Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 433 | 433.Security Auditor Perform comprehensive security audit of a repository with detailed findings and step-by-step PoCs. | commercetools/ | 154 | — | ~3.3k | Automated safety check: Notes | MIT | 8 days ago |
| 434 | 434.Rust Review Rust 服务审查:panic、SQL 注入、密钥、错误吞没、遗留标记 | liuyanghejerry/ | 204 | — | ~180 | Automated safety check: Pass | MIT | 12 days ago |
| 435 | Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants. | trailofbits/ | 7.5k | — | ~1.1k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 436 | A skill your agent uses when reviewing Swift Concurrency performance and responsiveness, including task explosions, actor hopping, MainActor bottlenecks, cancellation, AsyncSequence cleanup… | Livsy90/ | 117 | — | ~2.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 437 | Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk. | openqa-cn/ | 152 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 438 | Respond to blocked package installs and manage the Interlinked supply-chain allowlist. | QuentinCody/ | 178 | — | ~2.8k | Automated safety check: Pass | MIT | 2 days ago |
| 439 | 439.Static Analysis Expertise in LLVM-based static analysis including dataflow analysis, pointer analysis, taint tracking, and program verification. | aftermathlabs/ | 438 | — | ~1.8k | Automated safety check: Pass | AGPL-3.0 | 8 days ago |
| 440 | Detect persistent instruction injection or long-term memory poisoning. | Tencent/ | 6.8k | — | ~791 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 441 | AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment | Hack23/ | 239 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 442 | 442.Redamon Testing How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie. | samugit83/ | 3k | — | ~1.8k | Automated safety check: Pass | MIT | 3 days ago |
| 443 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 444 | Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging. | criptogus/ | 288 | — | ~965 | Automated safety check: Pass | CC-BY-SA-4.0 | 3 days ago |
| 445 | 445.Security Scan Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes. | bagofwords1/ | 459 | — | ~1.7k | Automated safety check: Pass | Unknown | yesterday |
| 446 | Comprehensive API security review against OWASP API Security Top 10 (2023). | OWASP/ | 188 | — | ~744 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 447 | 447.Static Security Static security review for Flutter mobile apps and Dart code: hardcoded secrets, insecure storage, unsafe network calls, leaky logs, vulnerable dependencies. | VeryGoodOpenSource/ | 170 | — | ~4.4k | Automated safety check: Notes | MIT | 5 days ago |
| 448 | 448.Program Analysis Use astgrepscan, sourcesinkscan, and smtcheckreachability (mantisprogramanalysis MCP server) to move a candidate toward a proven-reachable finding | deonmenezes/ | 503 | — | ~551 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 449 | 449.Sherlock OSINT username search across 400+ social networks. An agent skill from Tommy-yw/RunbookHermes. | Tommy-yw/ | 546 | 3 repos | ~1.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 450 | Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast. | trailofbits/ | 7.5k | — | ~5.6k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 451 | Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang. | trailofbits/ | 7.5k | — | ~6.1k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 452 | 452.Refactor Behaviour-preserving restructuring and cleanup — splitting an oversized module, removing dead code, finished scripts, flags or documents, consolidating duplicates, tightening comments. | guardana/ | 259 | — | ~786 | Automated safety check: Pass | Apache-2.0 | today |
| 453 | Usar para sincronizar la documentación viva del proyecto después de una fase. | 686f6c61/ | 117 | — | ~382 | Automated safety check: Pass | MIT | 1 mo ago |
| 454 | Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition. | bbartling/ | 173 | — | ~2.2k | Automated safety check: Pass | Unknown | today |
| 455 | 455.Malware Analysis A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction… | hypnguyen1209/ | 388 | — | ~2.3k | Automated safety check: Pass | MIT | 13 days ago |
| 456 | 456.AWS Iam Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 457 | 457.User Management Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~2.8k | Automated safety check: Notes | MIT | yesterday |
| 458 | 458.Windows Server Administer Windows Server systems. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~2.9k | Automated safety check: Pass | MIT | yesterday |
| 459 | 459.Cve Scan Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart). | softspark/ | 180 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 460 | Black-box security audit of a DEPLOYED AI agent (not the MCP server behind it) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR… | awarexone/ | 5.3k | — | ~1.1k | Automated safety check: Pass | MIT | 2 days ago |
| 461 | Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. | github/ | 40k | 1 repo | ~3.4k | Automated safety check: Pass | MIT | 2 days ago |
| 462 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 463 | 463.Lint Run and fix the repository static analysis suite. An agent skill from ethereum/execution-specs. | ethereum/ | 1.2k | — | ~286 | Automated safety check: Pass | CC0-1.0 | yesterday |
| 464 | Scan package manifests and lockfiles for outdated and vulnerable dependencies. | cobusgreyling/ | 11k | — | ~531 | Automated safety check: Pass | MIT | today |
| 465 | 465.Dast Zap Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection. | AgentSecOps/ | 220 | 1 repo | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 466 | Deep reentrancy vulnerability analysis for Solidity contracts. | alt-research2/ | 104 | — | ~1.8k | Automated safety check: Pass | Unknown | 4 mo ago |
| 467 | 467.SQL Code Review Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle). | totvs/ | 143 | — | ~3.5k | Automated safety check: Pass | MIT | 6 days ago |
| 468 | S3 resiliency, security, and data protection review. An agent skill from aws/tools-for-devops-agent. | aws/ | 103 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 469 | Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. | trailofbits/ | 7.5k | — | ~996 | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 470 | Performs comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes. | trailofbits/ | 7.5k | — | ~11k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 471 | Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies… | eser/ | 128 | — | ~598 | Automated safety check: Pass | Unknown | 7 days ago |
| 472 | 472.Security Review Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. | affaan-m/ | 277k | 1 repo | ~3.2k | Automated safety check: Notes | MIT | today |
| 473 | 473.PR Audit Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation… | akitaonrails/ | 216 | — | ~4.8k | Automated safety check: Pass | No licence | 18 days ago |
| 474 | Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 475 | 475.Web Recon Web content discovery and technology fingerprinting using gobuster, ffuf, feroxbuster, katana, httpx, and wafw00f | CommonHuman-Lab/ | 157 | — | ~907 | Automated safety check: Pass | Unknown | 2 days ago |
| 476 | For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the… | lyonzin/ | 292 | — | ~2.3k | Automated safety check: Pass | MIT | 2 days ago |
| 477 | Generates edge case, failure mode, and spec-driven test cases. | ash1794/ | 163 | — | ~1.4k | Automated safety check: Pass | MIT | 4 days ago |
| 478 | Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 479 | 479.Distribution Constructs distributor accounts, inventory binds, commission or markup, and browse-and-quote, including the ready-to-sell scene. | openqa-cn/ | 152 | — | ~477 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 480 | Security-focused code review mapped to OWASP Top 10 and ASVS. | OWASP/ | 188 | — | ~549 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |