Search
Security · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 817 | Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations. | forefy/ | 152 | — | ~3.7k | Automated safety check: Notes | MIT | 7 days ago |
| 818 | Plan and coordinate a model deployment to Amazon SageMaker, including serving stack and real-time versus async inference. | waybarrios/ | 534 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 819 | Screen fetched web pages, tool results, emails and file contents for instructions aimed at the agent before they enter context, using a keyless multi-label classifier over chunks. | mrmps/ | 424 | — | ~1.5k | Automated safety check: Pass | MIT | 4 days ago |
| 820 | 820.Soc Alert Triage Rank a SIEM or EDR alert queue before a human opens it. An agent skill from mrmps/classifier-dev. | mrmps/ | 424 | — | ~1.5k | Automated safety check: Pass | MIT | 4 days ago |
| 821 | 821.Review Ревью изменений с фокусом на безопасность по стандартам команды. | justxor/ | 276 | — | ~135 | Automated safety check: Pass | MIT | 10 days ago |
| 822 | 822.Snyk Jira Ingest Pull REAL Snyk SAST findings from EPAM Jira (Data Center) via the search-export API using a Personal Access Token, and emit them as a stage-output.json artifact for a downstream triage stage. | epam/ | 504 | — | ~295 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 823 | A skill your agent uses when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit… | cwinvestments/ | 423 | — | ~3.9k | Automated safety check: Pass | Proprietary | 15 days ago |
| 824 | A skill your agent uses when the user says 'check RLS', 'audit RLS', 'RLS policies', 'row level security', 'Supabase security audit', or needs to verify table-level access control. | cwinvestments/ | 423 | — | ~2.9k | Automated safety check: Notes | Proprietary | 15 days ago |
| 825 | [omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and… | rlaope/ | 3.2k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 826 | [omh] Agent or automation safety risks: review prompt, tool, secret, dependency, destructive-action, and explicit local plugin risks before agent or code execution. | rlaope/ | 3.2k | — | ~2.3k | Automated safety check: Pass | MIT | yesterday |
| 827 | Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. | tobihagemann/ | 408 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 828 | 828.Security Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks. | notque/ | 441 | — | ~2.6k | Automated safety check: Notes | MIT | 2 days ago |
| 829 | IAM policy review, hardening, and least privilege implementation | aiskillstore/ | 433 | 4 repos | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 830 | Comprehensive AWS security posture assessment using AWS CLI and security best practices | aiskillstore/ | 433 | 4 repos | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 831 | 831.Create Policy Create OPA governance policies for Harness via MCP. An agent skill from harness/harness-skills. | harness/ | 115 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 832 | 832.Security Scan A skill your agent uses for a standard, single-pass security audit of an entire repository or a scoped path, package, folder, or submodule with no diff to review. | vlinx-io/ | 281 | — | ~1.7k | Automated safety check: Pass | MIT | 4 days ago |
| 833 | 833.Web2 Recon Web2 recon pipeline | sickn33/ | 47k | 1 repo | ~3.6k | Automated safety check: Notes | MIT | 2 days ago |
| 834 | Configure and execute authenticated (credentialed) vulnerability scans using OpenVAS/Greenbone Vulnerability Management (GVM) with SSH, SMB, or ESXi credentials to detect local vulnerabilities… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 835 | Plan and run authenticated (credentialed) vulnerability scans with scanners such as Nessus, Qualys, OpenVAS, or Rapid7 InsightVM, using SSH, SMB, WinRM, or SNMPv3 credentials to inspect installed… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 836 | Azure Key Vault SDK for Python. An agent skill from microsoft/skills. | microsoft/ | 3.1k | — | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 837 | 837.CI CD Security CI/CD pipeline security, supply chain security, SLSA compliance, artifact signing, dependency scanning | Hack23/ | 239 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 838 | A skill your agent uses when auditing an authorized website, SaaS, API, AI app, local code path, GitHub repo, staging URL, or owned runtime for security risks, vulnerability checklist scoring… | yaojingang/ | 1.3k | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 839 | Software supply-chain defensive security reference: SBOM generation and verification (SPDX / CycloneDX), dependency-confusion defense, malicious-package triage playbook, SLSA provenance levels… | modu-ai/ | 1.2k | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 840 | Provides expert guidance on Identity and Access Management (IAM) and authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default… | google/ | 21k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 841 | A skill your agent uses when auditing dependency health — outdated packages, CVE triage with attack-vector weighting, deprecated/declining library detection (trend-watch). | mizchi/ | 360 | — | ~1.5k | Automated safety check: Pass | No licence | 9 days ago |
| 842 | 842.Hunter 22 Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw… | aeonfun/ | 770 | — | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 843 | 843.Cpg Analysis Deep code property graph analysis with Joern CPG (AST+CFG+PDG) and CodeQL for control flow, data flow, taint analysis, and security auditing | alinaqi/ | 707 | — | ~2k | Automated safety check: Pass | MIT | 17 days ago |
| 844 | 844.Security Audit Structured, adversarial, multi-phase security audit of a codebase — recon → coverage-led hunting → finder≠validator validation → machine-readable findings → target-neutral report | alinaqi/ | 707 | — | ~1.6k | Automated safety check: Notes | MIT | 17 days ago |
| 845 | 845.Debug Rule Debug a rule or approximation that behaves unexpectedly by tracing where taint is dropped. | seqra/ | 163 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 846 | 846.Run Scan Run an OpenTaint scan on project and produces the SARIF report. | seqra/ | 163 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 847 | Mark which of a project's dependency libraries could introduce taint sources. | seqra/ | 163 | — | ~733 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 848 | Analyze session management implementations to identify security vulnerabilities in web applications. | jeremylongshore/ | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 849 | Validate encryption implementations and cryptographic practices. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 850 | Analyze code, infrastructure, and configurations by conducting comprehensive security audits. | jeremylongshore/ | 2.8k | — | ~1k | Automated safety check: Pass | MIT | yesterday |
| 851 | 851.Plugin Auditor Audit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review… | jeremylongshore/ | 2.8k | — | ~1.5k | Automated safety check: Notes | MIT | yesterday |
| 852 | Analyze and guide security incident response, investigation, and remediation processes. | jeremylongshore/ | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | yesterday |
| 853 | Execute use when you need to work with security and compliance. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 854 | Execute this skill enables comprehensive vulnerability scanning using the vulnerability-scanner plugin. | jeremylongshore/ | 2.8k | — | ~927 | Automated safety check: Pass | MIT | yesterday |
| 855 | A skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products… | jabrena/ | 447 | — | ~3k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 856 | 856.Security Vite Review Vite security audit patterns for SPA and dev server security. | IgorWarzocha/ | 122 | — | ~1.2k | Automated safety check: Notes | No licence | 8 mo ago |
| 857 | 857.Cve Risk Score Retrieve CVE risk scores from NVD. An agent skill from transilienceai/communitytools. | transilienceai/ | 563 | — | ~565 | Automated safety check: Notes | MIT | 2 mo ago |
| 858 | 858.Risk Prioritiser Risk-based prioritisation of confirmed attack paths. An agent skill from transilienceai/communitytools. | transilienceai/ | 563 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 859 | 859.Ti Ingest Threat-intel signal ingest — converts a CVE + affected-asset + claim payload into a queued engagement-scope row for the validation pipeline. | transilienceai/ | 563 | — | ~676 | Automated safety check: Pass | MIT | 2 mo ago |
| 860 | 860.Stack Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally… | guardana/ | 131 | — | ~568 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 861 | Hunt for credential access techniques like LSASS dumping or browser credential theft. | dandye/ | 127 | — | ~1.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 862 | Symbolic execution and constraint solving with angr, Z3, Unicorn, and Qiling. | ptn1411/ | 219 | — | ~1.8k | Automated safety check: Notes | No licence | 19 days ago |
| 863 | Detects prompt injection using regex signature matching, heuristic scoring for structural anomalies, and DeBERTa-based transformer classification, flagging direct injections (system-prompt… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 864 | Detect and defend against indirect prompt injection hidden in web pages, documents, and images consumed by an agent, via content extraction (HTML/PDF/OCR), normalization, and scanning with LLM… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |