Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 625 | 625.Security Audit Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. | decebals/ | 751 | — | ~3.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 626 | 626.Nmap Parse Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills. | SpecterOps/ | 706 | — | ~738 | Automated safety check: Pass | Apache-2.0 | 18 days ago |
| 627 | Reconstruct a method or type as C and IL — decompiled source, annotated source with hidden facts, raw IL, fidelity levels, and IL-offset lookup. | richlander/ | 151 | — | ~2.4k | Automated safety check: Pass | No licence | yesterday |
| 628 | 628.Sast Patterns Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. | vibeeval/ | 532 | — | ~4.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 629 | Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories. | alt-research2/ | 104 | — | ~1.6k | Automated safety check: Notes | Unknown | 4 mo ago |
| 630 | Review Maple security across authentication, account isolation, local persistence, Tauri IPC and capabilities, OAuth and deep links, the Local OpenAI Proxy, Agent Mode tools and permissions, MCP… | MaplePrivacyLabs/ | 102 | — | ~7.1k | Automated safety check: Pass | MIT | yesterday |
| 631 | 631.Autoresearch Autonomous goal-directed iteration loop: modify, verify, keep/discard against a metric or a checkable success predicate, with bounded cycles, plateau/ceiling backstops, safety-screened commands, and… | leo-kuang-ai/ | 107 | — | ~2.2k | Automated safety check: Pass | MIT | 3 days ago |
| 632 | Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to. | arandu-io/ | 281 | — | ~5.9k | Automated safety check: Pass | MIT | yesterday |
| 633 | 633.Wordpress Complete WordPress development workflow covering theme development, plugin creation, WooCommerce integration, performance optimization, and security hardening. | sickn33/ | 47k | 2 repos | ~348 | Automated safety check: Pass | MIT | 2 days ago |
| 634 | Assess race conditions, transactional invariants, idempotency, retries, replay, rate and quota enforcement, algorithmic complexity, resource amplification, and cost abuse during authorized… | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 635 | Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP… | trilwu/ | 157 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 636 | Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs. | forefy/ | 152 | — | ~3.1k | Automated safety check: Pass | MIT | 7 days ago |
| 637 | 637.Audit Recon A skill your agent uses when performing initial audit reconnaissance. | ccashwell/ | 131 | — | ~1.5k | Automated safety check: Pass | MIT | 11 days ago |
| 638 | Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 639 | 639.Dsl Vm Reverse Reverse JavaScript-based custom DSL/VM interpreters and risk-control engines: identify IIFE/switch-based opcode dispatch, extract opcode tables, and capture runtime semantics. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 640 | 640.Go Rust Reverse Reverse engineer stripped Go and Rust binaries: runtime recognition, pclntab/module metadata recovery, panic-string analysis, and idiomatic decompilation strategies. | sickn33/ | 47k | 1 repo | ~458 | Automated safety check: Pass | MIT | 2 days ago |
| 641 | 641.Hunt Auth Bypass Hunting skill for auth bypass vulnerabilities. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~6.6k | Automated safety check: Pass | MIT | 2 days ago |
| 642 | Hunt cloud / infrastructure misconfigurations. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~3.6k | Automated safety check: Notes | MIT | 2 days ago |
| 643 | 643.macOS Reverse Authorized macOS and Mach-O reverse engineering: codesign inspection, Objective-C/Swift recovery, endpoint-security surfaces, and Apple-platform malware analysis. | sickn33/ | 47k | 1 repo | ~466 | Automated safety check: Pass | MIT | 2 days ago |
| 644 | 644.Production Audit Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health. | sickn33/ | 47k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | 2 days ago |
| 645 | 645.Sast Scanning Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 646 | 646.Skill Optimizer Diagnose and optimize Agent Skills (SKILL.md) with real session data and research-backed static analysis. | sickn33/ | 47k | 1 repo | ~3k | Automated safety check: Pass | MIT | 2 days ago |
| 647 | Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Pass | CC0-1.0 | 2 days ago |
| 648 | Soroban smart contract security audit register: authorization checks, panic pathways, integer overflows, and storage footprint verification for Stellar. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Pass | MIT | 2 days ago |
| 649 | Automated market maker liquidity pool register: constant-product invariant curves, swap fee tiers, and LP token shares for Soroban DeFi. | sickn33/ | 47k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 2 days ago |
| 650 | Soroban ledger state rent and TTL extension register: live state tracking, bump thresholds, rent fee reserves, and archive boundaries. | sickn33/ | 47k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 2 days ago |
| 651 | Soroban SEP-41 token contract architecture register: admin control, supply caps, metadata standard, and transfer event emissions on Stellar. | sickn33/ | 47k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 2 days ago |
| 652 | Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 653 | Systematically deobfuscates multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure. | mukul975/ | 34k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 654 | Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 655 | Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 656 | Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 657 | Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images. | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 658 | Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and runs detection… | mukul975/ | 34k | — | ~9.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 659 | Laravel 框架特效安全审计工具。针对 Laravel 常见鉴权/CSRF/Session/模型填充/Blade 渲染等框架特性进行白盒静态审计,并将风险映射到你现有通用漏洞类型体系(AUTH/CSRF/LOGIC/XSS/CFG 等)。 | 0xShe/ | 402 | 1 repo | ~821 | Automated safety check: Pass | No licence | 6 mo ago |
| 660 | 660.Php Ssrf Audit PHP Web 源码 SSRF 审计工具。识别用户可控 URL/地址进入网络请求 Sink,追踪内网/协议/端口限制与回显,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~481 | Automated safety check: Pass | No licence | 6 mo ago |
| 661 | Symfony 框架特效安全审计工具。针对 Symfony 常见 security.yaml、CSRF、Twig/Twig raw、表达式与访问控制等框架机制做白盒静态审计,并将风险映射到通用漏洞类型体系(AUTH/CSRF/CFG/XSS/TPL/LOGIC 等)。 | 0xShe/ | 402 | 1 repo | ~599 | Automated safety check: Pass | No licence | 6 mo ago |
| 662 | ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。 | 0xShe/ | 402 | 1 repo | ~779 | Automated safety check: Pass | No licence | 6 mo ago |
| 663 | WordPress 框架特效安全审计工具。针对 WordPress 常见 nonce/capability/checkadminreferer、AJAX action、escape/sanitize、重定向、安全上传与远程请求等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/SQL/CFG/SSRF 等)。 | 0xShe/ | 402 | 1 repo | ~666 | Automated safety check: Pass | No licence | 6 mo ago |
| 664 | 664.Php Yii Audit Yii 框架特效安全审计工具。针对 Yii(通常指 Yii2)访问控制(AccessControl/RBAC)、CSRF、输入过滤规则、输出编码策略、URL/重定向安全等进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/CFG/LOGIC 等)。 | 0xShe/ | 402 | 1 repo | ~528 | Automated safety check: Pass | No licence | 6 mo ago |
| 665 | Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. | Varnan-Tech/ | 674 | — | ~3k | Automated safety check: Notes | MIT | 1 mo ago |
| 666 | Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains | NeoTheCapt/ | 143 | — | ~608 | Automated safety check: Pass | No licence | 2 mo ago |
| 667 | 667.Money Quality Code and product quality gates for shipping with confidence. | iamzifei/ | 1k | — | ~5.7k | Automated safety check: Pass | Unknown | 1 mo ago |
| 668 | A skill your agent uses when managing Alibaba Cloud Key Management Service (KMS) via OpenAPI/SDK, including the user needs key lifecycle/resource operations, policy/configuration changes, status… | cinience/ | 397 | — | ~699 | Automated safety check: Pass | MIT | 2 mo ago |
| 669 | 669.Security Review Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles. | affaan-m/ | 276k | — | ~3.4k | Automated safety check: Notes | MIT | yesterday |
| 670 | 670.Golang Testing Patrones de pruebas Go incluyendo pruebas basadas en tablas, subpruebas, benchmarks, fuzzing y cobertura de código. | affaan-m/ | 276k | — | ~4.3k | Automated safety check: Pass | MIT | yesterday |
| 671 | Quarkusプロジェクト検証ループ:ビルド、静的分析、カバレッジ付きテスト、セキュリティスキャン、ネイティブコンパイル、本番環境またはPR前の差分レビュー。 | affaan-m/ | 276k | — | ~2.2k | Automated safety check: Pass | MIT | yesterday |
| 672 | Buenas prácticas de Spring Security para autenticación/autorización, validación, CSRF, secretos, cabeceras, limitación de velocidad y seguridad de dependencias en servicios Java Spring Boot. | affaan-m/ | 276k | — | ~2.1k | Automated safety check: Pass | MIT | yesterday |