Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 193 | Status-first routing, bounded evidence collection, and safety guidance for issue-graph. | vercel-labs/ | 127 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 194 | Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. | wshobson/ | 40k | 12 repos | ~892 | Automated safety check: Pass | MIT | 6 days ago |
| 195 | Plans and runs material repository changes with the AI SAFE2 method: classify delivery shape and risk, isolate the work, collect test evidence and finish with a completion receipt. | CyberStrategyInstitute/ | 147 | — | ~833 | Automated safety check: Pass | Unknown | yesterday |
| 196 | Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages. | ruby-git/ | 1.8k | — | ~806 | Automated safety check: Pass | MIT | 9 days ago |
| 197 | Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify… | nvuillam/ | 248 | — | ~1.9k | Automated safety check: Notes | MIT | yesterday |
| 198 | Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis. | s0ld13rr/ | 828 | — | ~2.9k | Automated safety check: Pass | MIT | 8 days ago |
| 199 | 199.Dast Automation Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. | hardw00t/ | 105 | — | ~2.2k | Automated safety check: Pass | No licence | 5 mo ago |
| 200 | 200.Loop Factory Run a spec-driven agent loop where coding tasks live as markdown specs that move through inbox → active → archive, get implemented by Claude Code or Codex, and pass a review gate before they count… | JuliusBrussee/ | 162 | — | ~2k | Automated safety check: Pass | MIT | 2 mo ago |
| 201 | Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption. | wshobson/ | 40k | 11 repos | ~1.9k | Automated safety check: Pass | MIT | 6 days ago |
| 202 | Display Hak5 WiFi Pineapple recon scan data as a formatted table. | sneakerhax/ | 112 | — | ~298 | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 203 | 203.Do Analyze 对 jar-analyzer-engine 构建的 SQLite 数据库执行安全审计分析查询。支持方法调用搜索、调用链追踪、Spring 组件分析、字符串搜索、漏洞模式检测等。 | jar-analyzer/ | 141 | — | ~2.5k | Automated safety check: Pass | No licence | 6 mo ago |
| 204 | A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings… | villith/ | 156 | — | ~7.5k | Automated safety check: Pass | MIT | 15 days ago |
| 205 | Runs trace-mcp security, quality-gate and antipattern checks before a commit or pull request, and builds a symbol-level diff for the PR description. | nikolai-vysotskyi/ | 189 | — | ~565 | Automated safety check: Pass | MIT | today |
| 206 | 206.Security Review Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs. | deadlock-mod-manager/ | 478 | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 207 | Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis. | trailofbits/ | 7.5k | 3 repos | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 208 | Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe… | openclaw/ | 392k | — | ~14k | Automated safety check: Pass | MIT | today |
| 209 | 209.Create Template Creates a new Earl HCL template for a specific API, database, or shell command. | mathematic-inc/ | 113 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 210 | 210.MCP Server Tools Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token. | samugit83/ | 3k | — | ~1.8k | Automated safety check: Pass | MIT | 2 days ago |
| 211 | A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code… | ProgrammerAnthony/ | 235 | — | ~1.6k | Automated safety check: Pass | MIT | 5 mo ago |
| 212 | Close a case or alert with proper reason and documentation. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~615 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 213 | Perform a requested security review of a NemoClaw PR or a PR linked to an issue. | NVIDIA/ | 23k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 214 | Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. | Eyadkelleh/ | 389 | — | ~636 | Automated safety check: Pass | No licence | 4 mo ago |
| 215 | 215.Dep Scan Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema. | epam/ | 504 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 216 | A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning… | jabrena/ | 447 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 217 | 217.Add A Rule Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation… | guardana/ | 259 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 218 | 218.Nmap Professional network reconnaissance and port scanning using nmap. | BrownFineSecurity/ | 859 | 1 repo | ~3.8k | Automated safety check: Notes | MIT | 4 mo ago |
| 219 | Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. | elementalsouls/ | 4.9k | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 220 | 220.Fix Scan Finding Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in… | malloydata/ | 116 | — | ~5.1k | Automated safety check: Pass | MIT | today |
| 221 | Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows. | hashgraph-online/ | 845 | — | ~605 | Automated safety check: Pass | Apache-2.0 | today |
| 222 | 222.Sast Graphql Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input… | utkusen/ | 1.3k | — | ~4.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 223 | 223.Bug Hunter A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and… | WrongStack/ | 374 | — | ~2.4k | Automated safety check: Pass | MIT | today |
| 224 | 224.Codex Review Dual-model code review via Codex CLI. An agent skill from suyuan2022/suyuan-skill. | suyuan2022/ | 308 | — | ~3.5k | Automated safety check: Warn | MIT | 1 mo ago |
| 225 | 225.Tenuo Audit Audit, explain, or compare existing Tenuo warrants and delegation chains. | tenuo-ai/ | 103 | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 226 | Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input). | ash1794/ | 163 | — | ~722 | Automated safety check: Pass | MIT | 3 days ago |
| 227 | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. | trailofbits/ | 7.5k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 228 | 228.Ship Release The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main. | ibuilder/ | 122 | — | ~2.3k | Automated safety check: Pass | MIT | 2 days ago |
| 229 | 229.Threat Modeling Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks. | dralgorhythm/ | 125 | — | ~581 | Automated safety check: Pass | No licence | 2 mo ago |
| 230 | 230.Cloud Audit Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images | CommonHuman-Lab/ | 157 | — | ~1.1k | Automated safety check: Pass | Unknown | yesterday |
| 231 | Scans a Power Pages site project for security issues in source code and dependencies. | microsoft/ | 984 | — | ~3.4k | Automated safety check: Notes | MIT | yesterday |
| 232 | 232.Program Intel Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus. | bugbountywithmarco/ | 120 | — | ~524 | Automated safety check: Pass | No licence | 2 mo ago |
| 233 | Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP. | Encod3d-Sec/ | 329 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 234 | Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation. | transilienceai/ | 563 | — | ~1.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 235 | Public-records OSINT investigation framework — SEC EDGAR filings, USAspending contracts, Senate lobbying, OFAC sanctions, ICIJ offshore leaks, NYC property records (ACRIS), OpenCorporates… | johnson7788/ | 327 | — | ~3k | Automated safety check: Pass | MIT | 1 mo ago |
| 236 | Guide for creating new Android gradle modules in the android-components project. | SAP/ | 180 | 2 repos | ~1.8k | Automated safety check: Pass | GPL-3.0 | today |
| 237 | 237.Earl A skill your agent uses when you need to call an API, run a database query, or execute a shell command via Earl. | mathematic-inc/ | 113 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 238 | 238.Cloud Audit Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps. | briiirussell/ | 413 | — | ~1.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 239 | CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。 | 0xShe/ | 402 | 1 repo | ~477 | Automated safety check: Pass | No licence | 6 mo ago |
| 240 | Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira. | vw2x/ | 105 | — | ~637 | Automated safety check: Pass | GPL-3.0 | 6 days ago |