Search

Security

3,083 skills found, page 49.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
2305

Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: WarnApache-2.01 mo ago
2306

Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: WarnApache-2.01 mo ago
2307

Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: WarnApache-2.01 mo ago
2308

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: WarnApache-2.01 mo ago
2309

Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.01 mo ago
2310

Audit local AI model, adapter, tokenizer, configuration, and packaging artifacts for provenance, integrity, dependency, serialization, license, and loading-risk evidence.

cyberful/cyberful135—~535Automated safety check: PassAGPL-3.01 mo ago
2311

Test whether authorized direct or indirect untrusted content can alter an AI system's protected behavior, context use, memory, retrieval, output handling, or downstream capability.

cyberful/cyberful135—~538Automated safety check: PassAGPL-3.01 mo ago
2312

Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects.

cyberful/cyberful135—~549Automated safety check: PassAGPL-3.01 mo ago
2313

Reconstruct how instructions, retrieved content, memory, identities, approvals, tool schemas, arguments, outputs, delegation, and fallbacks propagate through an AI system.

cyberful/cyberful135—~517Automated safety check: PassAGPL-3.01 mo ago
2314

Decide whether a finding's suggested fix is a breaking change for top dependents.

alpha-omega-security/scrutineer242—~1.4kAutomated safety check: PassMITyesterday
2315

Match the repository to a CVE Numbering Authority so disclosures route to the CNA's security contact when one covers the repo.

alpha-omega-security/scrutineer242—~1.2kAutomated safety check: PassMITyesterday
2316

For one (finding, dependent) pair, decide whether the dependent's code reaches the upstream finding.

alpha-omega-security/scrutineer242—~989Automated safety check: PassMITyesterday
2317

Compare open findings in one repository and record how they relate.

alpha-omega-security/scrutineer242—~1.6kAutomated safety check: PassMITyesterday
2318

Build a read-only compromise timeline and evidence bundle from local Git history and public forge/archive records.

alpha-omega-security/scrutineer242—~2.1kAutomated safety check: NotesMITyesterday
2319
2319.Fork

Stage a scanned repository into a private repo in the configured GitHub organisation.

alpha-omega-security/scrutineer242—~3.3kAutomated safety check: PassMITyesterday
2320

Draft operational mitigations for a finding consumers can apply before a fix ships.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
2321
2321.Patch

Propose a code patch for a finding. An agent skill from alpha-omega-security/scrutineer.

alpha-omega-security/scrutineer242—~1.9kAutomated safety check: PassMITyesterday
2322

Check whether known sinks in this application's dependencies are reachable from its own trust boundaries.

alpha-omega-security/scrutineer242—~1.9kAutomated safety check: PassMITyesterday
2323
2323.Recon

Map distinct externally reachable input-processing subsystems into focus areas for the threat-model skill to carry into later security audits.

alpha-omega-security/scrutineer242—~951Automated safety check: PassMITyesterday
2324

After a finding has been marked fixed, watch the upstream for a release that contains the fix.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
2325

File a finding on the upstream repository through GitHub's private vulnerability reporting, request the temporary private fork, and push the proposed patch to it when available.

alpha-omega-security/scrutineer242—~2.6kAutomated safety check: PassMITyesterday
2326

High-recall static source-code vulnerability scan adapted from Anthropic's defending-code reference harness.

alpha-omega-security/scrutineer242—~3.2kAutomated safety check: PassMITyesterday
2327

Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations.

automateyournetwork/netclaw676—~2.3kAutomated safety check: NotesApache-2.0yesterday
2328

Run a third-party / vendor security review and assign a risk tier with required controls.

mohitagw15856/pm-claude-skills1.4k—~1.1kAutomated safety check: PassMITyesterday
2329

分析 Android 项目源码,用 LLM 从多维度生成 AI 自动化测试所需的先验知识文档,打包上报测试平台。核心价值:让 AI 测试 Agent 在运行前就知道「测什么、怎么断言、有哪些陷阱」。触发词:「分析我的 Android 项目」「生成测试画像」「理解这个 App 的业务」「提取测试先验知识」「帮我分析 Android 源码」

LeoYeAI/openclaw-master-skills2.2k—~2.7kAutomated safety check: PassMIT2 mo ago
2330

Comprehensive code security audit with AI-powered vulnerability detection.

LeoYeAI/openclaw-master-skills2.2k—~3.7kAutomated safety check: NotesMIT2 mo ago
2331

OpenClaw 多模式安全巡检工具:默认本地离线扫描,可选联网威胁情报上报. An agent skill from LeoYeAI/openclaw-master-skills.

LeoYeAI/openclaw-master-skills2.2k—~2.5kAutomated safety check: NotesMIT2 mo ago
2332

OpenClaw 安全巡检工具,一键执行系统安全扫描并生成通俗易懂的报告. An agent skill from LeoYeAI/openclaw-master-skills.

LeoYeAI/openclaw-master-skills2.2k—~2kAutomated safety check: NotesMIT2 mo ago
2333

Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

trilwu/secskills157—~2.9kAutomated safety check: PassMIT1 mo ago
2334

Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

trilwu/secskills157—~2kAutomated safety check: PassMIT1 mo ago
2335

Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

trilwu/secskills157—~2kAutomated safety check: PassMIT1 mo ago
2336

Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…

trilwu/secskills157—~4.3kAutomated safety check: PassMIT1 mo ago
2337

Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…

trilwu/secskills157—~2.8kAutomated safety check: PassMIT1 mo ago
2338

Write a new SecSkills skill end to end — choosing the plugin bucket and skill tier, writing a description that triggers correctly without stealing traffic from siblings, the required sections…

trilwu/secskills157—~3.1kAutomated safety check: PassMIT1 mo ago
2339

Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection…

trilwu/secskills157—~2.5kAutomated safety check: PassMIT1 mo ago
2340

Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…

trilwu/secskills157—~2.4kAutomated safety check: PassMIT1 mo ago
2341

Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices.

trilwu/secskills157—~3.3kAutomated safety check: PassMIT1 mo ago
2342

Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

trilwu/secskills157—~1.9kAutomated safety check: PassMIT1 mo ago
2343

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

trilwu/secskills157—~3.5kAutomated safety check: PassMIT1 mo ago
2344

Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access…

trilwu/secskills157—~4.8kAutomated safety check: PassMIT1 mo ago
2345

Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
2346

Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log…

trilwu/secskills157—~4.7kAutomated safety check: PassMIT1 mo ago
2347

Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
2348

Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the…

trilwu/secskills157—~2.2kAutomated safety check: PassMIT1 mo ago
2349

Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh…

trilwu/secskills157—~3.5kAutomated safety check: PassMIT1 mo ago
2350

Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…

trilwu/secskills157—~4.4kAutomated safety check: PassMIT1 mo ago
2351

Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with…

trilwu/secskills157—~2.7kAutomated safety check: PassMIT1 mo ago
2352

Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure.

trilwu/secskills157—~3.4kAutomated safety check: PassMIT1 mo ago