Search
Security · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1057 | 1057.Document In Case Add a comment to a case to document findings, actions, or recommendations. | dandye/ | 127 | — | ~450 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 1058 | 1058.Pp Nvd Search the U.S. An agent skill from mvanhorn/printing-press-library. | mvanhorn/ | 2.1k | — | ~1.9k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 1059 | 1059.Security Guidance Security-first development guidance based on OWASP ASVS (Application Security Verification Standard). | OWASP/ | 188 | — | ~8.1k | Automated safety check: Pass | Unknown | 16 days ago |
| 1060 | 1060.Tool Defs Analysis Read-only audit of MCP definition language across an existing surface — tools, resources, prompts, server instructions. | cyanheads/ | 158 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 1061 | 1061.Henry Ford A skill your agent uses whenever reasoning about manufacturing, scaling production, pricing strategies, operational efficiency, vertical integration, or labor compensation. | K-Dense-AI/ | 129 | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 1062 | 1062.John D Rockefeller A skill your agent uses whenever you need to reason like John D. | K-Dense-AI/ | 129 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 1063 | Extract bounded, deterministic evidence from crash and sanitizer logs, including signals, sanitizer classes, memory-safety indicators, stack-frame hashes, and source provenance, while reserving… | cyberful/ | 135 | — | ~563 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1064 | Normalize and compare authorized fraud-control observations from local evidence, highlighting decision drift, coverage gaps, and conflicting outcomes without making a fraud or vulnerability verdict. | cyberful/ | 135 | — | ~649 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1065 | Parse bounded classic PCAP files offline into deterministic capture metadata, packet-length and timestamp summaries, link and network protocol counts, truncation indicators, and source digests… | cyberful/ | 135 | — | ~590 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1066 | Model fraud and abuse threats across actors, account states, value flows, controls, and monetization paths. | cyberful/ | 135 | — | ~716 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1067 | Audit extracted embedded firmware for boot and update trust, credential and secret handling, service exposure, privilege boundaries, parsers, persistence, cryptography, hardening, recovery, and… | cyberful/ | 135 | — | ~644 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1068 | Audit security logging and telemetry from event creation through transport, storage, access, correlation, retention, and response use. | cyberful/ | 135 | — | ~597 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1069 | Test browser capability transfer across postMessage, opener, frame, portal, worker, service-worker, BroadcastChannel, MessagePort, and extension messaging boundaries. | cyberful/ | 135 | — | ~583 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1070 | Test payment decision and value-movement invariants with authorized synthetic instruments and reversible sandbox transactions. | cyberful/ | 135 | — | ~668 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1071 | Trace uploaded, imported, generated, archived, converted, scanned, rendered, and downloaded files across storage, naming, extraction, parser, sandbox, and cleanup boundaries. | cyberful/ | 135 | — | ~646 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1072 | Reconstruct how principal, actor, issuer, audience, assurance, scopes, and delegated authority change across requests, tokens, services, queues, and stored artifacts. | cyberful/ | 135 | — | ~730 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1073 | Reconstruct how tenant and organization context is authenticated, selected, routed, cached, queued, and bound to resources across distributed request paths. | cyberful/ | 135 | — | ~679 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1074 | Reconstruct transaction state across services, ledgers, queues, and compensations from local artifacts, identifying causal gaps, duplicate effects, and value mismatches without active traffic. | cyberful/ | 135 | — | ~635 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1075 | 1075.AWS Essentials A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or… | ericrisco/ | 180 | — | ~2.9k | Automated safety check: Notes | MIT | 2 days ago |
| 1076 | 1076.Go A skill your agent uses when writing, reviewing, testing, or shipping Go code and HTTP services: idioms, %w error wrapping, goroutine/context/errgroup concurrency, net/http 1.22 routing, log/slog… | ericrisco/ | 180 | — | ~3.9k | Automated safety check: Pass | MIT | 2 days ago |
| 1077 | 1077.Cis Controls Implement CIS Controls v8 critical security controls for effective cyber defense in CIA platform | Hack23/ | 239 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1078 | Implement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines | Hack23/ | 239 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1079 | Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support | Hack23/ | 239 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1080 | Hack23 Information Security Policy integration for SDLC — developer-facing mapping of ISP requirements to daily engineering activities, tooling, and evidence | Hack23/ | 239 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1081 | AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model | Hack23/ | 239 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1082 | 1082.MCP Gateway Security MCP gateway security patterns, token management, request validation, and audit logging for MCP communications | Hack23/ | 239 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1083 | 1083.Nist Csf Mapping Map CIA platform security controls to NIST Cybersecurity Framework functions: Identify, Protect, Detect, Respond, Recover | Hack23/ | 239 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1084 | Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform | Hack23/ | 239 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1085 | Hack23 secure development policy enforcement, SAST/DAST integration, dependency scanning, and code signing practices | Hack23/ | 239 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1086 | 1086.Security By Design Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC | Hack23/ | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1087 | Maintain comprehensive security documentation including SECURITYARCHITECTURE.md, THREATMODEL.md per Hack23 ISMS standards | Hack23/ | 239 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1088 | 1088.Audit Embedded Focused static audit of device firmware and IoT software for update, boot, provisioning, credential, debug-interface and device-communication boundary failures, using an ISVS-informed threat model. | alpha-omega-security/ | 242 | — | ~1.6k | Automated safety check: Notes | MIT | yesterday |
| 1089 | 1089.Audit Exfil Focused static audit for attacker-controlled reads, requests, parsers, or error paths that can disclose files, metadata, secrets, or internal responses. | alpha-omega-security/ | 242 | — | ~2.2k | Automated safety check: Notes | MIT | yesterday |
| 1090 | Audit package manager clients, registries, and proxies against a bundled threat model. | alpha-omega-security/ | 242 | — | ~1k | Automated safety check: Notes | MIT | yesterday |
| 1091 | 1091.Audit Pii Focused static audit for real personal or customer-identifying data committed to source or exposed through logs, URLs, telemetry, exports, and responses. | alpha-omega-security/ | 242 | — | ~3k | Automated safety check: Notes | MIT | yesterday |
| 1092 | 1092.Audit Web Focused static audit of web applications and APIs for session, browser-origin, upload and business-workflow boundary failures, using an ASVS-informed threat model. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Notes | MIT | yesterday |
| 1093 | 1093.Embedded Native Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized. | alpha-omega-security/ | 242 | — | ~425 | Automated safety check: Pass | MIT | yesterday |
| 1094 | Eval-only short-prompt variant of security-deep-dive for A/B testing against the production prompt. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 1095 | Audit a Claude/Agent SKILL.md (or any AI skill / system prompt) for safety before installing or merging it. | mohitagw15856/ | 1.4k | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 1096 | 1096.Repo Sentinel Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. | Mathews-Tom/ | 329 | — | ~2.2k | Automated safety check: Pass | MIT | 5 days ago |
| 1097 | 1097.Apt Emulation APT 模拟与情报驱动红队方法论。基于已知 APT 组织的 TTP(MITRE ATT&CK)设计红队行动计划。当需要模拟特定威胁组织、设计高仿真攻击演练、或根据威胁情报制定攻击策略时使用 | wgpsec/ | 1.8k | — | ~922 | Automated safety check: Pass | No licence | yesterday |
| 1098 | 1098.C2 Beacon Analysis C2 Beacon 配置提取与分析。当捕获到 Cobalt Strike/Sliver/Havoc 等 C2 框架的 Beacon 样本、内存 dump、或网络流量时使用。提取 C2 地址、通信协议、Malleable Profile、Watermark 等关键情报。红队视角:了解蓝队如何从 Beacon 提取 IOC 以改进 C2 OPSEC | wgpsec/ | 1.8k | — | ~1.2k | Automated safety check: Pass | No licence | yesterday |
| 1099 | C2框架免杀方法论:分析 C2 源码、搜索检测规则(YARA/Sigma/Snort)、逐规则分析、修改源码绕过检测。当遇到 YARA/Sigma/Snort 规则触发告警、beacon/implant 被杀软检测到时使用。第一步:确认 implant/beacon 语言和架构;第二步:搜索对应检测规则并逐规则分析修改 | wgpsec/ | 1.8k | — | ~557 | Automated safety check: Pass | No licence | yesterday |
| 1100 | 1100.Ioc Analysis IOC(失陷指标)分析与对抗方法论。蓝队视角:如何收集、富化、关联 IOC 进行威胁猎杀。红队视角:如何避免自身基础设施和工具产生可识别的 IOC,以及如何使 IOC 快速失效。当红队需要评估自身暴露面或规划 C2 基础设施时使用 | wgpsec/ | 1.8k | — | ~816 | Automated safety check: Pass | No licence | yesterday |
| 1101 | 威胁猎杀原理与规避方法论。理解蓝队如何主动猎杀(Hypothesis-driven / IOC-driven / Analytics-driven),红队如何设计行为使自己不被猎杀到。当需要评估自身操作是否可被威胁猎杀发现时使用 | wgpsec/ | 1.8k | — | ~1k | Automated safety check: Pass | No licence | yesterday |
| 1102 | 1102.Sicurezza GitHub Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot. | ccplugins/ | 970 | — | ~486 | Automated safety check: Notes | Apache-2.0 | 2 mo ago |
| 1103 | Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface. | LearnPrompt/ | 110 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 1104 | Answer "who did what" security questions from Audit Trail — deletions, config changes, login activity, permission changes, actions from a specific user or IP. | datadog-labs/ | 177 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |