Category
Best security skills, page 7
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 289 | 289.Security Review Skill to perform a thorough security audit of the codebase. An agent skill from fdhhhdjd/Class-AI-Agent. | fdhhhdjd/ | 266 | — | ~440 | Automated safety check: Notes | No licence | 5 mo ago |
| 290 | 用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF… | index-login/ | 144 | — | ~3k | Automated safety check: Pass | MIT | 9 days ago |
| 291 | 291.Bench Experiment Run and record a hardware experiment on the 2C53T bench using a controlled five-step cycle. | DavidClawson/ | 116 | — | ~1k | Automated safety check: Pass | GPL-3.0 | yesterday |
| 292 | Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. | trailofbits/ | 7.4k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 293 | Automate low-impact web vulnerability verification through Burp MCP. | langbyyi/ | 135 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 294 | A skill for running Yamagi Quake II savegame code generators (mmgen, fngen, mmproto, mmtable, fngenprotos, fngentables scripts). | yquake2/ | 113 | — | ~634 | Automated safety check: Pass | Unknown | today |
| 295 | 295.Audit Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills. | austintgriffith/ | 295 | — | ~829 | Automated safety check: Pass | No licence | 1 mo ago |
| 296 | Three-axis review of the branch diff — Standards (this repo's documented standards + public API surface), Spec (the originating Linear issue / PR), and Correctness (runtime bugs + the SDK threat… | getsentry/ | 873 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 297 | 297.Solidity Auditor Security audit of Solidity code while you develop. An agent skill from pashov/skills. | pashov/ | 1.2k | — | ~9.9k | Automated safety check: Pass | MIT | 4 days ago |
| 298 | A skill your agent uses when a user provides a TikTok profile or account link and asks for account analysis, competitor research, content or commerce performance, operational-logic research… | aronhy/ | 167 | — | ~492 | Automated safety check: Pass | MIT | 2 mo ago |
| 299 | 299.Showcase Video Record and cut a short showcase video of a game mod, or a compilation of clips, ready to post on X/YouTube. | rehan-remade/ | 5.8k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 300 | 300.Serenity Reply Serenity (@aleabitoreddit) 的思维框架与表达方式。基于 6 维度深度调研(1700+ 推文、Substack 长访谈、第三方分析、批评者观点), 提炼 5 个核心心智模型、8 条决策启发式和完整的表达 DNA。 | leslieyeo/ | 136 | — | ~3k | Automated safety check: Pass | MIT | 4 mo ago |
| 301 | 301.Triage Default pipeline scrutineer runs when a repository is added. | alpha-omega-security/ | 239 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 302 | 302.Defense In Depth A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally… | sandgardenhq/ | 137 | 3 repos | ~970 | Automated safety check: Pass | Unknown | 18 days ago |
| 303 | Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup. | Sergei-thinker/ | 189 | — | ~1.5k | Automated safety check: Notes | MIT | 5 mo ago |
| 304 | 304.Decompiler MCP A skill your agent uses when working with the DecompilerServer MCP server to inspect, search, decompile, analyze, or compare .NET assemblies, especially foreign code such as Unity/RimWorld… | pardeike/ | 106 | — | ~1.5k | Automated safety check: Pass | MIT | 8 days ago |
| 305 | 移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。 | s7safe/ | 211 | — | ~631 | Automated safety check: Pass | No licence | 5 mo ago |
| 306 | 306.Malware Analysis Professional malware analysis workflow for PE executables and suspicious files. | tsale/ | 323 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 4 mo ago |
| 307 | 307.Semgrep Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis. | waybarrios/ | 533 | — | ~2.4k | Automated safety check: Pass | MIT | 3 days ago |
| 308 | 308.Docs Update project documentation when features are added or changed. | boostsecurityio/ | 523 | — | ~336 | Automated safety check: Pass | Apache-2.0 | today |
| 309 | 309.Status Check HOL Guard local protection status for Claude Code without changing configuration. | hashgraph-online/ | 827 | — | ~231 | Automated safety check: Pass | Apache-2.0 | today |
| 310 | 310.Security Auditor Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting. | Archethect/ | 127 | — | ~5.9k | Automated safety check: Notes | No licence | 6 mo ago |
| 311 | 311.Find Skills Helps users discover agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. | burkeholland/ | 142 | — | ~1.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 312 | Format and pretty-print Hak5 WiFi Pineapple recon JSON scan files for readability. | sneakerhax/ | 112 | — | ~259 | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 313 | 313.Build DB 使用 jar-analyzer-engine 从 JAR/WAR/Class 文件构建 SQLite 分析数据库。这是进行 Java 代码安全审计、方法调用分析的第一步。 | jar-analyzer/ | 141 | — | ~898 | Automated safety check: Pass | No licence | 6 mo ago |
| 314 | 314.Short Game Make a short vertical (9:16) video where two AI models build the same self-playing game in lpm, side by side, and both games then play live in lpm's browser. | gug007/ | 152 | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 315 | 315.Nano Run First-time setup and guided sprint. An agent skill from garagon/nanostack. | garagon/ | 207 | — | ~3k | Automated safety check: Pass | Apache-2.0 | 29 days ago |
| 316 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 317 | Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 318 | Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths. | Tencent/ | 6.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 319 | Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute). | opensage-agent/ | 127 | — | ~542 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 320 | A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy… | SCStelz/ | 250 | — | ~3.8k | Automated safety check: Pass | MIT | today |
| 321 | Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links. | forefy/ | 152 | — | ~951 | Automated safety check: Pass | MIT | 4 days ago |
| 322 | A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a… | LIDR-academy/ | 278 | — | ~4.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 323 | A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability… | openclaw/ | 143 | — | ~1.1k | Automated safety check: Pass | MIT | 2 days ago |
| 324 | 324.Tenuo Warrant Create or delegate Tenuo warrants from natural-language authority requirements. | tenuo-ai/ | 103 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | today |
| 325 | Covers recovering and verifying the VC7 C runtime, compiler-runtime and D3DX library functions in the TH08 decompilation, with hash-pinned evidence. | N0zoM1z0/ | 102 | — | ~877 | Automated safety check: Pass | MIT | 20 days ago |
| 326 | Security audit checklist based on OWASP Top 10 and best practices. | unxed/ | 241 | — | ~5.4k | Automated safety check: Notes | BSD-3-Clause | today |
| 327 | Tests a security patch against the original bug, its variants and normal behavior, with reproducible baseline-versus-patched evidence before you merge or call it fixed. | trailofbits/ | 7.4k | — | ~3.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 328 | Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity. | thomast1906/ | 202 | — | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 329 | 329.Bom Evidence Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and… | cdxgen/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 330 | Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 331 | 331.Dfir Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. | transilienceai/ | 562 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 332 | Enforces explicit user permission before any file deletion. Activates when you're about to use rm, unlink, fs.rm, or any operation that removes… | MemTensor/ | 12k | — | ~291 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 333 | Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context. | codexstar69/ | 519 | — | ~629 | Automated safety check: Pass | MIT | 1 mo ago |
| 334 | Probes whether an agent can be hijacked by instructions hidden in documents, retrieved chunks or fetched web pages, using test prompts that embed a hidden instruction. | Tencent/ | 6.8k | — | ~1.1k | Automated safety check: Warn | Apache-2.0 | today |
| 335 | 335.Secureclaw Security hardening toolkit for OpenClaw. An agent skill from adversa-ai/secureclaw. | adversa-ai/ | 347 | 1 repo | ~193 | Automated safety check: Pass | MIT | 5 mo ago |
| 336 | 336.Idor Testing This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"… | zebbern/ | 4.7k | 8 repos | ~3.1k | Automated safety check: Pass | MIT | today |
Explore related skills
Topics in Security
- Security review637
- Web application vulnerabilities468
- Vulnerability scanning305
- Static analysis and SAST284
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,199
- Frontend & Design5,829
- Backend & APIs7,083
- Testing & QA5,062
- DevOps & Cloud5,955
- Databases2,353
- Data & Analytics3,632
- AI & LLM Engineering5,048
- Agent Workflows8,296
- Documents & Office4,290
- Writing & Content3,764
- Marketing & SEO3,901
- Sales & Support1,837
- Research & Science6,076
- Productivity & Automation4,035
- Business, Finance & HR3,880
- Legal & Compliance1,634
- Education1,086
- Media & Creative4,311
- Mobile2,737
- Product & Project Management2,339
- Knowledge Management1,438
- Game Development1,678