Search

Security · For developers

1,197 skills found, page 20.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
913

Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3…

utkusen/sast-skills1.3k—~7.2kAutomated safety check: PassMIT6 mo ago
914

Multi-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review).

ffroliva/gflow-cli269—~12kAutomated safety check: PassMIT2 days ago
915

Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

transilienceai/communitytools563—~2.5kAutomated safety check: PassMIT2 mo ago
916

Identify and remove negative-ROI skill content — orphan files, never-read entries, duplicates, content reintroducing challenge-specific lore.

transilienceai/communitytools563—~715Automated safety check: PassMIT2 mo ago
917

OSINT-side tech-stack identification — public repositories (GitHub/GitLab), job postings & ATS, and Wayback Machine historical snapshots.

transilienceai/communitytools563—~468Automated safety check: PassMIT2 mo ago
918

Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…

telagod/code-abyss244—~907Automated safety check: PassMIT2 mo ago
919

Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust.

borghei/Claude-Skills891—~1.8kAutomated safety check: PassMIT4 days ago
920

Solutions architecture for technical pre-sales. An agent skill from borghei/Claude-Skills.

borghei/Claude-Skills891—~4.1kAutomated safety check: PassMIT4 days ago
921

Code review using Codex exec. An agent skill from sd0xdev/sd0x-harness.

sd0xdev/sd0x-harness192—~9.8kAutomated safety check: PassMIT3 days ago
922

Implements, registers, and verifies fuzz tests in Chromium. An agent skill from nwjs/chromium.src.

nwjs/chromium.src160—~1.1kAutomated safety check: PassBSD-3-Clauseyesterday
923

A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data…

NoobyGains/godmode109—~2.4kAutomated safety check: NotesMIT7 mo ago
924

Application security covering input validation, auth, headers, secrets management, and dependency auditing

rohitg00/awesome-claude-code-toolkit2.7k—~1.5kAutomated safety check: NotesApache-2.05 mo ago
925

Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code.

ArabelaTso/Skills-4-SE253—~3kAutomated safety check: PassApache-2.01 mo ago
926

Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.

ArabelaTso/Skills-4-SE253—~2.1kAutomated safety check: PassApache-2.01 mo ago
927

Writing Windows-safe Infinite code from macOS: keep WIN32 out of nodes, three-sided Platform:: obligation, Windows trap catalogue (WASAPI, WinMM, GDI glyphs, Media Foundation stride, wide paths…

n1m21n/Infinite271—~4.6kAutomated safety check: PassUnknownyesterday
928

A skill your agent uses when auditing Docker images in this project for CVEs, base image staleness, or remediation recommendations — covers all four TUI images (Go, Python, Kotlin, C)

Habitat-Thinking/ai-literacy-superpowers114—~2kAutomated safety check: PassUnknown20 days ago
929

WordPress security code review and vulnerability detection. An agent skill from jorgerosal/wordpress-skills.

jorgerosal/wordpress-skills103—~6.4kAutomated safety check: PassMIT4 mo ago
930

A skill your agent uses when closing a patch cycle with rigorous stress LAST on the Railway hub, bensbench x86 fieldbus → MQTTS, CSV/synth59/Creekside/gate 19, B100 Railway-only, light OWASP ZAP…

bbartling/open-fdd173—~1.2kAutomated safety check: PassUnknownyesterday
931

Guide for using Repomix - a powerful tool that packs entire repositories into single, AI-friendly files.

einverne/dotfiles121—~2.5kAutomated safety check: NotesGPL-3.01 mo ago
932

Inspect Go module dependencies, detect outdated or vulnerable modules, and recommend safe updates or pinning strategies.

pilinux/gorest506—~273Automated safety check: PassMIT15 days ago
933

Cloudflare Workers security with authentication, CORS, rate limiting, input validation.

secondsky/claude-skills227—~1.9kAutomated safety check: PassMIT13 days ago
934

Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth…

cyanheads/pubmed-mcp-server158—~6.4kAutomated safety check: PassApache-2.0yesterday
935

Hunt Session Management vulnerabilities

sickn33/agentic-awesome-skills47k1 repo~5.4kAutomated safety check: PassMIT2 days ago
936

Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: WarnApache-2.01 mo ago
937

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: WarnApache-2.01 mo ago
938

Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects.

cyberful/cyberful135—~549Automated safety check: PassAGPL-3.01 mo ago
939

Build a read-only compromise timeline and evidence bundle from local Git history and public forge/archive records.

alpha-omega-security/scrutineer242—~2.1kAutomated safety check: NotesMITyesterday
940

Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations.

automateyournetwork/netclaw676—~2.3kAutomated safety check: NotesApache-2.0yesterday
941

Comprehensive code security audit with AI-powered vulnerability detection.

LeoYeAI/openclaw-master-skills2.2k—~3.7kAutomated safety check: NotesMIT2 mo ago
942

Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

trilwu/secskills157—~2kAutomated safety check: PassMIT1 mo ago
943

Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

trilwu/secskills157—~2kAutomated safety check: PassMIT1 mo ago
944

Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…

trilwu/secskills157—~4.3kAutomated safety check: PassMIT1 mo ago
945

Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…

trilwu/secskills157—~2.8kAutomated safety check: PassMIT1 mo ago
946

Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection…

trilwu/secskills157—~2.5kAutomated safety check: PassMIT1 mo ago
947

Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…

trilwu/secskills157—~2.4kAutomated safety check: PassMIT1 mo ago
948

Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

trilwu/secskills157—~1.9kAutomated safety check: PassMIT1 mo ago
949

Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access…

trilwu/secskills157—~4.8kAutomated safety check: PassMIT1 mo ago
950

Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
951

Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log…

trilwu/secskills157—~4.7kAutomated safety check: PassMIT1 mo ago
952

Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline.

trilwu/secskills157—~2.3kAutomated safety check: PassMIT1 mo ago
953

Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

trilwu/secskills157—~2.8kAutomated safety check: PassMIT1 mo ago
954

Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
955

Build and harden Phoenix auth and security — OAuth login, password hashing, sessions, RBAC, rate limiting, CSRF, XSS, SQL injection, secrets.

oliver-kriska/claude-elixir-phoenix565—~1kAutomated safety check: PassMIT5 days ago
956

结对编程搭档。当用户要求"边写边审"、"结对编程"、"写完自己 review 一遍"、"高可靠地实现",或明确希望代码交付时附带自我审查意见时使用。交付代码的同时输出结构化审查(正确性/安全/性能/可读性/健壮性五维度),重点捕捉 AI 生成代码的特有缺陷。不用于:对已有 PR 的正式评审(用 code review 流程)、安全专项扫描(用 security-audit)、10…

staruhub/ClaudeSkills728—~482Automated safety check: PassMIT1 mo ago
957
957.Rds Db2Official

Provisions, connects, migrates, and operates Amazon RDS for Db2.

aws/agent-toolkit-for-aws2.8k—~6.9kAutomated safety check: PassApache-2.0yesterday
958
958.Debug

Systematic diagnosis of a red test, a rule that fires or stays silent wrongly, a scan or probe whose artifact looks wrong, a collector error, a red CI run or a gate that is green for the wrong reason.

guardana/guardana131—~933Automated safety check: PassApache-2.0yesterday
959

Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection.

blacklanternsecurity/red-run287—~2.4kAutomated safety check: NotesGPL-3.012 days ago
960

Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.

jwynia/agent-skills170—~1.7kAutomated safety check: PassMIT7 mo ago