Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 865 | Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation. | majiayu000/ | 287 | — | ~561 | Automated safety check: Pass | MIT | 3 days ago |
| 866 | Dangling markup injection playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~3.3k | Automated safety check: Pass | MIT | 28 days ago |
| 867 | Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.5k | Automated safety check: Pass | MIT | 28 days ago |
| 868 | Advanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasses, and detection techniques. | yaklang/ | 2.4k | — | ~2.8k | Automated safety check: Pass | MIT | 28 days ago |
| 869 | Subdomain takeover detection and exploitation playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.6k | Automated safety check: Pass | MIT | 28 days ago |
| 870 | Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.8k | Automated safety check: Notes | MIT | 28 days ago |
| 871 | AV/EDR evasion playbook for Windows. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.9k | Automated safety check: Pass | MIT | 28 days ago |
| 872 | 872.Security Solidity security patterns, common vulnerabilities, and pre-deploy audit checklist. | austintgriffith/ | 295 | — | ~4.9k | Automated safety check: Pass | No licence | 1 mo ago |
| 873 | Binance Web3 official skill — security audit for token contracts, detecting honeypots, rug pulls, and malicious functions across BSC, Base, Solana, and Ethereum. | TermiX-official/ | 100 | — | ~695 | Automated safety check: Pass | MIT | 4 mo ago |
| 874 | ANALYSIS SKILL — Azure compliance and security auditing: best practices, Key Vault expiration monitoring, resource validation. | jonathan-vella/ | 217 | — | ~1.6k | Automated safety check: Pass | MIT | yesterday |
| 875 | Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. | SnailSploit/ | 7.4k | — | ~5k | Automated safety check: Pass | MIT | 21 days ago |
| 876 | 876.Secure Coding Apply security-conscious thinking when generating or modifying code. | techygarg/ | 199 | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 877 | Hunt Insecure Deserialization | sickn33/ | 47k | 1 repo | ~2.1k | Automated safety check: Notes | MIT | 2 days ago |
| 878 | 878.Hunt File Upload Hunt file upload bugs | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 879 | Azure Key Vault Certificates library for Rust. An agent skill from microsoft/skills. | microsoft/ | 3.1k | — | ~2k | Automated safety check: Pass | MIT | 2 days ago |
| 880 | Azure Key Vault Keys library for Rust. An agent skill from microsoft/skills. | microsoft/ | 3.1k | — | ~1.9k | Automated safety check: Pass | MIT | 2 days ago |
| 881 | 881.Glint Conventions for authoring or editing analyzers in the glint/ Go static-analysis package — Speakeasy's custom golangci-lint plugin built on go/analysis. | speakeasy-api/ | 273 | — | ~6.4k | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 882 | A skill your agent uses when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired… | coralogix/ | 121 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 883 | 883.Clerk Auth Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP… | LeoYeAI/ | 2.2k | — | ~6.1k | Automated safety check: Notes | MIT | 2 mo ago |
| 884 | 884.Fix Dependabot Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies. | owid/ | 159 | — | ~2.8k | Automated safety check: Pass | MIT | yesterday |
| 885 | A skill your agent uses when analyzing a Rust binary without source code, reverse engineering Rust executables or libraries, demangling Rust symbols, recovering likely crate namespaces, tracing… | hashgraph-online/ | 1.3k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 886 | Run a fast AWS Security Agent diff scan on only the changed code since a git ref. | aws/ | 2.8k | — | ~1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 887 | Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. | aws/ | 2.8k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 888 | Find decision-makers at a specific company using Apollo, Crustdata, Fiber, and PDL people search via Gooseworks MCP. | gooseworks-ai/ | 1.2k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | 2 days ago |
| 889 | Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. | microsoft/ | 255 | — | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 890 | 890.Cloud Defense Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step. | transilienceai/ | 563 | — | ~476 | Automated safety check: Pass | MIT | 2 mo ago |
| 891 | 891.Polygraph Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills. | BankrBot/ | 1.2k | — | ~3.4k | Automated safety check: Pass | No licence | yesterday |
| 892 | 安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。 | devcodex-labs/ | 439 | — | ~771 | Automated safety check: Pass | AGPL-3.0 | 24 days ago |
| 893 | 893.Loop Full execution protocol for MODE: LOOP — the compound-engineering loop: brainstorm → plan → build → review → improve, iterating under defense-in-depth stop conditions with generator/critic… | ZaxbyHub/ | 494 | — | ~3.9k | Automated safety check: Pass | MIT | yesterday |
| 894 | 894.Security Audit Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers. | Houseofmvps/ | 123 | — | ~3.9k | Automated safety check: Notes | MIT | 3 mo ago |
| 895 | 895.Hunt API API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 896 | 896.Hunt Burp Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)… | Encod3d-Sec/ | 329 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 897 | Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 898 | 898.Hunt Federation OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 899 | 899.Hunt Injection GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE. | Encod3d-Sec/ | 329 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 900 | 900.Hunt macOS macOS attack hunting - foothold to root/persistence on a macOS host. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 901 | 901.Metasploit Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup… | Encod3d-Sec/ | 329 | — | ~1k | Automated safety check: Pass | MIT | 1 mo ago |
| 902 | 902.Sca Audit Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook. | OWASP/ | 188 | — | ~494 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 903 | A skill your agent uses when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt, querying docaaesgcmcap for… | NVIDIA/ | 3.6k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 904 | 904.Azure Key Vault Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. | Kilo-Org/ | 190 | 1 repo | ~1.9k | Automated safety check: Pass | MIT | 12 days ago |
| 905 | Weekly. An agent skill from markfulton/ai-employees. | markfulton/ | 543 | — | ~14k | Automated safety check: Pass | MIT | yesterday |
| 906 | Systematically map and remove malware, backdoors, and attacker persistence mechanisms (registry Run keys, scheduled tasks, WMI subscriptions, services, cron/init.d) from infected Windows and Linux… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 907 | Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 908 | 908.Security Audit Periodic security sweep of Atlas in four areas (MCP and CLI, the Tauri desktop shell, the web renderer and connectors, the supply chain and CI) that follows untrusted input to what it can reach… | wlsdks/ | 142 | — | ~182 | Automated safety check: Pass | MIT | yesterday |
| 909 | 909.Java Audit Skill AI驱动的Java代码安全审计技能,实现系统化、高覆盖率的漏洞挖掘。使用场景: (1) 审计Java/Kotlin项目寻找安全漏洞(0day挖掘、代码审计、安全评估) (2) 企业级代码库的安全审计(支持大型项目) (3) 需要高质量、低幻觉率的安全审计报告 (4) CI/CD集成的前期漏洞发现 触发关键词:Java审计、代码审计、安全审计、漏洞挖掘、0day、安全评估、Java… | LeoYeAI/ | 2.2k | — | ~3.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 910 | A skill your agent uses when assessing code quality hygiene — TypeScript strictness, lint violations, dead code, and duplication. | mizchi/ | 360 | — | ~717 | Automated safety check: Pass | No licence | 9 days ago |
| 911 | 911.Testing Strategy A skill your agent uses when planning or reviewing tests for a code change, choosing between unit, focused regression, integration, contract, end-to-end, performance, security, property-based, or… | AnastasiyaW/ | 154 | — | ~2k | Automated safety check: Pass | MIT | yesterday |
| 912 | 912.Sast Ssti Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user… | utkusen/ | 1.3k | — | ~7.5k | Automated safety check: Pass | MIT | 6 mo ago |