Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities. | context-labs/ | 1.1k | 2 repos | ~3k | Automated safety check: Pass | MIT | 5 days ago |
| 50 | Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back. | samugit83/ | 3k | — | ~1.1k | Automated safety check: Pass | MIT | 2 days ago |
| 51 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 25 days ago |
| 52 | 52.Forensify Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 190 | — | ~2.5k | Automated safety check: Notes | Unknown | 13 days ago |
| 53 | Verify that code changes do not introduce OAuth security vulnerabilities. | doorkeeper-gem/ | 5.5k | — | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 54 | 54.Vibe Check Security audit for web apps, especially AI-built ("vibe coded") ones. | benavlabs/ | 118 | — | ~1.1k | Automated safety check: Notes | MIT | 21 days ago |
| 55 | Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and… | activepieces/ | 25k | — | ~2.9k | Automated safety check: Pass | Unknown | today |
| 56 | Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. | jeremylongshore/ | 2.8k | 2 repos | ~1.3k | Automated safety check: Notes | MIT | today |
| 57 | 57.Osint Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill. | smixs/ | 141 | — | ~5.5k | Automated safety check: Pass | MIT | 7 mo ago |
| 58 | 58.Audit Flow Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. | zebbern/ | 4.7k | — | ~4.2k | Automated safety check: Pass | MIT | today |
| 59 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 425 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 60 | Apply modern web development best practices for security, compatibility, and code quality. | midudev/ | 114 | 3 repos | ~3k | Automated safety check: Pass | MIT | 12 days ago |
| 61 | 61.Flounder Operates Flounder, an autonomous white-hat security auditor. | adshao/ | 518 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | 4 days ago |
| 62 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.5k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 63 | Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology. | greatpie/ | 101 | — | ~1.1k | Automated safety check: Pass | No licence | 7 mo ago |
| 64 | Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses. | pydantic/ | 8.6k | — | ~852 | Automated safety check: Pass | MIT | today |
| 65 | 65.Bug Hunter Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects. | codexstar69/ | 520 | — | ~5k | Automated safety check: Pass | MIT | 1 mo ago |
| 66 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | 3 days ago |
| 67 | Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. | EpicenterHQ/ | 4.8k | — | ~896 | Automated safety check: Pass | Unknown | 2 days ago |
| 68 | Verify or select a SageMaker execution role before creating models, endpoints, or training jobs. | waybarrios/ | 534 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 69 | Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner. | Fangcun-AI/ | 143 | — | ~2.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 70 | Django access control and IDOR security review. An agent skill from getsentry/skills. | getsentry/ | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 71 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 844 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 72 | Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files. | HarnessMD/ | 8.6k | — | ~350 | Automated safety check: Notes | MIT | yesterday |
| 73 | Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. | PrefectHQ/ | 28k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 74 | 74.Rsigma Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. | timescale/ | 165 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 75 | Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in… | samugit83/ | 3k | — | ~1.3k | Automated safety check: Pass | MIT | 2 days ago |
| 76 | Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | 1 repo | ~4.4k | Automated safety check: Pass | MIT | today |
| 77 | Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge. | Gabson0x/ | 442 | — | ~3.7k | Automated safety check: Pass | No licence | 23 days ago |
| 78 | Reverse-engineer missing or incomplete OpenFastTrace system requirements and arc42-style design documentation from a project's user guide, existing documentation, tests, and code. | itsallcode/ | 197 | — | ~2.9k | Automated safety check: Pass | GPL-3.0 | today |
| 79 | Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix. | pretend1111/ | 496 | 1 repo | ~502 | Automated safety check: Pass | Unknown | 5 mo ago |
| 80 | Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge. | TheDecipherist/ | 551 | — | ~1.3k | Automated safety check: Notes | MIT | 5 mo ago |
| 81 | 81.Myrqen Run an authorized, local-first application security assessment on the current project using this agent's own reasoning. | stijnswapped/ | 137 | — | ~2.1k | Automated safety check: Pass | Unknown | 1 mo ago |
| 82 | 82.Combine Dbc Combine multiple individual single-signal DBC files into one combined DBC at the application level. | CSS-Electronics/ | 184 | — | ~826 | Automated safety check: Pass | MIT | 4 days ago |
| 83 | Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings. | tradecatlabs/ | 17k | 1 repo | ~738 | Automated safety check: Pass | Apache-2.0 | today |
| 84 | Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity. | activepieces/ | 25k | — | ~3.6k | Automated safety check: Pass | Unknown | today |
| 85 | 85.Secskills 渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。 | Arenbai/ | 253 | — | ~1.8k | Automated safety check: Notes | MIT | 11 days ago |
| 86 | Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation. | obot-platform/ | 1.1k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 87 | Decompile NES ROM files (.nes) into C projects that can be rebuilt with dotnes. | jonathanpeppers/ | 780 | — | ~1.6k | Automated safety check: Pass | MIT | 17 days ago |
| 88 | Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams. | rfc-st/ | 379 | — | ~3.7k | Automated safety check: Pass | MIT | yesterday |
| 89 | Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the… | getsentry/ | 1.8k | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 90 | 90.Cyberowlai Check if recent cybersecurity alerts from 10 international CERTs affect your current project. | karimhabush/ | 263 | — | ~2.5k | Automated safety check: Pass | MIT | yesterday |
| 91 | Safely unpack and investigate existing archives through evidence-first static analysis. | AetherKiri/ | 154 | — | ~1.6k | Automated safety check: Pass | GPL-3.0 | yesterday |
| 92 | 92.Ghidra Re Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic… | OrbitCurve/ | 216 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 93 | 93.Edge Python Write, run, test and package Edge Python programs with the edge CLI. | dylan-sutton-chavez/ | 273 | — | ~11k | Automated safety check: Pass | Unknown | today |
| 94 | Migrate a .NET 9 project or solution to .NET 10 and resolve all breaking changes. | dotnet/ | 5.6k | 2 repos | ~4.8k | Automated safety check: Pass | MIT | today |
| 95 | Installs, tunes and enforces Sponsio contracts that block unsafe tool calls in LLM agents, covering setup, auditing, observe mode and flipping to enforce. | SponsioLabs/ | 454 | — | ~12k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 96 | Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps. | zereight/ | 2k | 1 repo | ~859 | Automated safety check: Notes | MIT | today |