Category

Best security skills, page 6

Skills #241–288 of 3,084, ranked by score.

Security skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Security skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
241
241.Audit

A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures.

vigolium/piolium140—~8.7kAutomated safety check: PassMIT18 days ago
242

按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…

jnMetaCode/shellward140—~1.1kAutomated safety check: PassApache-2.010 days ago
243

Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.

marketcalls/openalgo2.8k—~1.9kAutomated safety check: PassAGPL-3.0yesterday
244

Review and structure auto insurance bodily injury claims, including intake triage, evidence completeness, injury causation, treatment chronology, medical necessity, wage-loss support, negotiation…

samarailly51-pixel/claimpilot-harness117—~640Automated safety check: PassMIT1 mo ago
245

Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release.

clone45/voxglitch131—~1.2kAutomated safety check: PassGPL-3.024 days ago
246

Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

ZaxbyHub/opencode-swarm490—~2.8kAutomated safety check: PassMITyesterday
247

A skill your agent uses when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.

johnku2011/boilerplates-with-ai-skills240—~650Automated safety check: PassMIT1 mo ago
248
248.Sail

Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.

pillar-labs/sail-skill113—~5.1kAutomated safety check: PassUnknown3 mo ago
249

Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

addyosmani/agent-skills103k1 repo~4.4kAutomated safety check: NotesMIT5 days ago
250

Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.

openqa-cn/codexqa152—~2.6kAutomated safety check: PassApache-2.06 days ago
251

Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.

amElnagdy/guard-skills1.3k—~2.4kAutomated safety check: PassMIT3 mo ago
252

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassUnknown5 mo ago
253

Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

Hainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT2 mo ago
254

Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
255

Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.

pegasi-ai/reins392—~1.4kAutomated safety check: WarnApache-2.04 mo ago
256
256.SpecmapOfficial

Map relationships between a web spec section, its Firefox implementation code, and Web Platform Tests.

SAP/project-foxhound1802 repos~1.3kAutomated safety check: PassGPL-3.02 days ago
257

Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets.

Tencent/AI-Infra-Guard6.8k—~1.5kAutomated safety check: NotesApache-2.0yesterday
258

Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

garrytan/gstack136k—~4.5kAutomated safety check: PassMITyesterday
259

Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

nanocoai/nanoclaw31k1 repo~856Automated safety check: PassMIT2 days ago
260

Review a change (a PR, the current branch diff, or a set of files) or audit a Symfony UX package or the whole src/ tree for missing or incorrect security hardening.

symfony/ux1.1k—~2.9kAutomated safety check: PassMIT2 days ago
261

Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

OTRF/ThreatHunter-Playbook4.7k—~819Automated safety check: PassMIT9 mo ago
262

Migrate a .NET 9 project or solution to .NET 10 and resolve all breaking changes.

dotnet/skills5.6k2 repos~4.8kAutomated safety check: PassMITyesterday
263

A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…

openclaw/clawscan142—~3kAutomated safety check: PassMITyesterday
264

Add or retrofit Tenuo authorization for AI-agent tools and effects.

tenuo-ai/tenuo102—~2.3kAutomated safety check: PassApache-2.0yesterday
265

A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

jabrena/plinth446—~874Automated safety check: PassApache-2.0yesterday
266

Guide for writing eval conversation JSONs and running them through policy engines

open-bias/open-bias143—~1.5kAutomated safety check: PassApache-2.0yesterday
267

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

trailofbits/skills7.4k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.0yesterday
268

PHP Web 全链路白盒代码安全审计流水线(多文件版编排)。作为总编排参考,按 Sink 类型调用各子审计 skill(php-route-mapper/php-auth-audit/php-route-tracer/php--audit),并复用统一输出与分级标准。

0xShe/PHP-Code-Audit-Skill4021 repo~4.9kAutomated safety check: PassNo licence6 mo ago
269

Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…

samugit83/redamon3k—~2.2kAutomated safety check: PassMITyesterday
270
270.Fallow

Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills.

fallow-rs/fallow-skills129—~8.5kAutomated safety check: PassMITyesterday
271

Runs and interprets Psalm security (taint) analysis on a Laravel project.

cachethq/core230—~4.7kAutomated safety check: PassUnknown3 days ago
272

Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

ADScanPro/Claude-AD210—~2.6kAutomated safety check: PassMIT1 mo ago
273
273.Codeql

Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.

waybarrios/opencode-power-pack5332 repos~3.7kAutomated safety check: PassMIT3 days ago
274

Tells a model how to treat the tagged double-brace placeholders that Maskit's local privacy gateway substitutes for sensitive text, so tokens are copied exactly instead of guessed, split or faked.

xiaYuTian11/maskit295—~718Automated safety check: PassAGPL-3.03 days ago
275
275.Sentry SecurityOfficial

Sentry-specific security review based on real vulnerability history.

getsentry/sentry46k—~2.3kAutomated safety check: NotesUnknownyesterday
276

Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes.

seqra/opentaint162—~1.9kAutomated safety check: PassApache-2.0yesterday
277

Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

provos/ironcurtain613—~5.7kAutomated safety check: PassApache-2.0yesterday
278

Builds a skeptical reviewer grounded in the codebase and research notes to try to refute a spec before any code is written, citing file:line evidence and ending in a go or no-go gate.

JuliusBrussee/cavekit1.1k—~959Automated safety check: PassMIT1 mo ago
279

Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time.

mathematic-inc/earl113—~1.9kAutomated safety check: PassApache-2.02 days ago
280

Review code for quality, correctness, and security vulnerabilities.

hiroshiyui/GuilelessBopomofo135—~1.6kAutomated safety check: PassGPL-3.011 days ago
281

Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines.

zhaoxuya520/reverse-skill40k3 repos~2.3kAutomated safety check: PassMIT16 days ago
282

Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk.

GitbookIO/integrations131—~1.2kAutomated safety check: PassNo licenceyesterday
283

End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments.

VelaPayments/vela-payments131—~1.8kAutomated safety check: PassMIT2 days ago
284

Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

elastic/agent-skills592—~2kAutomated safety check: PassApache-2.0yesterday
285

Deep web-research methodology for the interceptor browser surface — investigate a topic the way researchers, intelligence analysts, investigative journalists, private investigators, and OSINT…

Hacker-Valley-Media/Interceptor517—~3.8kAutomated safety check: PassUnknown6 days ago
286

Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.

ptn1411/skill219—~830Automated safety check: NotesNo licence17 days ago
287

VulnHunter sandbox-depth decision procedure. An agent skill from nealbridges/VulnHunter.

nealbridges/VulnHunter646—~1.1kAutomated safety check: PassApache-2.0yesterday
288

Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems.

cdppcorp/KESE-KIT361—~1.1kAutomated safety check: PassMIT6 mo ago