Category
Best security skills, page 16
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 721 | Hunt for exploitable, bounty-worthy security issues in repositories. | affaan-m/ | 277k | 2 repos | ~907 | Automated safety check: Pass | MIT | today |
| 722 | A skill your agent uses when the user asks to log in or out with a wallet session, fetch a wallet sign-in challenge, verify an externally signed challenge, or troubleshoot AltLLM Portal wallet login… | internet-court/ | 6.6k | 1 repo | ~632 | Automated safety check: Pass | ISC | 1 mo ago |
| 723 | A skill your agent uses when the user asks to create a NOWPayments crypto payment link, poll payment status, or execute a supported direct wallet payment through the AltLLM Portal CLI. | internet-court/ | 6.6k | 1 repo | ~563 | Automated safety check: Pass | ISC | 1 mo ago |
| 724 | 724.Senior Security Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. | davila7/ | 33k | 2 repos | ~1.1k | Automated safety check: Notes | MIT | today |
| 725 | 725.HTTP Evidence Turn a captured HTTP request/response into a bounded, redacted evidence pack with a stable request-ref using the mantishttpaudit MCP server, instead of pasting raw traffic into a finding | deonmenezes/ | 503 | — | ~455 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 726 | 726.Edr Bypass Re 逆向防御方实现 → 红队针对性绕过。把 EDR / Defender / AV 的 hook 表、ETW provider、AMSI 实现先逆向出来, 再写针对性的 unhook / 间接 syscall / ETW patch / call stack spoof。对照 MITRE ATT&CK T1562 防御规避。 | zhaoxuya520/ | 41k | 1 repo | ~1.6k | Automated safety check: Warn | MIT | 19 days ago |
| 727 | A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level… | makifbaysal/ | 112 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | today |
| 728 | 728.Security Setup Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 729 | 729.Vuln Hunter Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation. | dariushoule/ | 209 | — | ~3.9k | Automated safety check: Notes | MIT | 7 mo ago |
| 730 | 730.Skill Ship Package and finalize completed work for delivery — use when a feature is done and ready to ship | nyldn/ | 4.2k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | today |
| 731 | 731.Create Rule Author and verify an OpenTaint rule. An agent skill from seqra/opentaint. | seqra/ | 163 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 732 | 732.Dep Security Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that… | tinyfish-io/ | 2.2k | — | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 733 | 733.Ghost Scan Deps Ghost Security - Software Composition Analysis (SCA) scanner. | ghostsecurity/ | 409 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | 13 days ago |
| 734 | Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel… | utkusen/ | 1.3k | — | ~5.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 735 | Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste. | microsoft/ | 107 | — | ~1k | Automated safety check: Pass | MIT | yesterday |
| 736 | 736.Gate Run this project's verification — the full local CI mirror (ruff, mypy, import contract, pytest with PostgreSQL, coverage floors, dogfood, generated docs and site, the isolated example suites, the… | guardana/ | 259 | — | ~757 | Automated safety check: Pass | Apache-2.0 | today |
| 737 | Scans text that has already been de-identified for leftover identifiers such as SSNs, card numbers, emails and dates, and blocks release if anything turns up. | maziyarpanahi/ | 5.5k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 738 | 738.Django Security Django 安全最佳实践、认证、授权、CSRF 防护、SQL 注入预防、XSS 预防和安全部署配置. An agent skill from affaan-m/ECC. | affaan-m/ | 277k | 3 repos | ~3.7k | Automated safety check: Notes | MIT | today |
| 739 | 739.Security Review 在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。 | affaan-m/ | 277k | 3 repos | ~2.5k | Automated safety check: Notes | MIT | today |
| 740 | Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。 | affaan-m/ | 277k | 3 repos | ~1.6k | Automated safety check: Pass | MIT | today |
| 741 | 741.Soak Manages the repo's supply-chain soak window (SOAKDAYS) — checks and fixes the derived surfaces, bumps or disables the window, adds dated per-package exclusions, and bumps pinned external tools. | nubjs/ | 4.4k | — | ~1.3k | Automated safety check: Warn | MIT | yesterday |
| 742 | Supply-chain security controls for the @cipherstash/stack monorepo. | cipherstash/ | 157 | — | ~5.2k | Automated safety check: Warn | MIT | yesterday |
| 743 | Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy. | quillai-network/ | 130 | — | ~3.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 744 | 744.Aster Config Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits. | Zfinix/ | 118 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 745 | 745.History Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive. | alpha-omega-security/ | 245 | — | ~2.9k | Automated safety check: Notes | MIT | today |
| 746 | A skill your agent uses when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a… | serejaris/ | 229 | — | ~3.4k | Automated safety check: Notes | MIT | 3 days ago |
| 747 | Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works. | nanocoai/ | 31k | — | ~598 | Automated safety check: Pass | MIT | yesterday |
| 748 | Reviews code for security, performance, quality and maintainability, then reports findings in a fixed template with a rating, severity levels and suggested fixes. | luongnv89/ | 42k | — | ~474 | Automated safety check: Pass | MIT | today |
| 749 | 749.Semgrep Skill Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules. | KimYx0207/ | 174 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 750 | 750.ffuf Web Fuzzer Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans. | AgentSecOps/ | 220 | 1 repo | ~3.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 751 | 751.Webcrypt MCP Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography. | putervision/ | 50 | — | ~847 | Automated safety check: Pass | MIT | 7 days ago |
| 752 | Path traversal / Local File Inclusion detection→file-read→RCE for web apps. | s0ld13rr/ | 828 | — | ~602 | Automated safety check: Notes | MIT | 9 days ago |
| 753 | Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments. | irahardianto/ | 156 | — | ~2.7k | Automated safety check: Notes | MIT | 6 days ago |
| 754 | Secure secrets in Google Cloud Secret Manager. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 3 repos | ~3.3k | Automated safety check: Pass | MIT | yesterday |
| 755 | Use before merging security-relevant Rust changes. An agent skill from Jxck/sptth. | Jxck/ | 133 | — | ~318 | Automated safety check: Pass | MIT | 7 mo ago |
| 756 | 756.Security Hygiene Detecta riscos básicos de segurança em repositórios (segredos expostos, configurações perigosas, padrões inseguros) e gera recomendações com evidências. | glaucia86/ | 121 | — | ~819 | Automated safety check: Warn | MIT | 3 mo ago |
| 757 | 生成安全审计 skill。两种模式:(1) 项目模式——根据项目文档生成定制化审计 skill;(2) 通用模式——仅指定语言+框架,从参考资料库生成通用审计 skill。当用户想创建安全审计 skill、生成审计规则、或提到"生成安全审计skill"、"创建code review skill"、"生成 Java 审计 skill"时使用。 | xwtro0tk1t-cloud/ | 265 | — | ~5.7k | Automated safety check: Pass | No licence | 5 mo ago |
| 758 | Audit Entra ID app registration and service principal security posture. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | 2 days ago |
| 759 | 759.Fp Check Systematic false positive verification for security findings. | vibeeval/ | 532 | — | ~1.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 760 | Analyzes Solidity contract entry points to map attack surface. | alt-research2/ | 104 | — | ~959 | Automated safety check: Pass | Unknown | 4 mo ago |
| 761 | 761.Dependency Audit Dependency audit and cleanup workflow for maintaining healthy project dependencies. | bobmatnyc/ | 156 | — | ~3.5k | Automated safety check: Pass | Unknown | 1 mo ago |
| 762 | Performs security-focused differential review of code changes (PRs, commits, diffs). | waybarrios/ | 534 | 5 repos | ~1.6k | Automated safety check: Pass | MIT | 5 days ago |
| 763 | Build structured threat actor profiles using the 5W1H framework and the Diamond Model. | tsale/ | 323 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 5 mo ago |
| 764 | 764.Threat Model MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness. | ruvnet/ | 696 | — | ~637 | Automated safety check: Notes | MIT | yesterday |
| 765 | Run splint after cppcheck/clang-format/clang-tidy precommit sanity to find memory issues, API misuse, and contract violations in staged C code (tolerates older C parser limitations). | MidnightBSD/ | 114 | — | ~348 | Automated safety check: Pass | Unknown | 2 days ago |
| 766 | 766.Ctf Writeup Generates a single standardized submission-style CTF writeup for competition handoff and organizer review. | ljagiello/ | 3.4k | — | ~1.2k | Automated safety check: Notes | MIT | 27 days ago |
| 767 | Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data. | trailofbits/ | 7.5k | — | ~2.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 768 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.5k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660