Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 721 | 721.Error Log Mining Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills. | uphiago/ | 1.3k | — | ~3.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 722 | Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints | uphiago/ | 1.3k | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 723 | Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall… | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 724 | Screen a pull request from an outside contributor for hidden, obfuscated, or supply-chain-risky changes before any of its code runs. | different-ai/ | 24k | — | ~939 | Automated safety check: Warn | Unknown | yesterday |
| 725 | CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows). | pskoett/ | 315 | — | ~1.1k | Automated safety check: Pass | No licence | 6 days ago |
| 726 | Automated .NET/C decompilation and security analysis. An agent skill from ptn1411/skill. | ptn1411/ | 219 | — | ~929 | Automated safety check: Notes | No licence | 19 days ago |
| 727 | Choose and implement the right Circle wallet type for your application. | circlefin/ | 155 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 728 | 728.Evm Audit Flow A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint… | mtarcure/ | 165 | — | ~1.5k | Automated safety check: Pass | MIT | 20 days ago |
| 729 | Use as the lead skill when Python tests must expose scheduler/interleaving bugs in asyncio, threading, queues, workers, databases, caches, or mixed-concurrency code | dzhalaevd/ | 135 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 730 | 730.Offensive Mobile Mobile (Android + iOS) application penetration testing methodology. | SnailSploit/ | 7.4k | — | ~3.5k | Automated safety check: Pass | MIT | 21 days ago |
| 731 | Audit architecture, dead code, duplication, type confusion, and code smells across a codebase. | pedronauck/ | 634 | 1 repo | ~524 | Automated safety check: Pass | No licence | 27 days ago |
| 732 | PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills. | alirezarezvani/ | 28k | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 733 | 733.Codeql Use the open-source CodeQL ecosystem for .NET security analysis. | managedcode/ | 486 | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 734 | A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including… | hyodotdev/ | 155 | — | ~766 | Automated safety check: Pass | MIT | yesterday |
| 735 | PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). | tetherto/ | 685 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 736 | 736.Hunt LLM AI Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). | elementalsouls/ | 4.8k | — | ~4k | Automated safety check: Warn | MIT | 2 days ago |
| 737 | Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts. | ancoleman/ | 525 | — | ~3.5k | Automated safety check: Notes | MIT | 10 mo ago |
| 738 | Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification… | kubernetes-sigs/ | 294 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 739 | 739.Bio Sra Data Download raw sequencing reads from NCBI SRA using sra-tools (prefetch, fasterq-dump, vdb-validate) or the ENA mirror. | GPTomics/ | 1.2k | 2 repos | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 740 | Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. | c0x12c/ | 106 | — | ~1.6k | Automated safety check: Warn | No licence | 3 mo ago |
| 741 | Audit MCP (Model Context Protocol) server configurations for security issues. | github/ | 40k | — | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 742 | 742.Security Review Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it… | trycompai/ | 2k | — | ~853 | Automated safety check: Pass | AGPL-3.0 | 2 days ago |
| 743 | Azure Key Vault Keys SDK for Rust. An agent skill from aiskillstore/marketplace. | aiskillstore/ | 433 | 4 repos | ~1.1k | Automated safety check: Pass | No licence | yesterday |
| 744 | This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp ... | aiskillstore/ | 433 | 4 repos | ~2.7k | Automated safety check: Pass | No licence | yesterday |
| 745 | 745.Web Ssrf Server-Side Request Forgery detection→internal-access→proof for web apps. | s0ld13rr/ | 828 | — | ~660 | Automated safety check: Warn | MIT | 9 days ago |
| 746 | 746.Web Enumeration Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect | uphiago/ | 1.3k | — | ~2.8k | Automated safety check: Notes | MIT | 1 mo ago |
| 747 | 747.Php Csrf Audit PHP Web 源码 CSRF 审计工具。识别状态变更接口是否受 CSRF 保护,追踪 token 生成、校验与绕过条件,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~398 | Automated safety check: Pass | No licence | 6 mo ago |
| 748 | 748.Php Xss Audit PHP Web 源码 XSS 审计工具。识别用户输入进入输出上下文(HTML/属性/JS/URL/模板),分析转义与防护策略,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~370 | Automated safety check: Pass | No licence | 6 mo ago |
| 749 | 749.Architecture Verter codebase architecture: high-level module map, TypeScript packages, plugin system, CSS analysis, MCP server, static analysis types | pikax/ | 113 | — | ~5.6k | Automated safety check: Pass | MIT | yesterday |
| 750 | Run osv-scanner via the mantisosvscanner MCP server for SCA (vulnerable dependency) findings | deonmenezes/ | 503 | — | ~298 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 751 | Composite Phase-2 audit worker (ADR-150). An agent skill from ruvnet/ruflo. | ruvnet/ | 74k | — | ~720 | Automated safety check: Notes | MIT | yesterday |
| 752 | Weekly supply-chain hygiene scan (Perplexity Bumblebee). An agent skill from Szotasz/marveen. | Szotasz/ | 117 | — | ~2.1k | Automated safety check: Pass | MIT | yesterday |
| 753 | 753.Security Secrets Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows. | IgorWarzocha/ | 122 | — | ~1.2k | Automated safety check: Notes | No licence | 8 mo ago |
| 754 | 754.Sec Check Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code. | waynesutton/ | 627 | — | ~753 | Automated safety check: Pass | MIT | 4 mo ago |
| 755 | 755.Review Code Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in… | tobihagemann/ | 408 | — | ~3.3k | Automated safety check: Pass | MIT | 2 days ago |
| 756 | Security review of MCP (Model Context Protocol) server implementations and configurations. | OWASP/ | 188 | — | ~574 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 757 | Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's… | mukul975/ | 34k | — | ~963 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 758 | 758.Type Juggling PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC. | langbyyi/ | 129 | 1 repo | ~2.9k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 759 | 759.Xslt Injection XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. | langbyyi/ | 129 | 1 repo | ~3k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 760 | Comprehensive smart contract security audit framework with multi-expert analysis. | forefy/ | 152 | 1 repo | ~5.1k | Automated safety check: Pass | MIT | 7 days ago |
| 761 | 761.File Inclusion Detect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution | NeoTheCapt/ | 143 | — | ~988 | Automated safety check: Warn | No licence | 2 mo ago |
| 762 | Turn smart-contract audit findings and source evidence into a submission-ready Markdown report with an issue index, ordered finding IDs, actor-based scenarios, self-contained unit-test proofs of… | aviggiano/ | 144 | — | ~2.4k | Automated safety check: Pass | MIT | 26 days ago |
| 763 | A skill your agent uses when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection… | hypnguyen1209/ | 388 | — | ~826 | Automated safety check: Pass | MIT | 13 days ago |
| 764 | 764.Release Release preparation workflow - security audit → E2E tests → review → changelog → docs | parcadei/ | 3.9k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 8 mo ago |
| 765 | 765.Mobile Security Analyze Android or iOS game-security trust boundaries, packages, native code, platform integrity, instrumentation, attestation, and signing. | gmh5225/ | 3.6k | — | ~282 | Automated safety check: Pass | MIT | yesterday |
| 766 | 766.Azure Pim Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups. | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 767 | Proactive supply-chain watch for this repo. An agent skill from epam/ai-dial-chat. | epam/ | 504 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 768 | 768.Frida Hooker Generate and inject Frida hooks for dynamic instrumentation — license bypass, SSL pinning bypass, function tracing, crypto interception, anti-debug bypass. | ptn1411/ | 219 | — | ~983 | Automated safety check: Notes | No licence | 19 days ago |