Category
Best security skills, page 21
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 961 | 961.Cybersecurity Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e… | ohmyjahh/ | 277 | — | ~895 | Automated safety check: Pass | MIT | 12 days ago |
| 962 | Scan package manifests and lockfiles for outdated and vulnerable dependencies. | cobusgreyling/ | 11k | — | ~531 | Automated safety check: Pass | MIT | today |
| 963 | 963.Dast Zap Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection. | AgentSecOps/ | 220 | 1 repo | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 964 | Systematically reviews code for SQL injection, XSS, SSRF, broken access control, cryptographic failures, and other common OWASP Top 10 vulnerabilities, providing vulnerable code examples and… | zebbern/ | 4.7k | — | ~4.7k | Automated safety check: Pass | MIT | yesterday |
| 965 | 965.Crypto Expert Cryptography expert for TLS, symmetric/asymmetric encryption, hashing, and key management | RightNow-AI/ | 18k | — | ~959 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 966 | 966.Security Audit Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology | RightNow-AI/ | 18k | — | ~858 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 967 | 967.Deps Vet Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner. | oliver-kriska/ | 565 | — | ~1.5k | Automated safety check: Pass | MIT | 6 days ago |
| 968 | Deep reentrancy vulnerability analysis for Solidity contracts. | alt-research2/ | 104 | — | ~1.8k | Automated safety check: Pass | Unknown | 4 mo ago |
| 969 | 969.SQL Code Review Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle). | totvs/ | 143 | — | ~3.5k | Automated safety check: Pass | MIT | 6 days ago |
| 970 | S3 resiliency, security, and data protection review. An agent skill from aws/tools-for-devops-agent. | aws/ | 103 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 971 | Run competitive research like an intelligence agency: eight collection disciplines (OSINT to MASINT), signal-to-inference chains, and fusion. | deanpeters/ | 7.2k | — | ~6.6k | Automated safety check: Pass | Unknown | 1 mo ago |
| 972 | Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. | trailofbits/ | 7.5k | — | ~996 | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 973 | Performs comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes. | trailofbits/ | 7.5k | — | ~11k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 974 | Query token security audit to detect scams, honeypots, and malicious contracts before trading. | npc-live/ | 156 | 1 repo | ~1.6k | Automated safety check: Pass | No licence | 3 mo ago |
| 975 | Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies… | eser/ | 128 | — | ~598 | Automated safety check: Pass | Unknown | 7 days ago |
| 976 | 976.Security Review Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. | affaan-m/ | 277k | 1 repo | ~3.2k | Automated safety check: Notes | MIT | today |
| 977 | 977.PR Audit Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation… | akitaonrails/ | 216 | — | ~4.8k | Automated safety check: Pass | No licence | 18 days ago |
| 978 | 978.LLM App Security Secure LLM-powered applications with input validation, output controls, tenant isolation, and abuse prevention. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 979 | Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 980 | 980.Get Caller Tool to get the caller of a function in the codebase. An agent skill from opensage-agent/opensage-adk. | opensage-agent/ | 127 | — | ~208 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 981 | 981.Audit Reentrancy Analyze user callbacks for re-entrancy defects (deadlock, corruption) | ben-manes/ | 18k | — | ~643 | Automated safety check: Pass | Apache-2.0 | today |
| 982 | Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export. | GRCEngClub/ | 419 | — | ~2.4k | Automated safety check: Notes | Unknown | 7 days ago |
| 983 | 983.Web Recon Web content discovery and technology fingerprinting using gobuster, ffuf, feroxbuster, katana, httpx, and wafw00f | CommonHuman-Lab/ | 157 | — | ~907 | Automated safety check: Pass | Unknown | 2 days ago |
| 984 | For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the… | lyonzin/ | 292 | — | ~2.3k | Automated safety check: Pass | MIT | 2 days ago |
| 985 | Generates edge case, failure mode, and spec-driven test cases. | ash1794/ | 163 | — | ~1.4k | Automated safety check: Pass | MIT | 4 days ago |
| 986 | A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit. | ccashwell/ | 131 | — | ~1.6k | Automated safety check: Pass | MIT | 11 days ago |
| 987 | Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 988 | [omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds. | rlaope/ | 3.2k | — | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 989 | 989.Distribution Constructs distributor accounts, inventory binds, commission or markup, and browse-and-quote, including the ready-to-sell scene. | openqa-cn/ | 152 | — | ~477 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 990 | Security review: (1) vet an untrusted SKILL.md or .mcp.json BEFORE installing it — the injection/exfiltration scanner; CRITICAL blocks the install; (2) audit code on an untrusted-input path (a… | redhat-et/ | 2.4k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 991 | 991.Finding Triage Triage a single security finding — from a scanner, audit, advisory, or report — to a defensible disposition with a mitigation plan, false-positive justification, or accepted-risk writeup. | briiirussell/ | 413 | — | ~3.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 992 | PHP Web 源码任意文件写入审计工具。识别用户可控数据进入写入 Sink 的链路,追踪任意落点写入/路径穿越到 write,并评估写入后的可执行性(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~1.2k | Automated safety check: Pass | No licence | 6 mo ago |
| 993 | 993.Proactive Agent Transform AI agents from task-followers into proactive partners. | LeoYeAI/ | 2.2k | — | ~4.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 994 | 994.Prompt Guard Meta's 86M prompt injection and jailbreak detector. An agent skill from Orchestra-Research/AI-Research-SKILLs. | Orchestra-Research/ | 13k | 1 repo | ~2.4k | Automated safety check: Warn | MIT | 3 mo ago |
| 995 | 995.Defense In Depth A skill your agent uses when invalid data causes failures deep in execution - validates at every layer data passes through to make bugs structurally impossible rather than temporarily fixed | ed3dai/ | 250 | — | ~1.2k | Automated safety check: Pass | No licence | 1 mo ago |
| 996 | Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting. | bitwarden/ | 155 | — | ~1.8k | Automated safety check: Pass | Unknown | 2 days ago |
| 997 | Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved… | digoal/ | 8.6k | — | ~2.2k | Automated safety check: Pass | GPL-2.0 | 2 days ago |
| 998 | 998.Hunt Apt Hunt for a specific APT/threat actor in your environment. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 999 | Perform a comprehensive security audit of all project files in the current working directory. | LaravelDaily/ | 136 | — | ~1.9k | Automated safety check: Notes | No licence | 5 mo ago |
| 1000 | Hunts for the other instances of a bug already found — the variants of one root cause across a codebase. | trailofbits/ | 7.5k | — | ~967 | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 1001 | 1001.Security Express Review Express.js security audit patterns for middleware and routes. | IgorWarzocha/ | 122 | — | ~1.8k | Automated safety check: Pass | No licence | 8 mo ago |
| 1002 | 1002.Code Review Security Security-focused code review mapped to OWASP Top 10 and ASVS. | OWASP/ | 188 | — | ~549 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 1003 | 1003.Create Threat Model Analyze a codebase and produce a structured threat model at .turbo/threat-model.md covering assets, trust boundaries, attack surfaces with existing mitigations, attacker stories, and calibrated… | tobihagemann/ | 408 | — | ~2.5k | Automated safety check: Pass | MIT | 2 days ago |
| 1004 | Autonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations | davila7/ | 33k | 7 repos | ~3.9k | Automated safety check: Warn | MIT | today |
| 1005 | 1005.Container Security Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and… | hardw00t/ | 105 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 1006 | Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks. | github/ | 40k | 1 repo | ~3k | Automated safety check: Pass | MIT | 2 days ago |
| 1007 | Verify supply chain integrity for AI agent plugins, tools, and dependencies. | github/ | 40k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | 2 days ago |
| 1008 | Quality standards for Salesforce Lightning Web Components (LWC), Aura components, and Visualforce pages. | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660