Category
Best security skills, page 18
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 817 | 817.Gcode To Text Decode and interpret text content from G-code files by analyzing toolpath geometry and coordinate patterns. | lazyFrogLOL/ | 128 | — | ~1.4k | Automated safety check: Pass | No licence | 4 mo ago |
| 818 | 818.Email Search Get verified emails and phones for contacts found by people-search. | extruct-ai/ | 109 | — | ~1.3k | Automated safety check: Pass | No licence | 13 days ago |
| 819 | 819.Secure Agent Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules. | mathematic-inc/ | 113 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 820 | Perform language and framework specific security best-practice reviews and suggest improvements. | trailofbits/ | 513 | 9 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 821 | Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. | trailofbits/ | 513 | 9 repos | ~1.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 mo ago |
| 822 | Create an OpenTaint test project with positive/negative samples for verifying a rule or approximation. | seqra/ | 163 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 823 | Implementation details for EF Core scaffolding (reverse engineering). | dotnet/ | 15k | — | ~321 | Automated safety check: Pass | MIT | yesterday |
| 824 | 当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM… | zhaji2333/ | 115 | — | ~4.7k | Automated safety check: Warn | MIT | 26 days ago |
| 825 | Reference vocabulary for interpreting vulnerability findings — detector-vs-impact distinction, severity anchoring on demonstrated evidence, the eleven-item interpretation rubric, delegation… | provos/ | 612 | — | ~6.3k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 826 | 减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。 | index-login/ | 158 | — | ~242 | Automated safety check: Pass | MIT | yesterday |
| 827 | 827.Sast Fileupload Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel… | utkusen/ | 1.3k | — | ~7.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 828 | 828.Web App Scanner Authorized web application testing from the CLI, including local pre-deploy source/config audits, subdomain enumeration, passive recon, non-destructive active vulnerability checks, and guarded SQL… | ptn1411/ | 219 | — | ~3.2k | Automated safety check: Notes | No licence | 19 days ago |
| 829 | 829.Plan Turn a development task into one work file in .work/ — goal, decisions, lanes with exact files and verification, done-criteria. | guardana/ | 259 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 830 | 830.Security Scan AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。 | affaan-m/ | 277k | 2 repos | ~796 | Automated safety check: Pass | MIT | today |
| 831 | 831.Security Review 認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。 | affaan-m/ | 277k | 2 repos | ~2.5k | Automated safety check: Notes | MIT | today |
| 832 | 832.Security Review 인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요. | affaan-m/ | 277k | 2 repos | ~2.7k | Automated safety check: Notes | MIT | today |
| 833 | 833.Security Audit A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance. | jellydn/ | 123 | — | ~2.9k | Automated safety check: Notes | MIT | yesterday |
| 834 | A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining… | hypnguyen1209/ | 388 | — | ~2.5k | Automated safety check: Pass | MIT | 13 days ago |
| 835 | Classify game-cheat capabilities and their defensive implications across memory, injection, rendering, input, engines, kernels, DMA, and remote transports. | gmh5225/ | 3.6k | — | ~356 | Automated safety check: Pass | MIT | today |
| 836 | Analyze a range of local commits, and reorganize them to minimize latency and friction in the review and landing process. | SAP/ | 180 | 1 repo | ~3.7k | Automated safety check: Pass | GPL-3.0 | yesterday |
| 837 | 837.Web2 Recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis… | awarexone/ | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | 2 days ago |
| 838 | Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates. | awarexone/ | 5.3k | — | ~1.9k | Automated safety check: Warn | MIT | 2 days ago |
| 839 | A skill your agent uses when choosing native or multi-LLM handling for init, review, or security requests | nyldn/ | 4.2k | 1 repo | ~643 | Automated safety check: Pass | MIT | today |
| 840 | Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation. | dslsdzc/ | 135 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 841 | 841.Ctf Forensics Provides digital forensics and signal analysis techniques for CTF challenges. | ljagiello/ | 3.4k | — | ~9.2k | Automated safety check: Warn | MIT | 27 days ago |
| 842 | Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. | trailofbits/ | 7.5k | — | ~3.6k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 843 | Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix. | trailofbits/ | 7.5k | — | ~3.1k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 844 | Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation. | trailofbits/ | 7.5k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 845 | Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay. | trailofbits/ | 7.5k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 846 | Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes. | trailofbits/ | 7.5k | — | ~2.9k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 847 | Scores a smart contract or blockchain codebase across 9 maturity categories with evidence, then delivers a scorecard and a priority-ordered improvement roadmap. | trailofbits/ | 7.5k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 848 | Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents. | trailofbits/ | 7.5k | — | ~2.7k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 849 | Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. | trailofbits/ | 7.5k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 850 | Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation. | trailofbits/ | 7.5k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 851 | Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact. | trailofbits/ | 7.5k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 852 | Reviews a smart contract project against Trail of Bits development guidelines, covering documentation, architecture, upgradeability, implementation quality, dependencies and tests. | trailofbits/ | 7.5k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 853 | Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. | trailofbits/ | 7.5k | — | ~4.3k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 854 | Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally. | trailofbits/ | 7.5k | — | ~4.2k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 855 | Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language. | trailofbits/ | 7.5k | — | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 856 | Guides through Trail of Bits' 5-step secure development workflow. | trailofbits/ | 7.5k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 857 | Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. | trailofbits/ | 7.5k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 858 | Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. | trailofbits/ | 7.5k | — | ~3.8k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 859 | Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark… | trailofbits/ | 7.5k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 860 | Validates cryptographic implementations against Project Wycheproof's test vectors, which encode known attacks and edge cases across AES, RSA, ECDSA, ECDH, and more. | trailofbits/ | 7.5k | — | ~4.9k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 861 | 861.Review Swarm Parallel read-only multi-agent review of a current git diff or explicit file scope to find behavioral regressions, security or privacy risks, performance or reliability issues, and contract or test… | Dimillian/ | 4k | — | ~1.6k | Automated safety check: Pass | MIT | 6 mo ago |
| 862 | 862.Django Security Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 277k | 1 repo | ~4.3k | Automated safety check: Notes | MIT | today |
| 863 | Security checklist for Solidity AMM contracts, liquidity pools, and swap flows. | affaan-m/ | 277k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | today |
| 864 | Diagnostics-only BGP troubleshooting patterns for neighbor state, route exchange, prefix policy, AS path inspection, and safe evidence collection. | affaan-m/ | 277k | 1 repo | ~1.4k | Automated safety check: Pass | MIT | today |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660