Search
Security · Python
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | 威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 125 | 1 repo | ~1.1k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 50 | Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. | Eyadkelleh/ | 388 | — | ~636 | Automated safety check: Pass | No licence | 4 mo ago |
| 51 | Extracts app.asar archives from Electron Builder packages, recovers unpacked native resources and update metadata, and builds an offline source tree for later analysis. | ptn1411/ | 219 | — | ~683 | Automated safety check: Notes | No licence | 16 days ago |
| 52 | 52.Tenuo Audit Audit, explain, or compare existing Tenuo warrants and delegation chains. | tenuo-ai/ | 102 | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | today |
| 53 | Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 54 | Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates… | johnson7788/ | 327 | — | ~3k | Automated safety check: Pass | MIT | 1 mo ago |
| 55 | 55.Ssti Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or… | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 56 | AI 도구(Claude, ChatGPT, Cursor, Copilot)용 시큐어 코딩 프롬프트와 가이드를 생성합니다. | cdppcorp/ | 361 | — | ~1.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 57 | 57.Bandit Run bandit against the Python source in the repository and map its hits into the findings shape. | alpha-omega-security/ | 231 | — | ~615 | Automated safety check: Notes | MIT | today |
| 58 | Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner. | majiayu000/ | 286 | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 59 | Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority. | tenuo-ai/ | 102 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 60 | Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports. | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 61 | When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain | deonmenezes/ | 505 | — | ~510 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 62 | Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura. | liuyanghejerry/ | 204 | — | ~164 | Automated safety check: Pass | MIT | 9 days ago |
| 63 | Reconstructs folder browsing history from Windows Shellbag registry data using SBECmd and Shellbags Explorer, even for folders that were later deleted. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 64 | Changing or adding a project setting / default value in RedAmon. | samugit83/ | 3k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 65 | Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 66 | Finds exploitable application security vulnerabilities in code changes. | getsentry/ | 414 | — | ~1.8k | Automated safety check: Pass | Unknown | 8 days ago |
| 67 | 67.Case Review Reviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff. | zhaoxuya520/ | 40k | 1 repo | ~1.6k | Automated safety check: Warn | MIT | 16 days ago |
| 68 | Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste. | microsoft/ | 107 | — | ~1k | Automated safety check: Pass | MIT | today |
| 69 | Scans text that has already been de-identified for leftover identifiers such as SSNs, card numbers, emails and dates, and blocks release if anything turns up. | maziyarpanahi/ | 5.5k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 70 | Dependency audit and cleanup workflow for maintaining healthy project dependencies. | bobmatnyc/ | 155 | — | ~3.5k | Automated safety check: Pass | Unknown | 1 mo ago |
| 71 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 72 | Insecure deserialization detection and gadget chain exploitation | NeoTheCapt/ | 142 | — | ~836 | Automated safety check: Pass | No licence | 2 mo ago |
| 73 | Perform language and framework specific security best-practice reviews and suggest improvements. | trailofbits/ | 512 | 9 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 74 | Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates. | awarexone/ | 5.3k | — | ~1.9k | Automated safety check: Warn | MIT | 3 days ago |
| 75 | A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection. | openJiuwen-ai/ | 442 | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | today |
| 76 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 77 | 77.Domain Intel Passive domain reconnaissance using Python stdlib. An agent skill from Tommy-yw/RunbookHermes. | Tommy-yw/ | 546 | 2 repos | ~1.1k | Automated safety check: Pass | MIT | 4 mo ago |
| 78 | 78.Corpus Sweep Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run). | nubjs/ | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 79 | 79.Pytm Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification. | AgentSecOps/ | 220 | 2 repos | ~4.4k | Automated safety check: Notes | Unknown | 5 mo ago |
| 80 | 80.Sca Trivy Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license… | AgentSecOps/ | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 81 | 81.Sast Bandit Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. | AgentSecOps/ | 220 | 1 repo | ~2.6k | Automated safety check: Pass | Unknown | 5 mo ago |
| 82 | AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching… | github/ | 40k | 1 repo | ~2.3k | Automated safety check: Notes | MIT | today |
| 83 | Build a two-tier PKI Certificate Authority hierarchy (offline Root CA plus issuing Intermediate CA) using OpenSSL and the Python cryptography library, covering certificate extensions, CRL… | mukul975/ | 34k | — | ~879 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 84 | Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 85 | Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 86 | Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and producer in Python, covering TAXII server discovery, collection polling, parsing STIX bundles with the stix2 library, and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 87 | Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 88 | Query the Malpedia API to look up malware family aliases and naming (platform.familyname), pull community/vendor YARA rules, link families to threat actors, and map family relationships such as… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 89 | Parse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 90 | Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK… | mukul975/ | 34k | — | ~667 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 91 | Parse Windows Prefetch (.pf) files with the windowsprefetch Python library to reconstruct application execution history, run counts, and accessed file/volume lists. | mukul975/ | 34k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 92 | Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 93 | Build an automated adversary infrastructure tracking system in Python (dnspython, python-whois, shodan, networkx) that pivots across passive DNS, certificate transparency logs, WHOIS records, and IP… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 94 | Parse cyber threat intelligence reports (Mandiant, CrowdStrike, Talos, Microsoft) with stix2, mitreattack-python, and spaCy to extract adversary behaviors, map them to MITRE ATT&CK technique IDs… | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 95 | Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC… | mukul975/ | 34k | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 96 | Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |