Category
Best security skills, page 6
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 241 | 241.Audit A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures. | vigolium/ | 140 | — | ~8.7k | Automated safety check: Pass | MIT | 18 days ago |
| 242 | 按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's… | jnMetaCode/ | 140 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 243 | 243.Security Audit Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report. | marketcalls/ | 2.8k | — | ~1.9k | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 244 | Review and structure auto insurance bodily injury claims, including intake triage, evidence completeness, injury causation, treatment chronology, medical necessity, wage-loss support, negotiation… | samarailly51-pixel/ | 117 | — | ~640 | Automated safety check: Pass | MIT | 1 mo ago |
| 245 | Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release. | clone45/ | 131 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 24 days ago |
| 246 | Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files. | ZaxbyHub/ | 490 | — | ~2.8k | Automated safety check: Pass | MIT | yesterday |
| 247 | 247.Project Security A skill your agent uses when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping. | johnku2011/ | 240 | — | ~650 | Automated safety check: Pass | MIT | 1 mo ago |
| 248 | 248.Sail Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. | pillar-labs/ | 113 | — | ~5.1k | Automated safety check: Pass | Unknown | 3 mo ago |
| 249 | Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data. | addyosmani/ | 103k | 1 repo | ~4.4k | Automated safety check: Notes | MIT | 5 days ago |
| 250 | Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis. | openqa-cn/ | 152 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 251 | Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries. | amElnagdy/ | 1.3k | — | ~2.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 252 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 220 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 253 | 253.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 281 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 254 | Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 255 | Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision. | pegasi-ai/ | 392 | — | ~1.4k | Automated safety check: Warn | Apache-2.0 | 4 mo ago |
| 256 | Map relationships between a web spec section, its Firefox implementation code, and Web Platform Tests. | SAP/ | 180 | 2 repos | ~1.3k | Automated safety check: Pass | GPL-3.0 | 2 days ago |
| 257 | Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets. | Tencent/ | 6.8k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 258 | Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled. | garrytan/ | 136k | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 259 | 259.OneCLI Gateway Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys. | nanocoai/ | 31k | 1 repo | ~856 | Automated safety check: Pass | MIT | 2 days ago |
| 260 | Review a change (a PR, the current branch diff, or a set of files) or audit a Symfony UX package or the whole src/ tree for missing or incorrect security hardening. | symfony/ | 1.1k | — | ~2.9k | Automated safety check: Pass | MIT | 2 days ago |
| 261 | Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas. | OTRF/ | 4.7k | — | ~819 | Automated safety check: Pass | MIT | 9 mo ago |
| 262 | Migrate a .NET 9 project or solution to .NET 10 and resolve all breaking changes. | dotnet/ | 5.6k | 2 repos | ~4.8k | Automated safety check: Pass | MIT | yesterday |
| 263 | 263.Clawscan CLI A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and… | openclaw/ | 142 | — | ~3k | Automated safety check: Pass | MIT | yesterday |
| 264 | Add or retrofit Tenuo authorization for AI-agent tools and effects. | tenuo-ai/ | 102 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 265 | A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI… | jabrena/ | 446 | — | ~874 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 266 | Guide for writing eval conversation JSONs and running them through policy engines | open-bias/ | 143 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 267 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.4k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 268 | PHP Web 全链路白盒代码安全审计流水线(多文件版编排)。作为总编排参考,按 Sink 类型调用各子审计 skill(php-route-mapper/php-auth-audit/php-route-tracer/php--audit),并复用统一输出与分级标准。 | 0xShe/ | 402 | 1 repo | ~4.9k | Automated safety check: Pass | No licence | 6 mo ago |
| 269 | 269.Graph DB Writes Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must… | samugit83/ | 3k | — | ~2.2k | Automated safety check: Pass | MIT | yesterday |
| 270 | 270.Fallow Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills. | fallow-rs/ | 129 | — | ~8.5k | Automated safety check: Pass | MIT | yesterday |
| 271 | Runs and interprets Psalm security (taint) analysis on a Laravel project. | cachethq/ | 230 | — | ~4.7k | Automated safety check: Pass | Unknown | 3 days ago |
| 272 | 272.Acl Abuse Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication… | ADScanPro/ | 210 | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 273 | 273.Codeql Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF. | waybarrios/ | 533 | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 3 days ago |
| 274 | Tells a model how to treat the tagged double-brace placeholders that Maskit's local privacy gateway substitutes for sensitive text, so tokens are copied exactly instead of guessed, split or faked. | xiaYuTian11/ | 295 | — | ~718 | Automated safety check: Pass | AGPL-3.0 | 3 days ago |
| 275 | Sentry-specific security review based on real vulnerability history. | getsentry/ | 46k | — | ~2.3k | Automated safety check: Notes | Unknown | yesterday |
| 276 | Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes. | seqra/ | 162 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 277 | Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2… | provos/ | 613 | — | ~5.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 278 | Builds a skeptical reviewer grounded in the codebase and research notes to try to refute a spec before any code is written, citing file:line evidence and ending in a go or no-go gate. | JuliusBrussee/ | 1.1k | — | ~959 | Automated safety check: Pass | MIT | 1 mo ago |
| 279 | 279.Migrate To Earl Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time. | mathematic-inc/ | 113 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 280 | Review code for quality, correctness, and security vulnerabilities. | hiroshiyui/ | 135 | — | ~1.6k | Automated safety check: Pass | GPL-3.0 | 11 days ago |
| 281 | 281.Dsl Vm Reverse Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines. | zhaoxuya520/ | 40k | 3 repos | ~2.3k | Automated safety check: Pass | MIT | 16 days ago |
| 282 | Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk. | GitbookIO/ | 131 | — | ~1.2k | Automated safety check: Pass | No licence | yesterday |
| 283 | 283.Stellar Dev End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments. | VelaPayments/ | 131 | — | ~1.8k | Automated safety check: Pass | MIT | 2 days ago |
| 284 | Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. | elastic/ | 592 | — | ~2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 285 | Deep web-research methodology for the interceptor browser surface — investigate a topic the way researchers, intelligence analysts, investigative journalists, private investigators, and OSINT… | Hacker-Valley-Media/ | 517 | — | ~3.8k | Automated safety check: Pass | Unknown | 6 days ago |
| 286 | Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script. | ptn1411/ | 219 | — | ~830 | Automated safety check: Notes | No licence | 17 days ago |
| 287 | VulnHunter sandbox-depth decision procedure. An agent skill from nealbridges/VulnHunter. | nealbridges/ | 646 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 288 | 288.Kesekit Fix Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems. | cdppcorp/ | 361 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
Explore related skills
Topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,229
- Frontend & Design5,834
- Backend & APIs7,161
- Testing & QA5,085
- DevOps & Cloud5,962
- Databases2,339
- Data & Analytics3,647
- AI & LLM Engineering5,096
- Agent Workflows8,311
- Documents & Office4,273
- Writing & Content3,731
- Marketing & SEO3,910
- Sales & Support1,815
- Research & Science6,075
- Productivity & Automation4,016
- Business, Finance & HR3,836
- Legal & Compliance1,617
- Education1,065
- Media & Creative4,286
- Mobile2,765
- Product & Project Management2,360
- Knowledge Management1,433
- Game Development1,673