Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1057 | 1057.Re Stego 隐写术检测与提取:文件尾附加、图片 LSB、音频与其他载体、提取验证. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 1058 | 1058.Re Tracing 系统调用/函数调用跟踪:strace/ltrace/dtruss. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~940 | Automated safety check: Notes | Apache-2.0 | 6 days ago |
| 1059 | 1059.Re Uefi UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 1060 | 1060.Re Zig Zig 编译产物逆向:产物识别、comptime 展开、panic/错误处理路径、C ABI 边界. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 1061 | 1061.Security Hardening RBAC configuration, row policies, quotas, network security, audit logging, and access control best practices. | chmonitor/ | 300 | — | ~440 | Automated safety check: Pass | GPL-3.0 | 5 days ago |
| 1062 | A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed… | jeremylongshore/ | 2.8k | — | ~3.7k | Automated safety check: Notes | MIT | yesterday |
| 1063 | Implement security best practices for Gamma integration. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Notes | MIT | yesterday |
| 1064 | Token security: Indexing tokens have write access -- never expose in frontend. | jeremylongshore/ | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 1065 | 1065.Hex Security Basics Apply Hex security best practices for secrets and access control. | jeremylongshore/ | 2.8k | — | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 1066 | Apply Hootsuite security best practices for secrets and access control. | jeremylongshore/ | 2.8k | — | ~876 | Automated safety check: Notes | MIT | yesterday |
| 1067 | Detect sql injection detector operations. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~585 | Automated safety check: Pass | MIT | yesterday |
| 1068 | Analyze and update dependencies with vulnerability scanning. | jeremylongshore/ | 2.8k | — | ~510 | Automated safety check: Pass | MIT | yesterday |
| 1069 | 1069.Fuzzing Fuzzing skill for automated input-driven bug finding in C/C++. | mohitmishra786/ | 252 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 1070 | 1070.Static Analysis Static analysis skill for C/C++ codebases. An agent skill from mohitmishra786/low-level-dev-skills. | mohitmishra786/ | 252 | — | ~1.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 1071 | Guide to software engineering research topics and methodologies | wentorai/ | 298 | 1 repo | ~2k | Automated safety check: Pass | MIT | 3 mo ago |
| 1072 | 1072.Nmap Network Scan Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging. | automateyournetwork/ | 676 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1073 | 1073.Nmap Scan Management Custom nmap scans with arbitrary flags, plus scan history retrieval and management. | automateyournetwork/ | 676 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1074 | Service fingerprinting, OS detection, NSE script execution, and vulnerability scanning using nmap MCP. | automateyournetwork/ | 676 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1075 | 1075.Security Checklist Security best practices for Micronaut/Kotlin backend including authentication, authorization, input validation, and OWASP prevention. | c0x12c/ | 106 | — | ~672 | Automated safety check: Notes | No licence | 3 mo ago |
| 1076 | Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context. | ArabelaTso/ | 253 | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 1077 | Generate randomized and edge-case inputs to detect unexpected failures, bugs, and security vulnerabilities through fuzz testing. | ArabelaTso/ | 253 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 1078 | 1078.Static Bug Detector Analyze source code statically to detect potential functional bugs including null dereferences, incorrect condition checks, unreachable code, inconsistent state updates, logic errors, resource… | ArabelaTso/ | 253 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 1079 | Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials… | ArabelaTso/ | 253 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 1080 | Automatically load this skill when investigating application outages, service degradation, or errors that could have security-related root causes — including unexplained downtime, authentication or… | aws/ | 103 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1081 | 1081.Fuzzing Python Creating fuzz driver for Python libraries using LibFuzzer. An agent skill from benchflow-ai/skillsbench. | benchflow-ai/ | 1.8k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 1082 | 1082.Wp Security Review WordPress security code review for Codex. An agent skill from jorgerosal/wordpress-skills. | jorgerosal/ | 103 | — | ~490 | Automated safety check: Pass | MIT | 4 mo ago |
| 1083 | Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses. | jamditis/ | 416 | — | ~2k | Automated safety check: Warn | MIT | 6 days ago |
| 1084 | Subagent for figma-from-code Phase 0b. An agent skill from bitovi/ai-enablement-prompts. | bitovi/ | 121 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 1085 | 1085.Secure Code Guidance Review or write Python, JavaScript, TypeScript, or Go code using secure defaults. | nightly-labs/ | 489 | — | ~369 | Automated safety check: Pass | Unknown | yesterday |
| 1086 | 1086.Gemini CLI Google Gemini CLI for second opinions, architectural advice, code reviews, security audits. | secondsky/ | 227 | — | ~2.8k | Automated safety check: Pass | MIT | 13 days ago |
| 1087 | REST API security hardening with authentication, rate limiting, input validation, security headers. | secondsky/ | 227 | — | ~718 | Automated safety check: Pass | MIT | 13 days ago |
| 1088 | 1088.Csrf Protection Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes. | secondsky/ | 227 | — | ~656 | Automated safety check: Pass | MIT | 13 days ago |
| 1089 | Configures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks. | secondsky/ | 227 | — | ~638 | Automated safety check: Pass | MIT | 13 days ago |
| 1090 | 1090.Xss Prevention XSS attack prevention with input sanitization, output encoding, Content Security Policy. | secondsky/ | 227 | — | ~1.5k | Automated safety check: Pass | MIT | 13 days ago |
| 1091 | 1091.Golang Rules Go coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit. | softspark/ | 179 | — | ~3k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 1092 | 1092.Skill Scanner Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. | sundial-org/ | 663 | 1 repo | ~364 | Automated safety check: Pass | No licence | 7 mo ago |
| 1093 | Write up a supply chain disruption — port delay, carrier failure, customs hold, or in-transit damage — as a decision-ready incident report. | mohitagw15856/ | 1.4k | — | ~1.7k | Automated safety check: Pass | MIT | 2 days ago |
| 1094 | 1094.AWS Networking Audit AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource… | LeoYeAI/ | 2.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 1095 | 1095.Cisco Firewall Audit Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment… | LeoYeAI/ | 2.2k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 1096 | Cross-cloud security posture assessment covering IAM analysis, encryption audit, and public exposure detection across AWS, Azure, and GCP using [AWS]/[Azure]/[GCP] inline labels for… | LeoYeAI/ | 2.2k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 1097 | Network forensics evidence collection and analysis during security incidents. | LeoYeAI/ | 2.2k | — | ~5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 1098 | Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow… | trilwu/ | 157 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 1099 | 1099.Cot Injection 思维链 (Chain-of-Thought) 注入攻击方法论。当目标系统使用 ReAct/CoT 框架进行多步推理、 Agent 依赖中间推理结果做决策、或需要测试思维链完整性时触发。 | wgpsec/ | 1.8k | — | ~640 | Automated safety check: Pass | No licence | yesterday |
| 1100 | CTF/靶场 Flag 强制验证流程。当通过任何方式发现疑似 flag 字符串(含 flag{、FLAG{、ctf{ 等格式)时必须立即使用此 skill 验证,不要直接提交。防止因字符截断、编码错误、HTML 实体、base64 不完整解码、hex 截断等原因导致提交错误 flag。即使 flag 看起来完整,也可能存在隐藏字符或编码问题。覆盖 SQL… | wgpsec/ | 1.8k | — | ~644 | Automated safety check: Pass | No licence | yesterday |
| 1101 | 1101.Ctf Web Recon CTF Web 挑战专用侦察方法。当面对 CTF 靶场目标需要快速发现攻击入口时使用。与真实渗透的 recon 不同——CTF 是单个应用、有意留线索、侦察应在 2-3 轮内完成。覆盖源码泄露、备份文件、隐藏路径、页面线索提取 | wgpsec/ | 1.8k | — | ~624 | Automated safety check: Notes | No licence | yesterday |
| 1102 | 1102.Naabu Portscan 使用 naabu 进行高速端口扫描。当需要对目标主机/网段进行端口发现、存活检测时使用。naabu 是 ProjectDiscovery 出品的快速端口扫描器,支持 SYN/CONNECT/UDP 扫描,性能远超 nmap,支持批量目标、CDN 排除、nmap 集成。任何涉及端口扫描、端口发现、主机存活检测、网段探测的场景都应使用此技能。如果 naabu 结果不足再降级用 nmap | wgpsec/ | 1.8k | — | ~812 | Automated safety check: Notes | No licence | yesterday |
| 1103 | 1103.Nmap Scan 使用 nmap 进行端口扫描和服务识别。当需要对目标进行精细端口扫描、服务版本探测、操作系统指纹识别、NSE 脚本漏洞扫描时使用。nmap 是最经典的网络扫描器,支持 SYN/TCP/UDP/ACK 等多种扫描模式,内置 600+ NSE 脚本。任何涉及端口扫描、服务识别、漏洞脚本扫描、操作系统指纹的场景都应使用此技能。速度不如 naabu,但功能远超 naabu | wgpsec/ | 1.8k | — | ~652 | Automated safety check: Notes | No licence | yesterday |
| 1104 | 1104.Nuclei Scan Nuclei 漏洞扫描工具使用方法论。当需要对目标进行已知漏洞扫描、CVE 验证、批量 PoC 检测时使用。Nuclei 拥有社区维护的 9000+ 模板,覆盖 CVE、默认口令、配置错误、信息泄露等。任何涉及 nuclei 扫描、CVE 批量验证、PoC 检测、漏洞模板搜索的场景都应使用此技能。也适用于需要从 nuclei 模板中提取 payload 用于手动利用的场景 | wgpsec/ | 1.8k | — | ~1.1k | Automated safety check: Pass | No licence | yesterday |