Category
Best security skills, page 43
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 2017 | 2017.Firewall Review Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate… | transilienceai/ | 563 | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 2018 | 2018.Osint Open-source intelligence gathering - company repository enumeration, secret scanning, git history analysis, employee footprint, and code exposure discovery. | transilienceai/ | 563 | — | ~494 | Automated safety check: Notes | MIT | 2 mo ago |
| 2019 | 2019.Reconnaissance Domain assessment and web application mapping - subdomain discovery, port scanning, endpoint enumeration, API discovery, and attack surface analysis. | transilienceai/ | 563 | — | ~1.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 2020 | 2020.Regression Sweep Re-validates every previously-confirmed finding against its current target — detects drift (patched, mitigated, re-introduced). | transilienceai/ | 563 | — | ~1k | Automated safety check: Pass | MIT | 2 mo ago |
| 2021 | 2021.Risk Prioritiser Risk-based prioritisation of confirmed attack paths. An agent skill from transilienceai/communitytools. | transilienceai/ | 563 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 2022 | OSINT-based technology stack identification. An agent skill from transilienceai/communitytools. | transilienceai/ | 563 | — | ~826 | Automated safety check: Pass | MIT | 2 mo ago |
| 2023 | 2023.Ti Ingest Threat-intel signal ingest — converts a CVE + affected-asset + claim payload into a queued engagement-scope row for the validation pipeline. | transilienceai/ | 563 | — | ~676 | Automated safety check: Pass | MIT | 2 mo ago |
| 2024 | 2024.Mobile Code Review Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0. | OWASP/ | 188 | — | ~622 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 2025 | WordPress plugin development with hooks, security, REST API, custom post types. | secondsky/ | 227 | — | ~4.6k | Automated safety check: Pass | MIT | 13 days ago |
| 2026 | 2026.Cloud Security Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails. | borghei/ | 891 | — | ~3.5k | Automated safety check: Pass | MIT | 4 days ago |
| 2027 | A skill your agent uses when handling database errors in Frappe/ERPNext. | Impertio-Studio/ | 189 | — | ~3.9k | Automated safety check: Pass | MIT | 24 days ago |
| 2028 | A skill your agent uses when debugging or preventing errors in Frappe Server Scripts. | Impertio-Studio/ | 189 | — | ~3k | Automated safety check: Pass | MIT | 24 days ago |
| 2029 | 2029.Tool Reference Optimized command-line arguments for all Android RE tools — jadx, baksmali, aapt, apkid, rg. | Paresh-Maheshwari/ | 178 | — | ~1.4k | Automated safety check: Pass | GPL-3.0 | 12 days ago |
| 2030 | 2030.Security Testing Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests… | petrkindlmann/ | 170 | — | ~4.9k | Automated safety check: Pass | MIT | 4 mo ago |
| 2031 | 2031.Smart Contract Audit A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check. | elophanto/ | 106 | — | ~2.7k | Automated safety check: Pass | Unknown | 10 days ago |
| 2032 | 2032.Dx Apexguru Scan Run an ApexGuru performance scan on a Salesforce Apex project via the ApexGuru SFAP Scan API. | forcedotcom/ | 1.1k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2033 | 2033.Sca Security Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to… | hardw00t/ | 105 | — | ~3k | Automated safety check: Pass | No licence | 5 mo ago |
| 2034 | 2034.Security Essentials A skill your agent uses when code touches user input, tokens, redirects, raw SQL, or logging — injection, XSS, atom exhaustion, timing attacks, audit tooling. | j-morgan6/ | 167 | — | ~2k | Automated safety check: Pass | MIT | 3 mo ago |
| 2035 | 2035.Security Hardening Harden code against vulnerabilities. An agent skill from BlackBeltTechnology/pi-agent-dashboard. | BlackBeltTechnology/ | 315 | — | ~4.7k | Automated safety check: Notes | MIT | yesterday |
| 2036 | 2036.Hunt Auth Bypass Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~8.2k | Automated safety check: Pass | MIT | 2 days ago |
| 2037 | 2037.Hunt Cache Poison Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.7k | Automated safety check: Pass | MIT | 2 days ago |
| 2038 | 2038.Hunt Sqli Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.5k | Automated safety check: Pass | MIT | 2 days ago |
| 2039 | 2039.Stack Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally… | guardana/ | 131 | — | ~568 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2040 | Hunt for credential access techniques like LSASS dumping or browser credential theft. | dandye/ | 127 | — | ~1.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2041 | 2041.API Hardening API hardening for Express, FastAPI, and serverless. An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~12k | Automated safety check: Pass | MIT | 7 days ago |
| 2042 | 2042.Secure Auth Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~14k | Automated safety check: Pass | MIT | 7 days ago |
| 2043 | 2043.Security Checklist Pre-deployment security audit organized by OWASP Top 10. An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~8k | Automated safety check: Notes | MIT | 7 days ago |
| 2044 | Social media monitoring, narrative tracking, and OSINT. An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~7.1k | Automated safety check: Pass | MIT | 7 days ago |
| 2045 | 2045.Sast Sqli Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 2046 | Symbolic execution and constraint solving with angr, Z3, Unicorn, and Qiling. | ptn1411/ | 219 | — | ~1.8k | Automated safety check: Notes | No licence | 19 days ago |
| 2047 | 2047.Vulnerability Lookup Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill. | ptn1411/ | 219 | — | ~1.1k | Automated safety check: Pass | No licence | 19 days ago |
| 2048 | 2048.Web Logic Auditor Authorized testing of access-control and business-logic flaws that pattern scanners cannot find — IDOR/BOLA, broken function-level authorization, mass assignment, business-logic abuse, and race… | ptn1411/ | 219 | — | ~1.9k | Automated safety check: Notes | No licence | 19 days ago |
| 2049 | 2049.Purple Team A skill your agent uses when the user wants to automatically harden a guardrail, classifier, content filter, prompt, or API they own by running attack and defense together as a closed loop, not just… | gaasher/ | 174 | — | ~2.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 2050 | 2050.Mcaf Dotnet Codeql Use the open-source CodeQL ecosystem for .NET security analysis. | managedcode/ | 138 | — | ~977 | Automated safety check: Pass | MIT | 4 days ago |
| 2051 | Use the open-source free Roslynator analyzer packages and optional CLI for .NET. | managedcode/ | 138 | — | ~1.2k | Automated safety check: Pass | MIT | 4 days ago |
| 2052 | 2052.LLM Security Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP… | sickn33/ | 47k | 1 repo | ~1.2k | Automated safety check: Warn | MIT | 2 days ago |
| 2053 | 2053.Security Arsenal Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. | sickn33/ | 47k | 1 repo | ~3.2k | Automated safety check: Warn | MIT | 2 days ago |
| 2054 | External recon for software supply-chain attack surface. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~4.3k | Automated safety check: Warn | MIT | 2 days ago |
| 2055 | Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2056 | Detects prompt injection using regex signature matching, heuristic scoring for structural anomalies, and DeBERTa-based transformer classification, flagging direct injections (system-prompt… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2057 | Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2058 | Detect and defend against indirect prompt injection hidden in web pages, documents, and images consumed by an agent, via content extraction (HTML/PDF/OCR), normalization, and scanning with LLM… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2059 | Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2060 | Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2061 | Extracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2062 | Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. | mukul975/ | 34k | — | ~593 | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2063 | Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2064 | Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660