Search
Security · By cyberful
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Design and interpret advanced content discovery with ffuf and complementary web fuzzers. | cyberful/ | 135 | — | ~1.5k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2 | Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 3 | Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits. | cyberful/ | 135 | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 4 | Operate Syft, Grype, Trivy, Gitleaks, Retire.js, package-manager metadata, and build evidence for advanced software-supply-chain assessment. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 5 | Assess race conditions, transactional invariants, idempotency, retries, replay, rate and quota enforcement, algorithmic complexity, resource amplification, and cost abuse during authorized… | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 6 | Test native or language object reconstruction, polymorphic type selection, gadget reachability, schema bypass, mass object binding, and unsafe serializer configuration in authorized applications or… | cyberful/ | 135 | — | ~654 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 7 | Test authorized web-cache key construction, variation, partitioning, authenticated response handling, revalidation, poisoning, deception, purge, and TTL behavior. | cyberful/ | 135 | — | ~631 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 8 | Audit local AI model, adapter, tokenizer, configuration, and packaging artifacts for provenance, integrity, dependency, serialization, license, and loading-risk evidence. | cyberful/ | 135 | — | ~535 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 9 | Test whether authorized direct or indirect untrusted content can alter an AI system's protected behavior, context use, memory, retrieval, output handling, or downstream capability. | cyberful/ | 135 | — | ~538 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 10 | Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects. | cyberful/ | 135 | — | ~549 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 11 | Reconstruct how instructions, retrieved content, memory, identities, approvals, tool schemas, arguments, outputs, delegation, and fallbacks propagate through an AI system. | cyberful/ | 135 | — | ~517 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 12 | Extract bounded, deterministic evidence from crash and sanitizer logs, including signals, sanitizer classes, memory-safety indicators, stack-frame hashes, and source provenance, while reserving… | cyberful/ | 135 | — | ~563 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 13 | Normalize and compare authorized fraud-control observations from local evidence, highlighting decision drift, coverage gaps, and conflicting outcomes without making a fraud or vulnerability verdict. | cyberful/ | 135 | — | ~649 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 14 | Parse bounded classic PCAP files offline into deterministic capture metadata, packet-length and timestamp summaries, link and network protocol counts, truncation indicators, and source digests… | cyberful/ | 135 | — | ~590 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 15 | Model fraud and abuse threats across actors, account states, value flows, controls, and monetization paths. | cyberful/ | 135 | — | ~716 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 16 | Assess the security of a smart-contract system across protocol economics, trust roles, upgrade and governance paths, oracle and bridge dependencies, deployment state, and off-chain operators. | cyberful/ | 135 | — | ~651 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 17 | Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures. | cyberful/ | 135 | — | ~637 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 18 | Audit extracted embedded firmware for boot and update trust, credential and secret handling, service exposure, privilege boundaries, parsers, persistence, cryptography, hardening, recovery, and… | cyberful/ | 135 | — | ~644 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 19 | Audit security logging and telemetry from event creation through transport, storage, access, correlation, retention, and response use. | cyberful/ | 135 | — | ~597 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 20 | Test browser capability transfer across postMessage, opener, frame, portal, worker, service-worker, BroadcastChannel, MessagePort, and extension messaging boundaries. | cyberful/ | 135 | — | ~583 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 21 | Test whether every segmentation and scope-reduction control isolates the cardholder data environment from claimed out-of-scope systems and differing security levels. | cyberful/ | 135 | — | ~928 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 22 | Test payment decision and value-movement invariants with authorized synthetic instruments and reversible sandbox transactions. | cyberful/ | 135 | — | ~668 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 23 | Trace uploaded, imported, generated, archived, converted, scanned, rendered, and downloaded files across storage, naming, extraction, parser, sandbox, and cleanup boundaries. | cyberful/ | 135 | — | ~646 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 24 | Reconstruct how principal, actor, issuer, audience, assurance, scopes, and delegated authority change across requests, tokens, services, queues, and stored artifacts. | cyberful/ | 135 | — | ~730 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 25 | Reconstruct how tenant and organization context is authenticated, selected, routed, cached, queued, and bound to resources across distributed request paths. | cyberful/ | 135 | — | ~679 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 26 | Reconstruct transaction state across services, ledgers, queues, and compensations from local artifacts, identifying causal gaps, duplicate effects, and value mismatches without active traffic. | cyberful/ | 135 | — | ~635 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 27 | Build or challenge an application threat model from architecture, dataflows, identities, trust boundaries, business invariants, dependencies, and deployment context. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 28 | Route broad AI-agent security reviews to focused Cyberful skills across risk, model supply chain, context and capabilities, prompt injection, tool authorization, and RAG isolation. | cyberful/ | 135 | — | ~723 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 29 | Coordinate a repository-wide white-box application security audit across architecture, source, configuration, dependencies, build, and deployment paths. | cyberful/ | 135 | — | ~774 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 30 | Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk. | cyberful/ | 135 | — | ~829 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 31 | Coordinate an authorized software-supply-chain audit from dependency resolution through build, artifact, release, deployment, and runtime trust. | cyberful/ | 135 | — | ~737 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 32 | 32.Cyberful Operate Cyberful as an authorized application-security control room. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0-only | 1 mo ago |
| 33 | Operate Ghidra headless analysis, radare2, platform binary utilities, decompilers, and targeted dynamic evidence for advanced native and bytecode security review. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 34 | Operate Prowler, Cloudsplaining, cloud CLIs, policy documents, and resource evidence for advanced AWS, Azure, GCP, and Kubernetes-adjacent posture assessment. | cyberful/ | 135 | — | ~907 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 35 | Operate Cyberful's pinned Foundry toolchain and engagement-owned Anvil lab for authorized EVM smart-contract bug bounty work. | cyberful/ | 135 | — | ~851 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 36 | Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment. | cyberful/ | 135 | — | ~898 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 37 | Operate AFL++, libFuzzer with Clang sanitizers, and Jazzer for advanced coverage-guided native and JVM fuzzing. | cyberful/ | 135 | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 38 | Use sqlmap to confirm and characterize suspected SQL injection with faithful requests and bounded evidence. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 39 | Coordinate testing of product invariants and multi-step workflows across money, entitlements, approvals, quotas, inventory, onboarding, and distributed state. | cyberful/ | 135 | — | ~714 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 40 | Assess sensitive-data lifecycle, secret handling, cryptographic design and implementation, key management, password storage, randomness, signing, encryption, transport protection, and side channels… | cyberful/ | 135 | — | ~924 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 41 | Assess server-side URL retrieval and network egress during authorized penetration tests or code audits. | cyberful/ | 135 | — | ~867 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 42 | Test and audit authenticated session state across cookies, opaque tokens, bearer tokens, refresh tokens, devices, browsers, APIs, and privilege transitions. | cyberful/ | 135 | — | ~915 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 43 | Reconstruct request and event causality across gateways, services, queues, workers, data stores, and external providers while preserving identity, tenant, authorization, retry, and side-effect… | cyberful/ | 135 | — | ~617 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 44 | Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 45 | Transform bounded HAR captures into deterministic HTTP evidence about methods, origins, paths, status classes, header presence, redirects, cookies, and body sizes without replaying traffic or… | cyberful/ | 135 | — | ~544 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 46 | Normalize and correlate bounded SARIF and Cyberful finding exports offline by rule, location, fingerprint, source, level, suppression, and evidence reference without treating scanner severity as… | cyberful/ | 135 | — | ~543 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 47 | Assess AI-system risk from architecture, intended use, affected actors, model limitations, data lineage, autonomy, human oversight, monitoring, and failure consequences. | cyberful/ | 135 | — | ~566 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 48 | Audit container runtime isolation across namespaces, capabilities, seccomp, mandatory access control, mounts, devices, daemon sockets, cgroups, identity, and host integration. | cyberful/ | 135 | — | ~545 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |