Search
Security · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 961 | A skill your agent uses when auditing a project for secrets committed to source control, setting up gitleaks, or hardening the "No secrets in source" harness constraint — covers scanning… | Habitat-Thinking/ | 114 | — | ~2.2k | Automated safety check: Notes | Unknown | 21 days ago |
| 962 | Scaffold and validate new toolkit skills with the standard file layout, metadata, output contract, and orchestrator registration checklist. | ptn1411/ | 219 | — | ~272 | Automated safety check: Pass | No licence | 19 days ago |
| 963 | Audit dependency manifests and lockfiles for SBOM extraction, risky install scripts, unpinned versions, remote/git dependency sources, dependency-confusion and typosquat/known-malicious package… | ptn1411/ | 219 | — | ~445 | Automated safety check: Pass | No licence | 19 days ago |
| 964 | Usar antes de aceptar una dependencia nueva. An agent skill from 686f6c61/alfred-dev. | 686f6c61/ | 117 | — | ~379 | Automated safety check: Pass | MIT | 1 mo ago |
| 965 | Inspect Go module dependencies, detect outdated or vulnerable modules, and recommend safe updates or pinning strategies. | pilinux/ | 506 | — | ~273 | Automated safety check: Pass | MIT | 15 days ago |
| 966 | 966.Static Analysis Run CI-aligned static analysis (vet, gosec, govulncheck) and convert findings into prioritized remediation steps. | pilinux/ | 506 | — | ~266 | Automated safety check: Pass | MIT | 15 days ago |
| 967 | 967.Nis2 Navigator NIS2 Compliance Navigator — scope classification, Art. An agent skill from lawve-ai/awesome-legal-skills. | lawve-ai/ | 847 | — | ~3.6k | Automated safety check: Pass | AGPL-3.0 | 9 days ago |
| 968 | 968.Security Pass Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth… | cyanheads/ | 158 | — | ~6.4k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 969 | 969.Hunt Aspnet Hunt ASP.NET-specific surface | sickn33/ | 47k | 1 repo | ~5.5k | Automated safety check: Pass | MIT | 2 days ago |
| 970 | 970.Hunt Session Hunt Session Management vulnerabilities | sickn33/ | 47k | 1 repo | ~5.4k | Automated safety check: Pass | MIT | 2 days ago |
| 971 | Audit local AI model, adapter, tokenizer, configuration, and packaging artifacts for provenance, integrity, dependency, serialization, license, and loading-risk evidence. | cyberful/ | 135 | — | ~535 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 972 | Test whether authorized direct or indirect untrusted content can alter an AI system's protected behavior, context use, memory, retrieval, output handling, or downstream capability. | cyberful/ | 135 | — | ~538 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 973 | Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects. | cyberful/ | 135 | — | ~549 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 974 | Reconstruct how instructions, retrieved content, memory, identities, approvals, tool schemas, arguments, outputs, delegation, and fallbacks propagate through an AI system. | cyberful/ | 135 | — | ~517 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 975 | 975.Breaking Change Decide whether a finding's suggested fix is a breaking change for top dependents. | alpha-omega-security/ | 242 | — | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 976 | 976.Cna Match Match the repository to a CVE Numbering Authority so disclosures route to the CNA's security contact when one covers the repo. | alpha-omega-security/ | 242 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 977 | 977.Exposure For one (finding, dependent) pair, decide whether the dependent's code reaches the upstream finding. | alpha-omega-security/ | 242 | — | ~989 | Automated safety check: Pass | MIT | yesterday |
| 978 | 978.Finding Dedup Compare open findings in one repository and record how they relate. | alpha-omega-security/ | 242 | — | ~1.6k | Automated safety check: Pass | MIT | yesterday |
| 979 | 979.Fork Stage a scanned repository into a private repo in the configured GitHub organisation. | alpha-omega-security/ | 242 | — | ~3.3k | Automated safety check: Pass | MIT | yesterday |
| 980 | 980.Mitigate Draft operational mitigations for a finding consumers can apply before a fix ships. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 981 | 981.Patch Propose a code patch for a finding. An agent skill from alpha-omega-security/scrutineer. | alpha-omega-security/ | 242 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 982 | 982.Reachability Check whether known sinks in this application's dependencies are reachable from its own trust boundaries. | alpha-omega-security/ | 242 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 983 | 983.Recon Map distinct externally reachable input-processing subsystems into focus areas for the threat-model skill to carry into later security audits. | alpha-omega-security/ | 242 | — | ~951 | Automated safety check: Pass | MIT | yesterday |
| 984 | 984.Release Watch After a finding has been marked fixed, watch the upstream for a release that contains the fix. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 985 | 985.Report Upstream File a finding on the upstream repository through GitHub's private vulnerability reporting, request the temporary private fork, and push the proposed patch to it when available. | alpha-omega-security/ | 242 | — | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 986 | 986.Vuln Scan High-recall static source-code vulnerability scan adapted from Anthropic's defending-code reference harness. | alpha-omega-security/ | 242 | — | ~3.2k | Automated safety check: Pass | MIT | yesterday |
| 987 | 分析 Android 项目源码,用 LLM 从多维度生成 AI 自动化测试所需的先验知识文档,打包上报测试平台。核心价值:让 AI 测试 Agent 在运行前就知道「测什么、怎么断言、有哪些陷阱」。触发词:「分析我的 Android 项目」「生成测试画像」「理解这个 App 的业务」「提取测试先验知识」「帮我分析 Android 源码」 | LeoYeAI/ | 2.2k | — | ~2.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 988 | OpenClaw 多模式安全巡检工具:默认本地离线扫描,可选联网威胁情报上报. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~2.5k | Automated safety check: Notes | MIT | 2 mo ago |
| 989 | OpenClaw 安全巡检工具,一键执行系统安全扫描并生成通俗易懂的报告. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~2k | Automated safety check: Notes | MIT | 2 mo ago |
| 990 | Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices. | trilwu/ | 157 | — | ~3.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 991 | Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage… | trilwu/ | 157 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 992 | 992.Hunting Threats Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk… | trilwu/ | 157 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 993 | Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 994 | Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh… | trilwu/ | 157 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 995 | Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with… | trilwu/ | 157 | — | ~2.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 996 | Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline. | trilwu/ | 157 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 997 | Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and… | trilwu/ | 157 | — | ~2.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 998 | Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment… | trilwu/ | 157 | — | ~2.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 999 | Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with… | trilwu/ | 157 | — | ~4.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 1000 | 1000.Agent Onboarding Onboard yourself to a repo where several agents work in parallel, syncing through a shared TODO.md. | forefy/ | 152 | — | ~536 | Automated safety check: Pass | MIT | 6 days ago |
| 1001 | 1001.Phx Deps Audit Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. | oliver-kriska/ | 565 | — | ~2.2k | Automated safety check: Pass | MIT | 6 days ago |
| 1002 | 1002.Phx Deps Vet Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner. | oliver-kriska/ | 565 | — | ~1.5k | Automated safety check: Pass | MIT | 6 days ago |
| 1003 | 1003.Phx Deps Vet Record vetted Hex versions after security review. An agent skill from oliver-kriska/claude-elixir-phoenix. | oliver-kriska/ | 565 | — | ~1.5k | Automated safety check: Pass | MIT | 6 days ago |
| 1004 | 1004.Phx Deps Vet Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner. | oliver-kriska/ | 565 | — | ~1.5k | Automated safety check: Pass | MIT | 6 days ago |
| 1005 | Run evidence-backed workflows for supply chain, dependency neighborhoods, architecture, performance, unsafe and ownership review, upgrades, and ecosystem integration. | richlander/ | 151 | — | ~4.4k | Automated safety check: Pass | No licence | yesterday |
| 1006 | 1006.Solution Architect 解决方案架构师助手。当用户要设计新系统架构、评审现有架构、做技术选型决策、诊断性能/可扩展性/可用性问题、规划架构演进或重构时使用。覆盖微服务、事件驱动、云原生等架构模式,技术趋势通过实时搜索获取而非依赖内置知识。不用于:具体功能的代码实现、安全漏洞审计(用security-audit)、产品需求分析(用product-manager)、只需一句话回答的技术常识问题。 | staruhub/ | 728 | — | ~670 | Automated safety check: Pass | MIT | 1 mo ago |
| 1007 | 1007.Threat Model Security threat modeling, attack surface mapping, and trust boundary analysis on a codebase. | pproenca/ | 215 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 1008 | 1008.Threat Patch Remediate security findings by producing minimal, surgical code patches. | pproenca/ | 215 | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |