⏳ This skill is pending AI review.

Scores will appear once the review pipeline completes.

version unknown

ai-redteam

@garyson26⭐ 15 stars

AI and LLM red-teaming skill for evaluating prompt injection, jailbreak, data exfiltration, tool abuse, agent hijack, RAG poisoning, model denial of service, and unsafe tool-use chains in Gemini, Claude, GPT, and open-weight models. Use to build evaluation harnesses, attack corpora, defensive guardrails, and red-team reports for AI systems you own or are authorized to test.

Choose how to use this skill

You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.

1. Native installer

This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.

Do not guess an installer command or replace an existing version without reviewing the diff.

2. Complete package recommended

Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.

No complete ProSkills package is published for this listing yet.

3. Prompt-only

Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.

Need only the instruction file?

Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.

No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.

—/10

// RATINGS

⭐GitHub Stars
⭐⭐ 15 on GitHubGitHub ↗

Growing

🟢ProSkills Score
—
📍

Not yet listed on ClawHub or SkillsMP

// README

Trident SecOps Skills

Trident SecOps Skills banner

A curated collection of 24 SKILL.md capabilities for security work — offensive security, SOC and detection engineering, cloud and Kubernetes hardening, DFIR, threat intel, secure programming, reverse engineering, prompt improvement, and multilingual communication.

The same skills run on three agents: Gemini CLI, Claude Code, and OpenAI Codex. There is one canonical skills/ tree; each platform reads it through a thin adapter.

Repository URL:

https://github.com/Garyson26/Trident-SecOps-Skills

What is included

This repository contains 24 skills, grouped below.

Cyber security automation

  • gemini-tool-orchestrator: Translate natural-language intent into safe, scoped pipelines of nmap, nuclei, ffuf, semgrep, trivy, and friends.
  • ai-redteam: Evaluate prompt injection, jailbreak, tool abuse, agent hijack, and RAG poisoning on LLM and agent systems you own.
  • threat-intel-fusion: Collect, normalize, enrich, dedupe, and prioritize IOCs and actor profiles into STIX, Sigma, YARA, and blocklists.
  • cloud-security-automation: AWS, Azure, GCP posture, IaC scanning, and drift-and-fix workflows shipped as code, not console clicks.
  • detection-engineering: Author and tune Sigma, YARA, Suricata, KQL, SPL, and EQL detections with ATT&CK coverage and tests.
  • kubernetes-security: Cluster hardening, admission control with Gatekeeper/Kyverno, runtime defense, and signed-image supply chain.
  • purple-team-automation: Link Atomic Red Team, Caldera, and Stratus emulation to detection validation and coverage scoring.
  • osint-recon-automation: Passive recon, asset graphing, and exposure monitoring for authorized scopes only.
  • api-security-automation: REST, GraphQL, and gRPC assessment covering OWASP API Top 10, JWT abuse, BOLA, mass assignment, and replay.
  • forensics-triage: DFIR across disk, memory, network, cloud, and identity with defensible timelines and chain of custody.
  • bug-bounty-workflow: Scope-aware recon, dedupe, and high-signal reporting for HackerOne, Bugcrowd, Intigriti, and YesWeHack.
  • smart-contract-audit: Solidity, Vyper, and Move audit with Slither, Foundry, Echidna, invariants, MEV, and bridge risk.

Core security

  • offensive-security: Plan authorized offensive security assessments.
  • exploit-development: Analyze lab vulnerabilities and safe proof of concept workflows.
  • malware-reverse-engineering: Triage suspicious artifacts and produce defensive findings.
  • devsecops: Harden CI/CD, infrastructure, containers, and releases.
  • soc-operations: Triage alerts, hunt threats, and produce incident notes.
  • cybersecurity-partner: Act as a practical security reviewer and advisor.

Engineering and language

  • go-programming: Build, debug, test, and review idiomatic Go systems.
  • python-programming: Build, test, type, package, and maintain Python code.
  • assembly-programming: Read, write, explain, and debug low-level assembly.
  • prompt-enhancement: Improve prompts, task specs, and agent instructions.
  • multilingual: Translate, localize, and improve multilingual content.
  • claude-mythos-emulation: Create Claude-like assistant behavior specs without identity claims or proprietary prompt copying.

Install

AgentMethodCommand
Gemini CLIextensiongemini extensions install https://github.com/Garyson26/Trident-SecOps-Skills --consent
Claude Codeplugin marketplace/plugin marketplace add Garyson26/Trident-SecOps-Skills then /plugin install trident-secops-skills@trident-secops
Codexinstaller script./install.sh codex (or ./install.ps1 -Platform codex)

Full instructions, including manual and project-scoped installs, are in INSTALL.md.

Why Codex needs a script

Gemini reads skills/ and Claude's plugin manifest points at the same directory, so both install straight from the repository. Codex discovers skills under .agents/skills, so the installer copies the tree there.

Documentation

Read the documentation set for installation details, usage patterns, and skill knowledge:

Safety model

The cyber security skills are written for authorized, defensive, educational, and lab-scoped work. They emphasize scope confirmation, safe proof, containment, reporting, and remediation. They intentionally avoid unauthorized access, stealth, persistence, credential theft, destructive activity, and malware improvement.

Repository layout

Each skill is self-contained:

skills/
└── skill-name/
    ├── SKILL.md
    └── agents/
        └── openai.yaml

skills/ is the single canonical tree — there are no duplicate copies elsewhere in the repository. Every skill is a directory holding a SKILL.md whose YAML frontmatter supplies name and description, which is the format Gemini CLI, Claude Code, and Codex all read. The agents/openai.yaml files provide Codex interface metadata and are ignored by the other two agents.

Run bash scripts/validate.sh to check the tree.

Source references

The installation docs were checked against each agent's published skill format. Gemini references were verified on May 9, 2026; Claude and Codex references on September 16, 2026.

Gemini CLI:

Claude Code:

Codex:

// HOW IT'S BUILT

KEY FILES

skills/ai-redteam/SKILL.mdREADME.md

// REPO STATS

15 stars