Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1105 | 1105.Doorman Dependency gatekeeper. An agent skill from ccplugins/awesome-claude-code-plugins. | ccplugins/ | 970 | — | ~1.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 1106 | 1106.Security Review Security review gate for MCP server installations. An agent skill from bobmatnyc/claude-mpm. | bobmatnyc/ | 156 | — | ~1.1k | Automated safety check: Pass | Unknown | 1 mo ago |
| 1107 | 1107.AWS Advisor AWS Advisor workflow skill. An agent skill from diegosouzapw/awesome-omni-skills. | diegosouzapw/ | 159 | — | ~4.3k | Automated safety check: Pass | MIT | 3 mo ago |
| 1108 | 1108.Source Code Audit 当拿到源码、代码片段、反编译产物,或用户要求代码审计时调用。负责输入点→传播链→危险函数Sink的静态审计,跨语言(PHP/Java/Python/Node/Go)危险函数速查,输出可疑调用链与缺陷触发条件。 | zhaji2333/ | 115 | — | ~409 | Automated safety check: Pass | MIT | 26 days ago |
| 1109 | 1109.04 Audit Audit a codebase read-only across seven quality pillars into one ranked report. | ai-driven-dev/ | 513 | — | ~672 | Automated safety check: Pass | MIT | yesterday |
| 1110 | 1110.Vul Analyse 漏扫报告分析 Skill。输入主流厂商漏扫报告(绿盟/深信服/悬镜/明鉴/等保/奇安信/启明/华云安/长亭/Nessus/Trivy/Grype/Snyk/OpenVAS 等 Excel/HTML/JSON/XML/.nessus 格式),自动提取漏洞并去重,可选对接知识库 Provider(修复历史)和威胁情报 Provider(CVE 情报),生成 7… | infometa/ | 348 | — | ~3.9k | Automated safety check: Pass | No licence | yesterday |
| 1111 | 1111.Web Security Audit 基于 OWASP Top 10 (2021) 标准提供代码安全审查,逐项检查 SQL 注入、XSS、SSRF、访问控制、加密失败等常见漏洞,并给出具体的漏洞代码示例与修复方案。当用户需要代码安全审查、安全加固、渗透测试辅助,或提及 OWASP、安全检查、SQL 注入、XSS、代码审计、安全清单等关键词时触发此技能。 | rongxinzy/ | 154 | — | ~3k | Automated safety check: Pass | MIT | yesterday |
| 1112 | 1112.Owasp Security Comprehensive OWASP-aligned security guidance across six standards - Top 10 (2021) for web apps, ASVS 5.0, MASVS v2.1.0 for mobile, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the… | davila7/ | 33k | — | ~7.4k | Automated safety check: Warn | MIT | yesterday |
| 1113 | 1113.Enforce Sbom Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing Harness pipeline to verify SBOM attestations and apply OPA SBOM policy sets. | harness/ | 115 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 1114 | 1114.Php Tooling Configure PHP ecosystem tooling, dependency management, and static analysis. | HoangNguyen0403/ | 572 | — | ~615 | Automated safety check: Pass | MIT | yesterday |
| 1115 | 1115.Security Review AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files. | danielvm-git/ | 260 | — | ~1.5k | Automated safety check: Pass | MIT | 19 days ago |
| 1116 | Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident… | instructa/ | 139 | — | ~1.8k | Automated safety check: Pass | No licence | 12 days ago |
| 1117 | 安全测试助手 - 专业的应用安全测试与防护专家。适用场景: (1) Web应用安全测试(OWASP Top 10漏洞检测) (2) API安全测试(认证/授权/数据泄露) (3) 安全测试用例设计与评审 (4) 渗透测试方案制定与执行指导 (5) 安全漏洞分析与风险评估 (6) 安全加固建议与最佳实践 (7) 安全合规检查(GDPR/等保) (8) 安全测试报告编写… | chendongqi/ | 126 | — | ~1.7k | Automated safety check: Pass | No licence | 8 mo ago |
| 1118 | 1118.Elixir Conventions Elixir code conventions covering Elixir 1.14+/OTP 25+, pattern matching, mix format, Credo/Dialyzer, ExUnit, ExDoc, OTP process patterns, and dependency security. | Goldziher/ | 159 | — | ~316 | Automated safety check: Pass | MIT | yesterday |
| 1119 | 1119.Centralization Risk Trigger Pattern Protocol has privileged authorities (admin, operator, upgrade authority, governance) - Inject Into Breadth agents (optional), depth-state-trace | PlamenTSV/ | 303 | — | ~3k | Automated safety check: Pass | MIT | 14 days ago |
| 1120 | Trigger Pattern updatecurrentcontractwasm detected in codebase - Inject Into Breadth agents, depth-state-trace | PlamenTSV/ | 303 | — | ~2k | Automated safety check: Pass | MIT | 14 days ago |
| 1121 | 1121.Cross Chain Timing Trigger Pattern stellarbridge|sorobanbridge|horizon|anchorprotocol|bridge|crosschain|relay|wormhole|allbridge|debridge|axelar|LayerZero|sequence|emitter - Inject Into Breadth agents, depth-external | PlamenTSV/ | 303 | — | ~4.1k | Automated safety check: Pass | MIT | 14 days ago |
| 1122 | Trigger Pattern MONETARYPARAMETER flag (fee, rate, emission, cap, bps values) - Inject Into Breadth agents (merged via M4 hierarchy) | PlamenTSV/ | 303 | — | ~2.1k | Automated safety check: Pass | MIT | 14 days ago |
| 1123 | Trigger Pattern Any env.invokecontract() or env.tryinvokecontract() detected in contract - Inject Into Breadth agents | PlamenTSV/ | 303 | — | ~2.2k | Automated safety check: Pass | MIT | 14 days ago |
| 1124 | 1124.Fork Ancestry Trigger Pattern Always (run during recon TASK 0, not breadth) - Inject Into Recon agent only (metabuffer.md enrichment) | PlamenTSV/ | 303 | — | ~2.4k | Automated safety check: Pass | MIT | 14 days ago |
| 1125 | 1125.Migration Analysis Trigger Pattern Contract upgrades via updatecurrentcontractwasm, storage migration, deprecated functions, token migrations - Inject Into Breadth agents, depth-state-trace | PlamenTSV/ | 303 | — | ~3.9k | Automated safety check: Pass | MIT | 14 days ago |
| 1126 | 1126.Overflow Safety Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth-edge-case | PlamenTSV/ | 303 | — | ~1.9k | Automated safety check: Pass | MIT | 14 days ago |
| 1127 | 1127.Semi Trusted Roles Trigger Pattern operator/keeper/crank requireauth checks, authority-gated functions - Inject Into Breadth agents, depth-state-trace | PlamenTSV/ | 303 | — | ~2.1k | Automated safety check: Pass | MIT | 14 days ago |
| 1128 | 1128.Sep41 Token Safety Trigger Pattern SEP-41 token patterns detected (approve/transfer/transferfrom/allowance/balance) - Inject Into Breadth agents, depth-token-flow, depth-edge-case | PlamenTSV/ | 303 | — | ~2.5k | Automated safety check: Pass | MIT | 14 days ago |
| 1129 | 1129.Storage Lifecycle Trigger Pattern Always required for Soroban audits - Inject Into Breadth agents, depth agents | PlamenTSV/ | 303 | — | ~2.5k | Automated safety check: Pass | MIT | 14 days ago |
| 1130 | Trigger Pattern interval|period|duration|delay|cooldown|lockperiod|timelock|unbonding|claimdelay|withdrawdelay|maturity|ledgersequence|timestamp - Inject Into Breadth agents, depth-state-trace | PlamenTSV/ | 303 | — | ~3.2k | Automated safety check: Pass | MIT | 14 days ago |
| 1131 | 1131.Token Flow Tracing Trigger Pattern SEP-41 token transfers, TokenClient::new, transfer/transferfrom/burn, XLM native balance - Inject Into Lifecycle, External-Env agents | PlamenTSV/ | 303 | — | ~3.2k | Automated safety check: Pass | MIT | 14 days ago |
| 1132 | Reviews package dependencies for security vulnerabilities, outdated versions, and license compliance. | aiskillstore/ | 433 | — | ~2.2k | Automated safety check: Notes | No licence | yesterday |
| 1133 | 1133.Go Review Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications. | SpecterOps/ | 706 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 17 days ago |
| 1134 | Assess identity trust topology, assurance boundaries, issuer and relying-party responsibilities, and failure containment before testing a specific authentication or authorization mechanism. | cyberful/ | 135 | — | ~710 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1135 | 1135.Security Audit 2 Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or… | sundial-org/ | 663 | — | ~875 | Automated safety check: Pass | No licence | 7 mo ago |
| 1136 | A skill your agent uses when deciding whether a software-engineering project belongs at IEEE ICSME (maintenance, evolution, reverse engineering, program comprehension, technical debt, refactoring… | brycewang-stanford/ | 1.2k | — | ~1.7k | Automated safety check: Pass | MIT | 14 days ago |
| 1137 | Help an adopter or framework developer file a clean, redacted GitHub issue against the Apache Magpie framework repo when a skill, tool, or doc misbehaves. | apache/ | 114 | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1138 | Read-only GitHub Actions workflow security audit for one repository, a repository set, or a whole GitHub org. | apache/ | 114 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1139 | 1139.Phy Security Headers HTTP security header auditor that fetches response headers from any URL and grades them against OWASP, Mozilla Observatory, and Google standards. | LeoYeAI/ | 2.2k | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 1140 | Java 源码认证与配置安全审计。当在 Java 白盒审计中需要检测认证绕过、权限缺陷或安全配置问题时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~888 | Automated safety check: Pass | No licence | yesterday |
| 1141 | 1141.Java Framework Audit Java 框架特定漏洞源码审计。当在 Java 白盒审计中需要检测框架层面的已知漏洞模式时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~1.3k | Automated safety check: Pass | No licence | yesterday |
| 1142 | 1142.Java Frontend Audit Java 源码前端安全类漏洞审计。当在 Java 白盒审计中需要检测前端安全漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~1.4k | Automated safety check: Pass | No licence | yesterday |
| 1143 | PHP 源码认证、配置与逻辑类漏洞审计。当在 PHP 白盒审计中需要检测认证绕过、 权限控制、安全配置、密码学误用或业务逻辑漏洞时触发。 | wgpsec/ | 1.8k | — | ~704 | Automated safety check: Pass | No licence | yesterday |
| 1144 | 1144.Php Framework Audit PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。 | wgpsec/ | 1.8k | — | ~767 | Automated safety check: Notes | No licence | yesterday |
| 1145 | 1145.Php Frontend Audit PHP 源码前端交互类漏洞审计。当在 PHP 白盒审计中需要检测前端安全相关漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~777 | Automated safety check: Pass | No licence | yesterday |
| 1146 | 1146.Harden Applies NIST/CWE security hardening to Python and Rust code. | athola/ | 341 | — | ~2.7k | Automated safety check: Pass | MIT | yesterday |
| 1147 | Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity. | athola/ | 341 | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 1148 | 1148.File Upload Testing File upload vulnerability testing — webshells, bypass, path traversal | NeoTheCapt/ | 143 | — | ~1.6k | Automated safety check: Pass | No licence | 2 mo ago |
| 1149 | Information disclosure detection — error messages, files, headers, debug endpoints | NeoTheCapt/ | 143 | — | ~1.1k | Automated safety check: Notes | No licence | 2 mo ago |
| 1150 | 1150.Ssti Testing Server-side template injection detection, engine identification, and RCE | NeoTheCapt/ | 143 | — | ~748 | Automated safety check: Pass | No licence | 2 mo ago |
| 1151 | 1151.Re Android Crypto Android 加密体系审计(crypto audit):AndroidKeyStore 密钥体系分析(别名/算法/用途/硬件背书)、 Cipher/KeyInfo 审计、加密调用点 hook(Frida 拦截密钥别名与用途)。 | dslsdzc/ | 135 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 1152 | 1152.Re Arm ARM 架构逆向(非 Android):Cortex-M/A 向量表、Thumb/ARM 切换、AAPCS 调用约定、位置相关代码重定位、MMIO 外设寄存器交叉。 | dslsdzc/ | 135 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 5 days ago |