Category
Best security skills, page 47
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 2209 | 2209.Hunt macOS macOS attack hunting - foothold to root/persistence on a macOS host. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 2210 | 2210.Hunt MCP MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. | Encod3d-Sec/ | 329 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 2211 | 2211.Hunt Smuggling HTTP request smuggling / desync hunting - CL.TE, TE.CL, TE.TE, CL.0, and HTTP/2 downgrade. | Encod3d-Sec/ | 329 | — | ~1.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 2212 | 2212.Hunt Sqli SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection. | Encod3d-Sec/ | 329 | — | ~3.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 2213 | 2213.Hunt Ssrf SSRF hunting - OOB-mandatory methodology. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 2214 | 2214.Hunt Upload File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS. | Encod3d-Sec/ | 329 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 2215 | 2215.Hunt Xss XSS hunting - reflected, stored, DOM-based. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 2216 | 2216.Metasploit Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup… | Encod3d-Sec/ | 329 | — | ~1k | Automated safety check: Pass | MIT | 1 mo ago |
| 2217 | 2217.Triage Finding validation gate - 7-Question triage adapted for FIND schema. | Encod3d-Sec/ | 329 | — | ~848 | Automated safety check: Pass | MIT | 1 mo ago |
| 2218 | 2218.Wiki Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status. | Encod3d-Sec/ | 329 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 2219 | Test LLM-integrated applications against known prompt injection techniques, evasion methods, and attack intents using the Arcanum PI Taxonomy. | OWASP/ | 188 | — | ~758 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 2220 | 2220.Sca Audit Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook. | OWASP/ | 188 | — | ~494 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 2221 | Tile two-dimensional torch.gather(dim=1) kernels for Triton-Ascend so the logical grid stays near the physical vector-core count while each program handles multiple batch rows and loops over K. | Krusty84/ | 106 | — | ~583 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 2222 | A skill your agent uses when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt, querying docaaesgcmcap for… | NVIDIA/ | 3.6k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 2223 | A skill your agent uses when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for… | NVIDIA/ | 3.6k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 2224 | A skill your agent uses when the user is doing hands-on DOCA SHA programming — offloading SHA-1, SHA-256, or SHA-512 hashing onto a BlueField DPU or ConnectX accelerator, picking between one-shot… | NVIDIA/ | 3.6k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 2225 | 2225.Azure Key Vault Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. | Kilo-Org/ | 190 | 1 repo | ~1.9k | Automated safety check: Pass | MIT | 13 days ago |
| 2226 | 2226.Web Dependency Run Weekly. An agent skill from markfulton/ai-employees. | markfulton/ | 543 | — | ~14k | Automated safety check: Pass | MIT | yesterday |
| 2227 | 2227.Skill Audit Pre-install security scanner for AI agent skills. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Warn | MIT | 2 days ago |
| 2228 | 2228.Threat Modeling Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. | hardw00t/ | 105 | — | ~2.6k | Automated safety check: Pass | No licence | 5 mo ago |
| 2229 | Systematically map and remove malware, backdoors, and attacker persistence mechanisms (registry Run keys, scheduled tasks, WMI subscriptions, services, cron/init.d) from infected Windows and Linux… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2230 | Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2231 | 2231.Security Fuzzing Essential fuzzing payloads: SQL injection, command injection, special characters. | Ch1nfo/ | 114 | 1 repo | ~329 | Automated safety check: Pass | MIT | 20 days ago |
| 2232 | 2232.Security Audit Periodic security sweep of Atlas in four areas (MCP and CLI, the Tauri desktop shell, the web renderer and connectors, the supply chain and CI) that follows untrusted input to what it can reach… | wlsdks/ | 142 | — | ~182 | Automated safety check: Pass | MIT | yesterday |
| 2233 | 2233.Dependency Auditor Audit project dependencies for vulnerabilities, license risks, upgrade planning, and ecosystem health across multiple languages. | aAAaqwq/ | 105 | 1 repo | ~3.1k | Automated safety check: Pass | MIT | 3 days ago |
| 2234 | 2234.Ghost Scan Code Ghost Security - SAST code scanner. An agent skill from aAAaqwq/AGI-Super-Team. | aAAaqwq/ | 105 | 1 repo | ~1.4k | Automated safety check: Notes | Apache-2.0 | 3 days ago |
| 2235 | 2235.Java Audit Skill AI驱动的Java代码安全审计技能,实现系统化、高覆盖率的漏洞挖掘。使用场景: (1) 审计Java/Kotlin项目寻找安全漏洞(0day挖掘、代码审计、安全评估) (2) 企业级代码库的安全审计(支持大型项目) (3) 需要高质量、低幻觉率的安全审计报告 (4) CI/CD集成的前期漏洞发现 触发关键词:Java审计、代码审计、安全审计、漏洞挖掘、0day、安全评估、Java… | LeoYeAI/ | 2.2k | — | ~3.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 2236 | A skill your agent uses when assessing code quality hygiene — TypeScript strictness, lint violations, dead code, and duplication. | mizchi/ | 360 | — | ~717 | Automated safety check: Pass | No licence | 9 days ago |
| 2237 | 2237.Hackerone Report Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes. | forefy/ | 152 | — | ~2.1k | Automated safety check: Pass | MIT | 6 days ago |
| 2238 | 2238.Pre Bounty Map a bug-bounty scope and rank targets by payout, crowding, and freshness. | forefy/ | 152 | — | ~2.1k | Automated safety check: Pass | MIT | 6 days ago |
| 2239 | Audit an LLM application for indirect prompt injection - compose objective x technique payloads, deliver them through the channels the agent actually reads, and prove impact with an out-of-band… | forefy/ | 152 | — | ~2.3k | Automated safety check: Pass | MIT | 6 days ago |
| 2240 | 2240.Harness Feedback A skill your agent uses when an agent says a test, VM, proof, evaluator, or release gate is overloaded, too strict, blocking staging, or causing false positives; split checks by profile, measure the… | AnastasiyaW/ | 154 | — | ~1k | Automated safety check: Pass | MIT | 2 days ago |
| 2241 | 2241.Testing Strategy A skill your agent uses when planning or reviewing tests for a code change, choosing between unit, focused regression, integration, contract, end-to-end, performance, security, property-based, or… | AnastasiyaW/ | 154 | — | ~2k | Automated safety check: Pass | MIT | 2 days ago |
| 2242 | Write a self-contained OpenTaint engine-issue report from an analysis diagnosis or a full-scan failure. | seqra/ | 163 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 2243 | Check for outdated or vulnerable dependencies. An agent skill from enuno/unifi-mcp-server. | enuno/ | 282 | — | ~206 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2244 | Harden OpenClaw self-hosted environments with baseline host controls, auth tightening, secret handling, network segmentation, and safe update/rollback workflows. | BagelHole/ | 1.2k | — | ~1k | Automated safety check: Notes | MIT | 4 mo ago |
| 2245 | 2245.Sast Ssrf Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to destinations in parallel… | utkusen/ | 1.3k | — | ~6.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 2246 | 2246.Sast Ssti Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user… | utkusen/ | 1.3k | — | ~7.5k | Automated safety check: Pass | MIT | 6 mo ago |
| 2247 | 2247.Sast Xss Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 2248 | 2248.Sast Xxe Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 2249 | 2249.PR Council Review Multi-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review). | ffroliva/ | 269 | — | ~12k | Automated safety check: Pass | MIT | 3 days ago |
| 2250 | 2250.Cryptography Cryptanalysis techniques — lattice attacks, padding oracles, weak-RNG exploitation, signature forgery, secret-sharing recovery. | transilienceai/ | 563 | — | ~465 | Automated safety check: Pass | MIT | 2 mo ago |
| 2251 | 2251.Hackthebox HackTheBox platform operations and automations to solve challenges, machines and capture the flags hacking competitions | transilienceai/ | 563 | — | ~697 | Automated safety check: Pass | MIT | 2 mo ago |
| 2252 | 2252.Infrastructure Network infrastructure testing - port scanning, DNS attacks, MITM, VLAN hopping, IPv6, SMB/NetBIOS, sniffing, and DoS assessment. | transilienceai/ | 563 | — | ~768 | Automated safety check: Pass | MIT | 2 mo ago |
| 2253 | 2253.Mobile Security Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC… | transilienceai/ | 563 | — | ~2.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 2254 | 2254.Patt Fetcher Fetches and extracts payloads from PayloadsAllTheThings on demand. | transilienceai/ | 563 | — | ~1.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 2255 | 2255.Server Side Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection. | transilienceai/ | 563 | — | ~484 | Automated safety check: Pass | MIT | 2 mo ago |
| 2256 | 2256.Skill Prune Identify and remove negative-ROI skill content — orphan files, never-read entries, duplicates, content reintroducing challenge-specific lore. | transilienceai/ | 563 | — | ~715 | Automated safety check: Pass | MIT | 2 mo ago |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660