Category
Best security skills, page 9
Security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 385 | Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption. | wshobson/ | 40k | 11 repos | ~1.9k | Automated safety check: Pass | MIT | 4 days ago |
| 386 | 386.Update Updating Add an entry to the UPDATING file at the repository root. An agent skill from MidnightBSD/src. | MidnightBSD/ | 114 | — | ~1.6k | Automated safety check: Pass | Unknown | 5 days ago |
| 387 | 387.Triage Self-validates a bug bounty report draft before submission. An agent skill from yeswehack/claude-kit. | yeswehack/ | 109 | — | ~1k | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 388 | Display Hak5 WiFi Pineapple recon scan data as a formatted table. | sneakerhax/ | 112 | — | ~298 | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 389 | 389.Do Analyze 对 jar-analyzer-engine 构建的 SQLite 数据库执行安全审计分析查询。支持方法调用搜索、调用链追踪、Spring 组件分析、字符串搜索、漏洞模式检测等。 | jar-analyzer/ | 141 | — | ~2.5k | Automated safety check: Pass | No licence | 6 mo ago |
| 390 | 390.Security Use before shipping to production. An agent skill from garagon/nanostack. | garagon/ | 207 | — | ~3.7k | Automated safety check: Notes | Apache-2.0 | 29 days ago |
| 391 | 391.Deobf String Decrypt and recover obfuscated strings from binaries by analyzing encryption patterns and generating decryption scripts | P4nda0s/ | 140 | — | ~876 | Automated safety check: Pass | No licence | 4 mo ago |
| 392 | A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings… | villith/ | 156 | — | ~7.5k | Automated safety check: Pass | MIT | 14 days ago |
| 393 | Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 394 | OpenClaw 安全检测工具,基于安全实践指南验证配置安全、权限隔离、网络策略、日志审计和运行时完整性. An agent skill from jd-opensource/JoySafeter. | jd-opensource/ | 313 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 395 | Manages who can reach Claude through a Discord channel: approve pairing codes, edit the allowlist and set direct-message and group policy. | anthropics/ | 38k | 1 repo | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 396 | Update copyright year references across the project at the beginning of each calendar year. | MichaelGrafnetter/ | 2k | — | ~404 | Automated safety check: Pass | MIT | 27 days ago |
| 397 | This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks"… | zebbern/ | 4.7k | 8 repos | ~6.1k | Automated safety check: Pass | MIT | today |
| 398 | Systematic static analysis of ELF firmware binaries using command-line tools (file, strings, readelf, objdump, xxd). | OrbitCurve/ | 215 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 399 | Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis. | trilwu/ | 157 | — | ~3.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 400 | Recovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force. | zhaoxuya520/ | 40k | 1 repo | ~1.5k | Automated safety check: Pass | MIT | 17 days ago |
| 401 | Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence. | zhaoxuya520/ | 40k | 1 repo | ~1k | Automated safety check: Pass | MIT | 17 days ago |
| 402 | Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report. | forefy/ | 152 | — | ~1.4k | Automated safety check: Pass | MIT | 4 days ago |
| 403 | Perform post-implementation security review on recent code changes and produce prioritized hardening recommendations with file evidence and fix guidance. | Bald0Wang/ | 187 | — | ~694 | Automated safety check: Pass | No licence | 7 mo ago |
| 404 | 404.Security Review Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs. | deadlock-mod-manager/ | 477 | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 405 | A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability… | openclaw/ | 143 | — | ~1.9k | Automated safety check: Pass | MIT | 2 days ago |
| 406 | Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related… | microsoft/ | 979 | — | ~3k | Automated safety check: Notes | MIT | today |
| 407 | Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis. | trailofbits/ | 7.4k | 3 repos | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 408 | 408.Bom Explore Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences… | cdxgen/ | 1.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 409 | Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures. | Encod3d-Sec/ | 329 | — | ~611 | Automated safety check: Pass | MIT | 1 mo ago |
| 410 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.4k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 411 | Audits, detects gaps, and remediates Android permissions and IPC component security vulnerabilities. | rosuH/ | 1.9k | 1 repo | ~7k | Automated safety check: Pass | MIT | 3 days ago |
| 412 | Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe… | openclaw/ | 392k | — | ~14k | Automated safety check: Pass | MIT | today |
| 413 | Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings. | seb1n/ | 206 | — | ~2.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 414 | 414.Create Template Creates a new Earl HCL template for a specific API, database, or shell command. | mathematic-inc/ | 113 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 415 | 415.Breach Patterns Learn from public breach disclosures — extract the audit question each one implies and check your own stack. | briiirussell/ | 413 | — | ~3.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 416 | 416.Php Cmd Audit PHP Web 源码命令注入审计工具。识别命令执行 Sink(exec/system/shellexec 等),追踪用户输入进入命令拼接,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~465 | Automated safety check: Pass | No licence | 6 mo ago |
| 417 | 417.Mod Any Game Mod a PC game the user owns, taking an idea to working in the real game and recorded. | rehan-remade/ | 5.8k | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 418 | 418.MCP Server Tools Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token. | samugit83/ | 3k | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 419 | A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code… | ProgrammerAnthony/ | 235 | — | ~1.6k | Automated safety check: Pass | MIT | 5 mo ago |
| 420 | Generate prioritized CVE watchlists and actionable security recommendations for repositories. | ArabelaTso/ | 253 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 421 | Close a case or alert with proper reason and documentation. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~615 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 422 | Perform a requested security review of a NemoClaw PR or a PR linked to an issue. | NVIDIA/ | 23k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 423 | 423.Cve Doctor Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix. | getlago/ | 163 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 424 | 424.Absolute Audit Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without… | maddhruv/ | 218 | 1 repo | ~1.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 425 | 425.Gstack Cso Security audit workflow for OPC code, providers, plugins, Electron surfaces, local HTTP bridges, filesystem access, and command execution. | LING71671/ | 962 | — | ~321 | Automated safety check: Notes | Unknown | 2 mo ago |
| 426 | Reference for ten classes of DeFi smart contract bugs, each with root cause, vulnerable code, fix, grep patterns and paid examples, for audits and bug bounty reviews. | tradecatlabs/ | 17k | 2 repos | ~10k | Automated safety check: Pass | MIT | today |
| 427 | Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup. | tradecatlabs/ | 17k | 2 repos | ~9.9k | Automated safety check: Pass | MIT | today |
| 428 | Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting. | tradecatlabs/ | 17k | 2 repos | ~7.7k | Automated safety check: Pass | MIT | today |
| 429 | Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. | Eyadkelleh/ | 388 | — | ~636 | Automated safety check: Pass | No licence | 4 mo ago |
| 430 | 430.Ctf Key Recovery Reconstruct CTF key, serial, and flag verifiers using known plaintext, repeating XOR, encoded constants, bytecode replacement, hash constraints, SMT, and bounded brute force. | manyuegong33/ | 310 | — | ~434 | Automated safety check: Pass | No licence | 19 days ago |
| 431 | 431.Dep Scan Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema. | epam/ | 504 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 432 | Extracts app.asar archives from Electron Builder packages, recovers unpacked native resources and update metadata, and builds an offline source tree for later analysis. | ptn1411/ | 220 | — | ~683 | Automated safety check: Notes | No licence | 17 days ago |
Explore related skills
Topics in Security
- Security review637
- Web application vulnerabilities468
- Vulnerability scanning305
- Static analysis and SAST284
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38
Products these skills work with
Roles that use these skills
Other categories
- Development15,199
- Frontend & Design5,829
- Backend & APIs7,083
- Testing & QA5,062
- DevOps & Cloud5,955
- Databases2,353
- Data & Analytics3,632
- AI & LLM Engineering5,048
- Agent Workflows8,296
- Documents & Office4,290
- Writing & Content3,764
- Marketing & SEO3,901
- Sales & Support1,837
- Research & Science6,076
- Productivity & Automation4,035
- Business, Finance & HR3,880
- Legal & Compliance1,634
- Education1,086
- Media & Creative4,311
- Mobile2,737
- Product & Project Management2,339
- Knowledge Management1,438
- Game Development1,678