Search
Security · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 913 | 913.Secrets Scan Run trufflehog via the mantistrufflehog MCP server and handle secret findings without ever exposing the raw secret | deonmenezes/ | 503 | — | ~347 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 914 | 914.Security Scan Review trust boundaries, auth, input handling, secrets, and dependency risk before release. | PacificStudio/ | 268 | — | ~865 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 915 | Enterprise-review-grade threat model from harness threat-model {path}. | ruvnet/ | 74k | — | ~363 | Automated safety check: Notes | MIT | yesterday |
| 916 | 916.Security Audit Comprehensive security auditing for Clawdbot deployments. An agent skill from aAAaqwq/AGI-Super-Team. | aAAaqwq/ | 105 | 2 repos | ~619 | Automated safety check: Notes | MIT | 3 days ago |
| 917 | AI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范. An agent skill from ProgrammerAnthony/Expert-Coding-Harness. | ProgrammerAnthony/ | 235 | — | ~3k | Automated safety check: Pass | MIT | 5 mo ago |
| 918 | Inline orchestration workflow for security vulnerability detection and remediation with Beads integration. | maslennikov-ig/ | 260 | — | ~2k | Automated safety check: Pass | Unknown | 7 mo ago |
| 919 | 安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。 | devcodex-labs/ | 439 | — | ~771 | Automated safety check: Pass | AGPL-3.0 | 24 days ago |
| 920 | Runs a guided, end-to-end security review of a Power Pages site and consolidates every finding into one HTML report covering source code and dependencies, the live site, browser headers, firewall… | microsoft/ | 984 | — | ~4.3k | Automated safety check: Notes | MIT | yesterday |
| 921 | 921.Pivot On Ioc Explore GTI relationships for an IOC to discover related entities. | dandye/ | 127 | — | ~690 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 922 | 922.Respond Malware Respond to a malware incident following PICERL methodology. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 923 | Respond to a ransomware incident following PICERL methodology. | dandye/ | 127 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 924 | 924.Triage Alert Triage a security alert or case. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 925 | Triage suspicious login alerts like impossible travel, untrusted location, or multiple failures. | dandye/ | 127 | — | ~1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 926 | 当开始新目标、攻击面不清晰、需要资产测绘/信息收集/前端JS分析/接口与敏感信息提取时调用。负责webpack拆解、source map还原、API端点与密钥提取、历史资产发现、高价值入口定位。命中场景:找不到接口、需要找密钥/隐藏功能/旧版本接口、JS加密与签名逻辑需要还原。 | zhaji2333/ | 115 | — | ~1.1k | Automated safety check: Pass | MIT | 26 days ago |
| 927 | 927.Disclosure Drive responsible disclosure of a proven finding to a CVE. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~686 | Automated safety check: Pass | MIT | 1 mo ago |
| 928 | 928.Evidence Evidence hygiene before any FIND moves to Completed or enters a report. | Encod3d-Sec/ | 329 | — | ~700 | Automated safety check: Pass | MIT | 1 mo ago |
| 929 | 929.Hunt Bizlogic Business-logic flaw hunting - workflow/state bypass, price/quantity tampering, negative/overflow values, coupon/refund abuse, mass assignment, and logic races. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 930 | 930.Hunt Cache Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking. | Encod3d-Sec/ | 329 | — | ~1.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 931 | 931.Hunt MCP MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. | Encod3d-Sec/ | 329 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 932 | 932.Hunt Smuggling HTTP request smuggling / desync hunting - CL.TE, TE.CL, TE.TE, CL.0, and HTTP/2 downgrade. | Encod3d-Sec/ | 329 | — | ~1.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 933 | 933.Hunt Sqli SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection. | Encod3d-Sec/ | 329 | — | ~3.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 934 | 934.Triage Finding validation gate - 7-Question triage adapted for FIND schema. | Encod3d-Sec/ | 329 | — | ~848 | Automated safety check: Pass | MIT | 1 mo ago |
| 935 | 935.Wiki Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status. | Encod3d-Sec/ | 329 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 936 | Test LLM-integrated applications against known prompt injection techniques, evasion methods, and attack intents using the Arcanum PI Taxonomy. | OWASP/ | 188 | — | ~758 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 937 | Tile two-dimensional torch.gather(dim=1) kernels for Triton-Ascend so the logical grid stays near the physical vector-core count while each program handles multiple batch rows and loops over K. | Krusty84/ | 106 | — | ~583 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 938 | A skill your agent uses when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for… | NVIDIA/ | 3.6k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 939 | A skill your agent uses when the user is doing hands-on DOCA SHA programming — offloading SHA-1, SHA-256, or SHA-512 hashing onto a BlueField DPU or ConnectX accelerator, picking between one-shot… | NVIDIA/ | 3.6k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 940 | 940.Skill Audit Pre-install security scanner for AI agent skills. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Warn | MIT | 2 days ago |
| 941 | 941.Threat Modeling Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. | hardw00t/ | 105 | — | ~2.6k | Automated safety check: Pass | No licence | 5 mo ago |
| 942 | Audit an LLM application for indirect prompt injection - compose objective x technique payloads, deliver them through the channels the agent actually reads, and prove impact with an out-of-band… | forefy/ | 152 | — | ~2.3k | Automated safety check: Pass | MIT | 7 days ago |
| 943 | 943.Harness Feedback A skill your agent uses when an agent says a test, VM, proof, evaluator, or release gate is overloaded, too strict, blocking staging, or causing false positives; split checks by profile, measure the… | AnastasiyaW/ | 154 | — | ~1k | Automated safety check: Pass | MIT | 2 days ago |
| 944 | Write a self-contained OpenTaint engine-issue report from an analysis diagnosis or a full-scan failure. | seqra/ | 163 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 945 | Check for outdated or vulnerable dependencies. An agent skill from enuno/unifi-mcp-server. | enuno/ | 282 | — | ~206 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 946 | Harden OpenClaw self-hosted environments with baseline host controls, auth tightening, secret handling, network segmentation, and safe update/rollback workflows. | BagelHole/ | 1.2k | — | ~1k | Automated safety check: Notes | MIT | 4 mo ago |
| 947 | 947.Sast Xxe Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 948 | 948.Infrastructure Network infrastructure testing - port scanning, DNS attacks, MITM, VLAN hopping, IPv6, SMB/NetBIOS, sniffing, and DoS assessment. | transilienceai/ | 563 | — | ~768 | Automated safety check: Pass | MIT | 2 mo ago |
| 949 | 949.Patt Fetcher Fetches and extracts payloads from PayloadsAllTheThings on demand. | transilienceai/ | 563 | — | ~1.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 950 | Correlation, confidence scoring, and conflict resolution across all tech-stack signals. | transilienceai/ | 563 | — | ~459 | Automated safety check: Pass | MIT | 2 mo ago |
| 951 | 951.Techstack Infra Infrastructure tech-stack identification — cloud providers, CDN/WAF, DNS services, TLS/CT, DevOps tooling, plus asset discovery (domains, subdomains, IPs). | transilienceai/ | 563 | — | ~462 | Automated safety check: Pass | MIT | 2 mo ago |
| 952 | Security-posture and third-party SaaS identification — security headers, CSP, HSTS, email auth, security.txt, plus payments/analytics/auth/CRM/support integrations. | transilienceai/ | 563 | — | ~447 | Automated safety check: Pass | MIT | 2 mo ago |
| 953 | NIS2 Directive (EU 2022/2555) compliance for critical infrastructure entities, covering the 10 minimum security measures. | borghei/ | 891 | — | ~8.1k | Automated safety check: Pass | MIT | 4 days ago |
| 954 | 信息安全分析师与软件开发工程师在搭建文档处理流水线时,当需要拦截违规文件或外部URL,请挂载此技能作为强制前置安检,自动输出 pass/reject 判定与详细合规扫描报告,一键守住零信任安全底线。 | anbeime/ | 7.8k | — | ~321 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 955 | 955.Security Scan 对进入系统的文件或 URL 执行安全与合规扫描,输出 pass/reject 判定与扫描报告,作为所有文档处理的强制前置关卡。 | anbeime/ | 7.8k | — | ~310 | Automated safety check: Pass | No licence | 2 days ago |
| 956 | 956.Security Review Security review checklist for web applications. An agent skill from cohen-liel/hivemind. | cohen-liel/ | 110 | — | ~701 | Automated safety check: Notes | Apache-2.0 | 5 mo ago |
| 957 | 957.Security Scanner Review owned source, configuration and dependency metadata for supported security findings with precise evidence and remediation. | WrongStack/ | 371 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 958 | Application security covering input validation, auth, headers, secrets management, and dependency auditing | rohitg00/ | 2.7k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | 5 mo ago |
| 959 | A skill your agent uses when auditing project dependencies for known vulnerabilities, supply chain risk, or provenance issues — covers Go modules, Maven/JVM, and CI integration for automated scanning | Habitat-Thinking/ | 114 | — | ~2.1k | Automated safety check: Pass | Unknown | 21 days ago |
| 960 | A skill your agent uses when auditing Docker images in this project for CVEs, base image staleness, or remediation recommendations — covers all four TUI images (Go, Python, Kotlin, C) | Habitat-Thinking/ | 114 | — | ~2k | Automated safety check: Pass | Unknown | 21 days ago |