Search
Security · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | PHP Web 归档解压(Zip Slip/路径穿越)审计工具。识别解压条目名如何与目标目录拼接、是否存在 base dir 约束缺失,输出可利用性分级、可观测 PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~883 | Automated safety check: Pass | No licence | 6 mo ago |
| 50 | 50.Packslip Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and… | jdx/ | 136 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 51 | Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks. | seqra/ | 163 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | today |
| 52 | Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM. | relizaio/ | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | today |
| 53 | Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work. | LUC4N3X/ | 590 | — | ~2k | Automated safety check: Pass | GPL-3.0 | today |
| 54 | Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. | ktnyt/ | 675 | — | ~565 | Automated safety check: Pass | MIT | 7 mo ago |
| 55 | 55.Gates GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework. | Nebulock-Inc/ | 388 | — | ~12k | Automated safety check: Pass | MIT | yesterday |
| 56 | Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results. | block/ | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 57 | Monitor and manage your Clawdbot agent fleet from within an agent. | Temaki-AI/ | 115 | — | ~1.2k | Automated safety check: Pass | MIT | 7 mo ago |
| 58 | A skill your agent uses when scanning code for security vulnerabilities. | tanviet12/ | 289 | — | ~6.8k | Automated safety check: Notes | MIT | 12 days ago |
| 59 | 59.Semia Audit an agent skill with Semia Skill Behavior Mapping. An agent skill from berabuddies/Semia. | berabuddies/ | 612 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 60 | 60.Chipsec Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. | BrownFineSecurity/ | 859 | 1 repo | ~3.9k | Automated safety check: Notes | MIT | 4 mo ago |
| 61 | Audit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would. | hedioum/ | 139 | — | ~4.9k | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 62 | Enable, configure, and query Elasticsearch security audit logs. | aspectrr/ | 405 | — | ~1.7k | Automated safety check: Pass | MIT | 5 mo ago |
| 63 | 63.Attack Flow Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports. | wiz-sec-public/ | 182 | — | ~3.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 64 | Render app UI on the Gradle managed device and look at the result without spending a fortune in vision tokens. | parawanderer/ | 420 | — | ~1.4k | Automated safety check: Pass | MIT | 21 days ago |
| 65 | Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING… | MidnightBSD/ | 114 | — | ~2.2k | Automated safety check: Pass | Unknown | today |
| 66 | Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs. | eclipse-ankaios/ | 125 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 67 | 67.Audit A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures. | vigolium/ | 140 | — | ~8.7k | Automated safety check: Pass | MIT | 20 days ago |
| 68 | Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report. | marketcalls/ | 2.8k | — | ~1.9k | Automated safety check: Pass | AGPL-3.0 | today |
| 69 | Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release. | clone45/ | 131 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 25 days ago |
| 70 | A skill your agent uses when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping. | johnku2011/ | 240 | — | ~650 | Automated safety check: Pass | MIT | 1 mo ago |
| 71 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 220 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 72 | Map relationships between a web spec section, its Firefox implementation code, and Web Platform Tests. | SAP/ | 180 | 2 repos | ~1.3k | Automated safety check: Pass | GPL-3.0 | 4 days ago |
| 73 | Review a change (a PR, the current branch diff, or a set of files) or audit a Symfony UX package or the whole src/ tree for missing or incorrect security hardening. | symfony/ | 1.1k | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 74 | Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。 | aliyun/ | 148 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 75 | 75.Clawscan CLI A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and… | openclaw/ | 143 | — | ~3k | Automated safety check: Pass | MIT | 3 days ago |
| 76 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.5k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 77 | 77.Codeql Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF. | waybarrios/ | 534 | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 4 days ago |
| 78 | Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes. | seqra/ | 163 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 79 | VulnHunter sandbox-depth decision procedure. An agent skill from nealbridges/VulnHunter. | nealbridges/ | 678 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 80 | Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. | elastic/ | 592 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 81 | 81.Kesekit Fix Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems. | cdppcorp/ | 360 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 82 | Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. | vechain/ | 450 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 83 | Skill to perform a thorough security audit of the codebase. An agent skill from fdhhhdjd/Class-AI-Agent. | fdhhhdjd/ | 266 | — | ~440 | Automated safety check: Notes | No licence | 5 mo ago |
| 84 | Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. | trailofbits/ | 7.5k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 85 | 85.Triage Default pipeline scrutineer runs when a repository is added. | alpha-omega-security/ | 242 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 86 | A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally… | sandgardenhq/ | 137 | 3 repos | ~970 | Automated safety check: Pass | Unknown | 19 days ago |
| 87 | Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup. | Sergei-thinker/ | 189 | — | ~1.5k | Automated safety check: Notes | MIT | 5 mo ago |
| 88 | 88.Semgrep Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis. | waybarrios/ | 534 | — | ~2.4k | Automated safety check: Pass | MIT | 4 days ago |
| 89 | 89.Status Check HOL Guard local protection status for Claude Code without changing configuration. | hashgraph-online/ | 838 | — | ~231 | Automated safety check: Pass | Apache-2.0 | today |
| 90 | 90.Find Skills Helps users discover agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. | burkeholland/ | 142 | — | ~1.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 91 | 91.Build DB 使用 jar-analyzer-engine 从 JAR/WAR/Class 文件构建 SQLite 分析数据库。这是进行 Java 代码安全审计、方法调用分析的第一步。 | jar-analyzer/ | 141 | — | ~898 | Automated safety check: Pass | No licence | 6 mo ago |
| 92 | 92.Nano Run First-time setup and guided sprint. An agent skill from garagon/nanostack. | garagon/ | 207 | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 93 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.5k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 94 | A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability… | openclaw/ | 143 | — | ~1.1k | Automated safety check: Pass | MIT | 3 days ago |
| 95 | Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity. | thomast1906/ | 202 | — | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 96 | 96.Bom Evidence Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and… | cdxgen/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |