Search

Security · For devops and sre engineers

1,394 skills found, page 2.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

PHP Web 归档解压(Zip Slip/路径穿越)审计工具。识别解压条目名如何与目标目录拼接、是否存在 base dir 约束缺失,输出可利用性分级、可观测 PoC 与修复建议(禁止省略)。

0xShe/PHP-Code-Audit-Skill4021 repo~883Automated safety check: PassNo licence6 mo ago
50

Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and…

jdx/packslip136—~2.9kAutomated safety check: PassMITtoday
51

Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks.

seqra/opentaint163—~3.2kAutomated safety check: PassApache-2.0today
52

Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.

relizaio/rearm127—~2.9kAutomated safety check: PassAGPL-3.0today
53

Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work.

LUC4N3X/Levyra-deepsound590—~2kAutomated safety check: PassGPL-3.0today
54

Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling.

ktnyt/cclsp675—~565Automated safety check: PassMIT7 mo ago
55

GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

Nebulock-Inc/agentic-threat-hunting-framework388—~12kAutomated safety check: PassMITyesterday
56

Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

block/codecrucible117—~1.2kAutomated safety check: PassApache-2.03 days ago
57

Monitor and manage your Clawdbot agent fleet from within an agent.

Temaki-AI/clawd-control115—~1.2kAutomated safety check: PassMIT7 mo ago
58

A skill your agent uses when scanning code for security vulnerabilities.

tanviet12/vbsec289—~6.8kAutomated safety check: NotesMIT12 days ago
59

Audit an agent skill with Semia Skill Behavior Mapping. An agent skill from berabuddies/Semia.

berabuddies/Semia612—~2.6kAutomated safety check: PassApache-2.01 mo ago
60

Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

BrownFineSecurity/iothackbot8591 repo~3.9kAutomated safety check: NotesMIT4 mo ago
61

Audit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would.

hedioum/Hedioum-Pool-Tunnel139—~4.9kAutomated safety check: PassGPL-3.01 mo ago
62

Enable, configure, and query Elasticsearch security audit logs.

aspectrr/deer405—~1.7kAutomated safety check: PassMIT5 mo ago
63

Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports.

wiz-sec-public/SITF182—~3.1kAutomated safety check: PassUnknown2 mo ago
64

Render app UI on the Gradle managed device and look at the result without spending a fortune in vision tokens.

parawanderer/OpenTagViewer420—~1.4kAutomated safety check: PassMIT21 days ago
65

Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…

MidnightBSD/src114—~2.2kAutomated safety check: PassUnknowntoday
66

Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

eclipse-ankaios/ankaios125—~1.5kAutomated safety check: PassApache-2.0yesterday
67

A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures.

vigolium/piolium140—~8.7kAutomated safety check: PassMIT20 days ago
68

Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.

marketcalls/openalgo2.8k—~1.9kAutomated safety check: PassAGPL-3.0today
69

Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release.

clone45/voxglitch131—~1.2kAutomated safety check: PassGPL-3.025 days ago
70

A skill your agent uses when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.

johnku2011/boilerplates-with-ai-skills240—~650Automated safety check: PassMIT1 mo ago
71

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassUnknown5 mo ago
72
72.SpecmapOfficial

Map relationships between a web spec section, its Firefox implementation code, and Web Platform Tests.

SAP/project-foxhound1802 repos~1.3kAutomated safety check: PassGPL-3.04 days ago
73

Review a change (a PR, the current branch diff, or a set of files) or audit a Symfony UX package or the whole src/ tree for missing or incorrect security hardening.

symfony/ux1.1k—~2.9kAutomated safety check: PassMITtoday
74

Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

aliyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.01 mo ago
75

A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…

openclaw/clawscan143—~3kAutomated safety check: PassMIT3 days ago
76

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

trailofbits/skills7.5k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.0today
77

Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.

waybarrios/opencode-power-pack5342 repos~3.7kAutomated safety check: PassMIT4 days ago
78

Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes.

seqra/opentaint163—~1.9kAutomated safety check: PassApache-2.0today
79

VulnHunter sandbox-depth decision procedure. An agent skill from nealbridges/VulnHunter.

nealbridges/VulnHunter678—~1.1kAutomated safety check: PassApache-2.0today
80

Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

elastic/agent-skills592—~2kAutomated safety check: PassApache-2.02 days ago
81

Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems.

cdppcorp/KESE-KIT360—~1.1kAutomated safety check: PassMIT6 mo ago
82

Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

vechain/x-app-template450—~1.2kAutomated safety check: PassMIT2 mo ago
83

Skill to perform a thorough security audit of the codebase. An agent skill from fdhhhdjd/Class-AI-Agent.

fdhhhdjd/Class-AI-Agent266—~440Automated safety check: NotesNo licence5 mo ago
84

Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

trailofbits/skills7.5k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.0today
85

Default pipeline scrutineer runs when a repository is added.

alpha-omega-security/scrutineer242—~2.9kAutomated safety check: PassMITtoday
86

A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…

sandgardenhq/sgai1373 repos~970Automated safety check: PassUnknown19 days ago
87

Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.

Sergei-thinker/vpn-setup189—~1.5kAutomated safety check: NotesMIT5 mo ago
88

Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

waybarrios/opencode-power-pack534—~2.4kAutomated safety check: PassMIT4 days ago
89

Check HOL Guard local protection status for Claude Code without changing configuration.

hashgraph-online/hol-guard838—~231Automated safety check: PassApache-2.0today
90

Helps users discover agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities.

burkeholland/max142—~1.5kAutomated safety check: PassMIT4 mo ago
91

使用 jar-analyzer-engine 从 JAR/WAR/Class 文件构建 SQLite 分析数据库。这是进行 Java 代码安全审计、方法调用分析的第一步。

jar-analyzer/jar-analyzer-claude141—~898Automated safety check: PassNo licence6 mo ago
92

First-time setup and guided sprint. An agent skill from garagon/nanostack.

garagon/nanostack207—~3kAutomated safety check: PassApache-2.01 mo ago
93

Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

trailofbits/skills7.5k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0today
94

A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…

openclaw/clawscan143—~1.1kAutomated safety check: PassMIT3 days ago
95

Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

thomast1906/github-copilot-agent-skills202—~3.1kAutomated safety check: PassMIT2 days ago
96

Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

cdxgen/cdxgen1.1k—~1.9kAutomated safety check: PassApache-2.0today