Search
Security · GitHub
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL). | secondsky/ | 227 | — | ~4k | Automated safety check: Notes | MIT | 11 days ago |
| 50 | 50.Web2 Recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis… | awarexone/ | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | yesterday |
| 51 | 51.Audit Scope Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. | forefy/ | 152 | — | ~2.3k | Automated safety check: Pass | MIT | 5 days ago |
| 52 | 52.Public Issue File a low-severity finding as an ordinary public GitHub issue after explicit analyst confirmation. | alpha-omega-security/ | 239 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 53 | Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. | github/ | 40k | 1 repo | ~3.4k | Automated safety check: Pass | MIT | today |
| 54 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 55 | 55.PR Audit Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation… | akitaonrails/ | 213 | — | ~4.8k | Automated safety check: Pass | No licence | 16 days ago |
| 56 | Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export. | GRCEngClub/ | 420 | — | ~2.4k | Automated safety check: Notes | Unknown | 5 days ago |
| 57 | Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration. | github/ | 5.4k | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 58 | 58.Reviewdog Automated code review and security linting integration for CI/CD pipelines using reviewdog. | AgentSecOps/ | 220 | 1 repo | ~3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 59 | Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. | sickn33/ | 47k | 2 repos | ~2.1k | Automated safety check: Notes | MIT | today |
| 60 | Human review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service. | sickn33/ | 47k | 2 repos | ~1.1k | Automated safety check: Pass | MIT | today |
| 61 | Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 62 | Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 63 | Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 64 | Google Workspace administration via the gws CLI (github.com/googleworkspace/cli). | alirezarezvani/ | 28k | — | ~3k | Automated safety check: Notes | MIT | 1 mo ago |
| 65 | Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 66 | 66.Pii Guard Personally identifiable information (PII) leak prevention for EverClaw. | profbernardoj/ | 112 | — | ~921 | Automated safety check: Pass | MIT | 1 mo ago |
| 67 | 67.Recon Osint A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover… | hypnguyen1209/ | 388 | — | ~2.2k | Automated safety check: Pass | MIT | 12 days ago |
| 68 | 68.Analyze Cve Full Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers. | openshift-eng/ | 120 | — | ~2k | Automated safety check: Notes | Apache-2.0 | 3 days ago |
| 69 | Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health. | sickn33/ | 47k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | today |
| 70 | CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows). | pskoett/ | 314 | — | ~1.1k | Automated safety check: Pass | No licence | 4 days ago |
| 71 | 71.Codeql Use the open-source CodeQL ecosystem for .NET security analysis. | managedcode/ | 486 | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 72 | A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including… | hyodotdev/ | 155 | — | ~766 | Automated safety check: Pass | MIT | today |
| 73 | PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). | tetherto/ | 683 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 74 | Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows. | IgorWarzocha/ | 122 | — | ~1.2k | Automated safety check: Notes | No licence | 8 mo ago |
| 75 | Proactive supply-chain watch for this repo. An agent skill from epam/ai-dial-chat. | epam/ | 504 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 76 | High-precision Google dorks for exposed configs, secrets, and credentials -- real-world validated | uphiago/ | 1.3k | — | ~1.1k | Automated safety check: Notes | MIT | 1 mo ago |
| 77 | A skill your agent uses for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge… | hyodotdev/ | 155 | — | ~2k | Automated safety check: Pass | MIT | today |
| 78 | Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. | tobihagemann/ | 409 | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 79 | A skill your agent uses when auditing an authorized website, SaaS, API, AI app, local code path, GitHub repo, staging URL, or owned runtime for security risks, vulnerability checklist scoring… | yaojingang/ | 1.3k | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 80 | 80.Hunter 22 Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw… | aeonfun/ | 767 | — | ~1.7k | Automated safety check: Pass | MIT | 2 days ago |
| 81 | Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~8.2k | Automated safety check: Pass | MIT | yesterday |
| 82 | Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill. | ptn1411/ | 220 | — | ~1.1k | Automated safety check: Pass | No licence | 18 days ago |
| 83 | External recon for software supply-chain attack surface. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~4.3k | Automated safety check: Warn | MIT | today |
| 84 | Use the open-source CodeQL ecosystem for .NET security analysis. | managedcode/ | 138 | — | ~977 | Automated safety check: Pass | MIT | 3 days ago |
| 85 | Subdomain takeover detection and exploitation playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.6k | Automated safety check: Pass | MIT | 26 days ago |
| 86 | Binance Web3 official skill — security audit for token contracts, detecting honeypots, rug pulls, and malicious functions across BSC, Base, Solana, and Ethereum. | TermiX-official/ | 100 | — | ~695 | Automated safety check: Pass | MIT | 4 mo ago |
| 87 | Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies. | owid/ | 159 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 88 | 88.Disclosure Drive responsible disclosure of a proven finding to a CVE. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~686 | Automated safety check: Pass | MIT | 1 mo ago |
| 89 | OSINT-side tech-stack identification — public repositories (GitHub/GitLab), job postings & ATS, and Wayback Machine historical snapshots. | transilienceai/ | 562 | — | ~468 | Automated safety check: Pass | MIT | 2 mo ago |
| 90 | Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date. | ArabelaTso/ | 253 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 91 | Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early. | mukul975/ | 34k | — | ~3.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 92 | 92.Fork Stage a scanned repository into a private repo in the configured GitHub organisation. | alpha-omega-security/ | 239 | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 93 | File a finding on the upstream repository through GitHub's private vulnerability reporting, request the temporary private fork, and push the proposed patch to it when available. | alpha-omega-security/ | 239 | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 94 | Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables | Microck/ | 404 | 1 repo | ~2.7k | Automated safety check: Notes | Unknown | 1 mo ago |
| 95 | Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support | Hack23/ | 239 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | today |
| 96 | Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. | Mathews-Tom/ | 328 | — | ~2.2k | Automated safety check: Pass | MIT | 4 days ago |