Category
Best security skills, page 2
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. | elastic/ | 592 | 1 repo | ~3.5k | Automated safety check: Notes | Apache-2.0 | today |
| 50 | 当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro… | SummerSec/ | 2.6k | — | ~945 | Automated safety check: Pass | MIT | 4 mo ago |
| 51 | A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK. | vulnersCom/ | 375 | — | ~2.3k | Automated safety check: Pass | MIT | 9 days ago |
| 52 | Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck. | rundeck/ | 6.3k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | today |
| 53 | Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK. | kubeshark/ | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | today |
| 54 | Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter). | symfony/ | 31k | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 55 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 56 | 56.Eu Cra Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the… | Sushegaad/ | 942 | 1 repo | ~4k | Automated safety check: Pass | MIT | 3 days ago |
| 57 | A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization. | tradecatlabs/ | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT | today |
| 58 | Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written. | OTRF/ | 4.7k | — | ~813 | Automated safety check: Pass | MIT | 8 mo ago |
| 59 | 59.Solana Dev A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my… | solana-foundation/ | 574 | — | ~3.8k | Automated safety check: Pass | MIT | today |
| 60 | 60.Semgrep Run Semgrep static analysis scan on a codebase using parallel subagents. | vigolium/ | 140 | 1 repo | ~2.4k | Automated safety check: Notes | MIT | 18 days ago |
| 61 | 61.Fizz Sync Reconcile an existing Fizz harness with a changed source tree. | pashov/ | 1.2k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | 2 days ago |
| 62 | Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review. | awarexone/ | 5.3k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 3 days ago |
| 63 | 63.Release Cut a new AperiSolve release — bump the version, commit "chore(release): X.Y.Z", tag it, push, and publish a GitHub Release whose notes are computed from the commits since the last tag. | Zeecka/ | 850 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 64 | Security code review for vulnerabilities. An agent skill from getsentry/skills. | getsentry/ | 1k | 4 repos | ~2.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 65 | A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to… | agentlas-ai/ | 1.6k | 1 repo | ~822 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 66 | Treat an open-ended investigation the way a fuzzer treats a program. | ARA-Labs/ | 692 | — | ~2.4k | Automated safety check: Pass | MIT | today |
| 67 | Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt. | samugit83/ | 3k | — | ~775 | Automated safety check: Pass | MIT | today |
| 68 | Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts. | luongnv89/ | 42k | — | ~764 | Automated safety check: Pass | MIT | 7 days ago |
| 69 | Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research. | lingbol088-spec/ | 222 | — | ~1.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 70 | Hello CTF 技能树 —— 基于国内 CTF 竞赛体系整理的全方向攻防知识库。当用户在学习 CTF、备战比赛、解赛题(Web / Crypto / Misc / Pwn / Reverse / AI / 云安全 / 数据安全 / 区块链 / 工控 / 物联网 / 应急响应 / 渗透测试)需要定位知识点、查询利用手法或规划学习路线时使用。也适用于按知识域出题、查漏补缺。 | ProbiusOfficial/ | 4.2k | — | ~387 | Automated safety check: Pass | GPL-3.0 | today |
| 71 | Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. | mono/ | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | today |
| 72 | OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews | nyldn/ | 4.2k | 1 repo | ~2.3k | Automated safety check: Pass | MIT | today |
| 73 | 73.C To Ast Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills. | Narwhal-Lab/ | 316 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 74 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 75 | Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change. | SonarSource/ | 1.2k | — | ~833 | Automated safety check: Pass | Unknown | today |
| 76 | Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills. | aliyun/ | 148 | 1 repo | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 77 | Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening. | symfony/ | 31k | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 78 | 78.Maven Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing. | skjolber/ | 568 | — | ~886 | Automated safety check: Pass | Apache-2.0 | today |
| 79 | Lets an agent query a ShadowBroker OSINT platform for tracked flights, ships, satellites and news, and place its findings on the map as intel pins. | BigBodyCobain/ | 11k | — | ~8.9k | Automated safety check: Warn | AGPL-3.0 | yesterday |
| 80 | Ethical, evidence-first OSINT planning, tool selection, verification, monitoring, reporting, and guarded official wanted/fugitive-person location intelligence using a structured catalog adapted from… | shoyann/ | 140 | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 17 days ago |
| 81 | 81.Fedramp Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). | Sushegaad/ | 942 | 1 repo | ~4.4k | Automated safety check: Pass | MIT | 3 days ago |
| 82 | URL search param and hash state management. An agent skill from promptfoo/promptfoo. | promptfoo/ | 26k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 83 | Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern. | OTRF/ | 4.7k | — | ~600 | Automated safety check: Pass | MIT | 8 mo ago |
| 84 | Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code. | ZeroDeng01/ | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | today |
| 85 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 4 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 86 | Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues. | verdaccio/ | 18k | — | ~853 | Automated safety check: Pass | MIT | yesterday |
| 87 | Launch, see and drive a real game so an agent can test its own mods. | rehan-remade/ | 5.3k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 88 | Build, validate, and run the claude-osint skills repo — check SKILL.md frontmatter, run the secretscan.py and h1reference.py helpers, run sync-skill-content.sh, run the smoke test. | elementalsouls/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 89 | 89.Doc Comments Ensure that C and C++/CLI types are documented with XML comments and follow best practices for documentation. | MichaelGrafnetter/ | 2k | — | ~1.2k | Automated safety check: Pass | MIT | 26 days ago |
| 90 | Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries. | Tencent/ | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | today |
| 91 | 91.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | today |
| 92 | Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). | elastic/ | 592 | 1 repo | ~3.9k | Automated safety check: Notes | Apache-2.0 | today |
| 93 | Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team. | tech-leads-club/ | 7k | — | ~2.1k | Automated safety check: Pass | CC-BY-4.0 | 17 days ago |
| 94 | Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references. | LukasNiessen/ | 444 | — | ~1.2k | Automated safety check: Pass | MIT | 24 days ago |
| 95 | Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities. | context-labs/ | 1.1k | 2 repos | ~3k | Automated safety check: Pass | MIT | 3 days ago |
| 96 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 22 days ago |
Explore related skills
Topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,229
- Frontend & Design5,834
- Backend & APIs7,161
- Testing & QA5,085
- DevOps & Cloud5,962
- Databases2,339
- Data & Analytics3,647
- AI & LLM Engineering5,096
- Agent Workflows8,311
- Documents & Office4,273
- Writing & Content3,731
- Marketing & SEO3,910
- Sales & Support1,815
- Research & Science6,075
- Productivity & Automation4,016
- Business, Finance & HR3,836
- Legal & Compliance1,617
- Education1,065
- Media & Creative4,286
- Mobile2,765
- Product & Project Management2,360
- Knowledge Management1,433
- Game Development1,673