Category

Best security skills, page 59

Skills #2,785–2,832 of 3,084, ranked by score.

Security skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Security skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
2785

Normalize and correlate bounded SARIF and Cyberful finding exports offline by rule, location, fingerprint, source, level, suppression, and evidence reference without treating scanner severity as…

cyberful/cyberful135—~543Automated safety check: PassAGPL-3.01 mo ago
2786

Assess AI-system risk from architecture, intended use, affected actors, model limitations, data lineage, autonomy, human oversight, monitoring, and failure consequences.

cyberful/cyberful135—~566Automated safety check: PassAGPL-3.01 mo ago
2787

Audit container runtime isolation across namespaces, capabilities, seccomp, mandatory access control, mounts, devices, daemon sockets, cgroups, identity, and host integration.

cyberful/cyberful135—~545Automated safety check: PassAGPL-3.01 mo ago
2788

Find leaked API keys, tokens, and credentials in public GitHub repositories.

uphiago/recon-skills1.3k—~1.8kAutomated safety check: WarnMIT1 mo ago
2789

Implement comprehensive input validation to prevent XSS, SQL injection, and command injection attacks with sanitization strategies

Hack23/cia239—~5.9kAutomated safety check: PassApache-2.0yesterday
2790

OSINT collection, source evaluation, data integration, verification techniques for Swedish political intelligence

Hack23/cia239—~6.1kAutomated safety check: PassApache-2.0yesterday
2791

Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy

Hack23/cia239—~5.8kAutomated safety check: PassApache-2.0yesterday
2792

Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform

Hack23/cia239—~6.8kAutomated safety check: PassApache-2.0yesterday
2793

Systematic vulnerability lifecycle management with SLAs: Critical 7d, High 30d, Medium 90d, Low 180d aligned with OWASP, NIST, CIS Controls

Hack23/cia239—~6.2kAutomated safety check: PassApache-2.0yesterday
2794

Respond to a brand or executive impersonation incident — deepfaked executives, cloned support lines, fake apps, spoofed domains, or AI-generated scam content wearing your name.

mohitagw15856/pm-claude-skills1.4k—~1.7kAutomated safety check: PassMITyesterday
2795

A skill your agent uses when asked 数据出境要申报吗, 数据出境安全评估还是标准合同, 个人信息出境标准合同怎么备案, 我们把数据传到海外总部合规吗, or decide how to transfer data out of mainland China lawfully.

mohitagw15856/pm-claude-skills1.4k—~1.1kAutomated safety check: PassMITyesterday
2796

Respond to your data being breached — triage by what actually leaked, the freeze/rotate/monitor ladder in the right order, and the calibrated watchfulness that follows, without panic or paralysis.

mohitagw15856/pm-claude-skills1.4k—~1.5kAutomated safety check: PassMITyesterday
2797

Get your personal info off people-search and data-broker sites — a prioritized opt-out plan that targets the sites that matter and keeps them from reappearing.

mohitagw15856/pm-claude-skills1.4k—~1.1kAutomated safety check: PassMITyesterday
2798

Specify the safety and reliability guardrails for an LLM feature before it ships.

mohitagw15856/pm-claude-skills1.4k—~1.1kAutomated safety check: PassMITyesterday
2799

Write up a supply chain disruption — port delay, carrier failure, customs hold, or in-transit damage — as a decision-ready incident report.

mohitagw15856/pm-claude-skills1.4k—~1.7kAutomated safety check: PassMITyesterday
2800

Run or document a security incident response — contain, eradicate, recover, and learn.

mohitagw15856/pm-claude-skills1.4k—~1kAutomated safety check: PassMITyesterday
2801

Review a design, PR, or feature for security issues before it ships.

mohitagw15856/pm-claude-skills1.4k—~973Automated safety check: PassMITyesterday
2802

Write a STRIDE-based threat model for a service or feature. An agent skill from mohitagw15856/pm-claude-skills.

mohitagw15856/pm-claude-skills1.4k—~3.8kAutomated safety check: PassMITyesterday
2803

Turn an anxious spiral into a concrete list — separate the specific worries from the vague dread, sort what you can act on from what you can't, and get one action.

mohitagw15856/pm-claude-skills1.4k—~1.1kAutomated safety check: PassMITyesterday
2804

Threat-model a system or feature to find where it could be attacked, before you build it.

mohitagw15856/pm-claude-skills1.4k—~911Automated safety check: PassMITyesterday
2805

AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource…

LeoYeAI/openclaw-master-skills2.2k—~4.5kAutomated safety check: PassApache-2.02 mo ago
2806

Azure VNet networking audit covering address space design, NSG rule evaluation, Azure Firewall policy analysis, ExpressRoute and VPN Gateway connectivity, VNet Peering topology, and UDR validation…

LeoYeAI/openclaw-master-skills2.2k—~4.5kAutomated safety check: PassApache-2.02 mo ago
2807

Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment…

LeoYeAI/openclaw-master-skills2.2k—~4.8kAutomated safety check: PassApache-2.02 mo ago
2808

Agent-to-agent messaging with cryptographic signing and encryption.

LeoYeAI/openclaw-master-skills2.2k—~4.3kAutomated safety check: PassMIT2 mo ago
2809

Cross-cloud security posture assessment covering IAM analysis, encryption audit, and public exposure detection across AWS, Azure, and GCP using [AWS]/[Azure]/[GCP] inline labels for…

LeoYeAI/openclaw-master-skills2.2k—~4.8kAutomated safety check: PassApache-2.02 mo ago
2810

Network forensics evidence collection and analysis during security incidents.

LeoYeAI/openclaw-master-skills2.2k—~5kAutomated safety check: PassApache-2.02 mo ago
2811

Capture solved problems as searchable solution docs. An agent skill from oliver-kriska/claude-elixir-phoenix.

oliver-kriska/claude-elixir-phoenix565—~964Automated safety check: PassMIT3 days ago
2812

Capture solved problems as searchable solution docs. An agent skill from oliver-kriska/claude-elixir-phoenix.

oliver-kriska/claude-elixir-phoenix565—~929Automated safety check: PassMIT3 days ago
2813

Capture solved problems as searchable solution docs. An agent skill from oliver-kriska/claude-elixir-phoenix.

oliver-kriska/claude-elixir-phoenix565—~953Automated safety check: PassMIT3 days ago
2814

Assess the physical attack surface of embedded devices — finding and using UART consoles, JTAG/SWD debug, and SPI/I2C flash; dumping firmware off-chip; triaging secure boot; and studying sub-GHz RF…

trilwu/secskills156—~1.8kAutomated safety check: PassMIT1 mo ago
2815

Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher…

trilwu/secskills156—~1.6kAutomated safety check: PassMIT1 mo ago
2816

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…

trilwu/secskills156—~3.9kAutomated safety check: NotesMIT1 mo ago
2817

Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums…

trilwu/secskills156—~1.4kAutomated safety check: PassMIT1 mo ago
2818

Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow…

trilwu/secskills156—~2.3kAutomated safety check: PassMIT1 mo ago
2819

思维链 (Chain-of-Thought) 注入攻击方法论。当目标系统使用 ReAct/CoT 框架进行多步推理、 Agent 依赖中间推理结果做决策、或需要测试思维链完整性时触发。

wgpsec/AboutSecurity1.8k—~640Automated safety check: PassNo licence5 days ago
2820

CTF/靶场 Flag 强制验证流程。当通过任何方式发现疑似 flag 字符串(含 flag{、FLAG{、ctf{ 等格式)时必须立即使用此 skill 验证,不要直接提交。防止因字符截断、编码错误、HTML 实体、base64 不完整解码、hex 截断等原因导致提交错误 flag。即使 flag 看起来完整,也可能存在隐藏字符或编码问题。覆盖 SQL…

wgpsec/AboutSecurity1.8k—~644Automated safety check: PassNo licence5 days ago
2821

CTF Web 挑战专用侦察方法。当面对 CTF 靶场目标需要快速发现攻击入口时使用。与真实渗透的 recon 不同——CTF 是单个应用、有意留线索、侦察应在 2-3 轮内完成。覆盖源码泄露、备份文件、隐藏路径、页面线索提取

wgpsec/AboutSecurity1.8k—~624Automated safety check: NotesNo licence5 days ago
2822

使用 DalFox 进行 XSS 漏洞扫描。当需要检测反射型/存储型/DOM XSS、分析参数注入点、绕过 WAF 时使用。DalFox 支持自动参数分析、DOM 挖掘、Blind XSS 回调、WAF 绕过、自动生成 PoC。任何涉及 XSS 漏洞检测、参数测试、WAF 绕过的场景都应使用此技能

wgpsec/AboutSecurity1.8k—~551Automated safety check: PassNo licence5 days ago
2823

使用 dirsearch 进行 Web 目录和文件暴力枚举。当需要发现隐藏的目录、文件、后台路径、备份文件时使用。dirsearch 内置高质量字典,支持多扩展名、递归扫描、状态码过滤。任何涉及目录枚举、路径发现、后台查找、敏感文件发现的场景都应使用此技能

wgpsec/AboutSecurity1.8k—~520Automated safety check: PassNo licence5 days ago
2824

GitHub 安全研究方法论:搜索 GitHub 上的免杀/Loader/C2 技术仓库,分析代码模式,提取新技术入库。当知识库中没有针对当前检测环境的免杀技术时使用——先搜索 GitHub 高星仓库,分析代码后写入 evasion-techniques-db.json 或 loader-components-db.json 入库

wgpsec/AboutSecurity1.8k—~432Automated safety check: PassNo licence5 days ago
2825

ffuf 模糊测试工具完整参考。用于目录/文件发现、参数 Fuzz、虚拟主机枚举、POST 数据 Fuzz、多位置 Fuzz。当需要对 Web 应用进行路径爆破、参数发现、子域名枚举时使用。比 gobuster/dirsearch 更灵活——支持多 FUZZ 位置和自定义过滤。任何需要 Web 路径或参数暴力枚举的场景都应使用此 skill

wgpsec/AboutSecurity1.8k—~1.2kAutomated safety check: PassNo licence5 days ago
2826

使用 masscan 进行超大规模高速端口扫描。当需要扫描大范围 CIDR 网段、全互联网规模扫描时使用。masscan 是异步无状态扫描器,速度可达每秒百万包级别,适合大规模资产发现。需要 root 权限。任何涉及大规模网段扫描、高速端口发现、互联网测绘的场景都应使用此技能

wgpsec/AboutSecurity1.8k—~523Automated safety check: NotesNo licence5 days ago
2827

使用 naabu 进行高速端口扫描。当需要对目标主机/网段进行端口发现、存活检测时使用。naabu 是 ProjectDiscovery 出品的快速端口扫描器,支持 SYN/CONNECT/UDP 扫描,性能远超 nmap,支持批量目标、CDN 排除、nmap 集成。任何涉及端口扫描、端口发现、主机存活检测、网段探测的场景都应使用此技能。如果 naabu 结果不足再降级用 nmap

wgpsec/AboutSecurity1.8k—~812Automated safety check: NotesNo licence5 days ago
2828

使用 Nikto 进行 Web 服务器漏洞扫描。当需要检测 Web 服务器的已知漏洞、过时软件版本、危险文件/CGI、配置错误时使用。Nikto 内置 7000+ 检查项,覆盖 OWASP 常见问题。任何涉及 Web 漏洞扫描、服务器安全检查、配置审计的场景都应使用此技能

wgpsec/AboutSecurity1.8k—~495Automated safety check: PassNo licence5 days ago
2829

使用 nmap 进行端口扫描和服务识别。当需要对目标进行精细端口扫描、服务版本探测、操作系统指纹识别、NSE 脚本漏洞扫描时使用。nmap 是最经典的网络扫描器,支持 SYN/TCP/UDP/ACK 等多种扫描模式,内置 600+ NSE 脚本。任何涉及端口扫描、服务识别、漏洞脚本扫描、操作系统指纹的场景都应使用此技能。速度不如 naabu,但功能远超 naabu

wgpsec/AboutSecurity1.8k—~652Automated safety check: NotesNo licence5 days ago
2830

Nuclei 漏洞扫描工具使用方法论。当需要对目标进行已知漏洞扫描、CVE 验证、批量 PoC 检测时使用。Nuclei 拥有社区维护的 9000+ 模板,覆盖 CVE、默认口令、配置错误、信息泄露等。任何涉及 nuclei 扫描、CVE 批量验证、PoC 检测、漏洞模板搜索的场景都应使用此技能。也适用于需要从 nuclei 模板中提取 payload 用于手动利用的场景

wgpsec/AboutSecurity1.8k—~1.1kAutomated safety check: PassNo licence5 days ago
2831

使用 spray 进行高性能目录爆破和指纹识别。当需要对 Web 目标进行目录/文件枚举、备份文件发现、指纹识别时使用。spray 是 chainreactors 出品的下一代目录爆破工具,性能超过 ffuf 50%+,支持智能过滤、掩码字典、断点续传、批量目标。任何涉及目录爆破、路径枚举、备份文件扫描、Web 指纹识别的场景都应考虑此技能

wgpsec/AboutSecurity1.8k—~697Automated safety check: NotesNo licence5 days ago
2832

使用 subfinder 进行被动子域名枚举。当需要发现目标域名的子域名、扩展攻击面时使用。subfinder 是 ProjectDiscovery 出品的被动子域名发现工具,聚合 Shodan、Censys、SecurityTrails、VirusTotal 等多数据源,快速且隐蔽。任何涉及子域名枚举、攻击面发现、被动信息收集的场景都应使用此技能

wgpsec/AboutSecurity1.8k—~500Automated safety check: PassNo licence5 days ago