Search
Security · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1297 | 1297.P2p Dos And Eclipse L1 trigger - audits peer-to-peer networking for DoS vectors (resource exhaustion, amplification), eclipse attack susceptibility, and discovery table poisoning (Kademlia/devp2p). | PlamenTSV/ | 303 | — | ~4k | Automated safety check: Pass | MIT | 14 days ago |
| 1298 | Trigger HASMULTICONTRACT flag in templaterecommendations.md (recon detects 2+ in-scope contracts/modules sharing parameters or formulas) - Agent Type general-purpose (standal... | PlamenTSV/ | 303 | — | ~2.8k | Automated safety check: Pass | MIT | 14 days ago |
| 1299 | 1299.Create Fix PR A skill your agent uses when opening or updating a GitHub pull request after Phase 5 of /compliance:analyze-cve has applied and verified a CVE fix locally. | openshift-eng/ | 120 | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 1300 | CRITICAL: Never modify files in content-addressable storage systems where the filename IS the content hash (SHA256, IPFS CID, etc.). | divinevideo/ | 266 | — | ~984 | Automated safety check: Pass | MPL-2.0 | yesterday |
| 1301 | Assess identity trust topology, assurance boundaries, issuer and relying-party responsibilities, and failure containment before testing a specific authentication or authorization mechanism. | cyberful/ | 135 | — | ~710 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1302 | Audit where access policy is decided and enforced across source, configuration, services, caches, jobs, and data stores, including deny behavior and decision-input integrity. | cyberful/ | 135 | — | ~725 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1303 | Route a cloud-native security audit across effective IAM, infrastructure as code, build and release paths, containers, Kubernetes, serverless workloads, secrets, event sources, and control-plane… | cyberful/ | 135 | — | ~852 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1304 | Operate a managed Firefox/Marionette laboratory for privileged chrome-context experiments, content automation, real WebDriver windows, permission readback, and synthetic X11 clipboard controls. | cyberful/ | 135 | — | ~673 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1305 | 1305.Operate Mitre Attack Use the release-embedded MITRE ATT&CK snapshot as a threat-informed reasoning lens without allowing the framework to constrain novel vulnerability discovery. | cyberful/ | 135 | — | ~1.5k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1306 | Test account and authenticator recovery as an assurance transition, including proofing, channel changes, support overrides, replay resistance, and post-recovery invalidation. | cyberful/ | 135 | — | ~665 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1307 | Route file-ingestion security work across processing pipelines, deserialization and object binding, and SOAP or XML services. | cyberful/ | 135 | — | ~600 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1308 | Route HTTP intermediary testing across request normalization, web-cache behavior, and offline traffic evidence. | cyberful/ | 135 | — | ~630 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1309 | Test identity linking, invitation, merge, provisioning, deprovisioning, and account-association ceremonies for proof-of-control, tenant binding, uniqueness, lifecycle, and rollback failures using… | cyberful/ | 135 | — | ~584 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1310 | Test promotions, referrals, quotas, inventory, and entitlement invariants through authorized, bounded, reversible experiments with tester-controlled accounts and assets. | cyberful/ | 135 | — | ~633 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 1311 | 1311.Network Scanner Scan networks to discover devices, gather MAC addresses, vendors, and hostnames. | sundial-org/ | 663 | — | ~726 | Automated safety check: Notes | No licence | 7 mo ago |
| 1312 | 1312.Ccs Author Response A skill your agent uses when drafting an ACM CCS rebuttal during the HotCRP author-response window, covering threat-model defenses, adaptive-attack objections, ethics and disclosure questions… | brycewang-stanford/ | 1.2k | — | ~949 | Automated safety check: Pass | MIT | 14 days ago |
| 1313 | 1313.Ccs Topic Selection A skill your agent uses when deciding whether a security project fits ACM CCS versus IEEE S&P, USENIX Security, NDSS, PETS, or a crypto/theory venue, identifying the security contribution type, and… | brycewang-stanford/ | 1.2k | — | ~945 | Automated safety check: Pass | MIT | 14 days ago |
| 1314 | A skill your agent uses when drafting the IEEE S&P (Oakland) rebuttal for second-round papers or the response plan for a Revise decision, including triaging reviews under the ~5-day window… | brycewang-stanford/ | 1.2k | — | ~1.3k | Automated safety check: Pass | MIT | 14 days ago |
| 1315 | A skill your agent uses when deciding whether a security or privacy project belongs at IEEE S&P (Oakland), including the threat-model test, SoK fit, routing among USENIX Security, CCS, NDSS, PETS… | brycewang-stanford/ | 1.2k | — | ~1.3k | Automated safety check: Pass | MIT | 14 days ago |
| 1316 | 1316.Issta Supplementary A skill your agent uses when deciding what lives in the ISSTA 18-page body versus the artifact and any appendix, covering the no-unlimited-appendix reality, what reviewers will and will not open… | brycewang-stanford/ | 1.2k | — | ~1k | Automated safety check: Pass | MIT | 14 days ago |
| 1317 | A skill your agent uses when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses… | brycewang-stanford/ | 1.2k | — | ~1.5k | Automated safety check: Pass | MIT | 14 days ago |
| 1318 | A skill your agent uses when reasoning about how a USENIX Security Symposium cycle actually decides — early-reject notifications, multi-round reviewing, the retirement of Major Revision in favor of… | brycewang-stanford/ | 1.2k | — | ~1.3k | Automated safety check: Pass | MIT | 14 days ago |
| 1319 | 1319.Audit Finding Fix For a batch of findings from a non-security audit tool (<audit-tool — ruff / flake8 / mypy / pylint / CodeQL / Apache Verum / Apache Caer / equivalent; full list in the body) against <upstream… | apache/ | 114 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1320 | 1320.Agentsecrets Zero-knowledge secrets infrastructure — AI agents manage the complete credential lifecycle without ever seeing values | LeoYeAI/ | 2.2k | — | ~6k | Automated safety check: Notes | MIT | 2 mo ago |
| 1321 | 1321.Java File Audit Java 源码文件操作类漏洞审计。当在 Java 白盒审计中需要检测文件相关漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~989 | Automated safety check: Pass | No licence | yesterday |
| 1322 | 1322.Java Framework Audit Java 框架特定漏洞源码审计。当在 Java 白盒审计中需要检测框架层面的已知漏洞模式时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~1.3k | Automated safety check: Pass | No licence | yesterday |
| 1323 | Java 源码序列化类漏洞审计。当在 Java 白盒审计中需要检测序列化/反序列化相关漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~1k | Automated safety check: Pass | No licence | yesterday |
| 1324 | PHP 源码序列化与模板类漏洞审计。当在 PHP 白盒审计中需要检测反序列化、XML 解析或模板注入漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~689 | Automated safety check: Pass | No licence | yesterday |
| 1325 | 1325.Recon Full 主动式全流程资产侦察。当需要对目标进行从零到漏洞发现的完整侦察、渗透测试的第一阶段、或需要全面了解目标攻击面时使用。覆盖子域名枚举→端口扫描→存活检测→指纹识别→POC 扫描的完整链条 | wgpsec/ | 1.8k | — | ~487 | Automated safety check: Pass | No licence | yesterday |
| 1326 | 1326.Self Improve Audit the conversation and the project for what could have gone better, then turn the generalizable lessons into committed improvements in the repo that hosts this skill. | forefy/ | 152 | — | ~1k | Automated safety check: Pass | MIT | 6 days ago |
| 1327 | 1327.Tiny Auditor Audit codebase to uncover critical issues explicitly without false positives | forefy/ | 152 | — | ~2.9k | Automated safety check: Pass | MIT | 6 days ago |
| 1328 | Screen a weather- or event-triggered demand spike for Amazon product opportunities by checking local supply-capacity gaps, installation or usage-friction barriers, and one's own supply-chain… | xjli360/ | 251 | — | ~666 | Automated safety check: Pass | MIT | 13 days ago |
| 1329 | Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity. | athola/ | 341 | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 1330 | 1330.Review Security Review application and infrastructure changes for exploitable security risks by tracing assets, trust boundaries, attacker-controlled input, authorization, sensitive data, and dangerous sinks. | hashgraph-online/ | 1.3k | — | ~601 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1331 | セキュリティ観点の通常レビューエージェント. An agent skill from hashgraph-online/awesome-codex-plugins. | hashgraph-online/ | 1.3k | — | ~730 | Automated safety check: Pass | MIT | yesterday |
| 1332 | Repository または subsystem を対象に、source-only で明示的なセキュリティ監査を行う entry skill。 | hashgraph-online/ | 1.3k | — | ~4.2k | Automated safety check: Pass | MIT | yesterday |
| 1333 | 完成した差分・PR・検証証拠に残る Unknown(未確認の前提・調査されていない影響・ 不足している証拠)を横断合成する evidence-sufficiency のメタ観点。個別 defect の 検出は既存 skill へ委譲し、本 skill は「そのリスク種別を調査した証拠が残っているか」 の meta 評価のみを行う。通常は finding verification 後の… | hashgraph-online/ | 1.3k | — | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 1334 | 1334.Dependency Auditor Audit npm dependencies for security vulnerabilities, outdated packages, and unused dependencies. | OneWave-AI/ | 336 | — | ~835 | Automated safety check: Pass | MIT | 9 days ago |
| 1335 | A skill your agent uses to run real static analysis over a diff or repo before shipping — Semgrep, CodeQL, secret scanning, dependency CVEs — and triage the findings into what must be fixed now… | OneWave-AI/ | 336 | — | ~836 | Automated safety check: Pass | MIT | 9 days ago |
| 1336 | 1336.Re Anti Cheat 反作弊对抗分析:EAC/BattlEye 驱动、内存校验、检测机制还原. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 1337 | 1337.Re Crypto Decrypt 加密数据还原:定位解密函数、写解密脚本. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 1338 | 1338.Re Crypto Id 加密算法识别:常量表指纹、自定义加密模式. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 1339 | 1339.Re Evasion 检测规避/EDR 对抗分析:AMSI/ETW 绕过、无文件、lolbin 链. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 1340 | 1340.Re Ransomware 勒索软件分析:加密识别、勒索信、解密恢复思路. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 1341 | Security review checklist for construction software systems. | datadrivenconstruction/ | 345 | — | ~3.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 1342 | Run security scans and vulnerability checks. An agent skill from enuno/unifi-mcp-server. | enuno/ | 282 | — | ~194 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 1343 | 1343.Kernel Security Linux kernel security skill for LSM, hardening, and exploit mitigations. | mohitmishra786/ | 252 | — | ~1.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 1344 | 1344.Zz Code Recon Deep architectural context building for security audits. An agent skill from sendaifun/skills. | sendaifun/ | 130 | — | ~3.3k | Automated safety check: Notes | Apache-2.0 | 2 mo ago |