Category
Best security skills, page 52
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 2449 | Normalize and compare authorized fraud-control observations from local evidence, highlighting decision drift, coverage gaps, and conflicting outcomes without making a fraud or vulnerability verdict. | cyberful/ | 135 | — | ~649 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2450 | Parse bounded classic PCAP files offline into deterministic capture metadata, packet-length and timestamp summaries, link and network protocol counts, truncation indicators, and source digests… | cyberful/ | 135 | — | ~590 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2451 | Model fraud and abuse threats across actors, account states, value flows, controls, and monetization paths. | cyberful/ | 135 | — | ~716 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2452 | Assess the security of a smart-contract system across protocol economics, trust roles, upgrade and governance paths, oracle and bridge dependencies, deployment state, and off-chain operators. | cyberful/ | 135 | — | ~651 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2453 | Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures. | cyberful/ | 135 | — | ~637 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2454 | Audit extracted embedded firmware for boot and update trust, credential and secret handling, service exposure, privilege boundaries, parsers, persistence, cryptography, hardening, recovery, and… | cyberful/ | 135 | — | ~644 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2455 | Audit security logging and telemetry from event creation through transport, storage, access, correlation, retention, and response use. | cyberful/ | 135 | — | ~597 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2456 | Test browser capability transfer across postMessage, opener, frame, portal, worker, service-worker, BroadcastChannel, MessagePort, and extension messaging boundaries. | cyberful/ | 135 | — | ~583 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2457 | Test whether every segmentation and scope-reduction control isolates the cardholder data environment from claimed out-of-scope systems and differing security levels. | cyberful/ | 135 | — | ~928 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2458 | Test payment decision and value-movement invariants with authorized synthetic instruments and reversible sandbox transactions. | cyberful/ | 135 | — | ~668 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2459 | Trace uploaded, imported, generated, archived, converted, scanned, rendered, and downloaded files across storage, naming, extraction, parser, sandbox, and cleanup boundaries. | cyberful/ | 135 | — | ~646 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2460 | Reconstruct how principal, actor, issuer, audience, assurance, scopes, and delegated authority change across requests, tokens, services, queues, and stored artifacts. | cyberful/ | 135 | — | ~730 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2461 | Reconstruct how tenant and organization context is authenticated, selected, routed, cached, queued, and bound to resources across distributed request paths. | cyberful/ | 135 | — | ~679 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2462 | Reconstruct transaction state across services, ledgers, queues, and compensations from local artifacts, identifying causal gaps, duplicate effects, and value mismatches without active traffic. | cyberful/ | 135 | — | ~635 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2463 | 2463.AWS Essentials A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or… | ericrisco/ | 180 | — | ~2.9k | Automated safety check: Notes | MIT | yesterday |
| 2464 | 2464.Cpp A skill your agent uses when writing, reviewing, modernizing, building, or debugging C++ - RAII and resource lifetime, smart-pointer ownership, move semantics and the Rule of Zero/Five, target-based… | ericrisco/ | 180 | — | ~4k | Automated safety check: Pass | MIT | yesterday |
| 2465 | 2465.Go A skill your agent uses when writing, reviewing, testing, or shipping Go code and HTTP services: idioms, %w error wrapping, goroutine/context/errgroup concurrency, net/http 1.22 routing, log/slog… | ericrisco/ | 180 | — | ~3.9k | Automated safety check: Pass | MIT | yesterday |
| 2466 | 2466.Security Scan A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 180 | — | ~2.8k | Automated safety check: Notes | MIT | yesterday |
| 2467 | 2467.Testing Go A skill your agent uses when writing or running Go tests — table-driven cases, named subtests, parallel isolation, fakes instead of mock frameworks, coverage profiles, benchmarks, fuzzing, golden… | ericrisco/ | 180 | — | ~3.7k | Automated safety check: Pass | MIT | yesterday |
| 2468 | 2468.Architect Init A skill your agent uses when bootstrapping architecture documentation for a brownfield project by reverse-engineering ADRs from an existing codebase. | tikalk/ | 141 | — | ~7.4k | Automated safety check: Pass | MIT | yesterday |
| 2469 | 2469.Cis Controls Implement CIS Controls v8 critical security controls for effective cyber defense in CIA platform | Hack23/ | 239 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2470 | Implement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines | Hack23/ | 239 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2471 | Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support | Hack23/ | 239 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2472 | Hack23 Information Security Policy integration for SDLC — developer-facing mapping of ISP requirements to daily engineering activities, tooling, and evidence | Hack23/ | 239 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2473 | Hack23 ISMS organization-wide compliance requirements, policy enforcement, audit preparation | Hack23/ | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2474 | AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model | Hack23/ | 239 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2475 | 2475.MCP Gateway Security MCP gateway security patterns, token management, request validation, and audit logging for MCP communications | Hack23/ | 239 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2476 | 2476.Nist Csf Mapping Map CIA platform security controls to NIST Cybersecurity Framework functions: Identify, Protect, Detect, Respond, Recover | Hack23/ | 239 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2477 | 2477.Open Source Policy Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development | Hack23/ | 239 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2478 | Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform | Hack23/ | 239 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2479 | Hack23 secure development policy enforcement, SAST/DAST integration, dependency scanning, and code signing practices | Hack23/ | 239 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2480 | Security architecture review, control validation, penetration testing guidance, and compliance verification for the CIA platform | Hack23/ | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2481 | 2481.Security By Design Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC | Hack23/ | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2482 | Maintain comprehensive security documentation including SECURITYARCHITECTURE.md, THREATMODEL.md per Hack23 ISMS standards | Hack23/ | 239 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2483 | 2483.Audit Embedded Focused static audit of device firmware and IoT software for update, boot, provisioning, credential, debug-interface and device-communication boundary failures, using an ISVS-informed threat model. | alpha-omega-security/ | 242 | — | ~1.6k | Automated safety check: Notes | MIT | yesterday |
| 2484 | 2484.Audit Exfil Focused static audit for attacker-controlled reads, requests, parsers, or error paths that can disclose files, metadata, secrets, or internal responses. | alpha-omega-security/ | 242 | — | ~2.2k | Automated safety check: Notes | MIT | yesterday |
| 2485 | Audit package manager clients, registries, and proxies against a bundled threat model. | alpha-omega-security/ | 242 | — | ~1k | Automated safety check: Notes | MIT | yesterday |
| 2486 | 2486.Audit Pii Focused static audit for real personal or customer-identifying data committed to source or exposed through logs, URLs, telemetry, exports, and responses. | alpha-omega-security/ | 242 | — | ~3k | Automated safety check: Notes | MIT | yesterday |
| 2487 | 2487.Audit Web Focused static audit of web applications and APIs for session, browser-origin, upload and business-workflow boundary failures, using an ASVS-informed threat model. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Notes | MIT | yesterday |
| 2488 | 2488.Embedded Native Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized. | alpha-omega-security/ | 242 | — | ~425 | Automated safety check: Pass | MIT | yesterday |
| 2489 | Eval-only short-prompt variant of security-deep-dive for A/B testing against the production prompt. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 2490 | Audit a Claude/Agent SKILL.md (or any AI skill / system prompt) for safety before installing or merging it. | mohitagw15856/ | 1.4k | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 2491 | Manage Google Security Operations (SecOps) SOAR cases throughout their lifecycle. | google/ | 21k | — | ~3.2k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 2492 | 2492.Dependency Audit Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat. | Mathews-Tom/ | 329 | — | ~2.7k | Automated safety check: Pass | MIT | 5 days ago |
| 2493 | 2493.Repo Sentinel Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. | Mathews-Tom/ | 329 | — | ~2.2k | Automated safety check: Pass | MIT | 5 days ago |
| 2494 | 2494.Apt Emulation APT 模拟与情报驱动红队方法论。基于已知 APT 组织的 TTP(MITRE ATT&CK)设计红队行动计划。当需要模拟特定威胁组织、设计高仿真攻击演练、或根据威胁情报制定攻击策略时使用 | wgpsec/ | 1.8k | — | ~922 | Automated safety check: Pass | No licence | yesterday |
| 2495 | 2495.C2 Beacon Analysis C2 Beacon 配置提取与分析。当捕获到 Cobalt Strike/Sliver/Havoc 等 C2 框架的 Beacon 样本、内存 dump、或网络流量时使用。提取 C2 地址、通信协议、Malleable Profile、Watermark 等关键情报。红队视角:了解蓝队如何从 Beacon 提取 IOC 以改进 C2 OPSEC | wgpsec/ | 1.8k | — | ~1.2k | Automated safety check: Pass | No licence | yesterday |
| 2496 | C2框架免杀方法论:分析 C2 源码、搜索检测规则(YARA/Sigma/Snort)、逐规则分析、修改源码绕过检测。当遇到 YARA/Sigma/Snort 规则触发告警、beacon/implant 被杀软检测到时使用。第一步:确认 implant/beacon 语言和架构;第二步:搜索对应检测规则并逐规则分析修改 | wgpsec/ | 1.8k | — | ~557 | Automated safety check: Pass | No licence | yesterday |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660