Search
Security
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization. | PentesterFlow/ | 1.4k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 98 | 98.Hol Guard Run HOL Guard scanner and guard operations via uv run hol-guard. | hashgraph-online/ | 838 | — | ~542 | Automated safety check: Pass | Apache-2.0 | today |
| 99 | Verify that code changes do not introduce OAuth security vulnerabilities. | doorkeeper-gem/ | 5.5k | — | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 100 | 100.Owasp Security Reviews code for security vulnerabilities and guides secure implementation using OWASP Top 10:2025, ASVS 5.0, the OWASP Top 10 for LLM Applications (2026), and the OWASP Top 10 for Agentic… | agamm/ | 377 | — | ~3.5k | Automated safety check: Pass | MIT | 16 days ago |
| 101 | 101.Vibe Check Security audit for web apps, especially AI-built ("vibe coded") ones. | benavlabs/ | 118 | — | ~1.1k | Automated safety check: Notes | MIT | 22 days ago |
| 102 | Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and… | activepieces/ | 25k | — | ~2.9k | Automated safety check: Pass | Unknown | today |
| 103 | Analyze user-provided reference images and reverse-engineer high-fidelity AI image-generation prompts. | LunarXuan/ | 467 | — | ~678 | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 104 | Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. | jeremylongshore/ | 2.8k | 2 repos | ~1.3k | Automated safety check: Notes | MIT | yesterday |
| 105 | 105.Osint Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill. | smixs/ | 141 | — | ~5.5k | Automated safety check: Pass | MIT | 7 mo ago |
| 106 | 106.Semia Audit an agent skill with Semia inside Codex. An agent skill from berabuddies/Semia. | berabuddies/ | 612 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 107 | 107.Audit Flow Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. | zebbern/ | 4.7k | — | ~4.2k | Automated safety check: Pass | MIT | yesterday |
| 108 | Reference knowledge for open-source intelligence collection: the collection cycle, source reliability tiers, search query patterns and entity extraction. | RightNow-AI/ | 18k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 109 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 425 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 110 | 110.Best Practices Apply modern web development best practices for security, compatibility, and code quality. | midudev/ | 114 | 3 repos | ~3k | Automated safety check: Pass | MIT | 12 days ago |
| 111 | 111.Game Recon Figure out how a specific installed game can be modded, before writing any mod code. | rehan-remade/ | 6.1k | — | ~1k | Automated safety check: Pass | MIT | today |
| 112 | 112.Flounder Operates Flounder, an autonomous white-hat security auditor. | adshao/ | 518 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | 5 days ago |
| 113 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.5k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 114 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.5k | 3 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 115 | Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology. | greatpie/ | 101 | — | ~1.1k | Automated safety check: Pass | No licence | 7 mo ago |
| 116 | Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses. | pydantic/ | 8.6k | — | ~852 | Automated safety check: Pass | MIT | yesterday |
| 117 | 117.Security Check Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. | gocronx-team/ | 801 | — | ~690 | Automated safety check: Pass | MIT | yesterday |
| 118 | 118.Bug Hunter Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects. | codexstar69/ | 520 | — | ~5k | Automated safety check: Pass | MIT | 1 mo ago |
| 119 | 119.Adversarial QA Repro-first QA for Inkline — minimal .ink.tsx reproductions, the visual-parity and cross-target harnesses, fuzz targets, and how to audit teammates' claims. | inkline/ | 1.5k | — | ~1.2k | Automated safety check: Pass | No licence | 29 days ago |
| 120 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | 3 days ago |
| 121 | Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. | EpicenterHQ/ | 4.8k | — | ~896 | Automated safety check: Pass | Unknown | 2 days ago |
| 122 | Verify or select a SageMaker execution role before creating models, endpoints, or training jobs. | waybarrios/ | 534 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 123 | Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written. | OTRF/ | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | 9 mo ago |
| 124 | 124.Vuln Research 安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research. | tanweai/ | 185 | — | ~847 | Automated safety check: Pass | No licence | 8 mo ago |
| 125 | 125.LLM Sast Scanner General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. | SunWeb3Sec/ | 288 | — | ~6.2k | Automated safety check: Pass | No licence | 1 mo ago |
| 126 | 126.Skillward Audit Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner. | Fangcun-AI/ | 143 | — | ~2.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 127 | Django access control and IDOR security review. An agent skill from getsentry/skills. | getsentry/ | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 128 | Scans eight warning signs behind a stock tip from a friend, chat group or online teacher and returns a four-level risk rating with evidence. | wbh604/ | 7.1k | — | ~450 | Automated safety check: Pass | MIT | 1 mo ago |
| 129 | Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 130 | 130.Write Cve Rule Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE. | evdenis/ | 138 | — | ~2.5k | Automated safety check: Pass | GPL-3.0 | 2 days ago |
| 131 | 131.Skylos Security Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 844 | — | ~545 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 132 | Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files. | HarnessMD/ | 8.6k | — | ~350 | Automated safety check: Notes | MIT | yesterday |
| 133 | Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. | PrefectHQ/ | 28k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 134 | 134.Run Assert Eval Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT. | responsibleai/ | 330 | — | ~11k | Automated safety check: Notes | MIT | 2 days ago |
| 135 | 135.Rsigma Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. | timescale/ | 165 | — | ~1.2k | Automated safety check: Pass | MIT | 2 days ago |
| 136 | Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in… | samugit83/ | 3k | — | ~1.3k | Automated safety check: Pass | MIT | 2 days ago |
| 137 | Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | 1 repo | ~4.4k | Automated safety check: Pass | MIT | yesterday |
| 138 | 138.Vulnhunter Run Unattended VulnHunter operator. An agent skill from nealbridges/VulnHunter. | nealbridges/ | 678 | — | ~711 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 139 | 139.Solidity Auditor Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge. | Gabson0x/ | 442 | — | ~3.7k | Automated safety check: Pass | No licence | 24 days ago |
| 140 | Reverse-engineer missing or incomplete OpenFastTrace system requirements and arc42-style design documentation from a project's user guide, existing documentation, tests, and code. | itsallcode/ | 197 | — | ~2.9k | Automated safety check: Pass | GPL-3.0 | today |
| 141 | Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix. | pretend1111/ | 496 | 1 repo | ~502 | Automated safety check: Pass | Unknown | 5 mo ago |
| 142 | 142.Sast Semgrep Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping. | AgentSecOps/ | 220 | 2 repos | ~2.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 143 | 143.Ohdear Manage Oh Dear website monitoring using the ohdear CLI. An agent skill from ohdearapp/ohdear-cli. | ohdearapp/ | 141 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 144 | 144.Security Audit Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge. | TheDecipherist/ | 551 | — | ~1.3k | Automated safety check: Notes | MIT | 5 mo ago |