Search
Security · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 433 | Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 434 | Conducts systematic reviews of privileged accounts to validate access rights, identify excessive or stale permissions, and enforce least privilege across PAM infrastructure. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 435 | Develops precise YARA and YARA-X rules for malware detection by identifying unique strings, byte sequences, PE header traits, and behavioral indicators in unpacked malware artifacts while minimizing… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 436 | Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 437 | Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 438 | 438.Keys Accounts Manage Ethereum keys, accounts, and keystores with Nethereum. | Nethereum/ | 2.3k | — | ~1.2k | Automated safety check: Pass | MIT | 6 days ago |
| 439 | 439.Audit Prep A skill your agent uses when preparing a codebase for security audit. | ccashwell/ | 131 | — | ~1.4k | Automated safety check: Pass | MIT | 11 days ago |
| 440 | A skill your agent uses when a B200/Blackwell kernel shows wrong results, uncoalesced global memory access, SMEM bank conflicts, a TMA swizzle that mismatches the Tensor Core read, or confused… | mirage-project/ | 2.5k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 441 | 441.Security Analyst Threat-model and find vulnerabilities, with practical remediation. | antonbabenko/ | 170 | — | ~1.1k | Automated safety check: Pass | MIT | 3 days ago |
| 442 | Produces a dynamic CycloneDX BOM by executing a command under the cdxgen safer-exec sandbox with tracebom, tracing dlopen shared-library loads, eBPF HTTP URL access, cryptographic library and… | cdxgen/ | 1.1k | — | ~2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 443 | Runs the cdxgen SBOM fidelity loop: scan with --introspect or --profile introspect, read the cdxgen fidelity report, execute its ranked remediations (the catalog spans the mainstream build… | cdxgen/ | 1.1k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 444 | Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials. | affaan-m/ | 276k | — | ~2.7k | Automated safety check: Pass | MIT | yesterday |
| 445 | Load a Spec Kitty agent profile on demand for interactive sessions, including identity, governance scope, boundaries, and initialization. | spec-kitty/ | 1.7k | — | ~364 | Automated safety check: Pass | MIT | yesterday |
| 446 | What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result | deonmenezes/ | 503 | — | ~376 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 447 | 447.Write Skill Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions. | apache/ | 114 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 448 | Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to… | microsoft/ | 4k | — | ~339 | Automated safety check: Pass | MIT | yesterday |
| 449 | 449.Security How to handle GRIDA-SEC-<id security boundaries in the Grida repo. | gridaco/ | 2.7k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 450 | 450.Serenity A skill your agent uses when evaluating US stocks through Serenity / @aleabitoreddit's AI and semiconductor supply-chain lens: upstream chokepoints, photonics/CPO bottlenecks, hyperscaler capex… | questflowai/ | 1.9k | — | ~935 | Automated safety check: Pass | MIT | 1 mo ago |
| 451 | Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold… | warpdotdev/ | 312 | 1 repo | ~2k | Automated safety check: Notes | MIT | 24 days ago |
| 452 | Assess a reported security vulnerability in GAIA and fill a PSIRT / JIRA triage: decide if it is valid & exploitable, whether it needs a CVE + bulletin, and produce the CVSS 4.0 score, CWE, and CVE… | amd/ | 1.6k | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 453 | 453.Atmos CI Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs… | cloudposse/ | 1.4k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 454 | Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation). | OWASP/ | 188 | — | ~694 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 455 | Pre-production audit, hardening, and go-live checklists for FrontMCP servers. | agentfront/ | 146 | — | ~6.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 456 | Secure AI agents against prompt injection, tool abuse, and data exfiltration with defense-in-depth controls. | sickn33/ | 47k | 1 repo | ~3.5k | Automated safety check: Notes | MIT | 2 days ago |
| 457 | Audit authorized codebases for exploitable vulnerabilities using scoped reconnaissance, adversarial review, validation, and structured reporting. | sickn33/ | 47k | 1 repo | ~3.3k | Automated safety check: Pass | MIT | 2 days ago |
| 458 | Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls. | sickn33/ | 47k | 1 repo | ~1k | Automated safety check: Notes | MIT | 2 days ago |
| 459 | 459.Email Security Authorized email security review: phishing analysis, SPF/DKIM/DMARC header authentication, BEC pattern investigation, and mailbox token abuse research. | sickn33/ | 47k | 1 repo | ~603 | Automated safety check: Pass | MIT | 2 days ago |
| 460 | 460.Ida Reverse Reverse engineer binaries with IDA Pro: decompilation, disassembly, data-flow tracking, cross-references, and IDA MCP automation for deep static analysis of PE/ELF/Mach-O targets. | sickn33/ | 47k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 461 | 461.Wifi Wireless Authorized wireless security assessment: Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauthentication testing. | sickn33/ | 47k | 1 repo | ~589 | Automated safety check: Pass | MIT | 2 days ago |
| 462 | 462.Infra Triage Infrastructure alert triage — dedup via YT search, deep PVE/K8s investigation, auto-escalation for recurring/flapping alerts, control plane deep dive for K8s controller nodes. | papadopouloskyriakos/ | 107 | — | ~714 | Automated safety check: Notes | No licence | 5 days ago |
| 463 | Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 464 | Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 465 | Analyzes bootkit and advanced rootkit malware infecting the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware for below-OS persistence, covering boot sector analysis, UEFI module… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 466 | Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 467 | Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 468 | Parse and analyze email headers (Received chain, Return-Path, Message-ID) to trace the true origin of a phishing email and validate SPF, DKIM, and DMARC results to confirm or rule out sender spoofing. | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 469 | Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 470 | Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules… | mukul975/ | 34k | — | ~654 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 471 | Query the Malpedia API to look up malware family aliases and naming (platform.familyname), pull community/vendor YARA rules, link families to threat actors, and map family relationships such as… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 472 | Parse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 473 | Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK… | mukul975/ | 34k | — | ~667 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 474 | Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. | mukul975/ | 34k | — | ~745 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 475 | Generate domain permutations with dnstwist and check DNS resolution to detect typosquatting, homograph phishing, and brand impersonation domains registered against your organization. | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 476 | Correlate Windows registry keys (USBSTOR, MountedDevices), Event Logs, and setupapi.dev.log to reconstruct USB device connection history, first/last-plugged timestamps, and drive letter mappings. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 477 | Parse Windows Prefetch (.pf) files with the windowsprefetch Python library to reconstruct application execution history, run counts, and accessed file/volume lists. | mukul975/ | 34k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 478 | Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 479 | Build an automated pipeline that ingests raw IOCs (URLs, IPs, domains, emails), normalizes and deduplicates them, then produces defanged renderings for safe human reading alongside canonical STIX… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 480 | Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |