Category
Best security skills, page 61
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 2881 | Reviews Kubernetes manifests and cluster config for security misconfigurations, ranks them by blast radius, and gives a minimal hardening patch for each. | criptogus/ | 288 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 28 days ago |
| 2882 | 2882.Osint Investigator Plans and correlates open-source intelligence collection on domains, organizations and infrastructure for authorized investigations and threat intel. | criptogus/ | 288 | — | ~1k | Automated safety check: Pass | CC-BY-SA-4.0 | 28 days ago |
| 2883 | 2883.Recon Attack Surface Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report. | criptogus/ | 288 | — | ~1.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 28 days ago |
| 2884 | 2884.Hunt Ssrf Hunting skill for ssrf vulnerabilities. | sickn33/ | 47k | 1 repo | ~4.5k | Automated safety check: Warn | MIT | yesterday |
| 2885 | 2885.Centralization Risk Trigger Pattern Protocol has privileged authorities (admin, operator, upgrade authority, governance) - Inject Into Breadth agents (optional), depth-state-trace | PlamenTSV/ | 303 | — | ~3k | Automated safety check: Pass | MIT | 12 days ago |
| 2886 | Trigger Pattern updatecurrentcontractwasm detected in codebase - Inject Into Breadth agents, depth-state-trace | PlamenTSV/ | 303 | — | ~2k | Automated safety check: Pass | MIT | 12 days ago |
| 2887 | 2887.Cross Chain Timing Trigger Pattern stellarbridge|sorobanbridge|horizon|anchorprotocol|bridge|crosschain|relay|wormhole|allbridge|debridge|axelar|LayerZero|sequence|emitter - Inject Into Breadth agents, depth-external | PlamenTSV/ | 303 | — | ~4.1k | Automated safety check: Pass | MIT | 12 days ago |
| 2888 | Trigger Pattern MONETARYPARAMETER flag (fee, rate, emission, cap, bps values) - Inject Into Breadth agents (merged via M4 hierarchy) | PlamenTSV/ | 303 | — | ~2.1k | Automated safety check: Pass | MIT | 12 days ago |
| 2889 | Trigger Pattern Any external module interaction detected in attacksurface.md - Inject Into Breadth agents (merged via M5 hierarchy) | PlamenTSV/ | 303 | — | ~1.1k | Automated safety check: Pass | MIT | 12 days ago |
| 2890 | Trigger Pattern Any env.invokecontract() or env.tryinvokecontract() detected in contract - Inject Into Breadth agents | PlamenTSV/ | 303 | — | ~2.2k | Automated safety check: Pass | MIT | 12 days ago |
| 2891 | 2891.Fork Ancestry Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment) | PlamenTSV/ | 303 | — | ~2.4k | Automated safety check: Pass | MIT | 12 days ago |
| 2892 | Trigger FASTANDARD flag detected (protocol uses FungibleAsset standard) - Used by Breadth agents, depth-token-flow | PlamenTSV/ | 303 | — | ~3.3k | Automated safety check: Pass | MIT | 12 days ago |
| 2893 | Protocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries). | PlamenTSV/ | 303 | — | ~3.7k | Automated safety check: Pass | MIT | 12 days ago |
| 2894 | 2894.Migration Analysis Trigger Pattern Contract upgrades via updatecurrentcontractwasm, storage migration, deprecated functions, token migrations - Inject Into Breadth agents, depth-state-trace | PlamenTSV/ | 303 | — | ~3.9k | Automated safety check: Pass | MIT | 12 days ago |
| 2895 | 2895.Overflow Safety Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth-edge-case | PlamenTSV/ | 303 | — | ~1.9k | Automated safety check: Pass | MIT | 12 days ago |
| 2896 | 2896.P2p Dos And Eclipse L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p). | PlamenTSV/ | 303 | — | ~4k | Automated safety check: Pass | MIT | 12 days ago |
| 2897 | 2897.Reentrancy Analysis Trigger REENTRANCY flag detected (dynamic dispatch, closures, dispatchable FA, function values) - Used by Breadth agents, depth-state-trace | PlamenTSV/ | 303 | — | ~2.9k | Automated safety check: Pass | MIT | 12 days ago |
| 2898 | Trigger HASMULTICONTRACT flag in templaterecommendations.md (recon detects 2+ in-scope contracts/modules sharing parameters or formulas) - Agent Type general-purpose (standal... | PlamenTSV/ | 303 | — | ~2.8k | Automated safety check: Pass | MIT | 12 days ago |
| 2899 | 2899.Semi Trusted Roles Trigger Pattern operator/keeper/crank requireauth checks, authority-gated functions - Inject Into Breadth agents, depth-state-trace | PlamenTSV/ | 303 | — | ~2.1k | Automated safety check: Pass | MIT | 12 days ago |
| 2900 | 2900.Sep41 Token Safety Trigger Pattern SEP-41 token patterns detected (approve/transfer/transferfrom/allowance/balance) - Inject Into Breadth agents, depth-token-flow, depth-edge-case | PlamenTSV/ | 303 | — | ~2.5k | Automated safety check: Pass | MIT | 12 days ago |
| 2901 | 2901.Storage Lifecycle Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth agents | PlamenTSV/ | 303 | — | ~2.5k | Automated safety check: Pass | MIT | 12 days ago |
| 2902 | Trigger Pattern interval|period|duration|delay|cooldown|lockperiod|timelock|unbonding|claimdelay|withdrawdelay|maturity|ledgersequence|timestamp - Inject Into Breadth agents, depth-state-trace | PlamenTSV/ | 303 | — | ~3.2k | Automated safety check: Pass | MIT | 12 days ago |
| 2903 | 2903.Token Flow Tracing Trigger Pattern SEP-41 token transfers, TokenClient::new, transfer/transferfrom/burn, XLM native balance - Inject Into Lifecycle, External-Env agents | PlamenTSV/ | 303 | — | ~3.2k | Automated safety check: Pass | MIT | 12 days ago |
| 2904 | Generate a STRIDE-based security threat model for a repository. | Factory-AI/ | 110 | — | ~2.1k | Automated safety check: Pass | No licence | yesterday |
| 2905 | Reviews package dependencies for security vulnerabilities, outdated versions, and license compliance. | aiskillstore/ | 430 | — | ~2.2k | Automated safety check: Notes | No licence | yesterday |
| 2906 | 2906.Security Audit Security auditing and vulnerability assessment specialist. An agent skill from aiskillstore/marketplace. | aiskillstore/ | 430 | 1 repo | ~383 | Automated safety check: Pass | No licence | yesterday |
| 2907 | 2907.Serenity Skill Turn an investment agent into a supply-chain bottleneck hunter. | aiskillstore/ | 430 | — | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 2908 | Comprehensive dependency mapping, analysis, and visualization tool for software projects | aiskillstore/ | 430 | 1 repo | ~1.6k | Automated safety check: Pass | No licence | yesterday |
| 2909 | 2909.Create Fix PR A skill your agent uses when opening or updating a GitHub pull request after Phase 5 of /compliance:analyze-cve has applied and verified a CVE fix locally. | openshift-eng/ | 120 | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2910 | 2910.Audit On-demand security and code quality audit. An agent skill from MadAppGang/claude-code. | MadAppGang/ | 284 | — | ~3.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 2911 | 2911.Network Scanner Scan networks to discover devices, gather MAC addresses, vendors, and hostnames. | sundial-org/ | 663 | — | ~726 | Automated safety check: Notes | No licence | 7 mo ago |
| 2912 | 2912.Security Audit 2 Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or… | sundial-org/ | 663 | — | ~875 | Automated safety check: Pass | No licence | 7 mo ago |
| 2913 | 2913.Security Auditor Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow. | dralgorhythm/ | 125 | — | ~496 | Automated safety check: Pass | No licence | 2 mo ago |
| 2914 | CRITICAL: Never modify files in content-addressable storage systems where the filename IS the content hash (SHA256, IPFS CID, etc.). | divinevideo/ | 266 | — | ~984 | Automated safety check: Pass | MPL-2.0 | today |
| 2915 | 2915.Go Review Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications. | SpecterOps/ | 702 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 15 days ago |
| 2916 | Assess identity trust topology, assurance boundaries, issuer and relying-party responsibilities, and failure containment before testing a specific authentication or authorization mechanism. | cyberful/ | 135 | — | ~710 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2917 | Audit where access policy is decided and enforced across source, configuration, services, caches, jobs, and data stores, including deny behavior and decision-input integrity. | cyberful/ | 135 | — | ~725 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2918 | Route a cloud-native security audit across effective IAM, infrastructure as code, build and release paths, containers, Kubernetes, serverless workloads, secrets, event sources, and control-plane… | cyberful/ | 135 | — | ~852 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2919 | Operate a managed Firefox/Marionette laboratory for privileged chrome-context experiments, content automation, real WebDriver windows, permission readback, and synthetic X11 clipboard controls. | cyberful/ | 135 | — | ~673 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2920 | 2920.Operate Mitre Attack Use the release-embedded MITRE ATT&CK snapshot as a threat-informed reasoning lens without allowing the framework to constrain novel vulnerability discovery. | cyberful/ | 135 | — | ~1.5k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2921 | Test account and authenticator recovery as an assurance transition, including proofing, channel changes, support overrides, replay resistance, and post-recovery invalidation. | cyberful/ | 135 | — | ~665 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2922 | Route file-ingestion security work across processing pipelines, deserialization and object binding, and SOAP or XML services. | cyberful/ | 135 | — | ~600 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2923 | Route HTTP intermediary testing across request normalization, web-cache behavior, and offline traffic evidence. | cyberful/ | 135 | — | ~630 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2924 | Test identity linking, invitation, merge, provisioning, deprovisioning, and account-association ceremonies for proof-of-control, tenant binding, uniqueness, lifecycle, and rollback failures using… | cyberful/ | 135 | — | ~584 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2925 | Test promotions, referrals, quotas, inventory, and entitlement invariants through authorized, bounded, reversible experiments with tester-controlled accounts and assets. | cyberful/ | 135 | — | ~633 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2926 | 2926.Ccs Author Response A skill your agent uses when drafting an ACM CCS rebuttal during the HotCRP author-response window, covering threat-model defenses, adaptive-attack objections, ethics and disclosure questions… | brycewang-stanford/ | 1.2k | — | ~949 | Automated safety check: Pass | MIT | 11 days ago |
| 2927 | 2927.Ccs Related Work A skill your agent uses when positioning an ACM CCS submission against the security big-four and specialist literature, including arXiv preprints, prior CCS/S&P/USENIX/NDSS papers, concurrent… | brycewang-stanford/ | 1.2k | — | ~876 | Automated safety check: Pass | MIT | 11 days ago |
| 2928 | 2928.Ccs Topic Selection A skill your agent uses when deciding whether a security project fits ACM CCS versus IEEE S&P, USENIX Security, NDSS, PETS, or a crypto/theory venue, identifying the security contribution type, and… | brycewang-stanford/ | 1.2k | — | ~945 | Automated safety check: Pass | MIT | 11 days ago |
Explore related skills
Topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,229
- Frontend & Design5,834
- Backend & APIs7,161
- Testing & QA5,085
- DevOps & Cloud5,962
- Databases2,339
- Data & Analytics3,647
- AI & LLM Engineering5,096
- Agent Workflows8,311
- Documents & Office4,273
- Writing & Content3,731
- Marketing & SEO3,910
- Sales & Support1,815
- Research & Science6,075
- Productivity & Automation4,016
- Business, Finance & HR3,836
- Legal & Compliance1,617
- Education1,065
- Media & Creative4,286
- Mobile2,765
- Product & Project Management2,360
- Knowledge Management1,433
- Game Development1,673