Category
Best security skills, page 22
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1009 | 1009.Robotics Security Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection. | arpitg1304/ | 369 | — | ~7.8k | Automated safety check: Warn | Apache-2.0 | 2 mo ago |
| 1010 | 1010.Generate Poc Reproduce a true-positive finding against the running application. | seqra/ | 163 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 1011 | 1011.Sast JWT Detect insecure JWT (JSON Web Token) implementations in a codebase using a two-phase approach: first map all JWT issuance and verification sites to understand the token lifecycle and signing… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 1012 | 1012.Site Check Check the landing page and the generated documentation site (site/, guardana.dev) in a real browser — confirm a page renders after a docs change, review it at phone width, read the console and… | guardana/ | 259 | — | ~679 | Automated safety check: Pass | Apache-2.0 | today |
| 1013 | 1013.Corpus Sweep Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run). | nubjs/ | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 1014 | 1014.Malware Analyst MASTER MALWARE ANALYSIS: Threat Intelligence, Phishing Detection. | Dokhacgiakhoa/ | 508 | — | ~419 | Automated safety check: Notes | Unknown | 4 mo ago |
| 1015 | Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration. | github/ | 5.4k | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 1016 | Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence. | github/ | 5.4k | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 1017 | 1017.Pytm Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification. | AgentSecOps/ | 220 | 2 repos | ~4.4k | Automated safety check: Notes | Unknown | 5 mo ago |
| 1018 | 1018.Sca Trivy Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license… | AgentSecOps/ | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 1019 | 1019.Wargame Multi-turn adversary simulation. An agent skill from NovusEdge/palpatine. | NovusEdge/ | 110 | — | ~1.1k | Automated safety check: Pass | Unknown | 27 days ago |
| 1020 | Assess game build, launcher, update, distribution, mod, plugin, dependency, signing, provenance, and recovery trust. | gmh5225/ | 3.6k | — | ~227 | Automated safety check: Pass | MIT | today |
| 1021 | 1021.Security Scan Deep security scanning for .NET applications across 6 layers: vulnerable packages, secrets detection, OWASP code patterns, auth configuration, CORS policy, and data protection. | codewithmukesh/ | 756 | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 1022 | Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps. | google/ | 21k | 1 repo | ~4.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 1023 | Expert guidance for proactive threat hunting in Google SecOps. | google/ | 21k | 1 repo | ~2.6k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 1024 | Expert guidance for deep security incident and entity investigations in Google SecOps. | google/ | 21k | 1 repo | ~4.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 1025 | Expert guidance for security alert triage in Google SecOps. An agent skill from google/skills. | google/ | 21k | 1 repo | ~3.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 1026 | 1026.Hunt RAG Vector Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from… | elementalsouls/ | 4.8k | — | ~2.6k | Automated safety check: Pass | MIT | 2 days ago |
| 1027 | 1027.Security Audit 全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -… | staruhub/ | 728 | — | ~1.3k | Automated safety check: Notes | MIT | 1 mo ago |
| 1028 | Protocol Reverse Engineering workflow skill. An agent skill from diegosouzapw/awesome-omni-skills. | diegosouzapw/ | 159 | — | ~3.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 1029 | 1029.Domain Intel Passive domain reconnaissance using Python stdlib. An agent skill from Tommy-yw/RunbookHermes. | Tommy-yw/ | 546 | 1 repo | ~1.1k | Automated safety check: Pass | MIT | 4 mo ago |
| 1030 | KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. | SnailSploit/ | 7.4k | — | ~1.1k | Automated safety check: Notes | MIT | 21 days ago |
| 1031 | 1031.Detection Sigma Generic detection rule creation and management using Sigma, the universal SIEM rule format. | AgentSecOps/ | 220 | 1 repo | ~4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 1032 | 1032.Forensics Osquery SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases. | AgentSecOps/ | 220 | 1 repo | ~4.9k | Automated safety check: Notes | Unknown | 5 mo ago |
| 1033 | 1033.Ir Velociraptor Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale. | AgentSecOps/ | 220 | 1 repo | ~3.1k | Automated safety check: Pass | Unknown | 5 mo ago |
| 1034 | 1034.Recon Nmap Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection. | AgentSecOps/ | 220 | 1 repo | ~4.6k | Automated safety check: Notes | Unknown | 5 mo ago |
| 1035 | 1035.Reviewdog Automated code review and security linting integration for CI/CD pipelines using reviewdog. | AgentSecOps/ | 220 | 1 repo | ~3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 1036 | 1036.Sast Bandit Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. | AgentSecOps/ | 220 | 1 repo | ~2.6k | Automated safety check: Pass | Unknown | 5 mo ago |
| 1037 | 1037.Sbom Syft Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives. | AgentSecOps/ | 220 | 1 repo | ~3.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 1038 | 1038.Webapp Nikto Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. | AgentSecOps/ | 220 | 1 repo | ~2.8k | Automated safety check: Pass | Unknown | 5 mo ago |
| 1039 | 1039.Webapp Sqlmap Automated SQL injection detection and exploitation tool for web application security testing. | AgentSecOps/ | 220 | 1 repo | ~3.2k | Automated safety check: Pass | Unknown | 5 mo ago |
| 1040 | A skill your agent uses when a user asks what the EU Cyber Resilience Act (CRA) means for their product, whether and when they must report a vulnerability or incident, or what a specific CVE… | davila7/ | 33k | 1 repo | ~4.5k | Automated safety check: Pass | CC-BY-4.0 | yesterday |
| 1041 | A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU… | davila7/ | 33k | 1 repo | ~4.7k | Automated safety check: Pass | CC-BY-4.0 | yesterday |
| 1042 | 1042.Cmmc Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). | Sushegaad/ | 946 | 1 repo | ~5.5k | Automated safety check: Pass | MIT | yesterday |
| 1043 | 1043.Dora Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. | Sushegaad/ | 946 | 1 repo | ~6.9k | Automated safety check: Pass | MIT | yesterday |
| 1044 | 1044.Web Ssti Server-Side Template Injection detection→engine-fingerprint→RCE for web apps. | s0ld13rr/ | 828 | — | ~621 | Automated safety check: Pass | MIT | 9 days ago |
| 1045 | 1045.007 Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project. | sickn33/ | 47k | 2 repos | ~410 | Automated safety check: Pass | MIT | 2 days ago |
| 1046 | Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. | sickn33/ | 47k | 2 repos | ~2.1k | Automated safety check: Notes | MIT | 2 days ago |
| 1047 | Analyze cryptographic code to detect operations that leak secret data through execution timing variations. | sickn33/ | 47k | 2 repos | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 1048 | Secure the AI model supply chain with artifact signing, provenance attestation, SBOM workflows, dependency controls, and trusted model promotion. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | 2 days ago |
| 1049 | 1049.Vibers Code Review Human review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service. | sickn33/ | 47k | 2 repos | ~1.1k | Automated safety check: Pass | MIT | 2 days ago |
| 1050 | 6 production-ready AI engineering workflows: prompt evaluation (8-dimension scoring), context budget planning, RAG pipeline design, agent security audit (65-point checklist), eval harness building… | sickn33/ | 47k | 2 repos | ~1.9k | Automated safety check: Pass | MIT | 2 days ago |
| 1051 | 1051.Report Generator Generates professional security audit reports from findings. | alt-research2/ | 104 | — | ~1k | Automated safety check: Pass | Unknown | 4 mo ago |
| 1052 | AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching… | github/ | 40k | 1 repo | ~2.3k | Automated safety check: Notes | MIT | 2 days ago |
| 1053 | Full STRIDE-A threat model analysis and incremental update skill for repositories and systems. | github/ | 40k | 1 repo | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 1054 | 1054.Golang Security Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory… | unxed/ | 243 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | yesterday |
| 1055 | 1055.Offensive Fuzzing Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies… | SnailSploit/ | 7.4k | — | ~3k | Automated safety check: Warn | MIT | 21 days ago |
| 1056 | Generate or refresh a STRIDE-based threat model for the current repository using Bug Hunter-native artifacts. | codexstar69/ | 520 | — | ~408 | Automated safety check: Pass | MIT | 1 mo ago |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660