Category
Best security skills, page 20
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 913 | 913.Redamon Testing How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie. | samugit83/ | 3k | — | ~1.8k | Automated safety check: Pass | MIT | 3 days ago |
| 914 | Working on RedAmon's supply-chain scanner (offline OSV + GuardDog + retire + trufflehog): the offline OSV database that the scan path does not bootstrap, the world-readable requirement for the… | samugit83/ | 3k | — | ~855 | Automated safety check: Pass | MIT | 3 days ago |
| 915 | 915.Traffic Capture Working on the HTTP capture proxy and its replay/fuzz path: the egress guard that stops the proxy becoming an SSRF pivot, why it checks the resolved IP, and keeping capture off the scan's critical… | samugit83/ | 3k | — | ~771 | Automated safety check: Pass | MIT | 3 days ago |
| 916 | 916.Ad Persistence AD 域环境持久化技术。当已获取域管/本地管理员权限、需要建立持久访问以确保重启或密码更改后仍能回到目标环境时使用。覆盖主机级持久化(计划任务/注册表Run/COM劫持/WMI事件订阅/Windows服务/启动文件夹)、域级持久化(Golden Ticket/Silver Ticket/Skeleton… | wgpsec/ | 1.8k | — | ~2.3k | Automated safety check: Pass | No licence | yesterday |
| 917 | Discover hidden directories, files, and endpoints on a web server | NeoTheCapt/ | 143 | — | ~737 | Automated safety check: Notes | No licence | 2 mo ago |
| 918 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 919 | Bootstrap a development environment and set the npm registry to https://npm.artifacts-mirror.internal-corp.dev | cisco-ai-defense/ | 2.6k | — | ~169 | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 920 | Security-focused review for frontend/Web3 code. An agent skill from hyperlane-xyz/hyperlane-explorer. | hyperlane-xyz/ | 102 | — | ~185 | Automated safety check: Pass | Unknown | 2 days ago |
| 921 | Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging. | criptogus/ | 288 | — | ~965 | Automated safety check: Pass | CC-BY-SA-4.0 | 3 days ago |
| 922 | 922.Security Scan Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes. | bagofwords1/ | 459 | — | ~1.7k | Automated safety check: Pass | Unknown | yesterday |
| 923 | Comprehensive API security review against OWASP API Security Top 10 (2023). | OWASP/ | 188 | — | ~744 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 924 | 924.Static Security Static security review for Flutter mobile apps and Dart code: hardcoded secrets, insecure storage, unsafe network calls, leaky logs, vulnerable dependencies. | VeryGoodOpenSource/ | 170 | — | ~4.4k | Automated safety check: Notes | MIT | 5 days ago |
| 925 | 925.Program Analysis Use astgrepscan, sourcesinkscan, and smtcheckreachability (mantisprogramanalysis MCP server) to move a candidate toward a proven-reachable finding | deonmenezes/ | 503 | — | ~551 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 926 | Agent skill for security-manager - invoke with $agent-security-manager | ruvnet/ | 74k | 2 repos | ~4.9k | Automated safety check: Pass | MIT | yesterday |
| 927 | Agent skill for v3-security-architect - invoke with $agent-v3-security-architect | ruvnet/ | 74k | 2 repos | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 928 | 928.Replica Build Rebuilds an app screen by screen from the recon map: app shell first, then the core flow as a vertical slice, then every screen with all its states, ticking off the feature matrix as it goes. | Jakeschincariol/ | 1.4k | — | ~928 | Automated safety check: Pass | MIT | 8 days ago |
| 929 | 929.Oob Detection Detect out-of-bounds memory accesses in CPU or GPU code using static interval analysis and runtime assertions/printfs. | ROCm/ | 291 | — | ~1k | Automated safety check: Notes | Unknown | today |
| 930 | A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. | ADScanPro/ | 211 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 931 | 931.Webvuln Web vulnerability hunting playbook. An agent skill from PentesterFlow/agent. | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 932 | Flag only new security issues introduced by this diff. An agent skill from different-ai/openwork. | different-ai/ | 24k | — | ~1.2k | Automated safety check: Pass | Unknown | today |
| 933 | 933.Sherlock OSINT username search across 400+ social networks. An agent skill from Tommy-yw/RunbookHermes. | Tommy-yw/ | 546 | 3 repos | ~1.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 934 | Classify project-used dependency members and record taint sources as rule-authoring units. | seqra/ | 163 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 935 | Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates. | utkusen/ | 1.3k | — | ~6.5k | Automated safety check: Notes | MIT | 6 mo ago |
| 936 | Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast. | trailofbits/ | 7.5k | — | ~5.6k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 937 | Measures timing side channels in cryptographic implementations by running them, using dudect for statistical analysis and Timecop over Valgrind for dynamic tracing. | trailofbits/ | 7.5k | — | ~5.2k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 938 | Measures and interprets what a fuzzing campaign actually reaches, using llvm-cov, lcov, or a fuzzer's own coverage output. | trailofbits/ | 7.5k | — | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 939 | Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang. | trailofbits/ | 7.5k | — | ~6.1k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 940 | 940.Refactor Behaviour-preserving restructuring and cleanup — splitting an oversized module, removing dead code, finished scripts, flags or documents, consolidating duplicates, tightening comments. | guardana/ | 259 | — | ~786 | Automated safety check: Pass | Apache-2.0 | today |
| 941 | Usar para sincronizar la documentación viva del proyecto después de una fase. | 686f6c61/ | 117 | — | ~382 | Automated safety check: Pass | MIT | 1 mo ago |
| 942 | Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition. | bbartling/ | 173 | — | ~2.2k | Automated safety check: Pass | Unknown | today |
| 943 | 943.Malware Analysis A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction… | hypnguyen1209/ | 388 | — | ~2.3k | Automated safety check: Pass | MIT | 13 days ago |
| 944 | 安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust… | telagod/ | 244 | — | ~712 | Automated safety check: Pass | MIT | 2 mo ago |
| 945 | 945.Audit Logging Implement centralized audit logging and SIEM integration. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.5k | Automated safety check: Pass | MIT | yesterday |
| 946 | 946.AWS Iam Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 947 | 947.Firewall Config Configure iptables, nftables, and cloud firewalls. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.2k | Automated safety check: Notes | MIT | yesterday |
| 948 | Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 949 | Automate security workflows and remediation. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~1k | Automated safety check: Pass | MIT | yesterday |
| 950 | 950.Threat Modeling Conduct threat modeling using STRIDE methodology. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~4.3k | Automated safety check: Pass | MIT | yesterday |
| 951 | 951.User Management Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~2.8k | Automated safety check: Notes | MIT | yesterday |
| 952 | 952.Windows Server Administer Windows Server systems. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~2.9k | Automated safety check: Pass | MIT | yesterday |
| 953 | 953.Cve Scan Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart). | softspark/ | 180 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 954 | 954.Public Issue File a low-severity finding as an ordinary public GitHub issue after explicit analyst confirmation. | alpha-omega-security/ | 245 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 955 | Black-box security audit of a DEPLOYED AI agent (not the MCP server behind it) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR… | awarexone/ | 5.3k | — | ~1.1k | Automated safety check: Pass | MIT | 2 days ago |
| 956 | Judge product usability and evidence quality. An agent skill from aryaniyaps/lamina. | aryaniyaps/ | 116 | — | ~432 | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 957 | Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. | github/ | 40k | 1 repo | ~3.4k | Automated safety check: Pass | MIT | 2 days ago |
| 958 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 959 | 959.Lint Run and fix the repository static analysis suite. An agent skill from ethereum/execution-specs. | ethereum/ | 1.2k | — | ~286 | Automated safety check: Pass | CC0-1.0 | today |
| 960 | 960.Re Attribution 威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660