Search
Security
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 193 | 193.Bom Audit Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk… | cdxgen/ | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | today |
| 194 | 194.Security Audit A skill your agent uses to perform a security-focused audit of the codebase to identify vulnerabilities, sandbox escapes, and logic flaws. | ziggy42/ | 439 | — | ~924 | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 195 | 195.Lfd Design Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD). | elvisun/ | 176 | — | ~2.9k | Automated safety check: Notes | MIT | 4 mo ago |
| 196 | 196.Code Review Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles. | MichaelGrafnetter/ | 2k | — | ~4k | Automated safety check: Pass | MIT | 29 days ago |
| 197 | 197.Packslip Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and… | jdx/ | 137 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 198 | PHP Web 归档解压(Zip Slip/路径穿越)审计工具。识别解压条目名如何与目标目录拼接、是否存在 base dir 约束缺失,输出可利用性分级、可观测 PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~883 | Automated safety check: Pass | No licence | 6 mo ago |
| 199 | Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged… | samugit83/ | 3k | — | ~1.4k | Automated safety check: Pass | MIT | 2 days ago |
| 200 | Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk. | bodadotsh/ | 858 | — | ~1k | Automated safety check: Warn | MIT | 10 days ago |
| 201 | Maximum-fidelity Python source reconstruction from Nuitka .nbc / NBC/2 files produced by nuitkadecompiler.py. | DimaReverse/ | 132 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 202 | Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks. | seqra/ | 163 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 203 | 203.Vex Authoring Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM. | relizaio/ | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 204 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 205 | 205.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 391 | — | ~660 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 206 | Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks. | telagod/ | 244 | — | ~552 | Automated safety check: Notes | MIT | 2 mo ago |
| 207 | Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work. | LUC4N3X/ | 591 | — | ~2k | Automated safety check: Pass | GPL-3.0 | today |
| 208 | 208.Security Review Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. | ktnyt/ | 675 | — | ~565 | Automated safety check: Pass | MIT | 7 mo ago |
| 209 | 209.Gates GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework. | Nebulock-Inc/ | 388 | — | ~12k | Automated safety check: Pass | MIT | 2 days ago |
| 210 | 210.Agent Creator Creates structured agent definitions using the 7-component format grounded in persona science (the alignment-accuracy tradeoff), vocabulary routing, and the MAST failure taxonomy + Forge watchlist. | jdforsythe/ | 151 | — | ~4.5k | Automated safety check: Pass | MIT | 3 mo ago |
| 211 | Run a security scan on the kedro-plugins codebase or a pull request. | kedro-org/ | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 212 | Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results. | block/ | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 213 | Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers. | CyberStrategyInstitute/ | 147 | — | ~1.2k | Automated safety check: Pass | Unknown | yesterday |
| 214 | 214.Gmgn Token Research any crypto or meme token by address — real-time price, market cap, liquidity, holder list, trader list, top Smart Money and KOL positions, security audit (honeypot, rug pull risk, dev… | GMGNAI/ | 609 | 1 repo | ~10k | Automated safety check: Notes | MIT | 12 days ago |
| 215 | 215.Oss Forensics Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. | Tommy-yw/ | 546 | 3 repos | ~5k | Automated safety check: Pass | MIT | 4 mo ago |
| 216 | A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR. | DataDog/ | 417 | — | ~2.6k | Automated safety check: Pass | Unknown | yesterday |
| 217 | Connect to a Windows 98 game or app that a person is running in their browser on wine-assembly, then see its screen and play it with mouse and keyboard. | vgrichina/ | 116 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 218 | 218.Clawd Control Monitor and manage your Clawdbot agent fleet from within an agent. | Temaki-AI/ | 115 | — | ~1.2k | Automated safety check: Pass | MIT | 7 mo ago |
| 219 | Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation. | ptn1411/ | 219 | — | ~917 | Automated safety check: Pass | No licence | 19 days ago |
| 220 | A skill your agent uses when scanning code for security vulnerabilities. | tanviet12/ | 289 | — | ~6.8k | Automated safety check: Notes | MIT | 13 days ago |
| 221 | 221.Kesekit Check Ko KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT. | cdppcorp/ | 360 | — | ~956 | Automated safety check: Pass | MIT | 6 mo ago |
| 222 | Routes a whole-product security request to the right Strix test per asset, source code, a live app, an API or a CI pipeline, then turns results into one ranked remediation plan. | usestrix/ | 68k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 223 | 223.Semia Audit an agent skill with Semia Skill Behavior Mapping. An agent skill from berabuddies/Semia. | berabuddies/ | 612 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 224 | 224.Chipsec Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. | BrownFineSecurity/ | 859 | 1 repo | ~3.9k | Automated safety check: Notes | MIT | 4 mo ago |
| 225 | 225.Security Updates Check and apply security updates across the photofield project (api/Go, ui/npm, docs/npm, e2e/npm). | SmilyOrg/ | 608 | — | ~808 | Automated safety check: Pass | MIT | 1 mo ago |
| 226 | 226.Censorship Audit Audit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would. | hedioum/ | 139 | — | ~4.9k | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 227 | Enable, configure, and query Elasticsearch security audit logs. | aspectrr/ | 405 | — | ~1.7k | Automated safety check: Pass | MIT | 5 mo ago |
| 228 | 228.Security Audit Security best practices, vulnerability review, and full security audits for LLM Gateway. | theopenco/ | 1.7k | — | ~1.8k | Automated safety check: Pass | Unknown | today |
| 229 | CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines. | context-labs/ | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT | 6 days ago |
| 230 | 230.Attack Flow Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports. | wiz-sec-public/ | 182 | — | ~3.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 231 | Render app UI on the Gradle managed device and look at the result without spending a fortune in vision tokens. | parawanderer/ | 420 | — | ~1.4k | Automated safety check: Pass | MIT | 21 days ago |
| 232 | Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects. | microsoft/ | 22k | — | ~737 | Automated safety check: Pass | MIT | today |
| 233 | Security-focused code review checklist and automated scanning patterns. | nicepkg/ | 195 | 1 repo | ~3.9k | Automated safety check: Pass | MIT | 8 mo ago |
| 234 | Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING… | MidnightBSD/ | 114 | — | ~2.2k | Automated safety check: Pass | Unknown | yesterday |
| 235 | 235.Ctf Malware Provides malware analysis and network traffic techniques for CTF challenges. | ljagiello/ | 3.4k | — | ~2.1k | Automated safety check: Notes | MIT | 27 days ago |
| 236 | Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs. | eclipse-ankaios/ | 125 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 237 | 237.Audit A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures. | vigolium/ | 140 | — | ~8.7k | Automated safety check: Pass | MIT | 21 days ago |
| 238 | 按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's… | jnMetaCode/ | 140 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 12 days ago |
| 239 | 239.Security Audit Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report. | marketcalls/ | 2.8k | — | ~1.9k | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 240 | Review and structure auto insurance bodily injury claims, including intake triage, evidence completeness, injury causation, treatment chronology, medical necessity, wage-loss support, negotiation… | samarailly51-pixel/ | 117 | — | ~640 | Automated safety check: Pass | MIT | 1 mo ago |