⏳ This skill is pending AI review.
Scores will appear once the review pipeline completes.
ai-redteam
AI and LLM red-teaming skill for evaluating prompt injection, jailbreak, data exfiltration, tool abuse, agent hijack, RAG poisoning, model denial of service, and unsafe tool-use chains in Gemini, Claude, GPT, and open-weight models. Use to build evaluation harnesses, attack corpora, defensive guardrails, and red-team reports for AI systems you own or are authorized to test.
Choose how to use this skill
You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.
1. Native installer
This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.
Do not guess an installer command or replace an existing version without reviewing the diff.
2. Complete package recommended
Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.
No complete ProSkills package is published for this listing yet.3. Prompt-only
Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.
Need only the instruction file?
Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.
No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.
// RATINGS
// README
Trident SecOps Skills
A curated collection of 24 SKILL.md capabilities for security work —
offensive security, SOC and detection engineering, cloud and Kubernetes
hardening, DFIR, threat intel, secure programming, reverse engineering,
prompt improvement, and multilingual communication.
The same skills run on three agents: Gemini CLI, Claude Code, and
OpenAI Codex. There is one canonical skills/ tree; each platform reads
it through a thin adapter.
Repository URL:
https://github.com/Garyson26/Trident-SecOps-Skills
What is included
This repository contains 24 skills, grouped below.
Cyber security automation
gemini-tool-orchestrator: Translate natural-language intent into safe, scoped pipelines of nmap, nuclei, ffuf, semgrep, trivy, and friends.ai-redteam: Evaluate prompt injection, jailbreak, tool abuse, agent hijack, and RAG poisoning on LLM and agent systems you own.threat-intel-fusion: Collect, normalize, enrich, dedupe, and prioritize IOCs and actor profiles into STIX, Sigma, YARA, and blocklists.cloud-security-automation: AWS, Azure, GCP posture, IaC scanning, and drift-and-fix workflows shipped as code, not console clicks.detection-engineering: Author and tune Sigma, YARA, Suricata, KQL, SPL, and EQL detections with ATT&CK coverage and tests.kubernetes-security: Cluster hardening, admission control with Gatekeeper/Kyverno, runtime defense, and signed-image supply chain.purple-team-automation: Link Atomic Red Team, Caldera, and Stratus emulation to detection validation and coverage scoring.osint-recon-automation: Passive recon, asset graphing, and exposure monitoring for authorized scopes only.api-security-automation: REST, GraphQL, and gRPC assessment covering OWASP API Top 10, JWT abuse, BOLA, mass assignment, and replay.forensics-triage: DFIR across disk, memory, network, cloud, and identity with defensible timelines and chain of custody.bug-bounty-workflow: Scope-aware recon, dedupe, and high-signal reporting for HackerOne, Bugcrowd, Intigriti, and YesWeHack.smart-contract-audit: Solidity, Vyper, and Move audit with Slither, Foundry, Echidna, invariants, MEV, and bridge risk.
Core security
offensive-security: Plan authorized offensive security assessments.exploit-development: Analyze lab vulnerabilities and safe proof of concept workflows.malware-reverse-engineering: Triage suspicious artifacts and produce defensive findings.devsecops: Harden CI/CD, infrastructure, containers, and releases.soc-operations: Triage alerts, hunt threats, and produce incident notes.cybersecurity-partner: Act as a practical security reviewer and advisor.
Engineering and language
go-programming: Build, debug, test, and review idiomatic Go systems.python-programming: Build, test, type, package, and maintain Python code.assembly-programming: Read, write, explain, and debug low-level assembly.prompt-enhancement: Improve prompts, task specs, and agent instructions.multilingual: Translate, localize, and improve multilingual content.claude-mythos-emulation: Create Claude-like assistant behavior specs without identity claims or proprietary prompt copying.
Install
| Agent | Method | Command |
|---|---|---|
| Gemini CLI | extension | gemini extensions install https://github.com/Garyson26/Trident-SecOps-Skills --consent |
| Claude Code | plugin marketplace | /plugin marketplace add Garyson26/Trident-SecOps-Skills then /plugin install trident-secops-skills@trident-secops |
| Codex | installer script | ./install.sh codex (or ./install.ps1 -Platform codex) |
Full instructions, including manual and project-scoped installs, are in INSTALL.md.
Why Codex needs a script
Gemini reads skills/ and Claude's plugin manifest points at the same
directory, so both install straight from the repository. Codex discovers
skills under .agents/skills, so the installer copies the tree there.
Documentation
Read the documentation set for installation details, usage patterns, and skill knowledge:
- Install
- Usage
- Knowledge base
- Comparison
- Contributing
- Security policy
- FAQ
- Roadmap
- Installation guide
- Skill catalog
- CLI usage
- Security boundaries
- Cybersecurity workflows
- Programming workflows
- Prompting and multilingual workflows
- Development and maintenance
- Troubleshooting
Safety model
The cyber security skills are written for authorized, defensive, educational, and lab-scoped work. They emphasize scope confirmation, safe proof, containment, reporting, and remediation. They intentionally avoid unauthorized access, stealth, persistence, credential theft, destructive activity, and malware improvement.
Repository layout
Each skill is self-contained:
skills/
└── skill-name/
├── SKILL.md
└── agents/
└── openai.yaml
skills/ is the single canonical tree — there are no duplicate copies
elsewhere in the repository. Every skill is a directory holding a SKILL.md
whose YAML frontmatter supplies name and description, which is the format
Gemini CLI, Claude Code, and Codex all read. The agents/openai.yaml files
provide Codex interface metadata and are ignored by the other two agents.
Run bash scripts/validate.sh to check the tree.
Source references
The installation docs were checked against each agent's published skill format. Gemini references were verified on May 9, 2026; Claude and Codex references on September 16, 2026.
Gemini CLI:
- Agent Skills overview: https://geminicli.com/docs/cli/skills/
- Managing Agent Skills: https://geminicli.com/docs/cli/using-agent-skills/
- Extension reference: https://geminicli.com/docs/extensions/reference/
- Command reference: https://google-gemini.github.io/gemini-cli/docs/cli/cli-reference.html
Claude Code:
- Plugin reference: https://code.claude.com/docs/en/plugins-reference
- Plugin marketplaces: https://code.claude.com/docs/en/plugin-marketplaces
Codex:
- Building skills: https://learn.chatgpt.com/docs/build-skills
// HOW IT'S BUILT
KEY FILES