything, in phase order |
Quick Start
0. Prerequisites
- Claude Code installed and configured
- A tar
Related Skills
Talon
Penetration Testing MCP for Claude Code. AI-assisted security testing with automated recon, service enumeratio
Check
by rygwdn - Performs comprehensive code quality and security checks, featuring static analysis integration, se
Heeler Vulnerabilities Scan
Run Heeler dependency vulnerability scanning and policy gating. Use when the user asks for CVE analysis, sever
Attack Surface
External attack-surface / recon audit of domains YOU OWN (your sites + subdomains, client sites under contract
Pentest Swarm AI
Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, a
Secure Plugin Installer
Audit and gate third-party Claude Code plugins / OpenClaw skills before enabling them: capability enumeration,
Related Agents
Go Security Release
Security scanning, vulnerability assessment, release readiness checks
Docker Sandbox
Isolated autonomous scanning agent — runs in a temporary worktree with restricted Bash access. Requires ROE au
Ops Security
Head of Operations + Security. Owns the security axis of review — threat modeling, auth/authz audits, OWASP To