Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 913 | 913.Sast Xss Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 914 | Multi-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review). | ffroliva/ | 269 | — | ~12k | Automated safety check: Pass | MIT | 2 days ago |
| 915 | 915.Mobile Security Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC… | transilienceai/ | 563 | — | ~2.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 916 | 916.Skill Prune Identify and remove negative-ROI skill content — orphan files, never-read entries, duplicates, content reintroducing challenge-specific lore. | transilienceai/ | 563 | — | ~715 | Automated safety check: Pass | MIT | 2 mo ago |
| 917 | 917.Techstack Osint OSINT-side tech-stack identification — public repositories (GitHub/GitLab), job postings & ATS, and Wayback Machine historical snapshots. | transilienceai/ | 563 | — | ~468 | Automated safety check: Pass | MIT | 2 mo ago |
| 918 | 918.Security Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries… | telagod/ | 244 | — | ~907 | Automated safety check: Pass | MIT | 2 mo ago |
| 919 | Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust. | borghei/ | 891 | — | ~1.8k | Automated safety check: Pass | MIT | 4 days ago |
| 920 | Solutions architecture for technical pre-sales. An agent skill from borghei/Claude-Skills. | borghei/ | 891 | — | ~4.1k | Automated safety check: Pass | MIT | 4 days ago |
| 921 | Code review using Codex exec. An agent skill from sd0xdev/sd0x-harness. | sd0xdev/ | 192 | — | ~9.8k | Automated safety check: Pass | MIT | 3 days ago |
| 922 | 922.Fuzzing Implements, registers, and verifies fuzz tests in Chromium. An agent skill from nwjs/chromium.src. | nwjs/ | 160 | — | ~1.1k | Automated safety check: Pass | BSD-3-Clause | yesterday |
| 923 | A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data… | NoobyGains/ | 109 | — | ~2.4k | Automated safety check: Notes | MIT | 7 mo ago |
| 924 | Application security covering input validation, auth, headers, secrets management, and dependency auditing | rohitg00/ | 2.7k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | 5 mo ago |
| 925 | Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code. | ArabelaTso/ | 253 | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 926 | Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date. | ArabelaTso/ | 253 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 927 | 927.Windows Parity Writing Windows-safe Infinite code from macOS: keep WIN32 out of nodes, three-sided Platform:: obligation, Windows trap catalogue (WASAPI, WinMM, GDI glyphs, Media Foundation stride, wide paths… | n1m21n/ | 271 | — | ~4.6k | Automated safety check: Pass | Unknown | yesterday |
| 928 | A skill your agent uses when auditing Docker images in this project for CVEs, base image staleness, or remediation recommendations — covers all four TUI images (Go, Python, Kotlin, C) | Habitat-Thinking/ | 114 | — | ~2k | Automated safety check: Pass | Unknown | 20 days ago |
| 929 | WordPress security code review and vulnerability detection. An agent skill from jorgerosal/wordpress-skills. | jorgerosal/ | 103 | — | ~6.4k | Automated safety check: Pass | MIT | 4 mo ago |
| 930 | A skill your agent uses when closing a patch cycle with rigorous stress LAST on the Railway hub, bensbench x86 fieldbus → MQTTS, CSV/synth59/Creekside/gate 19, B100 Railway-only, light OWASP ZAP… | bbartling/ | 173 | — | ~1.2k | Automated safety check: Pass | Unknown | yesterday |
| 931 | 931.Repomix Guide for using Repomix - a powerful tool that packs entire repositories into single, AI-friendly files. | einverne/ | 121 | — | ~2.5k | Automated safety check: Notes | GPL-3.0 | 1 mo ago |
| 932 | Inspect Go module dependencies, detect outdated or vulnerable modules, and recommend safe updates or pinning strategies. | pilinux/ | 506 | — | ~273 | Automated safety check: Pass | MIT | 15 days ago |
| 933 | Cloudflare Workers security with authentication, CORS, rate limiting, input validation. | secondsky/ | 227 | — | ~1.9k | Automated safety check: Pass | MIT | 13 days ago |
| 934 | 934.Security Pass Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth… | cyanheads/ | 158 | — | ~6.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 935 | 935.Hunt Session Hunt Session Management vulnerabilities | sickn33/ | 47k | 1 repo | ~5.4k | Automated safety check: Pass | MIT | 2 days ago |
| 936 | Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 937 | Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 938 | Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects. | cyberful/ | 135 | — | ~549 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 939 | 939.Forensics Build a read-only compromise timeline and evidence bundle from local Git history and public forge/archive records. | alpha-omega-security/ | 242 | — | ~2.1k | Automated safety check: Notes | MIT | yesterday |
| 940 | 940.Checkpoint Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations. | automateyournetwork/ | 676 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 941 | Comprehensive code security audit with AI-powered vulnerability detection. | LeoYeAI/ | 2.2k | — | ~3.7k | Automated safety check: Notes | MIT | 2 mo ago |
| 942 | Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling… | trilwu/ | 157 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 943 | Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and… | trilwu/ | 157 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 944 | Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse… | trilwu/ | 157 | — | ~4.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 945 | Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash… | trilwu/ | 157 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 946 | Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection… | trilwu/ | 157 | — | ~2.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 947 | Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed… | trilwu/ | 157 | — | ~2.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 948 | Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage… | trilwu/ | 157 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 949 | Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access… | trilwu/ | 157 | — | ~4.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 950 | Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 951 | Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log… | trilwu/ | 157 | — | ~4.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 952 | Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline. | trilwu/ | 157 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 953 | Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities. | trilwu/ | 157 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 954 | Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 955 | 955.Security Build and harden Phoenix auth and security — OAuth login, password hashing, sessions, RBAC, rate limiting, CSRF, XSS, SQL injection, secrets. | oliver-kriska/ | 565 | — | ~1k | Automated safety check: Pass | MIT | 5 days ago |
| 956 | 956.Pair Programming 结对编程搭档。当用户要求"边写边审"、"结对编程"、"写完自己 review 一遍"、"高可靠地实现",或明确希望代码交付时附带自我审查意见时使用。交付代码的同时输出结构化审查(正确性/安全/性能/可读性/健壮性五维度),重点捕捉 AI 生成代码的特有缺陷。不用于:对已有 PR 的正式评审(用 code review 流程)、安全专项扫描(用 security-audit)、10… | staruhub/ | 728 | — | ~482 | Automated safety check: Pass | MIT | 1 mo ago |
| 957 | Provisions, connects, migrates, and operates Amazon RDS for Db2. | aws/ | 2.8k | — | ~6.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 958 | 958.Debug Systematic diagnosis of a red test, a rule that fires or stays silent wrongly, a scan or probe whose artifact looks wrong, a collector error, a red CI run or a gate that is green for the wrong reason. | guardana/ | 131 | — | ~933 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 959 | Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection. | blacklanternsecurity/ | 287 | — | ~2.4k | Automated safety check: Notes | GPL-3.0 | 12 days ago |
| 960 | 960.Dependency Scan Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills. | jwynia/ | 170 | — | ~1.7k | Automated safety check: Pass | MIT | 7 mo ago |