/security-passwords
Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).
$ npx -y skills add Eyadkelleh/awesome-skills-security --skill security-passwords --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/security-passwords
Context preview
The summary Claude sees to decide when to auto-load this skill.
Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).
SKILL.md
security-passwords.SKILL.mdname: security-passwords
description: "Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB)."
SecLists Passwords (Curated)
Description
Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).
**Source:** [SecLists/Passwords](https://github.com/danielmiessler/SecLists/tree/master/Passwords) **Repository:** https://github.com/danielmiessler/SecLists **License:** MIT
When to Use This Skill
Use this skill when you need:
- Password spraying (authorized)
- Credential testing
- Password policy validation
- Brute force testing (authorized)
- Authentication testing
**⚠️ IMPORTANT:** Only use for authorized security testing, bug bounty programs, CTF competitions, or educational purposes.
Key Files in This Skill
- `500-worst-passwords.txt - 500 worst passwords`
- `10k-most-common.txt - 10K common passwords`
- `100k-most-used-passwords-NCSC.txt - 100K passwords`
- `darkweb2017_top-10000.txt - 10K from breaches`
- `probable-v2_top-12000.txt - 12K probable passwords`
Usage Example
# Access files from this skill
import os
# Example: Load patterns/payloads
skill_path = "references/Passwords"
# List all available files
for root, dirs, files in os.walk(skill_path):
for file in files:
if file.endswith('.txt'):
filepath = os.path.join(root, file)
print(f"Found: {filepath}")
# Read file content
with open(filepath, 'r', errors='ignore') as f:
content = f.read().splitlines()
print(f" Lines: {len(content)}")Security & Ethics
Authorized Use Cases ✅
- Authorized penetration testing with written permission
- Bug bounty programs (within scope)
- CTF competitions
- Security research in controlled environments
- Testing your own systems
- Educational demonstrations
Prohibited Use Cases ❌
- Unauthorized access attempts
- Testing without permission
- Malicious activities
- Privacy violations
- Any illegal activities
Complete SecLists Collection
This is a curated subset of SecLists. For the complete collection:
- **Full repository:** https://github.com/danielmiessler/SecLists
- **Size:** 4.5 GB with 6,000+ files
- **All categories:** Passwords, Usernames, Discovery, Fuzzing, Payloads, Web-Shells, Pattern-Matching, AI, Miscellaneous
---
**Generated by Skill Seeker** | SecLists Passwords Collection **License:** MIT - Use responsibly with proper authorization
Read more
name: security-passwords description: "Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB)."
SecLists Passwords (Curated)
Description
Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).
**Source:** [SecLists/Passwords](https://github.com/danielmiessler/SecLists/tree/master/Passwords) **Repository:** https://github.com/danielmiessler/SecLists **License:** MIT
When to Use This Skill
Use this skill when you need:
- Password spraying (authorized)
- Credential testing
- Password policy validation
- Brute force testing (authorized)
- Authentication testing
**⚠️ IMPORTANT:** Only use for authorized security testing, bug bounty programs, CTF competitions, or educational purposes.
Key Files in This Skill
- `500-worst-passwords.txt - 500 worst passwords`
- `10k-most-common.txt - 10K common passwords`
- `100k-most-used-passwords-NCSC.txt - 100K passwords`
- `darkweb2017_top-10000.txt - 10K from breaches`
- `probable-v2_top-12000.txt - 12K probable passwords`
Usage Example
# Access files from this skill
import os
# Example: Load patterns/payloads
skill_path = "references/Passwords"
# List all available files
for root, dirs, files in os.walk(skill_path):
for file in files:
if file.endswith('.txt'):
filepath = os.path.join(root, file)
print(f"Found: {filepath}")
# Read file content
with open(filepath, 'r', errors='ignore') as f:
content = f.read().splitlines()
print(f" Lines: {len(content)}")Security & Ethics
Authorized Use Cases ✅
- Authorized penetration testing with written permission
- Bug bounty programs (within scope)
- CTF competitions
- Security research in controlled environments
- Testing your own systems
- Educational demonstrations
Prohibited Use Cases ❌
- Unauthorized access attempts
- Testing without permission
- Malicious activities
- Privacy violations
- Any illegal activities
Complete SecLists Collection
This is a curated subset of SecLists. For the complete collection:
- **Full repository:** https://github.com/danielmiessler/SecLists
- **Size:** 4.5 GB with 6,000+ files
- **All categories:** Passwords, Usernames, Discovery, Fuzzing, Payloads, Web-Shells, Pattern-Matching, AI, Miscellaneous
---
**Generated by Skill Seeker** | SecLists Passwords Collection **License:** MIT - Use responsibly with proper authorization
A curated collection of security testing resources packaged as agent skills, available on skills.sh Repository: Eyadkelleh/awesome-skills-security · skills.sh: Eyadkelleh/awesome-skills-security
Repo: Eyadkelleh/awesome-skills-security
Other skills on awesome-skills-security.
- /llm-testing
Comprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.
Open skill - /security-fuzzing
Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.
Open skill - /security-patterns
Sensitive data patterns for security testing: API keys, credit cards, emails, SSNs, phone numbers, IPs, and more. Use for data discovery and validation.
Open skill - /security-payloads
Essential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testing.
Open skill - /security-usernames
Top username lists for enumeration: common usernames, default credentials, names. Curated essentials for authorized testing.
Open skill - /security-webshells
Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. Use for security research and detection system testing.
Open skill

