Category

Best security skills, page 2

Skills #49–96 of 3,084, ranked by score.

Security skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Security skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

elastic/agent-skills5921 repo~3.5kAutomated safety check: NotesApache-2.0today
50

当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

SummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT4 mo ago
51

A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

vulnersCom/api375—~2.3kAutomated safety check: PassMIT9 days ago
52

Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

rundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0today
53

Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

kubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0today
54

Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter).

symfony/symfony31k—~2.6kAutomated safety check: PassMITtoday
55

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

trailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.0today
56

Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~4kAutomated safety check: PassMIT3 days ago
57

A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

tradecatlabs/vibe-coding-cn17k2 repos~3.9kAutomated safety check: WarnMITtoday
58

Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written.

OTRF/ThreatHunter-Playbook4.7k—~813Automated safety check: PassMIT8 mo ago
59

A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

solana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMITtoday
60

Run Semgrep static analysis scan on a codebase using parallel subagents.

vigolium/piolium1401 repo~2.4kAutomated safety check: NotesMIT18 days ago
61

Reconcile an existing Fizz harness with a changed source tree.

pashov/skills1.2k2 repos~3.9kAutomated safety check: PassMIT2 days ago
62

Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

awarexone/Agentic-Bug-Hunter5.3k1 repo~2.4kAutomated safety check: PassMIT3 days ago
63

Cut a new AperiSolve release — bump the version, commit "chore(release): X.Y.Z", tag it, push, and publish a GitHub Release whose notes are computed from the commits since the last tag.

Zeecka/AperiSolve850—~1.9kAutomated safety check: PassMITtoday
64
64.Security ReviewOfficial

Security code review for vulnerabilities. An agent skill from getsentry/skills.

getsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.05 days ago
65

A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…

agentlas-ai/Agentlas-OS1.6k1 repo~822Automated safety check: PassApache-2.0yesterday
66

Treat an open-ended investigation the way a fuzzer treats a program.

ARA-Labs/Agent-Native-Research-Artifact692—~2.4kAutomated safety check: PassMITtoday
67

Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

samugit83/redamon3k—~775Automated safety check: PassMITtoday
68

Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

luongnv89/claude-howto42k—~764Automated safety check: PassMIT7 days ago
69

Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

lingbol088-spec/ReiPenFlow222—~1.8kAutomated safety check: PassMIT2 mo ago
70

Hello CTF 技能树 —— 基于国内 CTF 竞赛体系整理的全方向攻防知识库。当用户在学习 CTF、备战比赛、解赛题(Web / Crypto / Misc / Pwn / Reverse / AI / 云安全 / 数据安全 / 区块链 / 工控 / 物联网 / 应急响应 / 渗透测试)需要定位知识点、查询利用手法或规划学习路线时使用。也适用于按知识域出题、查漏补缺。

ProbiusOfficial/Hello-CTF4.2k—~387Automated safety check: PassGPL-3.0today
71

Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

mono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMITtoday
72

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

nyldn/claude-octopus4.2k1 repo~2.3kAutomated safety check: PassMITtoday
73

Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

Narwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT6 mo ago
74

A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

asyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.02 days ago
75

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

SonarSource/sonar-java1.2k—~833Automated safety check: PassUnknowntoday
76

Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

aliyun/alibabacloud-ecs-troubleshoot-skills1481 repo~2.4kAutomated safety check: NotesApache-2.01 mo ago
77

Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.

symfony/symfony31k—~2.9kAutomated safety check: PassMITtoday
78

Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing.

skjolber/3d-bin-container-packing568—~886Automated safety check: PassApache-2.0today
79

Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins.

BigBodyCobain/Shadowbroker11k—~8.9kAutomated safety check: WarnAGPL-3.0yesterday
80

Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from…

shoyann/RZK-The-Hunter140—~4.8kAutomated safety check: PassCC-BY-SA-4.017 days ago
81

Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~4.4kAutomated safety check: PassMIT3 days ago
82

URL search param and hash state management. An agent skill from promptfoo/promptfoo.

promptfoo/promptfoo26k—~1.1kAutomated safety check: PassMITtoday
83

Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.

OTRF/ThreatHunter-Playbook4.7k—~600Automated safety check: PassMIT8 mo ago
84

Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

ZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMITtoday
85

Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

trailofbits/skills7.4k4 repos~4.2kAutomated safety check: NotesCC-BY-SA-4.0today
86

Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

verdaccio/verdaccio18k—~853Automated safety check: PassMITyesterday
87

Launch, see and drive a real game so an agent can test its own mods.

rehan-remade/universal-modder5.3k—~1.9kAutomated safety check: PassMITtoday
88

Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test.

elementalsouls/Claude-OSINT2.8k—~1.2kAutomated safety check: PassMIT1 mo ago
89

Ensure that C and C++/CLI types are documented with XML comments and follow best practices for documentation.

MichaelGrafnetter/DSInternals2k—~1.2kAutomated safety check: PassMIT26 days ago
90

Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.

Tencent/AI-Infra-Guard6.8k—~753Automated safety check: PassApache-2.0today
91

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~581Automated safety check: PassApache-2.0today
92

Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

elastic/agent-skills5921 repo~3.9kAutomated safety check: NotesApache-2.0today
93

Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

tech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.017 days ago
94

Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

LukasNiessen/kubernetes-skill444—~1.2kAutomated safety check: PassMIT24 days ago
95

Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.

context-labs/whip1.1k2 repos~3kAutomated safety check: PassMIT3 days ago
96

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

fengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT22 days ago