Search

Security · For developers

1,197 skills found, page 19.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
865

Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation.

majiayu000/spellbook287—~561Automated safety check: PassMIT3 days ago
866

Dangling markup injection playbook. An agent skill from yaklang/hack-skills.

yaklang/hack-skills2.4k—~3.3kAutomated safety check: PassMIT28 days ago
867

Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills.

yaklang/hack-skills2.4k—~2.5kAutomated safety check: PassMIT28 days ago
868

Advanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasses, and detection techniques.

yaklang/hack-skills2.4k—~2.8kAutomated safety check: PassMIT28 days ago
869

Subdomain takeover detection and exploitation playbook. An agent skill from yaklang/hack-skills.

yaklang/hack-skills2.4k—~2.6kAutomated safety check: PassMIT28 days ago
870

Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills.

yaklang/hack-skills2.4k—~2.8kAutomated safety check: NotesMIT28 days ago
871

AV/EDR evasion playbook for Windows. An agent skill from yaklang/hack-skills.

yaklang/hack-skills2.4k—~2.9kAutomated safety check: PassMIT28 days ago
872

Solidity security patterns, common vulnerabilities, and pre-deploy audit checklist.

austintgriffith/ethskills295—~4.9kAutomated safety check: PassNo licence1 mo ago
873

Binance Web3 official skill — security audit for token contracts, detecting honeypots, rug pulls, and malicious functions across BSC, Base, Solana, and Ethereum.

TermiX-official/cryptoclaw100—~695Automated safety check: PassMIT4 mo ago
874

ANALYSIS SKILL — Azure compliance and security auditing: best practices, Key Vault expiration monitoring, resource validation.

jonathan-vella/apex217—~1.6kAutomated safety check: PassMITyesterday
875

Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces.

SnailSploit/Claude-Red7.4k—~5kAutomated safety check: PassMIT21 days ago
876

Apply security-conscious thinking when generating or modifying code.

techygarg/lattice199—~1.5kAutomated safety check: PassMITyesterday
877
sickn33/agentic-awesome-skills47k1 repo~2.1kAutomated safety check: NotesMIT2 days ago
878sickn33/agentic-awesome-skills47k1 repo~2.4kAutomated safety check: PassMIT2 days ago
879

Azure Key Vault Certificates library for Rust. An agent skill from microsoft/skills.

microsoft/skills3.1k—~2kAutomated safety check: PassMIT2 days ago
880

Azure Key Vault Keys library for Rust. An agent skill from microsoft/skills.

microsoft/skills3.1k—~1.9kAutomated safety check: PassMIT2 days ago
881
881.Glint

Conventions for authoring or editing analyzers in the glint/ Go static-analysis package — Speakeasy's custom golangci-lint plugin built on go/analysis.

speakeasy-api/gram273—~6.4kAutomated safety check: PassAGPL-3.0yesterday
882

A skill your agent uses when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired…

coralogix/cx-cli121—~1.8kAutomated safety check: PassApache-2.04 days ago
883

Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP…

LeoYeAI/openclaw-master-skills2.2k—~6.1kAutomated safety check: NotesMIT2 mo ago
884

Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.

owid/etl159—~2.8kAutomated safety check: PassMITyesterday
885

A skill your agent uses when analyzing a Rust binary without source code, reverse engineering Rust executables or libraries, demangling Rust symbols, recovering likely crate namespaces, tracing…

hashgraph-online/awesome-codex-plugins1.3k—~3.7kAutomated safety check: PassApache-2.0yesterday
886

Run a fast AWS Security Agent diff scan on only the changed code since a git ref.

aws/agent-toolkit-for-aws2.8k—~1kAutomated safety check: PassApache-2.0yesterday
887

Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.

aws/agent-toolkit-for-aws2.8k—~2.9kAutomated safety check: PassApache-2.0yesterday
888

Find decision-makers at a specific company using Apollo, Crustdata, Fiber, and PDL people search via Gooseworks MCP.

gooseworks-ai/goose-skills1.2k1 repo~2.7kAutomated safety check: PassMIT2 days ago
889
889.Azure Kusto IrqlOfficial

Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations.

microsoft/GitHub-Copilot-for-Azure255—~2.6kAutomated safety check: PassMITyesterday
890

Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step.

transilienceai/communitytools563—~476Automated safety check: PassMIT2 mo ago
891

Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills.

BankrBot/skills1.2k—~3.4kAutomated safety check: PassNo licenceyesterday
892

安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。

devcodex-labs/devcodex439—~771Automated safety check: PassAGPL-3.024 days ago
893
893.Loop

Full execution protocol for MODE: LOOP — the compound-engineering loop: brainstorm → plan → build → review → improve, iterating under defense-in-depth stop conditions with generator/critic…

ZaxbyHub/opencode-swarm494—~3.9kAutomated safety check: PassMITyesterday
894

Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers.

Houseofmvps/ultraship123—~3.9kAutomated safety check: NotesMIT3 mo ago
895

API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT1 mo ago
896

Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)…

Encod3d-Sec/TORCH329—~3.1kAutomated safety check: PassMIT1 mo ago
897

Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node.

Encod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT1 mo ago
898

OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection.

Encod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT1 mo ago
899

GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE.

Encod3d-Sec/TORCH329—~2kAutomated safety check: PassMIT1 mo ago
900

macOS attack hunting - foothold to root/persistence on a macOS host.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT1 mo ago
901

Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup…

Encod3d-Sec/TORCH329—~1kAutomated safety check: PassMIT1 mo ago
902

Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

OWASP/secure-agent-playbook188—~494Automated safety check: PassCC-BY-4.016 days ago
903
903.Doca Aes GcmOfficial

A skill your agent uses when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt, querying docaaesgcmcap for…

NVIDIA/skills3.6k—~4.2kAutomated safety check: PassApache-2.02 days ago
904

Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

Kilo-Org/kilo-marketplace1901 repo~1.9kAutomated safety check: PassMIT12 days ago
905

Weekly. An agent skill from markfulton/ai-employees.

markfulton/ai-employees543—~14kAutomated safety check: PassMITyesterday
906

Systematically map and remove malware, backdoors, and attacker persistence mechanisms (registry Run keys, scheduled tasks, WMI subscriptions, services, cron/init.d) from infected Windows and Linux…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.01 mo ago
907

Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.01 mo ago
908

Periodic security sweep of Atlas in four areas (MCP and CLI, the Tauri desktop shell, the web renderer and connectors, the supply chain and CI) that follows untrusted input to what it can reach…

wlsdks/ontology-atlas142—~182Automated safety check: PassMITyesterday
909

AI驱动的Java代码安全审计技能,实现系统化、高覆盖率的漏洞挖掘。使用场景: (1) 审计Java/Kotlin项目寻找安全漏洞(0day挖掘、代码审计、安全评估) (2) 企业级代码库的安全审计(支持大型项目) (3) 需要高质量、低幻觉率的安全审计报告 (4) CI/CD集成的前期漏洞发现 触发关键词:Java审计、代码审计、安全审计、漏洞挖掘、0day、安全评估、Java…

LeoYeAI/openclaw-master-skills2.2k—~3.1kAutomated safety check: PassMIT2 mo ago
910

A skill your agent uses when assessing code quality hygiene — TypeScript strictness, lint violations, dead code, and duplication.

mizchi/skills360—~717Automated safety check: PassNo licence9 days ago
911

A skill your agent uses when planning or reviewing tests for a code change, choosing between unit, focused regression, integration, contract, end-to-end, performance, security, property-based, or…

AnastasiyaW/codex-claude-code-config154—~2kAutomated safety check: PassMITyesterday
912

Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user…

utkusen/sast-skills1.3k—~7.5kAutomated safety check: PassMIT6 mo ago