Search
Security · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 145 | Generate a PR-ready technique proposal when an attack step doesn't map to existing SITF techniques. | wiz-sec-public/ | 182 | — | ~4.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 146 | Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation. | wshobson/ | 40k | 8 repos | ~742 | Automated safety check: Pass | MIT | 6 days ago |
| 147 | Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries. | nordstjernen-web/ | 127 | — | ~920 | Automated safety check: Pass | GPL-3.0 | yesterday |
| 148 | 148.Analyze Codescan 分析 Code Scanning (CodeQL) 告警,评估安全风险并创建修复任务。当用户要求分析 Code Scanning 告警、CodeQL 告警时触发。参数为告警编号。 | ModelEngine-Group/ | 2.1k | — | ~187 | Automated safety check: Pass | MIT | 7 mo ago |
| 149 | 149.Nuclei Scan Run a Nuclei security scan against the target URL and report findings by severity. | MigoXLab/ | 232 | — | ~846 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 150 | 150.Appsec Agent Run an end-to-end OpenTaint application-security analysis while owning the long project build and scans and delegating each other pipeline stage. | seqra/ | 163 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 151 | 151.Bom Signing Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 152 | 152.Codex Review Run a Codex-CLI static-analysis parity review of the current diff against the local RPython/PyPy sources, then act on it — fix the regressions and new mismatches in-session, and file the rest as… | youknowone/ | 116 | — | ~2.3k | Automated safety check: Pass | Unknown | yesterday |
| 153 | 153.Cloud Audit Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps. | briiirussell/ | 413 | — | ~1.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 154 | 154.Security Audit Audit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline. | mono/ | 5.6k | — | ~5.7k | Automated safety check: Pass | MIT | yesterday |
| 155 | 155.Correlate Ioc Check for existing SIEM alerts and case management entries related to IOCs. | dandye/ | 127 | — | ~624 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 156 | Handle confidential GitHub Security Advisory response for Paperclip. | paperclipai/ | 99k | — | ~2k | Automated safety check: Pass | MIT | yesterday |
| 157 | A skill your agent uses when stitching kernels into a multi-launch ELF and the AIE compiler rejects the merged module (BD exhaustion, channel routing, herd shape conflict, IR validation error, DMA… | Xilinx/ | 150 | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 158 | 158.Healthcheck Host security hardening and risk-tolerance configuration for OpenClaw deployments. | trpc-group/ | 1.9k | 9 repos | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 159 | 159.Audit Prep Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project… | PlamenTSV/ | 303 | — | ~3.7k | Automated safety check: Pass | MIT | 14 days ago |
| 160 | 160.Onvifscan ONVIF device security scanner for testing authentication and brute-forcing credentials. | BrownFineSecurity/ | 859 | 1 repo | ~608 | Automated safety check: Pass | MIT | 4 mo ago |
| 161 | 161.Bandit Run bandit against the Python source in the repository and map its hits into the findings shape. | alpha-omega-security/ | 242 | — | ~615 | Automated safety check: Notes | MIT | yesterday |
| 162 | 162.Zhin Audit Audit Zhin.js changes for security, performance, lifecycle, and architecture regressions. | zhinjs/ | 136 | — | ~596 | Automated safety check: Notes | MIT | yesterday |
| 163 | Apply STRIDE methodology to systematically identify threats. | sangrokjung/ | 852 | 9 repos | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 164 | Expert workflow for reviewing Tauri 2 desktop app security. An agent skill from mukiwu/tempo-term. | mukiwu/ | 229 | — | ~2.8k | Automated safety check: Notes | Apache-2.0 | 10 days ago |
| 165 | Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit. | microsoft/ | 111 | — | ~356 | Automated safety check: Pass | MIT | 22 days ago |
| 166 | Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds. | AgentSecOps/ | 220 | 1 repo | ~2.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 167 | 167.Watch PR Watch a pushed PR's checks with the Monitor tool, and act on the verdict. | parawanderer/ | 420 | — | ~1.9k | Automated safety check: Pass | MIT | 21 days ago |
| 168 | 168.Audit Full Single-pass codebase analysis leveraging a 1M-token context window for comprehensive security scanning, architecture review, and dependency auditing. | yonatangross/ | 292 | — | ~3.5k | Automated safety check: Notes | MIT | yesterday |
| 169 | Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. | alirezarezvani/ | 777 | — | ~1.2k | Automated safety check: Notes | MIT | 3 mo ago |
| 170 | A skill your agent uses when asked to sweep, clean up, or revisit pnpm overrides and minimumReleaseAge exclusions in platform/pnpm-workspace.yaml — unwinding a matured temporary CVE pin once its fix… | archestra-ai/ | 4.4k | — | ~1.4k | Automated safety check: Pass | Unknown | yesterday |
| 171 | Run Claude programmatically against collections of files in the codebase. | imbue-ai/ | 238 | — | ~308 | Automated safety check: Pass | MIT | yesterday |
| 172 | 172.Close Codescan 关闭 Code Scanning (CodeQL) 告警,需提供合理理由。当用户要求关闭 Code Scanning 告警、dismiss CodeQL 告警时触发。参数为告警编号。 | ModelEngine-Group/ | 2.1k | — | ~185 | Automated safety check: Pass | MIT | 7 mo ago |
| 173 | Run Warden security scans in this repo using Sentry's warden-skills. | UsefulSoftwareCo/ | 4.1k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 174 | 174.Forensics Disk 磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能. An agent skill from MuWinds/BUUCTF_Agent. | MuWinds/ | 267 | — | ~1k | Automated safety check: Warn | Apache-2.0 | 2 days ago |
| 175 | 175.Guard Mode Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems. | garrytan/ | 136k | — | ~1k | Automated safety check: Notes | MIT | yesterday |
| 176 | Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. | microsoft/ | 984 | — | ~3.2k | Automated safety check: Notes | MIT | yesterday |
| 177 | 177.Bom Slimmer Reviews a codebase's direct dependencies and designs lightweight, low-risk, zero-dependency custom replacements using cdxgen SBOM evidence, occurrence/callstack usage data, and license and… | cdxgen/ | 1.1k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 178 | 178.Oma Deepsec Set up and run Deepsec vulnerability scans, triage, and CI gates. | first-fluke/ | 223 | — | ~4.9k | Automated safety check: Notes | MIT | 5 days ago |
| 179 | 179.Hunter Deep behavioral code analysis agent for Bug Hunter. An agent skill from codexstar69/bug-hunter. | codexstar69/ | 520 | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 180 | 180.Php Config Audit PHP Web 配置安全审计工具。识别 CORS/错误暴露/调试开关/安全头/危险运行时开关等,输出分级、可利用性分析、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~417 | Automated safety check: Notes | No licence | 6 mo ago |
| 181 | 181.Deep Dive Ioc Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 182 | 182.Plugin Scanner Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. | iflytek/ | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 183 | 183.Python Review Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura. | liuyanghejerry/ | 204 | — | ~164 | Automated safety check: Pass | MIT | 11 days ago |
| 184 | 184.Build Project Build a target project into an opentaint project model. An agent skill from seqra/opentaint. | seqra/ | 163 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 185 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.5k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 186 | 186.Kesekit Start Run a security vulnerability assessment based on KISA guidelines. | cdppcorp/ | 360 | — | ~2.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 187 | Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. | mistralai/ | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 188 | Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings… | waynesutton/ | 406 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 13 days ago |
| 189 | 189.Compliance Audit the repository against the OpenSSF Baseline with darnit, resolve the controls darnit defers to LLM analysis or could not verify, and record per-control verdicts plus the attained Baseline level. | alpha-omega-security/ | 242 | — | ~1.4k | Automated safety check: Notes | MIT | yesterday |
| 190 | 190.Code Audit A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification. | zhaoxuya520/ | 41k | 2 repos | ~374 | Automated safety check: Warn | MIT | 19 days ago |
| 191 | 191.Email Security A skill your agent uses for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research. | zhaoxuya520/ | 41k | 2 repos | ~259 | Automated safety check: Warn | MIT | 19 days ago |
| 192 | A skill your agent uses for authorized hardware and embedded interface security research including UART/JTAG discovery, debug pad triage, secure boot overview, and offline firmware extraction support. | zhaoxuya520/ | 41k | 2 repos | ~266 | Automated safety check: Warn | MIT | 19 days ago |