Search

Security

3,083 skills found, page 47.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
2209

macOS attack hunting - foothold to root/persistence on a macOS host.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT1 mo ago
2210

MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta.

Encod3d-Sec/TORCH329—~1.4kAutomated safety check: PassMIT1 mo ago
2211

HTTP request smuggling / desync hunting - CL.TE, TE.CL, TE.TE, CL.0, and HTTP/2 downgrade.

Encod3d-Sec/TORCH329—~1.6kAutomated safety check: PassMIT1 mo ago
2212

SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection.

Encod3d-Sec/TORCH329—~3.4kAutomated safety check: PassMIT1 mo ago
2213

SSRF hunting - OOB-mandatory methodology. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~2.3kAutomated safety check: PassMIT1 mo ago
2214

File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS.

Encod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT1 mo ago
2215

XSS hunting - reflected, stored, DOM-based. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT1 mo ago
2216

Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup…

Encod3d-Sec/TORCH329—~1kAutomated safety check: PassMIT1 mo ago
2217
2217.Triage

Finding validation gate - 7-Question triage adapted for FIND schema.

Encod3d-Sec/TORCH329—~848Automated safety check: PassMIT1 mo ago
2218
2218.Wiki

Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status.

Encod3d-Sec/TORCH329—~1.1kAutomated safety check: PassMIT1 mo ago
2219

Test LLM-integrated applications against known prompt injection techniques, evasion methods, and attack intents using the Arcanum PI Taxonomy.

OWASP/secure-agent-playbook188—~758Automated safety check: PassCC-BY-4.016 days ago
2220

Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

OWASP/secure-agent-playbook188—~494Automated safety check: PassCC-BY-4.016 days ago
2221

Tile two-dimensional torch.gather(dim=1) kernels for Triton-Ascend so the logical grid stays near the physical vector-core count while each program handles multiple batch rows and loops over K.

Krusty84/triton-ascend-agent-dev-kit106—~583Automated safety check: PassApache-2.01 mo ago
2222
2222.Doca Aes GcmOfficial

A skill your agent uses when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt, querying docaaesgcmcap for…

NVIDIA/skills3.6k—~4.2kAutomated safety check: PassApache-2.02 days ago
2223
2223.Doca ArgusOfficial

A skill your agent uses when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for…

NVIDIA/skills3.6k—~4.8kAutomated safety check: PassApache-2.02 days ago
2224
2224.Doca ShaOfficial

A skill your agent uses when the user is doing hands-on DOCA SHA programming — offloading SHA-1, SHA-256, or SHA-512 hashing onto a BlueField DPU or ConnectX accelerator, picking between one-shot…

NVIDIA/skills3.6k—~3.4kAutomated safety check: PassApache-2.02 days ago
2225

Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

Kilo-Org/kilo-marketplace1901 repo~1.9kAutomated safety check: PassMIT12 days ago
2226

Weekly. An agent skill from markfulton/ai-employees.

markfulton/ai-employees543—~14kAutomated safety check: PassMITyesterday
2227

Pre-install security scanner for AI agent skills. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k1 repo~1.4kAutomated safety check: WarnMIT2 days ago
2228

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE.

hardw00t/ai-security-arsenal105—~2.6kAutomated safety check: PassNo licence5 mo ago
2229

Systematically map and remove malware, backdoors, and attacker persistence mechanisms (registry Run keys, scheduled tasks, WMI subscriptions, services, cron/init.d) from infected Windows and Linux…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.01 mo ago
2230

Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.01 mo ago
2231

Essential fuzzing payloads: SQL injection, command injection, special characters.

Ch1nfo/RiftX1141 repo~329Automated safety check: PassMIT20 days ago
2232

Periodic security sweep of Atlas in four areas (MCP and CLI, the Tauri desktop shell, the web renderer and connectors, the supply chain and CI) that follows untrusted input to what it can reach…

wlsdks/ontology-atlas142—~182Automated safety check: PassMITyesterday
2233

Audit project dependencies for vulnerabilities, license risks, upgrade planning, and ecosystem health across multiple languages.

aAAaqwq/AGI-Super-Team1051 repo~3.1kAutomated safety check: PassMIT3 days ago
2234

Ghost Security - SAST code scanner. An agent skill from aAAaqwq/AGI-Super-Team.

aAAaqwq/AGI-Super-Team1051 repo~1.4kAutomated safety check: NotesApache-2.03 days ago
2235

AI驱动的Java代码安全审计技能,实现系统化、高覆盖率的漏洞挖掘。使用场景: (1) 审计Java/Kotlin项目寻找安全漏洞(0day挖掘、代码审计、安全评估) (2) 企业级代码库的安全审计(支持大型项目) (3) 需要高质量、低幻觉率的安全审计报告 (4) CI/CD集成的前期漏洞发现 触发关键词:Java审计、代码审计、安全审计、漏洞挖掘、0day、安全评估、Java…

LeoYeAI/openclaw-master-skills2.2k—~3.1kAutomated safety check: PassMIT2 mo ago
2236

A skill your agent uses when assessing code quality hygiene — TypeScript strictness, lint violations, dead code, and duplication.

mizchi/skills360—~717Automated safety check: PassNo licence9 days ago
2237

Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes.

forefy/.context152—~2.1kAutomated safety check: PassMIT6 days ago
2238

Map a bug-bounty scope and rank targets by payout, crowding, and freshness.

forefy/.context152—~2.1kAutomated safety check: PassMIT6 days ago
2239

Audit an LLM application for indirect prompt injection - compose objective x technique payloads, deliver them through the channels the agent actually reads, and prove impact with an out-of-band…

forefy/.context152—~2.3kAutomated safety check: PassMIT6 days ago
2240

A skill your agent uses when an agent says a test, VM, proof, evaluator, or release gate is overloaded, too strict, blocking staging, or causing false positives; split checks by profile, measure the…

AnastasiyaW/codex-claude-code-config154—~1kAutomated safety check: PassMITyesterday
2241

A skill your agent uses when planning or reviewing tests for a code change, choosing between unit, focused regression, integration, contract, end-to-end, performance, security, property-based, or…

AnastasiyaW/codex-claude-code-config154—~2kAutomated safety check: PassMITyesterday
2242

Write a self-contained OpenTaint engine-issue report from an analysis diagnosis or a full-scan failure.

seqra/opentaint163—~1.1kAutomated safety check: PassApache-2.0yesterday
2243

Check for outdated or vulnerable dependencies. An agent skill from enuno/unifi-mcp-server.

enuno/unifi-mcp-server282—~206Automated safety check: PassApache-2.0yesterday
2244

Harden OpenClaw self-hosted environments with baseline host controls, auth tightening, secret handling, network segmentation, and safe update/rollback workflows.

BagelHole/DevOps-Security-Agent-Skills1.2k—~1kAutomated safety check: NotesMIT4 mo ago
2245

Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to destinations in parallel…

utkusen/sast-skills1.3k—~6.7kAutomated safety check: PassMIT6 mo ago
2246

Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user…

utkusen/sast-skills1.3k—~7.5kAutomated safety check: PassMIT6 mo ago
2247

Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3…

utkusen/sast-skills1.3k—~7.2kAutomated safety check: PassMIT6 mo ago
2248

Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to…

utkusen/sast-skills1.3k—~7.2kAutomated safety check: PassMIT6 mo ago
2249

Multi-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review).

ffroliva/gflow-cli269—~12kAutomated safety check: PassMIT2 days ago
2250

Cryptanalysis techniques — lattice attacks, padding oracles, weak-RNG exploitation, signature forgery, secret-sharing recovery.

transilienceai/communitytools563—~465Automated safety check: PassMIT2 mo ago
2251

HackTheBox platform operations and automations to solve challenges, machines and capture the flags hacking competitions

transilienceai/communitytools563—~697Automated safety check: PassMIT2 mo ago
2252

Network infrastructure testing - port scanning, DNS attacks, MITM, VLAN hopping, IPv6, SMB/NetBIOS, sniffing, and DoS assessment.

transilienceai/communitytools563—~768Automated safety check: PassMIT2 mo ago
2253

Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

transilienceai/communitytools563—~2.5kAutomated safety check: PassMIT2 mo ago
2254

Fetches and extracts payloads from PayloadsAllTheThings on demand.

transilienceai/communitytools563—~1.3kAutomated safety check: PassMIT2 mo ago
2255

Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection.

transilienceai/communitytools563—~484Automated safety check: PassMIT2 mo ago
2256

Identify and remove negative-ROI skill content — orphan files, never-read entries, duplicates, content reintroducing challenge-specific lore.

transilienceai/communitytools563—~715Automated safety check: PassMIT2 mo ago