Search
Security
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 2305 | Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2306 | Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2307 | Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps using automated scraping and keyword matching to detect breaches early. | mukul975/ | 34k | — | ~3.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2308 | Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2309 | Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 2310 | Audit local AI model, adapter, tokenizer, configuration, and packaging artifacts for provenance, integrity, dependency, serialization, license, and loading-risk evidence. | cyberful/ | 135 | — | ~535 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2311 | Test whether authorized direct or indirect untrusted content can alter an AI system's protected behavior, context use, memory, retrieval, output handling, or downstream capability. | cyberful/ | 135 | — | ~538 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2312 | Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects. | cyberful/ | 135 | — | ~549 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2313 | Reconstruct how instructions, retrieved content, memory, identities, approvals, tool schemas, arguments, outputs, delegation, and fallbacks propagate through an AI system. | cyberful/ | 135 | — | ~517 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2314 | 2314.Breaking Change Decide whether a finding's suggested fix is a breaking change for top dependents. | alpha-omega-security/ | 242 | — | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 2315 | 2315.Cna Match Match the repository to a CVE Numbering Authority so disclosures route to the CNA's security contact when one covers the repo. | alpha-omega-security/ | 242 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 2316 | 2316.Exposure For one (finding, dependent) pair, decide whether the dependent's code reaches the upstream finding. | alpha-omega-security/ | 242 | — | ~989 | Automated safety check: Pass | MIT | yesterday |
| 2317 | 2317.Finding Dedup Compare open findings in one repository and record how they relate. | alpha-omega-security/ | 242 | — | ~1.6k | Automated safety check: Pass | MIT | yesterday |
| 2318 | 2318.Forensics Build a read-only compromise timeline and evidence bundle from local Git history and public forge/archive records. | alpha-omega-security/ | 242 | — | ~2.1k | Automated safety check: Notes | MIT | yesterday |
| 2319 | 2319.Fork Stage a scanned repository into a private repo in the configured GitHub organisation. | alpha-omega-security/ | 242 | — | ~3.3k | Automated safety check: Pass | MIT | yesterday |
| 2320 | 2320.Mitigate Draft operational mitigations for a finding consumers can apply before a fix ships. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 2321 | 2321.Patch Propose a code patch for a finding. An agent skill from alpha-omega-security/scrutineer. | alpha-omega-security/ | 242 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 2322 | 2322.Reachability Check whether known sinks in this application's dependencies are reachable from its own trust boundaries. | alpha-omega-security/ | 242 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 2323 | 2323.Recon Map distinct externally reachable input-processing subsystems into focus areas for the threat-model skill to carry into later security audits. | alpha-omega-security/ | 242 | — | ~951 | Automated safety check: Pass | MIT | yesterday |
| 2324 | 2324.Release Watch After a finding has been marked fixed, watch the upstream for a release that contains the fix. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 2325 | 2325.Report Upstream File a finding on the upstream repository through GitHub's private vulnerability reporting, request the temporary private fork, and push the proposed patch to it when available. | alpha-omega-security/ | 242 | — | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 2326 | 2326.Vuln Scan High-recall static source-code vulnerability scan adapted from Anthropic's defending-code reference harness. | alpha-omega-security/ | 242 | — | ~3.2k | Automated safety check: Pass | MIT | yesterday |
| 2327 | 2327.Checkpoint Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations. | automateyournetwork/ | 676 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 2328 | Run a third-party / vendor security review and assign a risk tier with required controls. | mohitagw15856/ | 1.4k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 2329 | 分析 Android 项目源码,用 LLM 从多维度生成 AI 自动化测试所需的先验知识文档,打包上报测试平台。核心价值:让 AI 测试 Agent 在运行前就知道「测什么、怎么断言、有哪些陷阱」。触发词:「分析我的 Android 项目」「生成测试画像」「理解这个 App 的业务」「提取测试先验知识」「帮我分析 Android 源码」 | LeoYeAI/ | 2.2k | — | ~2.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 2330 | Comprehensive code security audit with AI-powered vulnerability detection. | LeoYeAI/ | 2.2k | — | ~3.7k | Automated safety check: Notes | MIT | 2 mo ago |
| 2331 | 2331.Ctct Security Patrol OpenClaw 多模式安全巡检工具:默认本地离线扫描,可选联网威胁情报上报. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~2.5k | Automated safety check: Notes | MIT | 2 mo ago |
| 2332 | 2332.Xxx Security Audit OpenClaw 安全巡检工具,一键执行系统安全扫描并生成通俗易懂的报告. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~2k | Automated safety check: Notes | MIT | 2 mo ago |
| 2333 | 2333.Analyzing Binaries Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. | trilwu/ | 157 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 2334 | Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling… | trilwu/ | 157 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 2335 | Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and… | trilwu/ | 157 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 2336 | 2336.Attacking Entra Id Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse… | trilwu/ | 157 | — | ~4.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 2337 | Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash… | trilwu/ | 157 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 2338 | Write a new SecSkills skill end to end — choosing the plugin bucket and skill tier, writing a description that triggers correctly without stealing traffic from siblings, the required sections… | trilwu/ | 157 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 2339 | Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection… | trilwu/ | 157 | — | ~2.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 2340 | Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed… | trilwu/ | 157 | — | ~2.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 2341 | Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices. | trilwu/ | 157 | — | ~3.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 2342 | Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage… | trilwu/ | 157 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 2343 | 2343.Hunting Threats Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk… | trilwu/ | 157 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 2344 | Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access… | trilwu/ | 157 | — | ~4.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 2345 | Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 2346 | Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log… | trilwu/ | 157 | — | ~4.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 2347 | Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 2348 | Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 2349 | Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh… | trilwu/ | 157 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 2350 | Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and… | trilwu/ | 157 | — | ~4.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 2351 | Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with… | trilwu/ | 157 | — | ~2.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 2352 | Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure. | trilwu/ | 157 | — | ~3.4k | Automated safety check: Pass | MIT | 1 mo ago |