Category
Best security skills, page 14
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 625 | 625.Django Security Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 277k | 5 repos | ~4k | Automated safety check: Notes | MIT | today |
| 626 | Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 627 | 627.Skill Update Skill creation, update and management — generates skill directory structure, validates against best practices, enforces line count limits. | transilienceai/ | 563 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 628 | 628.Security Guide OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation | jnMetaCode/ | 140 | — | ~644 | Automated safety check: Warn | Apache-2.0 | 12 days ago |
| 629 | Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by… | hardw00t/ | 105 | — | ~2.7k | Automated safety check: Pass | No licence | 5 mo ago |
| 630 | 630.Llvm Security Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation. | aftermathlabs/ | 438 | — | ~1.8k | Automated safety check: Pass | AGPL-3.0 | 7 days ago |
| 631 | Detect error propagation, chain failures, and single-point breakdowns that cascade across agent workflows. | Tencent/ | 6.8k | — | ~593 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 632 | 632.AI Governance AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents | Hack23/ | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 633 | Use webspec-index to query WHATWG, W3C, IETF and TC39 web specifications from the command line | SAP/ | 180 | 2 repos | ~1.1k | Automated safety check: Pass | GPL-3.0 | today |
| 634 | 634.Crypto Audit Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation. | briiirussell/ | 413 | — | ~2.8k | Automated safety check: Notes | MIT | 4 mo ago |
| 635 | 635.Security Audit Security audit skill. An agent skill from blueberrycongee/termcanvas. | blueberrycongee/ | 405 | — | ~966 | Automated safety check: Notes | MIT | 4 mo ago |
| 636 | Changing or adding a project setting / default value in RedAmon. | samugit83/ | 3k | — | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 637 | Route Mira detection findings into a reusable knowledge pipeline. | vw2x/ | 105 | — | ~1.1k | Automated safety check: Pass | GPL-3.0 | 6 days ago |
| 638 | Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. | ADScanPro/ | 211 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 639 | 639.Cors Testing CORS misconfiguration testing for data theft and access control bypass | NeoTheCapt/ | 143 | — | ~904 | Automated safety check: Pass | No licence | 2 mo ago |
| 640 | 640.Takeover Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the… | PentesterFlow/ | 1.4k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 641 | Lets the agent list and read the secrets a user has configured, such as API keys and tokens, through two tai tools instead of hardcoding credentials into code or commands. | YaoApp/ | 8.1k | — | ~415 | Automated safety check: Pass | Unknown | 2 days ago |
| 642 | 642.Enrich Ioc Enrich an IOC (IP, domain, hash, URL) with threat intelligence. | dandye/ | 127 | — | ~702 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 643 | 643.Snapshot Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions. | boostsecurityio/ | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 644 | 644.Apk Reversing 当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是… | zhaji2333/ | 115 | — | ~1.7k | Automated safety check: Pass | MIT | 26 days ago |
| 645 | Audits, detects gaps, and remediates Android permissions and IPC component security vulnerabilities. | sreichholf/ | 116 | 2 repos | ~7k | Automated safety check: Pass | GPL-3.0 | today |
| 646 | Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. | OWASP/ | 188 | — | ~542 | Automated safety check: Pass | CC-BY-4.0 | 15 days ago |
| 647 | 647.Security Review or implement security-sensitive code in the Static Web Server (SWS) project — path traversal defenses, symlink and hidden-file policy, TLS, security headers, CORS, basic auth, untrusted input… | static-web-server/ | 2.4k | — | ~2k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 648 | 648.Net 嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills. | zhinkgit/ | 734 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 649 | Follow the money via public records and sanctions data. An agent skill from Luciole-Studio/Misaka-Agent. | Luciole-Studio/ | 171 | 1 repo | ~2.9k | Automated safety check: Pass | MIT | 3 days ago |
| 650 | 650.Skill Scanner A skill your agent uses when reviewing an agent Skill before sharing, installing, or executing it and when checking a Skill bundle for credentials, dangerous commands, suspicious network behavior… | zrt-ai-lab/ | 287 | — | ~317 | Automated safety check: Pass | No licence | 2 mo ago |
| 651 | Shows, adds and removes the host directories that NanoClaw agent containers may access, recording each as read-only or read-write in an allowlist file. | nanocoai/ | 31k | — | ~474 | Automated safety check: Pass | MIT | today |
| 652 | 652.OneCLI Gateway Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys. | nanocoai/ | 31k | — | ~856 | Automated safety check: Pass | MIT | today |
| 653 | Code review covering security, performance, quality and maintainability, with a fixed report layout and two analysis scripts; the SKILL.md itself is in Ukrainian. | luongnv89/ | 42k | — | ~484 | Automated safety check: Pass | MIT | today |
| 654 | 654.TS Review TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura. | liuyanghejerry/ | 204 | — | ~166 | Automated safety check: Pass | MIT | 11 days ago |
| 655 | Finds exploitable application security vulnerabilities in code changes. | getsentry/ | 418 | — | ~1.8k | Automated safety check: Pass | Unknown | today |
| 656 | Model a method's taint propagation as a passThrough approximation. | seqra/ | 163 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 657 | 657.Ghost Report Ghost Security — combined security report. An agent skill from ghostsecurity/skills. | ghostsecurity/ | 409 | — | ~1.4k | Automated safety check: Notes | Apache-2.0 | 12 days ago |
| 658 | Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA. | trailofbits/ | 7.5k | — | ~5.9k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 659 | Hunt for the failure this project exists to prevent — code that compiles, types, tests green, and quietly reports "all clear" about something it never examined. | guardana/ | 259 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 660 | 660.Kesekit Start Ko KISA 기반 보안 취약점 분석평가를 수행합니다. An agent skill from cdppcorp/KESE-KIT. | cdppcorp/ | 360 | — | ~1.5k | Automated safety check: Pass | MIT | 6 mo ago |
| 661 | 661.Crypto Analysis A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum… | hypnguyen1209/ | 388 | — | ~2.2k | Automated safety check: Pass | MIT | 13 days ago |
| 662 | 662.Supply Chain Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops. | padamson/ | 159 | — | ~711 | Automated safety check: Pass | Apache-2.0 | today |
| 663 | 663.Dependencies Run git-pkgs list and sbom against the repository and emit one envelope with per-section status. | alpha-omega-security/ | 245 | — | ~596 | Automated safety check: Pass | MIT | today |
| 664 | Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself. | anthropics/ | 38k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 665 | 665.Repo Audit Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. | zebbern/ | 4.7k | — | ~831 | Automated safety check: Pass | MIT | yesterday |
| 666 | Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design. | revfactory/ | 1.3k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 667 | Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session. | avelikiy/ | 103 | — | ~884 | Automated safety check: Notes | MIT | today |
| 668 | 668.Variant Analysis Find similar vulnerabilities and bugs across codebases using pattern-based analysis. | waybarrios/ | 534 | 5 repos | ~1.4k | Automated safety check: Pass | MIT | 5 days ago |
| 669 | Paid API marketplace for AI agents via Corbits. An agent skill from moonpay/skills. | moonpay/ | 113 | — | ~1.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 670 | 670.Security Review Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment… | valory-xyz/ | 129 | — | ~11k | Automated safety check: Notes | Apache-2.0 | 26 days ago |
| 671 | Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs. | AgentSecOps/ | 220 | 1 repo | ~3.3k | Automated safety check: Notes | Unknown | 5 mo ago |
| 672 | 672.Sca AI Denoise SCA 漏洞 AI 降噪与风险优先级评估。对 Grype/Snyk/Xray 等 SCA 工具的漏洞发现进行多维度风险评估,按 P0-P3 分级,过滤噪音(DoS、本地提权、低影响信息泄露),聚焦真正可利用的高风险漏洞。当用户需要对 SCA 扫描结果降噪、漏洞优先级排序、或供应链风险评估时使用。 | xwtro0tk1t-cloud/ | 265 | — | ~787 | Automated safety check: Pass | No licence | 5 mo ago |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660