Category

Best security skills, page 10

Skills #433–480 of 3,087, ranked by score.

Security skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Security skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
433

A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

jabrena/plinth447—~3.2kAutomated safety check: PassApache-2.02 days ago
434

Explains authorization in an Arandu Go application: write a Policy, get a security.Grant through security.Authorize, re-authorize each row, and keep tenant isolation.

arandu-io/arandu281—~1.4kAutomated safety check: PassMIT5 days ago
435

A skill your agent uses when asked to generate a "no way to prevent this" / no-way-to-prevent-this satire post for a memory-safety CVE (out-of-bounds write/read, buffer/heap overflow…

Xe/site732—~816Automated safety check: PassZlibyesterday
436

Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging.

wshobson/agents40k9 repos~588Automated safety check: PassMIT4 days ago
437

Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

cdppcorp/KESE-KIT361—~1.4kAutomated safety check: PassMIT6 mo ago
438

Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

dslsdzc/rev-skills130—~2kAutomated safety check: PassApache-2.04 days ago
439
439.Nmap

Professional network reconnaissance and port scanning using nmap.

BrownFineSecurity/iothackbot8591 repo~3.8kAutomated safety check: NotesMIT4 mo ago
440

This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through…

zebbern/claude-code-guide4.7k5 repos~2.9kAutomated safety check: PassMITtoday
441

Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

malloydata/publisher116—~5.1kAutomated safety check: PassMITtoday
442

Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.

elementalsouls/Claude-BugHunter4.8k—~4.5kAutomated safety check: PassMITyesterday
443

C++ naming, formatting, static analysis, and RTTI rules for LuisaCompute.

LuisaGroup/LuisaCompute1.1k—~1.1kAutomated safety check: PassApache-2.0today
444

Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.

tsale/awesome-dfir-skills323—~3.4kAutomated safety check: PassApache-2.04 mo ago
445

Give a decisive, project-grounded verdict on an external input — judged against the current project, not in the abstract.

leo-kuang-ai/spec-first107—~4.5kAutomated safety check: PassMITyesterday
446

Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

hashgraph-online/hol-guard827—~605Automated safety check: PassApache-2.0today
447

A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

ccashwell/evm-cortex131—~25kAutomated safety check: PassMIT9 days ago
448

Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input…

utkusen/sast-skills1.3k—~4.7kAutomated safety check: PassMIT6 mo ago
449

Runs a security health check on an OpenClaw environment and audits skills before or after installation for supply-chain and data-leak risks.

Tencent/AI-Infra-Guard6.8k—~9.5kAutomated safety check: PassMITtoday
450

A skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan.

vlinx-io/VelaTerm275—~3.3kAutomated safety check: PassMIT2 days ago
451

Worked bug bounty case study of a yield aggregator: target scoring, fund-flow mapping, prior audit triage and a verdict per bug class, with role misconfiguration in focus.

tradecatlabs/vibe-coding-cn17k2 repos~3.5kAutomated safety check: PassMITtoday
452

Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring.

tradecatlabs/vibe-coding-cn17k2 repos~2.5kAutomated safety check: PassMITtoday
453

Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target.

tradecatlabs/vibe-coding-cn17k2 repos~2.2kAutomated safety check: PassMITtoday
454

Dual-model code review via Codex CLI. An agent skill from suyuan2022/suyuan-skill.

suyuan2022/suyuan-skill290—~3.5kAutomated safety check: WarnMIT1 mo ago
455

Generate a PR-ready technique proposal when an attack step doesn't map to existing SITF techniques.

wiz-sec-public/SITF182—~4.1kAutomated safety check: PassUnknown2 mo ago
456

Audit, explain, or compare existing Tenuo warrants and delegation chains.

tenuo-ai/tenuo103—~3.6kAutomated safety check: PassApache-2.0today
457

Builds attack trees that map how an attacker could reach a goal, with AND and OR nodes and cost, time, skill and detection ratings, to find defense gaps.

wshobson/agents40k8 repos~623Automated safety check: PassMIT4 days ago
458

Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition.

wshobson/agents40k8 repos~2kAutomated safety check: PassMIT4 days ago
459

Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

wshobson/agents40k8 repos~742Automated safety check: PassMIT4 days ago
460

Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input).

ash1794/vibe-engineering163—~722Automated safety check: PassMIT2 days ago
461

Static safety audit of a SKILL.md that scores five dimensions and acts as a gate: skills below the pass line do not ship, whatever else they score.

openJiuwen-ai/agent-core446—~3.5kAutomated safety check: WarnApache-2.0today
462
462.Sarif ParsingOfficial

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

trailofbits/skills7.4k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.02 days ago
463

The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main.

ibuilder/massing122—~2.3kAutomated safety check: PassMITtoday
464

分析 Code Scanning (CodeQL) 告警,评估安全风险并创建修复任务。当用户要求分析 Code Scanning 告警、CodeQL 告警时触发。参数为告警编号。

ModelEngine-Group/fit-framework2.1k—~187Automated safety check: PassMIT7 mo ago
465

Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.

nordstjernen-web/northstar-browser124—~920Automated safety check: PassGPL-3.0yesterday
466

Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks.

dralgorhythm/claude-agentic-framework125—~581Automated safety check: PassNo licence2 mo ago
467

Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
468

Run a Nuclei security scan against the target URL and report findings by severity.

MigoXLab/webqa-agent232—~846Automated safety check: PassApache-2.03 mo ago
469

Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

CommonHuman-Lab/nyxstrike157—~1.1kAutomated safety check: PassUnknown2 days ago
470

Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus.

bugbountywithmarco/bugbounty-disclosed-reports122—~524Automated safety check: PassNo licence2 mo ago
471
471.Scan CodeOfficial

Scans a Power Pages site project for security issues in source code and dependencies.

microsoft/power-platform-skills979—~3.4kAutomated safety check: NotesMITtoday
472

Run an end-to-end OpenTaint application-security analysis while owning the long project build and scans and delegating each other pipeline stage.

seqra/opentaint163—~2.2kAutomated safety check: PassApache-2.0yesterday
473

Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

cdxgen/cdxgen1.1k—~1.5kAutomated safety check: PassApache-2.0yesterday
474

Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

Encod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT1 mo ago
475

Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.

transilienceai/communitytools562—~1.8kAutomated safety check: PassMIT2 mo ago
476

Run a Codex-CLI static-analysis parity review of the current diff against the local RPython/PyPy sources, then act on it — fix the regressions and new mismatches in-session, and file the rest as…

youknowone/pyre116—~2.3kAutomated safety check: PassUnknowntoday
477

Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates…

johnson7788/MultiUserClaw327—~3kAutomated safety check: PassMIT1 mo ago
478
478.Android New ModuleOfficial

Guide for creating new Android gradle modules in the android-components project.

SAP/project-foxhound1802 repos~1.8kAutomated safety check: PassGPL-3.03 days ago
479
479.Earl

A skill your agent uses when you need to call an API, run a database query, or execute a shell command via Earl.

mathematic-inc/earl113—~1.3kAutomated safety check: PassApache-2.0yesterday
480

Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

briiirussell/cybersecurity-skills413—~1.3kAutomated safety check: NotesMIT4 mo ago