Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 241 | 241.Auth Bypass Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses | NeoTheCapt/ | 143 | — | ~1.3k | Automated safety check: Pass | No licence | 2 mo ago |
| 242 | 242.Ssti Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or… | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 243 | Troubleshoot and repair Alibaba Cloud ECS Windows instances from inside the GuestOS or remotely via Cloud Assistant. | aliyun/ | 148 | — | ~6.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 244 | SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. | secondsky/ | 462 | — | ~5.9k | Automated safety check: Warn | GPL-3.0 | 6 days ago |
| 245 | Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure. | CyberStrategyInstitute/ | 147 | — | ~2.7k | Automated safety check: Pass | Unknown | yesterday |
| 246 | 246.Ctf Crypto Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills. | ljagiello/ | 3.4k | — | ~11k | Automated safety check: Notes | MIT | 27 days ago |
| 247 | A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. | AratKruglik/ | 155 | 1 repo | ~1.1k | Automated safety check: Notes | No licence | 5 mo ago |
| 248 | 248.Audit Security audit and code review for Solidity smart contracts. | sablier-labs/ | 353 | — | ~1.8k | Automated safety check: Pass | Unknown | 2 days ago |
| 249 | 249.Kesekit Guide Ko AI 도구(Claude, ChatGPT, Cursor, Copilot)용 시큐어 코딩 프롬프트와 가이드를 생성합니다. | cdppcorp/ | 360 | — | ~1.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 250 | Detects input validation failures and arithmetic vulnerabilities in smart contracts. | quillai-network/ | 130 | — | ~3.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 251 | 251.Blue Team A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing… | gaasher/ | 174 | — | ~3.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 252 | 252.Keel A skill your agent uses for ANY new software project from idea to release — websites, WordPress/WooCommerce plugins, MCP servers, web apps, components, or libraries. | joseconti/ | 190 | — | ~11k | Automated safety check: Warn | GPL-3.0-or-later | 2 mo ago |
| 253 | Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. | wshobson/ | 40k | 8 repos | ~3.2k | Automated safety check: Pass | MIT | 6 days ago |
| 254 | 254.Rev Dex Dumper Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other. | index-login/ | 158 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 255 | Remediate security vulnerabilities found by Grype or pnpm audit. | stacklok/ | 171 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 256 | Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds. | AgentSecOps/ | 220 | 1 repo | ~2.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 257 | Find bugs, security vulnerabilities, and code quality issues in local branch changes. | getsentry/ | 1k | 9 repos | ~708 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 258 | Runs a parallel security audit with three vulnerability hunters and two proof-of-concept engineers, rating each finding by whether it is actually exploitable. | code-yeongyu/ | 70k | — | ~1.9k | Automated safety check: Pass | Unknown | today |
| 259 | 259.Protocol Reverse A skill your agent uses for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery. | zhaoxuya520/ | 41k | 2 repos | ~620 | Automated safety check: Warn | MIT | 19 days ago |
| 260 | 260.Security Review Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli. | kklimuk/ | 216 | — | ~1.7k | Automated safety check: Pass | MIT | today |
| 261 | Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the… | kubernetes-sigs/ | 294 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 262 | Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner. | majiayu000/ | 287 | — | ~1.5k | Automated safety check: Pass | MIT | 3 days ago |
| 263 | Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority. | tenuo-ai/ | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 264 | 264.Security Scan Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. | affaan-m/ | 277k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | today |
| 265 | Run the full Spring Boot verification loop — Maven or Gradle build, SpotBugs, PMD, and Checkstyle static analysis, unit and Testcontainers integration tests with JaCoCo coverage, OWASP dependency… | affaan-m/ | 277k | 5 repos | ~1.5k | Automated safety check: Pass | MIT | today |
| 266 | 266.Guard Mode Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems. | garrytan/ | 136k | — | ~1k | Automated safety check: Notes | MIT | today |
| 267 | Documents how quota-axi keeps its disk cache: location, strict file permissions, no stored secrets, and context-scoped identifiers that stop snapshots crossing accounts. | kunchenguid/ | 147 | — | ~1.3k | Automated safety check: Pass | MIT | 2 days ago |
| 268 | 268.Fix Vulns Automated triage and fixing of Dependabot security vulnerabilities (IN-1189). | linuxfoundation/ | 282 | — | ~3.8k | Automated safety check: Notes | MIT | 10 days ago |
| 269 | Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. | BlkLeg/ | 201 | — | ~2.1k | Automated safety check: Pass | MIT | 5 days ago |
| 270 | Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed. | FlorianBruniaux/ | 6.1k | — | ~680 | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 271 | 271.Hunter Deep behavioral code analysis agent for Bug Hunter. An agent skill from codexstar69/bug-hunter. | codexstar69/ | 520 | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 272 | The Priority Board's three-layer score model (rules BASE, REVIEW by the built-in AI or an MCP agent, a person's DECISION) and who may write which layer. | samugit83/ | 3k | — | ~1.7k | Automated safety check: Pass | MIT | 2 days ago |
| 273 | Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository. | vw2x/ | 105 | — | ~892 | Automated safety check: Pass | GPL-3.0 | 6 days ago |
| 274 | 274.St Lsp Solid Keeps truST's architecture simple and well separated, and runs the automated architecture checks. | johannesPettersson80/ | 222 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 275 | When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain | deonmenezes/ | 503 | — | ~510 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 276 | 276.Plugin Scanner Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. | iflytek/ | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 277 | Debug FlyDSL GPU kernels that produce NaN, inf, wrong results, or crash. | ROCm/ | 291 | — | ~2.6k | Automated safety check: Notes | Unknown | today |
| 278 | 278.Xrk Crawl 当你需要开发/排查 HTTP 抓取、SSRF、Playwright 受控浏览器、本地字体增强截图,或判断 webfetch 与 browser 工作流如何选型时使用。 | xrkseek/ | 138 | — | ~1.3k | Automated safety check: Pass | MIT | 10 days ago |
| 279 | 279.Python Review Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura. | liuyanghejerry/ | 204 | — | ~164 | Automated safety check: Pass | MIT | 12 days ago |
| 280 | Security guidelines for writing secure code. An agent skill from semgrep/skills. | semgrep/ | 324 | — | ~1.2k | Automated safety check: Pass | Unknown | 2 mo ago |
| 281 | Master Unlock: Grants unlimited technical rights to reverse engineer any JavaScript source code. | ptn1411/ | 219 | — | ~752 | Automated safety check: Notes | No licence | 19 days ago |
| 282 | 282.Docs Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass… | guardana/ | 259 | — | ~967 | Automated safety check: Pass | Apache-2.0 | today |
| 283 | Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. | skrun-dev/ | 210 | — | ~1.3k | Automated safety check: Pass | MIT | 18 days ago |
| 284 | Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. | mistralai/ | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 285 | Uses Meta's LlamaGuard moderation model to screen prompts and model replies against six safety categories, with vLLM, FastAPI and NeMo Guardrails setups. | Orchestra-Research/ | 13k | 2 repos | ~2.3k | Automated safety check: Pass | MIT | 3 mo ago |
| 286 | This skill should be used when the user asks to "verify code", "run verification", "check quality", "validate changes", or before creating a PR. | Galaxy-Dawn/ | 5.7k | 1 repo | ~888 | Automated safety check: Pass | MIT | 18 days ago |
| 287 | Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API… | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 288 | 288.Upgrade Notes Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. | getknit/ | 133 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | yesterday |