Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 961 | Audit and harden Algolia credentials, record exposure, index restrictions, and tenant search controls. | jeremylongshore/ | 2.8k | — | ~1k | Automated safety check: Pass | MIT | yesterday |
| 962 | Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls. | jeremylongshore/ | 2.8k | — | ~1k | Automated safety check: Pass | MIT | yesterday |
| 963 | Configure and audit security review capabilities as one layer in a defense-in-depth pull-request program. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 964 | Configure BYOK API keys for OpenAI, Anthropic, Google, Azure, and custom models in Cursor. | jeremylongshore/ | 2.8k | — | ~2.1k | Automated safety check: Pass | MIT | yesterday |
| 965 | Analyze and harden Flexport credentials, tokens, webhook verification, data exposure, and mutation controls. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 966 | Harden an Ideogram integration across credentials, untrusted media, content safety, copyright controls, storage, and tenant authorization. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 967 | Harden Instantly API v2 keys, scopes, tenant boundaries, logs, webhooks, and operational access. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 968 | Harden Persona API keys, identity data, inquiry sessions, webhook verification, and destructive redaction. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 969 | Audit MCP (Model Context Protocol) server configurations for security issues. | boshi-xixixi/ | 276 | — | ~2.2k | Automated safety check: Pass | MIT | 5 mo ago |
| 970 | Reviews a design or change for security before it ships — authentication and authorization, data handling, secrets, dependencies, and the secure-development practices around it. | cbrock84/ | 2k | — | ~1.1k | Automated safety check: Pass | MIT | 23 days ago |
| 971 | Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables | Microck/ | 404 | 1 repo | ~2.7k | Automated safety check: Notes | Unknown | 1 mo ago |
| 972 | 972.Senior Secops SecOps for application security, vulnerability management, compliance, and secure development. | borghei/ | 891 | — | ~1.7k | Automated safety check: Pass | MIT | 4 days ago |
| 973 | 扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。 | rongxinzy/ | 154 | — | ~868 | Automated safety check: Pass | MIT | yesterday |
| 974 | Run a Python fuzzer script (provided as a string) for a fixed duration. | opensage-agent/ | 127 | — | ~228 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 975 | 975.Fuzzing Patterns A skill your agent uses when writing fuzz tests for Solidity contracts. | ccashwell/ | 131 | — | ~1.6k | Automated safety check: Pass | MIT | 11 days ago |
| 976 | Comprehensive reentrancy attack patterns and defenses for Solidity. | ccashwell/ | 131 | — | ~1.9k | Automated safety check: Pass | MIT | 11 days ago |
| 977 | 977.Slither Analysis A skill your agent uses when running Slither static analysis on Solidity contracts. | ccashwell/ | 131 | — | ~1.5k | Automated safety check: Pass | MIT | 11 days ago |
| 978 | Security-focused Solidity development patterns. An agent skill from ccashwell/evm-cortex. | ccashwell/ | 131 | — | ~1.5k | Automated safety check: Pass | MIT | 11 days ago |
| 979 | 979.Dt Sec Insights Query and analyze Dynatrace security data in security.events with DQL: vulnerabilities, threat detections, compliance posture, and scan coverage. | Dynatrace/ | 163 | — | ~7.2k | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 980 | 980.Binary Re This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work. | aiskillstore/ | 433 | 1 repo | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 981 | Run defensive pre-release security tests for Python web applications. | aiskillstore/ | 433 | — | ~1.2k | Automated safety check: Notes | MIT | yesterday |
| 982 | 982.Semgrep Triage Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle | deonmenezes/ | 503 | — | ~312 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 983 | Assess the security of a smart-contract system across protocol economics, trust roles, upgrade and governance paths, oracle and bridge dependencies, deployment state, and off-chain operators. | cyberful/ | 135 | — | ~651 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 984 | Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures. | cyberful/ | 135 | — | ~637 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 985 | Audit extracted embedded firmware for boot and update trust, credential and secret handling, service exposure, privilege boundaries, parsers, persistence, cryptography, hardening, recovery, and… | cyberful/ | 135 | — | ~644 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 986 | 986.AWS Essentials A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or… | ericrisco/ | 180 | — | ~2.9k | Automated safety check: Notes | MIT | yesterday |
| 987 | 987.Cpp A skill your agent uses when writing, reviewing, modernizing, building, or debugging C++ - RAII and resource lifetime, smart-pointer ownership, move semantics and the Rule of Zero/Five, target-based… | ericrisco/ | 180 | — | ~4k | Automated safety check: Pass | MIT | yesterday |
| 988 | 988.Security Scan A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 180 | — | ~2.8k | Automated safety check: Notes | MIT | yesterday |
| 989 | 989.Testing Go A skill your agent uses when writing or running Go tests — table-driven cases, named subtests, parallel isolation, fakes instead of mock frameworks, coverage profiles, benchmarks, fuzzing, golden… | ericrisco/ | 180 | — | ~3.7k | Automated safety check: Pass | MIT | yesterday |
| 990 | 990.Architect Init A skill your agent uses when bootstrapping architecture documentation for a brownfield project by reverse-engineering ADRs from an existing codebase. | tikalk/ | 141 | — | ~7.4k | Automated safety check: Pass | MIT | yesterday |
| 991 | Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support | Hack23/ | 239 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 992 | MCP gateway security patterns, token management, request validation, and audit logging for MCP communications | Hack23/ | 239 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 993 | 993.Audit Embedded Focused static audit of device firmware and IoT software for update, boot, provisioning, credential, debug-interface and device-communication boundary failures, using an ISVS-informed threat model. | alpha-omega-security/ | 242 | — | ~1.6k | Automated safety check: Notes | MIT | yesterday |
| 994 | Manage Google Security Operations (SecOps) SOAR cases throughout their lifecycle. | google/ | 21k | — | ~3.2k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 995 | 995.Repo Sentinel Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. | Mathews-Tom/ | 329 | — | ~2.2k | Automated safety check: Pass | MIT | 5 days ago |
| 996 | 996.Ctf Forensics CTF 数字取证与信号分析技术。当挑战提供磁盘镜像(.dd/.E01)、内存 dump(.raw/.vmem)、网络抓包(.pcap/.pcapng)、隐写图片/音频、Windows 事件日志(.evtx)时使用。覆盖 Volatility 内存分析、Wireshark 流量还原、binwalk 隐写提取、文件系统恢复等取证全链路 | wgpsec/ | 1.8k | — | ~878 | Automated safety check: Notes | No licence | yesterday |
| 997 | 997.Ctf Source Audit CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式 | wgpsec/ | 1.8k | — | ~1.4k | Automated safety check: Notes | No licence | yesterday |
| 998 | 998.Log Evasion 日志分析与日志逃逸方法论。理解蓝队如何通过日志追踪攻击行为(SIEM/Event Log/Syslog),以及红队如何规避日志记录或精准清除痕迹。当需要设计无痕操作或分析日志监控覆盖范围时使用 | wgpsec/ | 1.8k | — | ~1.2k | Automated safety check: Pass | No licence | yesterday |
| 999 | 999.Sicurezza GitHub Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot. | ccplugins/ | 970 | — | ~486 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 1000 | 1000.Sqli Testing Detect and exploit SQL injection vulnerabilities in web application parameters | NeoTheCapt/ | 143 | — | ~1.2k | Automated safety check: Pass | No licence | 2 mo ago |
| 1001 | 1001.Xss Testing Detect and exploit cross-site scripting vulnerabilities in web applications | NeoTheCapt/ | 143 | — | ~1.4k | Automated safety check: Pass | No licence | 2 mo ago |
| 1002 | 1002.AWS SDK Java V2 Kms Provides AWS Key Management Service (KMS) patterns using AWS SDK for Java 2.x. | giuseppe-trisciuoglio/ | 357 | — | ~3.6k | Automated safety check: Notes | MIT | 1 mo ago |
| 1003 | 1003.Gemini Provides Gemini CLI delegation workflows for large-context analysis and complex reasoning using Gemini 3.0 Flash and Gemini 3.0 Pro models, including English prompt formulation, execution flags, and… | giuseppe-trisciuoglio/ | 357 | — | ~2.3k | Automated safety check: Notes | MIT | 1 mo ago |
| 1004 | Provides AWS CloudFormation patterns for security infrastructure including KMS encryption, Secrets Manager, IAM security, VPC security, ACM certificates, parameter security, outputs, and secure… | giuseppe-trisciuoglio/ | 357 | — | ~2.8k | Automated safety check: Notes | MIT | 1 mo ago |
| 1005 | Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. | giuseppe-trisciuoglio/ | 357 | — | ~2.4k | Automated safety check: Notes | MIT | 1 mo ago |
| 1006 | 1006.Dependency Awareness Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable… | Goldziher/ | 159 | — | ~250 | Automated safety check: Pass | MIT | yesterday |
| 1007 | 1007.Light Protocol Complete guide for Light Protocol on Solana - includes ZK Compression for rent-free compressed tokens and PDAs using zero-knowledge proofs, and the Light Token Program for high-performance token… | sendaifun/ | 130 | 1 repo | ~3.5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 1008 | 1008.Techstack Backend Backend tech-stack identification — web servers, runtimes, languages, frameworks, databases, APIs, and CMS via HTTP headers, cookies, error pages, and API discovery. | transilienceai/ | 563 | — | ~381 | Automated safety check: Pass | MIT | 2 mo ago |