Category
Best security skills, page 10
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 433 | A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning… | jabrena/ | 447 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 434 | Explains authorization in an Arandu Go application: write a Policy, get a security.Grant through security.Authorize, re-authorize each row, and keep tenant isolation. | arandu-io/ | 281 | — | ~1.4k | Automated safety check: Pass | MIT | 5 days ago |
| 435 | A skill your agent uses when asked to generate a "no way to prevent this" / no-way-to-prevent-this satire post for a memory-safety CVE (out-of-bounds write/read, buffer/heap overflow… | Xe/ | 732 | — | ~816 | Automated safety check: Pass | Zlib | yesterday |
| 436 | Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging. | wshobson/ | 40k | 9 repos | ~588 | Automated safety check: Pass | MIT | 4 days ago |
| 437 | 437.Kesekit Guide Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot). | cdppcorp/ | 361 | — | ~1.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 438 | Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it. | dslsdzc/ | 130 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 439 | 439.Nmap Professional network reconnaissance and port scanning using nmap. | BrownFineSecurity/ | 859 | 1 repo | ~3.8k | Automated safety check: Notes | MIT | 4 mo ago |
| 440 | This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through… | zebbern/ | 4.7k | 5 repos | ~2.9k | Automated safety check: Pass | MIT | today |
| 441 | 441.Fix Scan Finding Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in… | malloydata/ | 116 | — | ~5.1k | Automated safety check: Pass | MIT | today |
| 442 | Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. | elementalsouls/ | 4.8k | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 443 | 443.Cpp Style C++ naming, formatting, static analysis, and RTTI rules for LuisaCompute. | LuisaGroup/ | 1.1k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 444 | 444.Admiralty System Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis. | tsale/ | 323 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 4 mo ago |
| 445 | 445.Spec Pov Give a decisive, project-grounded verdict on an external input — judged against the current project, not in the abstract. | leo-kuang-ai/ | 107 | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 446 | Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows. | hashgraph-online/ | 827 | — | ~605 | Automated safety check: Pass | Apache-2.0 | today |
| 447 | 447.Xray Pre Audit A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview. | ccashwell/ | 131 | — | ~25k | Automated safety check: Pass | MIT | 9 days ago |
| 448 | 448.Sast Graphql Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input… | utkusen/ | 1.3k | — | ~4.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 449 | 449.EdgeOne ClawScan Runs a security health check on an OpenClaw environment and audits skills before or after installation for supply-chain and data-leak risks. | Tencent/ | 6.8k | — | ~9.5k | Automated safety check: Pass | MIT | today |
| 450 | A skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. | vlinx-io/ | 275 | — | ~3.3k | Automated safety check: Pass | MIT | 2 days ago |
| 451 | Worked bug bounty case study of a yield aggregator: target scoring, fund-flow mapping, prior audit triage and a verdict per bug class, with role misconfiguration in focus. | tradecatlabs/ | 17k | 2 repos | ~3.5k | Automated safety check: Pass | MIT | today |
| 452 | Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring. | tradecatlabs/ | 17k | 2 repos | ~2.5k | Automated safety check: Pass | MIT | today |
| 453 | Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target. | tradecatlabs/ | 17k | 2 repos | ~2.2k | Automated safety check: Pass | MIT | today |
| 454 | 454.Codex Review Dual-model code review via Codex CLI. An agent skill from suyuan2022/suyuan-skill. | suyuan2022/ | 290 | — | ~3.5k | Automated safety check: Warn | MIT | 1 mo ago |
| 455 | Generate a PR-ready technique proposal when an attack step doesn't map to existing SITF techniques. | wiz-sec-public/ | 182 | — | ~4.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 456 | 456.Tenuo Audit Audit, explain, or compare existing Tenuo warrants and delegation chains. | tenuo-ai/ | 103 | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | today |
| 457 | Builds attack trees that map how an attacker could reach a goal, with AND and OR nodes and cost, time, skill and detection ratings, to find defense gaps. | wshobson/ | 40k | 8 repos | ~623 | Automated safety check: Pass | MIT | 4 days ago |
| 458 | Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. | wshobson/ | 40k | 8 repos | ~2k | Automated safety check: Pass | MIT | 4 days ago |
| 459 | Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation. | wshobson/ | 40k | 8 repos | ~742 | Automated safety check: Pass | MIT | 4 days ago |
| 460 | Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input). | ash1794/ | 163 | — | ~722 | Automated safety check: Pass | MIT | 2 days ago |
| 461 | Static safety audit of a SKILL.md that scores five dimensions and acts as a gate: skills below the pass line do not ship, whatever else they score. | openJiuwen-ai/ | 446 | — | ~3.5k | Automated safety check: Warn | Apache-2.0 | today |
| 462 | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. | trailofbits/ | 7.4k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 463 | 463.Ship Release The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main. | ibuilder/ | 122 | — | ~2.3k | Automated safety check: Pass | MIT | today |
| 464 | 464.Analyze Codescan 分析 Code Scanning (CodeQL) 告警,评估安全风险并创建修复任务。当用户要求分析 Code Scanning 告警、CodeQL 告警时触发。参数为告警编号。 | ModelEngine-Group/ | 2.1k | — | ~187 | Automated safety check: Pass | MIT | 7 mo ago |
| 465 | Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries. | nordstjernen-web/ | 124 | — | ~920 | Automated safety check: Pass | GPL-3.0 | yesterday |
| 466 | 466.Threat Modeling Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks. | dralgorhythm/ | 125 | — | ~581 | Automated safety check: Pass | No licence | 2 mo ago |
| 467 | Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 468 | 468.Nuclei Scan Run a Nuclei security scan against the target URL and report findings by severity. | MigoXLab/ | 232 | — | ~846 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 469 | 469.Cloud Audit Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images | CommonHuman-Lab/ | 157 | — | ~1.1k | Automated safety check: Pass | Unknown | 2 days ago |
| 470 | 470.Program Intel Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus. | bugbountywithmarco/ | 122 | — | ~524 | Automated safety check: Pass | No licence | 2 mo ago |
| 471 | Scans a Power Pages site project for security issues in source code and dependencies. | microsoft/ | 979 | — | ~3.4k | Automated safety check: Notes | MIT | today |
| 472 | 472.Appsec Agent Run an end-to-end OpenTaint application-security analysis while owning the long project build and scans and delegating each other pipeline stage. | seqra/ | 163 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 473 | 473.Bom Signing Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 474 | Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP. | Encod3d-Sec/ | 329 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 475 | Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation. | transilienceai/ | 562 | — | ~1.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 476 | 476.Codex Review Run a Codex-CLI static-analysis parity review of the current diff against the local RPython/PyPy sources, then act on it — fix the regressions and new mismatches in-session, and file the rest as… | youknowone/ | 116 | — | ~2.3k | Automated safety check: Pass | Unknown | today |
| 477 | Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates… | johnson7788/ | 327 | — | ~3k | Automated safety check: Pass | MIT | 1 mo ago |
| 478 | Guide for creating new Android gradle modules in the android-components project. | SAP/ | 180 | 2 repos | ~1.8k | Automated safety check: Pass | GPL-3.0 | 3 days ago |
| 479 | 479.Earl A skill your agent uses when you need to call an API, run a database query, or execute a shell command via Earl. | mathematic-inc/ | 113 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 480 | 480.Cloud Audit Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps. | briiirussell/ | 413 | — | ~1.3k | Automated safety check: Notes | MIT | 4 mo ago |
Explore related skills
Topics in Security
- Security review637
- Web application vulnerabilities468
- Vulnerability scanning305
- Static analysis and SAST284
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,199
- Frontend & Design5,829
- Backend & APIs7,083
- Testing & QA5,062
- DevOps & Cloud5,955
- Databases2,353
- Data & Analytics3,632
- AI & LLM Engineering5,048
- Agent Workflows8,296
- Documents & Office4,290
- Writing & Content3,764
- Marketing & SEO3,901
- Sales & Support1,837
- Research & Science6,076
- Productivity & Automation4,035
- Business, Finance & HR3,880
- Legal & Compliance1,634
- Education1,086
- Media & Creative4,311
- Mobile2,737
- Product & Project Management2,339
- Knowledge Management1,438
- Game Development1,678