Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 145 | Runs and interprets Psalm security (taint) analysis on a Laravel project. | cachethq/ | 230 | — | ~4.7k | Automated safety check: Pass | Unknown | 6 days ago |
| 146 | Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2… | provos/ | 612 | — | ~5.7k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 147 | Builds a skeptical reviewer grounded in the codebase and research notes to try to refute a spec before any code is written, citing file:line evidence and ending in a go or no-go gate. | JuliusBrussee/ | 1.2k | — | ~959 | Automated safety check: Pass | MIT | 1 mo ago |
| 148 | 148.Migrate To Earl Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time. | mathematic-inc/ | 113 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 149 | 149.Dsl Vm Reverse Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines. | zhaoxuya520/ | 41k | 3 repos | ~2.3k | Automated safety check: Pass | MIT | 19 days ago |
| 150 | Review code for quality, correctness, and security vulnerabilities. | hiroshiyui/ | 135 | — | ~1.6k | Automated safety check: Pass | GPL-3.0 | today |
| 151 | Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk. | GitbookIO/ | 131 | — | ~1.2k | Automated safety check: Pass | No licence | 3 days ago |
| 152 | 152.Stellar Dev End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments. | VelaPayments/ | 131 | — | ~1.8k | Automated safety check: Pass | MIT | 4 days ago |
| 153 | 用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF… | index-login/ | 158 | — | ~3k | Automated safety check: Pass | MIT | yesterday |
| 154 | Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script. | ptn1411/ | 219 | — | ~830 | Automated safety check: Notes | No licence | 19 days ago |
| 155 | 155.Fallow Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills. | fallow-rs/ | 128 | — | ~8.6k | Automated safety check: Pass | MIT | today |
| 156 | 156.Code Vuln Audit Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection. | zebbern/ | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 157 | Evidence-based security report generation for firmware assessments. | OrbitCurve/ | 216 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 158 | Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. | vechain/ | 450 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 159 | 159.Bench Experiment Run and record a hardware experiment on the 2C53T bench using a controlled five-step cycle. | DavidClawson/ | 116 | — | ~1k | Automated safety check: Pass | GPL-3.0 | today |
| 160 | 160.Audit Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills. | austintgriffith/ | 295 | — | ~829 | Automated safety check: Pass | No licence | 1 mo ago |
| 161 | Automate low-impact web vulnerability verification through Burp MCP. | langbyyi/ | 129 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 162 | Three-axis review of the branch diff — Standards (this repo's documented standards + public API surface), Spec (the originating Linear issue / PR), and Correctness (runtime bugs + the SDK threat… | getsentry/ | 873 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 163 | 163.Solidity Auditor Security audit of Solidity code while you develop. An agent skill from pashov/skills. | pashov/ | 1.2k | — | ~9.9k | Automated safety check: Pass | MIT | 5 days ago |
| 164 | A skill your agent uses when a user provides a TikTok profile or account link and asks for account analysis, competitor research, content or commerce performance, operational-logic research… | aronhy/ | 168 | — | ~492 | Automated safety check: Pass | MIT | 2 mo ago |
| 165 | 165.Decompiler MCP A skill your agent uses when working with the DecompilerServer MCP server to inspect, search, decompile, analyze, or compare .NET assemblies, especially foreign code such as Unity/RimWorld… | pardeike/ | 108 | — | ~1.5k | Automated safety check: Pass | MIT | 9 days ago |
| 166 | 166.Fix Diagnose and fix Session Sniffer bugs, errors, tracebacks, logs, lint failures, static-analysis findings, and IDE-reported problems. | BUZZARDGTA/ | 105 | — | ~2.2k | Automated safety check: Pass | GPL-3.0 | today |
| 167 | 移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。 | s7safe/ | 211 | — | ~631 | Automated safety check: Pass | No licence | 5 mo ago |
| 168 | 168.Docs Update project documentation when features are added or changed. | boostsecurityio/ | 523 | — | ~336 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 169 | Format and pretty-print Hak5 WiFi Pineapple recon JSON scan files for readability. | sneakerhax/ | 112 | — | ~259 | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 170 | 170.Build DB 使用 jar-analyzer-engine 从 JAR/WAR/Class 文件构建 SQLite 分析数据库。这是进行 Java 代码安全审计、方法调用分析的第一步。 | jar-analyzer/ | 141 | — | ~898 | Automated safety check: Pass | No licence | 6 mo ago |
| 171 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.5k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 172 | Covers recovering and verifying the VC7 C runtime, compiler-runtime and D3DX library functions in the TH08 decompilation, with hash-pinned evidence. | N0zoM1z0/ | 105 | — | ~877 | Automated safety check: Pass | MIT | today |
| 173 | A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a… | LIDR-academy/ | 278 | — | ~4.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 174 | 174.Tenuo Warrant Create or delegate Tenuo warrants from natural-language authority requirements. | tenuo-ai/ | 103 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 175 | Tests a security patch against the original bug, its variants and normal behavior, with reproducible baseline-versus-patched evidence before you merge or call it fixed. | trailofbits/ | 7.5k | — | ~3.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 176 | Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity. | thomast1906/ | 202 | — | ~3.1k | Automated safety check: Pass | MIT | 3 days ago |
| 177 | 177.Bom Evidence Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and… | cdxgen/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 178 | 178.Dfir Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. | transilienceai/ | 563 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 179 | 179.Idor Testing This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"… | zebbern/ | 4.7k | 8 repos | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 180 | 180.Php Auth Audit PHP Web 源码鉴权机制审计工具。从源码中识别所有认证/鉴权实现并分析风险,输出路由-鉴权映射与漏洞分析(含 PoC 与修复建议)。 | 0xShe/ | 402 | 1 repo | ~951 | Automated safety check: Pass | No licence | 6 mo ago |
| 181 | Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry. | samugit83/ | 3k | — | ~1.1k | Automated safety check: Pass | MIT | 2 days ago |
| 182 | Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision. | backnotprop/ | 9.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 183 | Distills repeated workflows into new skills, improves existing ones and promotes them through local, project and community tiers after a default-deny safety scan. | telagod/ | 244 | — | ~794 | Automated safety check: Notes | MIT | 2 mo ago |
| 184 | A skill your agent uses for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic… | zhaoxuya520/ | 41k | 2 repos | ~366 | Automated safety check: Pass | MIT | 19 days ago |
| 185 | 185.Go Rust Reverse A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery. | zhaoxuya520/ | 41k | 2 repos | ~339 | Automated safety check: Pass | MIT | 19 days ago |
| 186 | 186.macOS Reverse A skill your agent uses for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis. | zhaoxuya520/ | 41k | 2 repos | ~366 | Automated safety check: Pass | MIT | 19 days ago |
| 187 | 187.Mission Planner Decomposes goals into team blueprints using evidence-based scaling laws, topology selection, and role design. | jdforsythe/ | 151 | — | ~3.5k | Automated safety check: Pass | MIT | 3 mo ago |
| 188 | Run Mira environment risk collection. An agent skill from vw2x/Mira. | vw2x/ | 105 | — | ~793 | Automated safety check: Pass | GPL-3.0 | 6 days ago |
| 189 | Debug and emulate specific code fragments or functions using the Unicorn engine. | index-login/ | 158 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 190 | Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout. | secondsky/ | 462 | — | ~4.8k | Automated safety check: Warn | GPL-3.0 | 5 days ago |
| 191 | 191.Cybersecurity Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity. | AgriciDaniel/ | 228 | — | ~11k | Automated safety check: Warn | MIT | 5 mo ago |
| 192 | Security review for Scalus/Cardano smart contracts. An agent skill from scalus3/scalus. | scalus3/ | 105 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | yesterday |