Search
Security
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 241 | Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release. | clone45/ | 131 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 26 days ago |
| 242 | Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files. | ZaxbyHub/ | 496 | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 243 | Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data. | addyosmani/ | 105k | 1 repo | ~4.4k | Automated safety check: Notes | MIT | yesterday |
| 244 | 244.Project Security A skill your agent uses when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping. | johnku2011/ | 240 | — | ~650 | Automated safety check: Pass | MIT | 1 mo ago |
| 245 | 245.Sail Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. | pillar-labs/ | 113 | — | ~5.1k | Automated safety check: Pass | Unknown | 3 mo ago |
| 246 | Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis. | openqa-cn/ | 152 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 247 | 247.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 283 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 248 | Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries. | amElnagdy/ | 1.3k | — | ~2.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 249 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 220 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 250 | Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 251 | Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision. | pegasi-ai/ | 392 | — | ~1.4k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 252 | Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets. | Tencent/ | 6.8k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 253 | Map relationships between a web spec section, its Firefox implementation code, and Web Platform Tests. | SAP/ | 180 | 2 repos | ~1.3k | Automated safety check: Pass | GPL-3.0 | today |
| 254 | Review a change (a PR, the current branch diff, or a set of files) or audit a Symfony UX package or the whole src/ tree for missing or incorrect security hardening. | symfony/ | 1.1k | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 255 | Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。 | aliyun/ | 148 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 256 | 256.Clawscan CLI A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and… | openclaw/ | 143 | — | ~3k | Automated safety check: Pass | MIT | 3 days ago |
| 257 | Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas. | OTRF/ | 4.7k | — | ~819 | Automated safety check: Pass | MIT | 9 mo ago |
| 258 | Add or retrofit Tenuo authorization for AI-agent tools and effects. | tenuo-ai/ | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 259 | A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI… | jabrena/ | 447 | — | ~874 | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 260 | Guide for writing eval conversation JSONs and running them through policy engines | open-bias/ | 143 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 261 | Shows how to call NEAR AI Cloud through an OpenAI-compatible API and verify that inference ran in a TEE, using attestation checks and signed chat responses. | internet-court/ | 6.6k | 1 repo | ~1.3k | Automated safety check: Pass | Unknown | 1 mo ago |
| 262 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.5k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 263 | PHP Web 全链路白盒代码安全审计流水线(多文件版编排)。作为总编排参考,按 Sink 类型调用各子审计 skill(php-route-mapper/php-auth-audit/php-route-tracer/php--audit),并复用统一输出与分级标准。 | 0xShe/ | 402 | 1 repo | ~4.9k | Automated safety check: Pass | No licence | 6 mo ago |
| 264 | 264.Graph DB Writes Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must… | samugit83/ | 3k | — | ~2.2k | Automated safety check: Pass | MIT | 2 days ago |
| 265 | 265.Acl Abuse Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication… | ADScanPro/ | 211 | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 266 | Sentry-specific security review based on real vulnerability history. | getsentry/ | 46k | — | ~2.3k | Automated safety check: Notes | Unknown | yesterday |
| 267 | Runs and interprets Psalm security (taint) analysis on a Laravel project. | cachethq/ | 230 | — | ~4.7k | Automated safety check: Pass | Unknown | 5 days ago |
| 268 | Tells a model how to treat the tagged double-brace placeholders that Maskit's local privacy gateway substitutes for sensitive text, so tokens are copied exactly instead of guessed, split or faked. | xiaYuTian11/ | 297 | — | ~718 | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 269 | 269.Codeql Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF. | waybarrios/ | 534 | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 5 days ago |
| 270 | Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes. | seqra/ | 163 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 271 | Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2… | provos/ | 612 | — | ~5.7k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 272 | 272.Ship Commit and push a finished change the way this repo requires — explicit paths, one commit per logical change, no attribution, the five documentation places answered, the site checks before a push (a… | guardana/ | 259 | — | ~964 | Automated safety check: Notes | Apache-2.0 | today |
| 273 | Builds a skeptical reviewer grounded in the codebase and research notes to try to refute a spec before any code is written, citing file:line evidence and ending in a go or no-go gate. | JuliusBrussee/ | 1.2k | — | ~959 | Automated safety check: Pass | MIT | 1 mo ago |
| 274 | 274.Migrate To Earl Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time. | mathematic-inc/ | 113 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 275 | 275.Dsl Vm Reverse Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines. | zhaoxuya520/ | 41k | 3 repos | ~2.3k | Automated safety check: Pass | MIT | 19 days ago |
| 276 | Review code for quality, correctness, and security vulnerabilities. | hiroshiyui/ | 135 | — | ~1.6k | Automated safety check: Pass | GPL-3.0 | today |
| 277 | VulnHunter sandbox-depth decision procedure. An agent skill from nealbridges/VulnHunter. | nealbridges/ | 678 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 278 | Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk. | GitbookIO/ | 131 | — | ~1.2k | Automated safety check: Pass | No licence | 3 days ago |
| 279 | 279.Stellar Dev End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments. | VelaPayments/ | 131 | — | ~1.8k | Automated safety check: Pass | MIT | 4 days ago |
| 280 | Deep web-research methodology for the interceptor browser surface — investigate a topic the way researchers, intelligence analysts, investigative journalists, private investigators, and OSINT… | Hacker-Valley-Media/ | 522 | — | ~3.8k | Automated safety check: Pass | Unknown | 8 days ago |
| 281 | Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. | elastic/ | 592 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 282 | 用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF… | index-login/ | 158 | — | ~3k | Automated safety check: Pass | MIT | yesterday |
| 283 | Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script. | ptn1411/ | 219 | — | ~830 | Automated safety check: Notes | No licence | 19 days ago |
| 284 | 284.Fallow Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills. | fallow-rs/ | 128 | — | ~8.6k | Automated safety check: Pass | MIT | today |
| 285 | 285.Write Structure and per-section format reference for a bug bounty report, aligned with YesWeHack's official guidance. | yeswehack/ | 110 | — | ~2.1k | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 286 | 286.Kesekit Fix Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems. | cdppcorp/ | 360 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 287 | Token-efficient smart contract security auditing via Behavioral State Analysis (BSA). | quillai-network/ | 130 | — | ~1.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 288 | 288.Code Vuln Audit Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection. | zebbern/ | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |