GitHub organization
Agent skills by cyberful
- skills
- 85
- repository
- 1
Repositories by cyberful
Skills by cyberful, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence. | cyberful/ | 135 | — | ~649 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2 | Audit Kubernetes admission and policy-as-code enforcement against local workload manifests, exception paths, namespace scope, and deployment evidence. | cyberful/ | 135 | — | ~610 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 3 | Audit PCI DSS penetration-test methodology, scope, internal and external reports, segmentation results, tester independence, remediation, retesting, retention, and multi-tenant support evidence. | cyberful/ | 135 | — | ~1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 4 | Design and interpret advanced content discovery with ffuf and complementary web fuzzers. | cyberful/ | 135 | — | ~1.5k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 5 | Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 6 | Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits. | cyberful/ | 135 | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 7 | Operate Syft, Grype, Trivy, Gitleaks, Retire.js, package-manager metadata, and build evidence for advanced software-supply-chain assessment. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 8 | Assemble reviewed compliance evidence into a versioned, traceable draft report for PCI DSS or GDPR. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 9 | Assess race conditions, transactional invariants, idempotency, retries, replay, rate and quota enforcement, algorithmic complexity, resource amplification, and cost abuse during authorized… | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 10 | Test native or language object reconstruction, polymorphic type selection, gadget reachability, schema bypass, mass object binding, and unsafe serializer configuration in authorized applications or… | cyberful/ | 135 | — | ~654 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 11 | Assess WebSocket, Server-Sent Events, webhook, event-stream, callback, and asynchronous integration security during authorized penetration tests or code audits. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 12 | Test executable smart-contract properties with deterministic, offline Foundry harnesses over a confined source snapshot. | cyberful/ | 135 | — | ~745 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 13 | Test authorized web-cache key construction, variation, partitioning, authenticated response handling, revalidation, poisoning, deception, purge, and TTL behavior. | cyberful/ | 135 | — | ~631 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 14 | Trace how clients, CDNs, proxies, protocol translators, gateways, frameworks, and origins derive HTTP message boundaries, authority, paths, queries, and trusted forwarding metadata. | cyberful/ | 135 | — | ~711 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 15 | Deterministically compare OpenAPI JSON operations with implementation and observation inventories to expose undocumented, unimplemented, unexercised, and security-declaration coverage gaps. | cyberful/ | 135 | — | ~585 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 16 | Audit local AI model, adapter, tokenizer, configuration, and packaging artifacts for provenance, integrity, dependency, serialization, license, and loading-risk evidence. | cyberful/ | 135 | — | ~535 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 17 | Test whether authorized direct or indirect untrusted content can alter an AI system's protected behavior, context use, memory, retrieval, output handling, or downstream capability. | cyberful/ | 135 | — | ~538 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 18 | Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects. | cyberful/ | 135 | — | ~549 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 19 | Reconstruct how instructions, retrieved content, memory, identities, approvals, tool schemas, arguments, outputs, delegation, and fallbacks propagate through an AI system. | cyberful/ | 135 | — | ~517 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 20 | Extract bounded, deterministic evidence from crash and sanitizer logs, including signals, sanitizer classes, memory-safety indicators, stack-frame hashes, and source provenance, while reserving… | cyberful/ | 135 | — | ~563 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 21 | Normalize and compare authorized fraud-control observations from local evidence, highlighting decision drift, coverage gaps, and conflicting outcomes without making a fraud or vulnerability verdict. | cyberful/ | 135 | — | ~649 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 22 | Parse bounded classic PCAP files offline into deterministic capture metadata, packet-length and timestamp summaries, link and network protocol counts, truncation indicators, and source digests… | cyberful/ | 135 | — | ~590 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 23 | Model fraud and abuse threats across actors, account states, value flows, controls, and monetization paths. | cyberful/ | 135 | — | ~716 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 24 | Coordinate a PCI DSS penetration-testing and CDE-scoping readiness assessment across methodology, scope, segmentation, execution evidence, remediation, and retesting. | cyberful/ | 135 | — | ~895 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 25 | Assess the security of a smart-contract system across protocol economics, trust roles, upgrade and governance paths, oracle and bridge dependencies, deployment state, and off-chain operators. | cyberful/ | 135 | — | ~651 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 26 | Audit application database access layers for query construction, authorization placement, tenant scoping, transaction boundaries, consistency, credential authority, and observable durable effects. | cyberful/ | 135 | — | ~599 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 27 | Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures. | cyberful/ | 135 | — | ~637 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 28 | Audit extracted embedded firmware for boot and update trust, credential and secret handling, service exposure, privilege boundaries, parsers, persistence, cryptography, hardening, recovery, and… | cyberful/ | 135 | — | ~644 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 29 | Audit security logging and telemetry from event creation through transport, storage, access, correlation, retention, and response use. | cyberful/ | 135 | — | ~597 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 30 | Audit smart-contract source and build evidence for authorization, accounting, state-machine, external-call, upgrade, signature, oracle, token-integration, and denial-of-service defects. | cyberful/ | 135 | — | ~650 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 31 | Plan an authorized PCI DSS penetration test around the cardholder data environment, critical systems, internal and external coverage, segmentation, tester independence, remediation, retesting, and… | cyberful/ | 135 | — | ~943 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 32 | Test browser capability transfer across postMessage, opener, frame, portal, worker, service-worker, BroadcastChannel, MessagePort, and extension messaging boundaries. | cyberful/ | 135 | — | ~583 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 33 | Test whether every segmentation and scope-reduction control isolates the cardholder data environment from claimed out-of-scope systems and differing security levels. | cyberful/ | 135 | — | ~928 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 34 | Test application email generation, recipient authority, template and header construction, link and token binding, inbound parsing, threading, reply handling, bounce processing, and tenant isolation. | cyberful/ | 135 | — | ~599 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 35 | Test payment decision and value-movement invariants with authorized synthetic instruments and reversible sandbox transactions. | cyberful/ | 135 | — | ~668 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 36 | Test service accounts, OAuth clients, workload federation, token exchange, audience binding, delegated actors, credential rotation, and machine-identity authorization. | cyberful/ | 135 | — | ~895 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 37 | Trace uploaded, imported, generated, archived, converted, scanned, rendered, and downloaded files across storage, naming, extraction, parser, sandbox, and cleanup boundaries. | cyberful/ | 135 | — | ~646 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 38 | Reconstruct how principal, actor, issuer, audience, assurance, scopes, and delegated authority change across requests, tokens, services, queues, and stored artifacts. | cyberful/ | 135 | — | ~730 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 39 | Reconstruct how tenant and organization context is authenticated, selected, routed, cached, queued, and bound to resources across distributed request paths. | cyberful/ | 135 | — | ~679 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 40 | Reconstruct transaction state across services, ledgers, queues, and compensations from local artifacts, identifying causal gaps, duplicate effects, and value mismatches without active traffic. | cyberful/ | 135 | — | ~635 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 41 | Build or challenge an application threat model from architecture, dataflows, identities, trust boundaries, business invariants, dependencies, and deployment context. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 42 | Route broad AI-agent security reviews to focused Cyberful skills across risk, model supply chain, context and capabilities, prompt injection, tool authorization, and RAG isolation. | cyberful/ | 135 | — | ~723 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 43 | Audit whether API handlers, gateways, serializers, validators, and generated clients implement the effective contract and its security invariants. | cyberful/ | 135 | — | ~666 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 44 | Coordinate a repository-wide white-box application security audit across architecture, source, configuration, dependencies, build, and deployment paths. | cyberful/ | 135 | — | ~774 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 45 | Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk. | cyberful/ | 135 | — | ~829 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 46 | Coordinate an authorized software-supply-chain audit from dependency resolution through build, artifact, release, deployment, and runtime trust. | cyberful/ | 135 | — | ~737 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 47 | 47.Cyberful Operate Cyberful as an authorized application-security control room. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0-only | 1 mo ago |
| 48 | Operate Ghidra headless analysis, radare2, platform binary utilities, decompilers, and targeted dynamic evidence for advanced native and bytecode security review. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
Questions, answered from the data.
What is the best skill by cyberful?
Audit Infrastructure As Code from cyberful/cyberful ranks first of the 85 skills by cyberful listed here, with the highest score: its repository has 135 GitHub stars, its SKILL.md loads about 649 tokens and it passes the automated safety check with no findings. Next come Audit Kubernetes Policy Enforcement and Audit Pci Dss Penetration Test Evidence.
Are cyberful's skills official?
None yet. All 85 skills by cyberful listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.