Search

Security

3,083 skills found, page 10.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
433

Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

dslsdzc/rev-skills135—~2kAutomated safety check: PassApache-2.06 days ago
434

Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.

epam/ai-dial-chat504—~1.2kAutomated safety check: PassApache-2.0yesterday
435

A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

jabrena/plinth447—~3.2kAutomated safety check: PassApache-2.04 days ago
436

Extracts app.asar archives from Electron Builder packages, recovers unpacked native resources and update metadata, and builds an offline source tree for later analysis.

ptn1411/skill219—~683Automated safety check: NotesNo licence19 days ago
437

Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation…

guardana/guardana259—~1.1kAutomated safety check: PassApache-2.0today
438

A skill your agent uses when asked to generate a "no way to prevent this" / no-way-to-prevent-this satire post for a memory-safety CVE (out-of-bounds write/read, buffer/heap overflow…

Xe/site732—~816Automated safety check: PassZlib2 days ago
439

Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging.

wshobson/agents40k9 repos~588Automated safety check: PassMIT6 days ago
440

Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

cdppcorp/KESE-KIT360—~1.4kAutomated safety check: PassMIT6 mo ago
441
441.Nmap

Professional network reconnaissance and port scanning using nmap.

BrownFineSecurity/iothackbot8591 repo~3.8kAutomated safety check: NotesMIT4 mo ago
442

This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through…

zebbern/claude-code-guide4.7k5 repos~2.9kAutomated safety check: PassMITyesterday
443

Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.

elementalsouls/Claude-BugHunter4.9k—~4.5kAutomated safety check: PassMITyesterday
444

Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

malloydata/publisher116—~5.1kAutomated safety check: PassMITtoday
445

C++ naming, formatting, static analysis, and RTTI rules for LuisaCompute.

LuisaGroup/LuisaCompute1.1k—~1.1kAutomated safety check: PassApache-2.0yesterday
446

Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

hashgraph-online/hol-guard845—~605Automated safety check: PassApache-2.0today
447

Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.

tsale/awesome-dfir-skills323—~3.4kAutomated safety check: PassApache-2.05 mo ago
448

Give a decisive, project-grounded verdict on an external input — judged against the current project, not in the abstract.

leo-kuang-ai/spec-first107—~4.5kAutomated safety check: PassMIT3 days ago
449

A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

ccashwell/evm-cortex131—~25kAutomated safety check: PassMIT11 days ago
450

Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input…

utkusen/sast-skills1.3k—~4.7kAutomated safety check: PassMIT6 mo ago
451

A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…

WrongStack/WrongStack374—~2.4kAutomated safety check: PassMITtoday
452

Dual-model code review via Codex CLI. An agent skill from suyuan2022/suyuan-skill.

suyuan2022/suyuan-skill308—~3.5kAutomated safety check: WarnMIT1 mo ago
453

A skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan.

vlinx-io/VelaTerm281—~3.3kAutomated safety check: PassMIT4 days ago
454

Runs a security health check on an OpenClaw environment and audits skills before or after installation for supply-chain and data-leak risks.

Tencent/AI-Infra-Guard6.8k—~9.5kAutomated safety check: PassMIT2 days ago
455

Worked bug bounty case study of a yield aggregator: target scoring, fund-flow mapping, prior audit triage and a verdict per bug class, with role misconfiguration in focus.

tradecatlabs/vibe-coding-cn17k2 repos~3.5kAutomated safety check: PassMITyesterday
456

Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring.

tradecatlabs/vibe-coding-cn17k2 repos~2.5kAutomated safety check: PassMITyesterday
457

Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target.

tradecatlabs/vibe-coding-cn17k2 repos~2.2kAutomated safety check: PassMITyesterday
458

Generate a PR-ready technique proposal when an attack step doesn't map to existing SITF techniques.

wiz-sec-public/SITF182—~4.1kAutomated safety check: PassUnknown2 mo ago
459

Audit, explain, or compare existing Tenuo warrants and delegation chains.

tenuo-ai/tenuo103—~3.6kAutomated safety check: PassApache-2.0yesterday
460

Builds attack trees that map how an attacker could reach a goal, with AND and OR nodes and cost, time, skill and detection ratings, to find defense gaps.

wshobson/agents40k8 repos~623Automated safety check: PassMIT6 days ago
461

Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition.

wshobson/agents40k8 repos~2kAutomated safety check: PassMIT6 days ago
462

Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

wshobson/agents40k8 repos~742Automated safety check: PassMIT6 days ago
463

Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input).

ash1794/vibe-engineering163—~722Automated safety check: PassMIT3 days ago
464

Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.

nordstjernen-web/northstar-browser128—~920Automated safety check: PassGPL-3.0yesterday
465

Static safety audit of a SKILL.md that scores five dimensions and acts as a gate: skills below the pass line do not ship, whatever else they score.

openJiuwen-ai/agent-core446—~3.5kAutomated safety check: WarnApache-2.0today
466
466.Sarif ParsingOfficial

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

trailofbits/skills7.5k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
467

The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main.

ibuilder/massing122—~2.3kAutomated safety check: PassMIT2 days ago
468

分析 Code Scanning (CodeQL) 告警,评估安全风险并创建修复任务。当用户要求分析 Code Scanning 告警、CodeQL 告警时触发。参数为告警编号。

ModelEngine-Group/fit-framework2.1k—~187Automated safety check: PassMIT7 mo ago
469

Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks.

dralgorhythm/claude-agentic-framework125—~581Automated safety check: PassNo licence2 mo ago
470

Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
471

Run a Nuclei security scan against the target URL and report findings by severity.

MigoXLab/webqa-agent232—~846Automated safety check: PassApache-2.03 mo ago
472

Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

CommonHuman-Lab/nyxstrike157—~1.1kAutomated safety check: PassUnknown2 days ago
473
473.Scan CodeOfficial

Scans a Power Pages site project for security issues in source code and dependencies.

microsoft/power-platform-skills984—~3.4kAutomated safety check: NotesMITyesterday
474

Run an end-to-end OpenTaint application-security analysis while owning the long project build and scans and delegating each other pipeline stage.

seqra/opentaint163—~2.2kAutomated safety check: PassApache-2.02 days ago
475

Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus.

bugbountywithmarco/bugbounty-disclosed-reports120—~524Automated safety check: PassNo licence2 mo ago
476

Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

cdxgen/cdxgen1.1k—~1.5kAutomated safety check: PassApache-2.0today
477

Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

Encod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT1 mo ago
478

Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.

transilienceai/communitytools563—~1.8kAutomated safety check: PassMIT2 mo ago
479

Run a Codex-CLI static-analysis parity review of the current diff against the local RPython/PyPy sources, then act on it — fix the regressions and new mismatches in-session, and file the rest as…

youknowone/pyre116—~2.3kAutomated safety check: PassUnknowntoday
480

Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates…

johnson7788/MultiUserClaw327—~3kAutomated safety check: PassMIT1 mo ago