Category
Best security skills, page 5
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 193 | 193.Chaitin CLI A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability… | chaitin/ | 114 | — | ~15k | Automated safety check: Notes | GPL-3.0 | 10 days ago |
| 194 | 194.Setup Install or initialize HOL Guard local runtime protection for Claude Code. | hashgraph-online/ | 815 | — | ~443 | Automated safety check: Pass | Apache-2.0 | today |
| 195 | 195.Bom Audit Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk… | cdxgen/ | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 196 | 196.Security Audit A skill your agent uses to perform a security-focused audit of the codebase to identify vulnerabilities, sandbox escapes, and logic flaws. | ziggy42/ | 439 | — | ~924 | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 197 | 197.Lfd Design Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD). | elvisun/ | 176 | — | ~2.9k | Automated safety check: Notes | MIT | 3 mo ago |
| 198 | 198.Code Review Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles. | MichaelGrafnetter/ | 2k | — | ~4k | Automated safety check: Pass | MIT | 27 days ago |
| 199 | PHP Web 归档解压(Zip Slip/路径穿越)审计工具。识别解压条目名如何与目标目录拼接、是否存在 base dir 约束缺失,输出可利用性分级、可观测 PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~883 | Automated safety check: Pass | No licence | 6 mo ago |
| 200 | Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk. | bodadotsh/ | 859 | — | ~1k | Automated safety check: Warn | MIT | 8 days ago |
| 201 | Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged… | samugit83/ | 3k | — | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 202 | Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py. | DimaReverse/ | 132 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 203 | Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks. | seqra/ | 162 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 204 | 204.Packslip Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and… | jdx/ | 130 | — | ~2.9k | Automated safety check: Pass | MIT | 2 days ago |
| 205 | 205.Vex Authoring Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM. | relizaio/ | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | today |
| 206 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 207 | 207.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 | today |
| 208 | Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks. | telagod/ | 243 | — | ~552 | Automated safety check: Notes | MIT | 2 mo ago |
| 209 | 209.Security Review Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. | ktnyt/ | 675 | — | ~565 | Automated safety check: Pass | MIT | 7 mo ago |
| 210 | 210.Gates GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework. | Nebulock-Inc/ | 385 | — | ~12k | Automated safety check: Pass | MIT | 6 days ago |
| 211 | 211.Agent Creator Creates structured agent definitions using the 7-component format grounded in persona science (the alignment-accuracy tradeoff), vocabulary routing, and the MAST failure taxonomy + Forge watchlist. | jdforsythe/ | 151 | — | ~4.5k | Automated safety check: Pass | MIT | 3 mo ago |
| 212 | Run a security scan on the kedro-plugins codebase or a pull request. | kedro-org/ | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 213 | Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results. | block/ | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 214 | 214.Oss Forensics Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. | Tommy-yw/ | 546 | 3 repos | ~5k | Automated safety check: Pass | MIT | 4 mo ago |
| 215 | A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR. | DataDog/ | 417 | — | ~2.6k | Automated safety check: Pass | Unknown | today |
| 216 | Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers. | CyberStrategyInstitute/ | 146 | — | ~1.2k | Automated safety check: Pass | Unknown | yesterday |
| 217 | 217.Gmgn Token Research any crypto or meme token by address — real-time price, market cap, liquidity, holder list, trader list, top Smart Money and KOL positions, security audit (honeypot, rug pull risk, dev… | GMGNAI/ | 604 | 1 repo | ~10k | Automated safety check: Notes | MIT | 10 days ago |
| 218 | 218.Clawd Control Monitor and manage your Clawdbot agent fleet from within an agent. | Temaki-AI/ | 115 | — | ~1.2k | Automated safety check: Pass | MIT | 7 mo ago |
| 219 | Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to. | arandu-io/ | 281 | — | ~1.2k | Automated safety check: Pass | MIT | 4 days ago |
| 220 | Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation. | ptn1411/ | 219 | — | ~917 | Automated safety check: Pass | No licence | 17 days ago |
| 221 | A skill your agent uses when scanning code for security vulnerabilities. | tanviet12/ | 287 | — | ~6.8k | Automated safety check: Notes | MIT | 10 days ago |
| 222 | 222.Kesekit Check Ko KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT. | cdppcorp/ | 361 | — | ~956 | Automated safety check: Pass | MIT | 6 mo ago |
| 223 | Connect to a Windows 98 game or app that a person is running in their browser on wine-assembly, then see its screen and play it with mouse and keyboard. | vgrichina/ | 113 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 224 | 224.Aisafetyhot Read AI Safety HOT daily digests, search recent AI safety research and incidents, and follow current hot topics. | wuyoscar/ | 224 | — | ~774 | Automated safety check: Pass | Unknown | today |
| 225 | Routes a whole-product security request to the right Strix test per asset, source code, a live app, an API or a CI pipeline, then turns results into one ranked remediation plan. | usestrix/ | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 226 | 226.Semia Audit an agent skill with Semia Skill Behavior Mapping. An agent skill from berabuddies/Semia. | berabuddies/ | 612 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 227 | Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work. | LUC4N3X/ | 531 | — | ~2k | Automated safety check: Pass | GPL-3.0 | today |
| 228 | 228.Security Updates Check and apply security updates across the photofield project (api/Go, ui/npm, docs/npm, e2e/npm). | SmilyOrg/ | 608 | — | ~808 | Automated safety check: Pass | MIT | 1 mo ago |
| 229 | 229.Censorship Audit Audit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would. | hedioum/ | 139 | — | ~4.9k | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 230 | Enable, configure, and query Elasticsearch security audit logs. | aspectrr/ | 405 | — | ~1.7k | Automated safety check: Pass | MIT | 5 mo ago |
| 231 | 231.Security Audit Security best practices, vulnerability review, and full security audits for LLM Gateway. | theopenco/ | 1.7k | — | ~1.8k | Automated safety check: Pass | Unknown | yesterday |
| 232 | CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines. | context-labs/ | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT | 3 days ago |
| 233 | 233.Wp Phpstan A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and… | Automattic/ | 211 | 1 repo | ~1k | Automated safety check: Pass | No licence | 8 mo ago |
| 234 | 234.Attack Flow Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports. | wiz-sec-public/ | 182 | — | ~3.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 235 | Render app UI on the Gradle managed device and look at the result without spending a fortune in vision tokens. | parawanderer/ | 418 | — | ~1.4k | Automated safety check: Pass | MIT | 19 days ago |
| 236 | Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects. | microsoft/ | 22k | — | ~737 | Automated safety check: Pass | MIT | today |
| 237 | Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING… | MidnightBSD/ | 114 | — | ~2.2k | Automated safety check: Pass | Unknown | 4 days ago |
| 238 | Security-focused code review checklist and automated scanning patterns. | nicepkg/ | 192 | 1 repo | ~3.9k | Automated safety check: Pass | MIT | 7 mo ago |
| 239 | Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn. | Encod3d-Sec/ | 329 | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 240 | Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs. | eclipse-ankaios/ | 125 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
Explore related skills
Topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,229
- Frontend & Design5,834
- Backend & APIs7,161
- Testing & QA5,085
- DevOps & Cloud5,962
- Databases2,339
- Data & Analytics3,647
- AI & LLM Engineering5,096
- Agent Workflows8,311
- Documents & Office4,273
- Writing & Content3,731
- Marketing & SEO3,910
- Sales & Support1,815
- Research & Science6,075
- Productivity & Automation4,016
- Business, Finance & HR3,836
- Legal & Compliance1,617
- Education1,065
- Media & Creative4,286
- Mobile2,765
- Product & Project Management2,360
- Knowledge Management1,433
- Game Development1,673