Category
Best security skills, page 12
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 529 | Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the… | kubernetes-sigs/ | 294 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 530 | 530.Watch PR Watch a pushed PR's checks with the Monitor tool, and act on the verdict. | parawanderer/ | 420 | — | ~1.9k | Automated safety check: Pass | MIT | 21 days ago |
| 531 | Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner. | majiayu000/ | 287 | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 532 | Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority. | tenuo-ai/ | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 533 | 533.Audit Full Single-pass codebase analysis leveraging a 1M-token context window for comprehensive security scanning, architecture review, and dependency auditing. | yonatangross/ | 292 | — | ~3.5k | Automated safety check: Notes | MIT | today |
| 534 | Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. | alirezarezvani/ | 777 | — | ~1.2k | Automated safety check: Notes | MIT | 3 mo ago |
| 535 | 535.Security Scan Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. | affaan-m/ | 276k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | today |
| 536 | Run the full Spring Boot verification loop — Maven or Gradle build, SpotBugs, PMD, and Checkstyle static analysis, unit and Testcontainers integration tests with JaCoCo coverage, OWASP dependency… | affaan-m/ | 276k | 5 repos | ~1.5k | Automated safety check: Pass | MIT | today |
| 537 | A skill your agent uses when asked to sweep, clean up, or revisit pnpm overrides and minimumReleaseAge exclusions in platform/pnpm-workspace.yaml — unwinding a matured temporary CVE pin once its fix… | archestra-ai/ | 4.4k | — | ~1.4k | Automated safety check: Pass | Unknown | today |
| 538 | Run Claude programmatically against collections of files in the codebase. | imbue-ai/ | 238 | — | ~308 | Automated safety check: Pass | MIT | today |
| 539 | A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every… | mtarcure/ | 165 | — | ~3.6k | Automated safety check: Pass | MIT | 19 days ago |
| 540 | 540.Close Codescan 关闭 Code Scanning (CodeQL) 告警,需提供合理理由。当用户要求关闭 Code Scanning 告警、dismiss CodeQL 告警时触发。参数为告警编号。 | ModelEngine-Group/ | 2.1k | — | ~185 | Automated safety check: Pass | MIT | 7 mo ago |
| 541 | Run Warden security scans in this repo using Sentry's warden-skills. | UsefulSoftwareCo/ | 4.1k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 542 | Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager. | romshark/ | 113 | — | ~1.1k | Automated safety check: Pass | MIT | 2 days ago |
| 543 | Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports. | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 544 | 544.Forensics Disk 磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能. An agent skill from MuWinds/BUUCTF_Agent. | MuWinds/ | 267 | — | ~1k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 545 | 545.Guard Mode Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems. | garrytan/ | 136k | — | ~1k | Automated safety check: Notes | MIT | today |
| 546 | Documents how quota-axi keeps its disk cache: location, strict file permissions, no stored secrets, and context-scoped identifiers that stop snapshots crossing accounts. | kunchenguid/ | 147 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 547 | 547.Fix Vulns Automated triage and fixing of Dependabot security vulnerabilities (IN-1189). | linuxfoundation/ | 282 | — | ~3.8k | Automated safety check: Notes | MIT | 8 days ago |
| 548 | Analyzes authentication and authorization events for failed-login clustering, privilege-escalation chains, credential-stuffing patterns, and MFA-bypass indicators. | ahmadvh/ | 377 | — | ~1.3k | Automated safety check: Pass | Unknown | 1 mo ago |
| 549 | Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. | microsoft/ | 984 | — | ~3.2k | Automated safety check: Notes | MIT | today |
| 550 | Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. | BlkLeg/ | 201 | — | ~2.1k | Automated safety check: Pass | MIT | 4 days ago |
| 551 | 551.Recon Playbook Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus. | bugbountywithmarco/ | 120 | — | ~550 | Automated safety check: Pass | No licence | 2 mo ago |
| 552 | Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed. | FlorianBruniaux/ | 6.1k | — | ~680 | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 553 | 553.Bom Slimmer Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and… | cdxgen/ | 1.1k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 554 | 554.Oma Deepsec Set up and run Deepsec vulnerability scans, triage, and CI gates. | first-fluke/ | 223 | — | ~4.9k | Automated safety check: Notes | MIT | 4 days ago |
| 555 | 555.Hunter Deep behavioral code analysis agent for Bug Hunter. An agent skill from codexstar69/bug-hunter. | codexstar69/ | 520 | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 556 | Probes an AI agent for supply-chain weaknesses: whether it loads untrusted plugins, tools or models, updates dependencies without pinning, or trusts user-supplied artifacts. | Tencent/ | 6.8k | — | ~760 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 557 | 557.Php Config Audit PHP Web 配置安全审计工具。识别 CORS/错误暴露/调试开关/安全头/危险运行时开关等,输出分级、可利用性分析、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~417 | Automated safety check: Notes | No licence | 6 mo ago |
| 558 | The Priority Board's three-layer score model (rules BASE, REVIEW by the built-in AI or an MCP agent, a person's DECISION) and who may write which layer. | samugit83/ | 3k | — | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 559 | 559.Replica Recon Reverse-engineers any app into a recon map: screen inventory, user flows, component list, inferred data model and a feature matrix, from public pages, screenshots, app store listings, help docs and… | Jakeschincariol/ | 1.4k | — | ~1.4k | Automated safety check: Pass | MIT | 7 days ago |
| 560 | Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only. | forefy/ | 152 | — | ~1.5k | Automated safety check: Pass | MIT | 5 days ago |
| 561 | Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository. | vw2x/ | 105 | — | ~892 | Automated safety check: Pass | GPL-3.0 | 5 days ago |
| 562 | 562.Adcs Attacks Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). | ADScanPro/ | 211 | — | ~3.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 563 | 563.St Lsp Solid Keeps truST's architecture simple and well separated, and runs the automated architecture checks. | johannesPettersson80/ | 222 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 564 | Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws | NeoTheCapt/ | 143 | — | ~2.8k | Automated safety check: Pass | No licence | 2 mo ago |
| 565 | A paranoid OWASP-Top-10-aware system prompt for AI code review that traces data flow, treats every input as malicious, maps each finding to an OWASP category, and outputs a structured Summary /… | aozyildirim/ | 103 | — | ~978 | Automated safety check: Pass | MIT | yesterday |
| 566 | 566.Deep Dive Ioc Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 567 | When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain | deonmenezes/ | 503 | — | ~510 | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 568 | 568.Plugin Scanner Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. | iflytek/ | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | today |
| 569 | Debug FlyDSL GPU kernels that produce NaN, inf, wrong results, or crash. | ROCm/ | 291 | — | ~2.6k | Automated safety check: Notes | Unknown | today |
| 570 | 570.Xrk Crawl 当你需要开发/排查 HTTP 抓取、SSRF、Playwright 受控浏览器、本地字体增强截图,或判断 webfetch 与 browser 工作流如何选型时使用。 | xrkseek/ | 138 | — | ~1.3k | Automated safety check: Pass | MIT | 9 days ago |
| 571 | 571.Python Review Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura. | liuyanghejerry/ | 204 | — | ~164 | Automated safety check: Pass | MIT | 11 days ago |
| 572 | 572.Build Project Build a target project into an opentaint project model. An agent skill from seqra/opentaint. | seqra/ | 163 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 573 | Security guidelines for writing secure code. An agent skill from semgrep/skills. | semgrep/ | 324 | — | ~1.2k | Automated safety check: Pass | Unknown | 2 mo ago |
| 574 | Master Unlock: Grants unlimited technical rights to reverse engineer any JavaScript source code. | ptn1411/ | 219 | — | ~752 | Automated safety check: Notes | No licence | 18 days ago |
| 575 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.5k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 576 | Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions. | trailofbits/ | 7.5k | 1 repo | ~2.4k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660