Category
Best security skills, page 53
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 2497 | 2497.Ctf AI ML CTF AI/ML 攻击技术。当挑战涉及 AI 模型攻击、对抗样本生成、模型提取、Prompt 注入/越狱、LoRA 权重操纵、LLM Token 走私、成员推理攻击、训练数据投毒、神经网络分析时使用。覆盖 FGSM/PGD/C&W 对抗攻击、模型反演、模型权重扰动还原、LLM 工具链劫持、上下文窗口操纵等 AI 安全全链路攻防技术 | wgpsec/ | 1.8k | — | ~533 | Automated safety check: Pass | No licence | yesterday |
| 2498 | 2498.Ctf Flag Hunting CTF 挑战中的 Flag 搜索策略。当通过 RCE/LFI/SQLi/webshell 等方式获得目标访问权限后、使用常规 ls/cat 命令找不到 flag 时使用。覆盖文件系统、数据库、环境变量、源码、内存等所有 flag 可能的存储位置。按成功率排序的搜索优先级——先试标准路径,再搜索全盘 | wgpsec/ | 1.8k | — | ~1k | Automated safety check: Notes | No licence | yesterday |
| 2499 | 2499.Ctf Forensics CTF 数字取证与信号分析技术。当挑战提供磁盘镜像(.dd/.E01)、内存 dump(.raw/.vmem)、网络抓包(.pcap/.pcapng)、隐写图片/音频、Windows 事件日志(.evtx)时使用。覆盖 Volatility 内存分析、Wireshark 流量还原、binwalk 隐写提取、文件系统恢复等取证全链路 | wgpsec/ | 1.8k | — | ~878 | Automated safety check: Notes | No licence | yesterday |
| 2500 | 2500.Ctf Osint CTF 开源情报(OSINT)技术。当挑战要求从公开信息中找线索——如给定用户名/邮箱追踪身份、给定照片进行地理定位、从历史网页快照中恢复数据时使用。覆盖社交媒体调查、Google Dorking、反向图片搜索、Wayback Machine、DNS 侦察、Tor 中继查询、元数据提取 | wgpsec/ | 1.8k | — | ~530 | Automated safety check: Pass | No licence | yesterday |
| 2501 | 2501.Ctf Source Audit CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式 | wgpsec/ | 1.8k | — | ~1.4k | Automated safety check: Notes | No licence | yesterday |
| 2502 | 2502.Ioc Analysis IOC(失陷指标)分析与对抗方法论。蓝队视角:如何收集、富化、关联 IOC 进行威胁猎杀。红队视角:如何避免自身基础设施和工具产生可识别的 IOC,以及如何使 IOC 快速失效。当红队需要评估自身暴露面或规划 C2 基础设施时使用 | wgpsec/ | 1.8k | — | ~816 | Automated safety check: Pass | No licence | yesterday |
| 2503 | 2503.Log Evasion 日志分析与日志逃逸方法论。理解蓝队如何通过日志追踪攻击行为(SIEM/Event Log/Syslog),以及红队如何规避日志记录或精准清除痕迹。当需要设计无痕操作或分析日志监控覆盖范围时使用 | wgpsec/ | 1.8k | — | ~1.2k | Automated safety check: Pass | No licence | yesterday |
| 2504 | 恶意软件分析方法论。当需要分析可疑二进制文件(PE/ELF/Mach-O)、内存 dump 中的恶意代码、或已知恶意软件家族样本时使用。覆盖静态分析、动态分析、代码逆向、IOC 提取全流程。红队视角:理解检测面以改进免杀 | wgpsec/ | 1.8k | — | ~903 | Automated safety check: Pass | No licence | yesterday |
| 2505 | 内存取证与反内存取证方法论。从蓝队视角理解内存取证如何发现恶意行为(Volatility3 分析流程),从红队视角掌握如何规避内存检测(进程隐藏、内存加密、痕迹清除)。当需要分析内存 dump 或设计反取证策略时使用 | wgpsec/ | 1.8k | — | ~975 | Automated safety check: Notes | No licence | yesterday |
| 2506 | 2506.Prompt Injection AI/LLM 间接 Prompt 注入攻击。当目标 AI 系统会处理外部数据源(网页、文档、邮件、数据库、API 返回)时使用。覆盖间接注入、工具链劫持、RAG 投毒、数据外泄等技术。OWASP LLM Top 10 1 漏洞类别 | wgpsec/ | 1.8k | — | ~704 | Automated safety check: Notes | No licence | yesterday |
| 2507 | 威胁猎杀原理与规避方法论。理解蓝队如何主动猎杀(Hypothesis-driven / IOC-driven / Analytics-driven),红队如何设计行为使自己不被猎杀到。当需要评估自身操作是否可被威胁猎杀发现时使用 | wgpsec/ | 1.8k | — | ~1k | Automated safety check: Pass | No licence | yesterday |
| 2508 | 2508.Sicurezza GitHub Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot. | ccplugins/ | 970 | — | ~486 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 2509 | Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface. | LearnPrompt/ | 110 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 2510 | 2510.Request Smuggling HTTP request smuggling via CL.TE/TE.CL desync and cache poisoning | NeoTheCapt/ | 143 | — | ~982 | Automated safety check: Pass | No licence | 2 mo ago |
| 2511 | 2511.Source Analysis Frontend source code analysis for hidden routes, API endpoints, and secrets | NeoTheCapt/ | 143 | — | ~3k | Automated safety check: Pass | No licence | 2 mo ago |
| 2512 | 2512.Sqli Testing Detect and exploit SQL injection vulnerabilities in web application parameters | NeoTheCapt/ | 143 | — | ~1.2k | Automated safety check: Pass | No licence | 2 mo ago |
| 2513 | 2513.Ssrf Testing Detect and exploit server-side request forgery to access internal resources and cloud metadata | NeoTheCapt/ | 143 | — | ~768 | Automated safety check: Pass | No licence | 2 mo ago |
| 2514 | Subdomain discovery via subfinder, DNS brute-force, and passive sources | NeoTheCapt/ | 143 | — | ~1.7k | Automated safety check: Notes | No licence | 2 mo ago |
| 2515 | 2515.Web Recon Enumerate web technologies, headers, endpoints, and metadata from a target | NeoTheCapt/ | 143 | — | ~770 | Automated safety check: Pass | No licence | 2 mo ago |
| 2516 | 2516.Xss Testing Detect and exploit cross-site scripting vulnerabilities in web applications | NeoTheCapt/ | 143 | — | ~1.4k | Automated safety check: Pass | No licence | 2 mo ago |
| 2517 | 2517.Xxe Testing XML external entity injection for file read, SSRF, and DoS. An agent skill from NeoTheCapt/RedteamAgent. | NeoTheCapt/ | 143 | — | ~1k | Automated safety check: Pass | No licence | 2 mo ago |
| 2518 | 2518.AWS SDK Java V2 Kms Provides AWS Key Management Service (KMS) patterns using AWS SDK for Java 2.x. | giuseppe-trisciuoglio/ | 357 | — | ~3.6k | Automated safety check: Notes | MIT | 1 mo ago |
| 2519 | 2519.Gemini Provides Gemini CLI delegation workflows for large-context analysis and complex reasoning using Gemini 3.0 Flash and Gemini 3.0 Pro models, including English prompt formulation, execution flags, and… | giuseppe-trisciuoglio/ | 357 | — | ~2.3k | Automated safety check: Notes | MIT | 1 mo ago |
| 2520 | Provides AWS CloudFormation patterns for security infrastructure including KMS encryption, Secrets Manager, IAM security, VPC security, ACM certificates, parameter security, outputs, and secure… | giuseppe-trisciuoglio/ | 357 | — | ~2.8k | Automated safety check: Notes | MIT | 1 mo ago |
| 2521 | Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. | giuseppe-trisciuoglio/ | 357 | — | ~2.4k | Automated safety check: Notes | MIT | 1 mo ago |
| 2522 | 2522.Dependency Awareness Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable… | Goldziher/ | 159 | — | ~250 | Automated safety check: Pass | MIT | yesterday |
| 2523 | 2523.Unauth Path Key Hunt 当未授权/零身份测试但路径不在主站 JS、禁止依赖登录 Network 截图、独立 H5/旧域名 NXDOMAIN/品牌迁域、兄弟域或同 IP Host 漏路径、网关 405 或 data 空数组、getRsaKey/JSEncrypt/前端加密被当成鉴权时调用。负责零身份公开面还原路径与密钥、响应指纹分流、加密证伪、迁域复查。JS 拆包见 recon-js-analysis;角色/IDOR… | zhaji2333/ | 115 | — | ~1.4k | Automated safety check: Pass | MIT | 26 days ago |
| 2524 | 当payload被拦截、请求被WAF/过滤/403拒绝、连续多次payload失败、需要绕过黑名单/白名单/正则/语义分析防御时调用。负责编码/变形/逻辑/协议层绕过、换入口、组合利用与时间维度攻击的完整升级路径。 | zhaji2333/ | 115 | — | ~620 | Automated safety check: Pass | MIT | 26 days ago |
| 2525 | 当目标存在评论/昵称/富文本/私信/工单/搜索反射/Markdown解析/AI输出渲染/前端DOM操作/postMessage/跨域配置等功能时调用。负责反射型/存储型/DOM XSS、AI/Markdown 渲染型存储 XSS、CSRF、CORS错误配置、Clickjacking 的深度挖掘与绕过。命中跳转页/开放重定向/target 参数驱动 location 跳转时优先测试跳转型… | zhaji2333/ | 115 | — | ~2.1k | Automated safety check: Pass | MIT | 26 days ago |
| 2526 | Answer "who did what" security questions from Audit Trail — deletions, config changes, login activity, permission changes, actions from a specific user or IP. | datadog-labs/ | 177 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 2527 | 2527.Light Protocol Complete guide for Light Protocol on Solana - includes ZK Compression for rent-free compressed tokens and PDAs using zero-knowledge proofs, and the Light Token Program for high-performance token… | sendaifun/ | 130 | 1 repo | ~3.5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 2528 | 2528.Client Side Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution. | transilienceai/ | 563 | — | ~374 | Automated safety check: Pass | MIT | 2 mo ago |
| 2529 | 2529.Techstack Backend Backend tech-stack identification — web servers, runtimes, languages, frameworks, databases, APIs, and CMS via HTTP headers, cookies, error pages, and API discovery. | transilienceai/ | 563 | — | ~381 | Automated safety check: Pass | MIT | 2 mo ago |
| 2530 | 2530.Techstack Frontend Frontend tech-stack identification — JavaScript frameworks, meta-frameworks, CSS frameworks, UI libraries, build tools, and CMS via DOM, JS globals, HTML, and bundle patterns. | transilienceai/ | 563 | — | ~382 | Automated safety check: Pass | MIT | 2 mo ago |
| 2531 | 2531.Audit On-demand security and code quality audit. An agent skill from MadAppGang/claude-code. | MadAppGang/ | 285 | — | ~3.3k | Automated safety check: Pass | MIT | 7 mo ago |
| 2532 | 2532.Aurakit Sonnet Amplified fullstack engine. An agent skill from davepoon/buildwithclaude. | davepoon/ | 3.6k | — | ~469 | Automated safety check: Pass | MIT | 2 days ago |
| 2533 | 2533.Security Audit Deep security audit covering OWASP Top 10, authentication, authorization, data protection, dependency vulnerabilities, and secrets scanning. | davepoon/ | 3.6k | — | ~442 | Automated safety check: Pass | MIT | 2 days ago |
| 2534 | 2534.Vuln Look up a vulnerability by ID or list all vulnerabilities for a package | davepoon/ | 3.6k | — | ~3.6k | Automated safety check: Notes | MIT | 2 days ago |
| 2535 | 2535.Security Audit 代码安全审计 - 漏洞扫描、依赖检查、安全最佳实践 | laolaoshiren/ | 880 | — | ~282 | Automated safety check: Pass | MIT | 6 days ago |
| 2536 | 2536.Cyber Evidence Captures redacted, provenance-aware cybersecurity observations with shared status fields, independent ground truth, and honest limitations. | HoangNguyen0403/ | 572 | — | ~630 | Automated safety check: Pass | MIT | yesterday |
| 2537 | Adjudicates authorized exercise outcomes against independently held ground truth, redacted evidence, and explicit status boundaries. | HoangNguyen0403/ | 572 | — | ~570 | Automated safety check: Pass | MIT | yesterday |
| 2538 | 2538.Php Security PHP-only security standards for database access, password handling, and input validation. | HoangNguyen0403/ | 572 | — | ~604 | Automated safety check: Pass | MIT | yesterday |
| 2539 | Design a focused lesson observation protocol with specific look-fors and evidence collection methods. | GarethManning/ | 840 | — | ~5k | Automated safety check: Pass | Unknown | 1 mo ago |
| 2540 | 2540.Selective Instrument Selective AFL++ instrumentation for directed fuzzing. An agent skill from opensage-agent/opensage-adk. | opensage-agent/ | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 2541 | 2541.Mobile Audit Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance. | briiirussell/ | 413 | — | ~2.6k | Automated safety check: Warn | MIT | 4 mo ago |
| 2542 | 2542.Spring AI Diagnose and operate Spring AI projects with version-aware Maven or Gradle checks for ChatClient, advisors, retrieval, conversation memory, tool/MCP boundaries, streaming, configuration, and… | magnus919/ | 115 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 2543 | 2543.Security References Serverless OpenClaw security model. An agent skill from serithemage/serverless-openclaw. | serithemage/ | 196 | — | ~633 | Automated safety check: Pass | No licence | 6 mo ago |
| 2544 | 2544.Security Audit 服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题. An agent skill from 312362115/claude. | 312362115/ | 107 | — | ~1.3k | Automated safety check: Pass | MIT | 5 mo ago |
Explore related skills
Topics in Security
- Security review639
- Web application vulnerabilities466
- Vulnerability scanning307
- Static analysis and SAST282
- Security operations247
- Supply chain security233
- Threat modeling224
- Penetration testing181
- Cryptography160
- Prompt injection and agent security156
- Red teaming and adversary simulation148
- Reverse engineering and malware131
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing77
- Bug bounty75
- Network security66
- Capture the flag46
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,214
- Frontend & Design5,827
- Backend & APIs7,095
- Testing & QA5,045
- DevOps & Cloud5,975
- Databases2,347
- Data & Analytics3,623
- AI & LLM Engineering5,042
- Agent Workflows8,310
- Documents & Office4,299
- Writing & Content3,744
- Marketing & SEO3,900
- Sales & Support1,809
- Research & Science6,061
- Productivity & Automation4,039
- Business, Finance & HR3,855
- Legal & Compliance1,617
- Education1,078
- Media & Creative4,318
- Mobile2,746
- Product & Project Management2,329
- Knowledge Management1,439
- Game Development1,660