Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 817 | 817.Fuzzing APIs Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. | jeremylongshore/ | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | yesterday |
| 818 | Execute use when you need to work with security and compliance. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 819 | Process use when you need to work with security and compliance. | jeremylongshore/ | 2.8k | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 820 | Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0. | OWASP/ | 188 | — | ~622 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 821 | WordPress plugin development with hooks, security, REST API, custom post types. | secondsky/ | 227 | — | ~4.6k | Automated safety check: Pass | MIT | 13 days ago |
| 822 | 822.Cloud Security Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails. | borghei/ | 891 | — | ~3.5k | Automated safety check: Pass | MIT | 4 days ago |
| 823 | A skill your agent uses when handling database errors in Frappe/ERPNext. | Impertio-Studio/ | 189 | — | ~3.9k | Automated safety check: Pass | MIT | 24 days ago |
| 824 | A skill your agent uses when debugging or preventing errors in Frappe Server Scripts. | Impertio-Studio/ | 189 | — | ~3k | Automated safety check: Pass | MIT | 24 days ago |
| 825 | 825.Tool Reference Optimized command-line arguments for all Android RE tools — jadx, baksmali, aapt, apkid, rg. | Paresh-Maheshwari/ | 178 | — | ~1.4k | Automated safety check: Pass | GPL-3.0 | 12 days ago |
| 826 | 826.Security Testing Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests… | petrkindlmann/ | 170 | — | ~4.9k | Automated safety check: Pass | MIT | 4 mo ago |
| 827 | A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check. | elophanto/ | 106 | — | ~2.7k | Automated safety check: Pass | Unknown | 10 days ago |
| 828 | 828.Sca Security Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to… | hardw00t/ | 105 | — | ~3k | Automated safety check: Pass | No licence | 5 mo ago |
| 829 | A skill your agent uses when code touches user input, tokens, redirects, raw SQL, or logging — injection, XSS, atom exhaustion, timing attacks, audit tooling. | j-morgan6/ | 167 | — | ~2k | Automated safety check: Pass | MIT | 3 mo ago |
| 830 | 830.Hunt Auth Bypass Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~8.2k | Automated safety check: Pass | MIT | yesterday |
| 831 | Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.7k | Automated safety check: Pass | MIT | yesterday |
| 832 | 832.Hunt Sqli Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.5k | Automated safety check: Pass | MIT | yesterday |
| 833 | 833.Stack Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally… | guardana/ | 131 | — | ~568 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 834 | 834.API Hardening API hardening for Express, FastAPI, and serverless. An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~12k | Automated safety check: Pass | MIT | 6 days ago |
| 835 | 835.Secure Auth Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~14k | Automated safety check: Pass | MIT | 6 days ago |
| 836 | 836.Sast Sqli Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 837 | Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill. | ptn1411/ | 219 | — | ~1.1k | Automated safety check: Pass | No licence | 19 days ago |
| 838 | Use the open-source CodeQL ecosystem for .NET security analysis. | managedcode/ | 138 | — | ~977 | Automated safety check: Pass | MIT | 4 days ago |
| 839 | Use the open-source free Roslynator analyzer packages and optional CLI for .NET. | managedcode/ | 138 | — | ~1.2k | Automated safety check: Pass | MIT | 4 days ago |
| 840 | External recon for software supply-chain attack surface. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~4.3k | Automated safety check: Warn | MIT | 2 days ago |
| 841 | Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 842 | Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 843 | Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 844 | Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 845 | Extracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 846 | Runs NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 847 | 847.Review Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit. | softspark/ | 179 | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | 3 days ago |
| 848 | 848.Waf Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic. | TheDecipherist/ | 338 | — | ~1.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 849 | 849.Runtime Sentinel Runtime security guardian for OpenClaw agents. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~1.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 850 | Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.5k | Automated safety check: Notes | MIT | yesterday |
| 851 | Audit a Python project's installed dependencies for known CVEs by wrapping pip-audit (PyPA's official vulnerability auditor) and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.3k | Automated safety check: Notes | MIT | yesterday |
| 852 | Probe a target for directories that return auto-generated index listings instead of denying or serving a specific file — exposes the full file tree under any reachable directory, including files the… | jeremylongshore/ | 2.8k | — | ~1.8k | Automated safety check: Notes | MIT | yesterday |
| 853 | Scan a source tree for SQL-injection vulnerable patterns: string concatenation into queries, f-string interpolation in SQL, string-format substitution into raw queries, deprecated cursor methods… | jeremylongshore/ | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 854 | Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies. | jeremylongshore/ | 2.8k | — | ~2.2k | Automated safety check: Notes | MIT | yesterday |
| 855 | 855.Validator Expert Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices. | jeremylongshore/ | 2.8k | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 856 | 856.Sast Scanning Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. | BagelHole/ | 1.2k | — | ~2.2k | Automated safety check: Pass | MIT | 4 mo ago |
| 857 | A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing… | jabrena/ | 447 | — | ~885 | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 858 | A skill your agent uses when you need to write or review programmatic JDBC with Spring — including JdbcClient (Spring Framework 7+) as the default API, JdbcTemplate only where batch/streaming APIs… | jabrena/ | 447 | — | ~975 | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 859 | 859.Audit Audit current changes, a path, or the full project for quality, security, performance, or test problems and record durable findings. | aiblueprinthq/ | 463 | — | ~6.7k | Automated safety check: Pass | MIT | 2 days ago |
| 860 | 860.Feature Verify Feature verification (READ-ONLY, P0-P5). An agent skill from sd0xdev/sd0x-harness. | sd0xdev/ | 192 | — | ~3.2k | Automated safety check: Notes | MIT | 3 days ago |
| 861 | 861.Security Review Security review via Codex exec. An agent skill from sd0xdev/sd0x-harness. | sd0xdev/ | 192 | — | ~1.1k | Automated safety check: Pass | MIT | 3 days ago |
| 862 | Coordinate Levyra work through OpenClaw using a dedicated repository workspace, compact delegation, specialized review and CI agents, project-native skills, evidence collection, durable memory, and… | LUC4N3X/ | 590 | — | ~2.2k | Automated safety check: Pass | GPL-3.0 | yesterday |
| 863 | A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. | SCStelz/ | 249 | — | ~13k | Automated safety check: Pass | MIT | 3 days ago |
| 864 | Turn a published threat-intelligence article into a tested threat-hunting campaign. | SCStelz/ | 249 | — | ~6.9k | Automated safety check: Pass | MIT | 3 days ago |