Category
Best security skills, page 3
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back. | samugit83/ | 3k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 98 | 98.Forensify Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 188 | — | ~2.5k | Automated safety check: Notes | Unknown | 11 days ago |
| 99 | Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization. | PentesterFlow/ | 1.4k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 100 | 100.Ctf Malware Provides malware analysis and network traffic techniques for CTF challenges. | ljagiello/ | 3.4k | 1 repo | ~2.1k | Automated safety check: Notes | MIT | 24 days ago |
| 101 | 101.Hol Guard Run HOL Guard scanner and guard operations via uv run hol-guard. | hashgraph-online/ | 815 | — | ~542 | Automated safety check: Pass | Apache-2.0 | today |
| 102 | 102.Security Review Verify that code changes do not introduce OAuth security vulnerabilities. | doorkeeper-gem/ | 5.5k | — | ~1.4k | Automated safety check: Pass | MIT | today |
| 103 | Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and… | activepieces/ | 25k | — | ~2.9k | Automated safety check: Pass | Unknown | today |
| 104 | 104.Owasp Security Reviews code for security vulnerabilities and guides secure implementation using OWASP Top 10:2025, ASVS 5.0, the OWASP Top 10 for LLM Applications (2026), and the OWASP Top 10 for Agentic… | agamm/ | 377 | — | ~3.5k | Automated safety check: Pass | MIT | 13 days ago |
| 105 | 105.Vibe Check Security audit for web apps, especially AI-built ("vibe coded") ones. | benavlabs/ | 118 | — | ~1.1k | Automated safety check: Notes | MIT | 19 days ago |
| 106 | Analyze user-provided reference images and reverse-engineer high-fidelity AI image-generation prompts. | LunarXuan/ | 465 | — | ~678 | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 107 | Command reference for omniroute's audit, logs, policy and telemetry commands: search and export audit trails, manage access policies and review request history for compliance work. | diegosouzapw/ | 74k | 1 repo | ~733 | Automated safety check: Pass | MIT | today |
| 108 | Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. | jeremylongshore/ | 2.8k | 2 repos | ~1.3k | Automated safety check: Notes | MIT | today |
| 109 | 109.Semia Audit an agent skill with Semia inside Codex. An agent skill from berabuddies/Semia. | berabuddies/ | 612 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 110 | 110.Osint Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill. | smixs/ | 140 | — | ~5.5k | Automated safety check: Pass | MIT | 7 mo ago |
| 111 | Reference knowledge for open-source intelligence collection: the collection cycle, source reliability tiers, search query patterns and entity extraction. | RightNow-AI/ | 18k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 112 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 423 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 113 | 113.Best Practices Apply modern web development best practices for security, compatibility, and code quality. | midudev/ | 114 | 3 repos | ~3k | Automated safety check: Pass | MIT | 9 days ago |
| 114 | Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。 | aliyun/ | 148 | 1 repo | ~2.6k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 115 | 115.Flounder Operates Flounder, an autonomous white-hat security auditor. | adshao/ | 519 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | 2 days ago |
| 116 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 117 | Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology. | greatpie/ | 101 | — | ~1.1k | Automated safety check: Pass | No licence | 7 mo ago |
| 118 | 118.Security Check Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. | gocronx-team/ | 808 | — | ~690 | Automated safety check: Pass | MIT | 5 days ago |
| 119 | Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses. | pydantic/ | 8.6k | — | ~852 | Automated safety check: Pass | MIT | today |
| 120 | 120.Bug Hunter Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects. | codexstar69/ | 519 | — | ~5k | Automated safety check: Pass | MIT | 1 mo ago |
| 121 | 121.Adversarial QA Repro-first QA for Inkline — minimal .ink.tsx reproductions, the visual-parity and cross-target harnesses, fuzz targets, and how to audit teammates' claims. | inkline/ | 1.5k | — | ~1.2k | Automated safety check: Pass | No licence | 26 days ago |
| 122 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | today |
| 123 | Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. | EpicenterHQ/ | 4.8k | — | ~896 | Automated safety check: Pass | Unknown | today |
| 124 | Verify or select a SageMaker execution role before creating models, endpoints, or training jobs. | waybarrios/ | 533 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 125 | Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written. | OTRF/ | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | 8 mo ago |
| 126 | 126.Vuln Research 安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research. | tanweai/ | 185 | — | ~847 | Automated safety check: Pass | No licence | 8 mo ago |
| 127 | 127.Skillward Audit Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner. | Fangcun-AI/ | 143 | — | ~2.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 128 | 128.LLM Sast Scanner General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. | SunWeb3Sec/ | 286 | — | ~6.2k | Automated safety check: Pass | No licence | 1 mo ago |
| 129 | Scans eight warning signs behind a stock tip from a friend, chat group or online teacher and returns a four-level risk rating with evidence. | wbh604/ | 7.1k | — | ~450 | Automated safety check: Pass | MIT | 1 mo ago |
| 130 | Django access control and IDOR security review. An agent skill from getsentry/skills. | getsentry/ | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | 5 days ago |
| 131 | 131.Game Recon Figure out how a specific installed game can be modded, before writing any mod code. | rehan-remade/ | 5.3k | — | ~1k | Automated safety check: Pass | MIT | today |
| 132 | Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 133 | 133.Write Cve Rule Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE. | evdenis/ | 138 | — | ~2.5k | Automated safety check: Pass | GPL-3.0 | 6 days ago |
| 134 | Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection. | open-edge-platform/ | 6.2k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 135 | 135.Skylos Security Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 136 | Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. | PrefectHQ/ | 28k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 137 | Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files. | HarnessMD/ | 8.6k | — | ~350 | Automated safety check: Notes | MIT | today |
| 138 | 138.Run Assert Eval Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT. | responsibleai/ | 328 | — | ~11k | Automated safety check: Notes | MIT | yesterday |
| 139 | 139.Rsigma Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. | timescale/ | 159 | — | ~1.2k | Automated safety check: Pass | MIT | 2 days ago |
| 140 | 140.Nmap Professional network reconnaissance and port scanning using nmap. | BrownFineSecurity/ | 858 | 2 repos | ~3.8k | Automated safety check: Notes | MIT | 4 mo ago |
| 141 | Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in… | samugit83/ | 3k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 142 | 142.Solidity Auditor Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge. | Gabson0x/ | 443 | — | ~3.7k | Automated safety check: Pass | No licence | 21 days ago |
| 143 | Reverse-engineer missing or incomplete OpenFastTrace system requirements and arc42-style design documentation from a project's user guide, existing documentation, tests, and code. | itsallcode/ | 198 | — | ~2.9k | Automated safety check: Pass | GPL-3.0 | today |
| 144 | 144.Vulnhunter Run Unattended VulnHunter operator. An agent skill from nealbridges/VulnHunter. | nealbridges/ | 646 | — | ~711 | Automated safety check: Pass | Apache-2.0 | today |
Explore related skills
Topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,229
- Frontend & Design5,834
- Backend & APIs7,161
- Testing & QA5,085
- DevOps & Cloud5,962
- Databases2,339
- Data & Analytics3,647
- AI & LLM Engineering5,096
- Agent Workflows8,311
- Documents & Office4,273
- Writing & Content3,731
- Marketing & SEO3,910
- Sales & Support1,815
- Research & Science6,075
- Productivity & Automation4,016
- Business, Finance & HR3,836
- Legal & Compliance1,617
- Education1,065
- Media & Creative4,286
- Mobile2,765
- Product & Project Management2,360
- Knowledge Management1,433
- Game Development1,673