Search
Security
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Hardens code against vulnerabilities. An agent skill from penpot/penpot. | penpot/ | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | today |
| 2 | Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT. | NVIDIA/ | 20k | 1 repo | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 3 | Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist. | eigent-ai/ | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | today |
| 4 | Reference for RuView's research-grade WiFi sensing features: multistatic fusion, cross-viewpoint geometry, persistent field models, RF tomography, intention signals and mesh security. | ruvnet/ | 97k | — | ~1.2k | Automated safety check: Notes | MIT | today |
| 5 | Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge. | nanocoai/ | 31k | — | ~4.6k | Automated safety check: Notes | MIT | 2 days ago |
| 6 | Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference. | Lakr233/ | 15k | — | ~530 | Automated safety check: Pass | MIT | today |
| 7 | Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows. | trailofbits/ | 7.4k | 1 repo | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 8 | A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. | jewbetcha/ | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 9 | Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns. | awarexone/ | 5.3k | 3 repos | ~4.5k | Automated safety check: Pass | MIT | 3 days ago |
| 10 | 10.Fizz Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects. | pashov/ | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | 3 days ago |
| 11 | Guides building Flowsint enrichers and types: where definitions live, how the base class and vault work, and when a new type is warranted. | reconurge/ | 9.5k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 12 | A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails | payloadcms/ | 45k | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 13 | Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept. | usestrix/ | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 14 | Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script. | nanocoai/ | 31k | — | ~1.1k | Automated safety check: Notes | MIT | 2 days ago |
| 15 | A skill your agent uses when the user is designing, prototyping, or rewriting a desktop app that must run on multiple OSes (macOS + Windows, optionally Linux) AND feel indistinguishable from a… | yetone/ | 1.9k | 1 repo | ~1.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 16 | Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs. | microsoft/ | 22k | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 17 | Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation. | vercel-labs/ | 8.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 9 days ago |
| 18 | 18.Code Audit Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 893 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 19 | Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works. | usestrix/ | 67k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 20 | Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo. | fla-org/ | 5.8k | — | ~6.3k | Automated safety check: Pass | MIT | today |
| 21 | Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages. | webhtv/ | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | today |
| 22 | Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments. | awarexone/ | 5.3k | 2 repos | ~4.7k | Automated safety check: Pass | MIT | 3 days ago |
| 23 | A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol. | tradecatlabs/ | 17k | 2 repos | ~3.3k | Automated safety check: Pass | MIT | today |
| 24 | Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner. | vercel-labs/ | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | 9 days ago |
| 25 | Shows how to call NEAR AI Cloud through an OpenAI-compatible API and verify that inference ran in a TEE, using attestation checks and signed chat responses. | internet-court/ | 6.4k | 2 repos | ~1.3k | Automated safety check: Pass | Unknown | 1 mo ago |
| 26 | 26.Reverse Flow Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts. | lingbol088-spec/ | 936 | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 27 | Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys. | j3ssie/ | 1.9k | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 28 | 28.Ctf Osint Provides open source intelligence techniques for CTF challenges. | ljagiello/ | 3.4k | 2 repos | ~2.3k | Automated safety check: Notes | MIT | 24 days ago |
| 29 | WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws… | tanweai/ | 1.8k | — | ~1.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 30 | 30.Geo Sleuth Geolocate or chronolocate a photo with tool-verified reasoning (where was this taken / when was it taken / photo geolocation / geo-guessing). | Oldcircle/ | 1.3k | — | ~6.1k | Automated safety check: Pass | MIT | today |
| 31 | Scan agent skills for security issues. An agent skill from getsentry/skills. | getsentry/ | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | 5 days ago |
| 32 | 32.X Ray Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)… | pashov/ | 1.2k | 1 repo | ~10k | Automated safety check: Pass | MIT | 3 days ago |
| 33 | 1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites). | boyang-hu/ | 1.4k | — | ~6.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 34 | Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept. | usestrix/ | 67k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 35 | Build, review, debug, reverse-engineer data sources for, and package FongMi/WebHome custom homepage single-file HTML. | webhtv/ | 1.7k | — | ~3.8k | Automated safety check: Pass | GPL-3.0 | today |
| 36 | Creates a Phorge code review diff for the current branch with arc diff, while applying public-repo confidentiality rules since Phorge content later lands verbatim on the public GitHub repo. | yugabyte/ | 11k | — | ~3.1k | Automated safety check: Pass | Unknown | today |
| 37 | Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments. | elastic/ | 21k | — | ~1.7k | Automated safety check: Pass | Unknown | today |
| 38 | Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet. | awarexone/ | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | 3 days ago |
| 39 | Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core… | digoal/ | 8.6k | — | ~4k | Automated safety check: Pass | GPL-2.0 | 10 days ago |
| 40 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 41 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | today |
| 42 | Polymarket integration for prediction market trading on Polygon. | Polymarket/ | 191 | 2 repos | ~2k | Automated safety check: Pass | No licence | 7 mo ago |
| 43 | Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics. | OTRF/ | 4.7k | — | ~1.2k | Automated safety check: Pass | MIT | 8 mo ago |
| 44 | 44.Audit Skills 当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。 | RuoJi6/ | 1k | — | ~447 | Automated safety check: Pass | No licence | 3 mo ago |
| 45 | Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report. | ruvnet/ | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | today |
| 46 | 46.Fizz Convert Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes. | pashov/ | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 3 days ago |
| 47 | Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment. | yan-labs/ | 480 | 1 repo | ~3.3k | Automated safety check: Pass | No licence | 7 days ago |
| 48 | A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability. | zhaoxuya520/ | 40k | 4 repos | ~953 | Automated safety check: Warn | MIT | 16 days ago |