Search
Security · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 241 | Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix. | codewhale-hq/ | 41k | — | ~844 | Automated safety check: Pass | MIT | today |
| 242 | OpenClaw 攻击模式检测工具,识别数据外传、反弹Shell、文件泄露、Prompt注入、供应链投毒等高危行为,支持 MITRE ATT&CK 映射 | jd-opensource/ | 314 | — | ~1.3k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 243 | Loads a missing environment variable or API key from the team's Infisical workspace into the current shell, or runs a command with all project secrets injected. | Devin-AXIS/ | 6.8k | 1 repo | ~516 | Automated safety check: Pass | Unknown | today |
| 244 | 244.Csf Mapping Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). | briiirussell/ | 413 | — | ~3k | Automated safety check: Notes | MIT | 4 mo ago |
| 245 | 245.Php Expr Audit PHP Web 源码表达式注入(非模板)审计工具。识别用户可控表达式字符串进入表达式引擎求值/编译并最终导致敏感语义执行,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~720 | Automated safety check: Pass | No licence | 6 mo ago |
| 246 | Search for existing cases related to specific indicators or entities. | dandye/ | 127 | — | ~562 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 247 | Security patterns for autonomous trading agents with wallet or transaction authority. | affaan-m/ | 277k | 2 repos | ~1.2k | Automated safety check: Pass | MIT | today |
| 248 | Hunt for exploitable, bounty-worthy security issues in repositories. | affaan-m/ | 277k | 2 repos | ~907 | Automated safety check: Pass | MIT | today |
| 249 | A skill your agent uses when the user asks to log in or out with a wallet session, fetch a wallet sign-in challenge, verify an externally signed challenge, or troubleshoot AltLLM Portal wallet login… | internet-court/ | 6.6k | 1 repo | ~632 | Automated safety check: Pass | ISC | 1 mo ago |
| 250 | 250.Edr Bypass Re 逆向防御方实现 → 红队针对性绕过。把 EDR / Defender / AV 的 hook 表、ETW provider、AMSI 实现先逆向出来, 再写针对性的 unhook / 间接 syscall / ETW patch / call stack spoof。对照 MITRE ATT&CK T1562 防御规避。 | zhaoxuya520/ | 41k | 1 repo | ~1.6k | Automated safety check: Warn | MIT | 19 days ago |
| 251 | 251.Security Setup Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 252 | 252.Vuln Hunter Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation. | dariushoule/ | 209 | — | ~3.9k | Automated safety check: Notes | MIT | 7 mo ago |
| 253 | 253.Skill Ship Package and finalize completed work for delivery — use when a feature is done and ready to ship | nyldn/ | 4.2k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | today |
| 254 | 254.Create Rule Author and verify an OpenTaint rule. An agent skill from seqra/opentaint. | seqra/ | 163 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 255 | Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel… | utkusen/ | 1.3k | — | ~5.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 256 | 256.Soak Manages the repo's supply-chain soak window (SOAKDAYS) — checks and fixes the derived surfaces, bumps or disables the window, adds dated per-package exclusions, and bumps pinned external tools. | nubjs/ | 4.4k | — | ~1.3k | Automated safety check: Warn | MIT | yesterday |
| 257 | 257.History Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive. | alpha-omega-security/ | 245 | — | ~2.9k | Automated safety check: Notes | MIT | today |
| 258 | 258.Semgrep Skill Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules. | KimYx0207/ | 174 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 259 | 259.Webcrypt MCP Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography. | putervision/ | 50 | — | ~847 | Automated safety check: Pass | MIT | 7 days ago |
| 260 | Path traversal / Local File Inclusion detection→file-read→RCE for web apps. | s0ld13rr/ | 828 | — | ~602 | Automated safety check: Notes | MIT | 8 days ago |
| 261 | Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments. | irahardianto/ | 156 | — | ~2.7k | Automated safety check: Notes | MIT | 6 days ago |
| 262 | Secure secrets in Google Cloud Secret Manager. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 3 repos | ~3.3k | Automated safety check: Pass | MIT | yesterday |
| 263 | Use before merging security-relevant Rust changes. An agent skill from Jxck/sptth. | Jxck/ | 133 | — | ~318 | Automated safety check: Pass | MIT | 7 mo ago |
| 264 | 264.Security Hygiene Detecta riscos básicos de segurança em repositórios (segredos expostos, configurações perigosas, padrões inseguros) e gera recomendações com evidências. | glaucia86/ | 121 | — | ~819 | Automated safety check: Warn | MIT | 3 mo ago |
| 265 | 生成安全审计 skill。两种模式:(1) 项目模式——根据项目文档生成定制化审计 skill;(2) 通用模式——仅指定语言+框架,从参考资料库生成通用审计 skill。当用户想创建安全审计 skill、生成审计规则、或提到"生成安全审计skill"、"创建code review skill"、"生成 Java 审计 skill"时使用。 | xwtro0tk1t-cloud/ | 265 | — | ~5.7k | Automated safety check: Pass | No licence | 5 mo ago |
| 266 | Run splint after cppcheck/clang-format/clang-tidy precommit sanity to find memory issues, API misuse, and contract violations in staged C code (tolerates older C parser limitations). | MidnightBSD/ | 114 | — | ~348 | Automated safety check: Pass | Unknown | yesterday |
| 267 | Expert in threat modeling methodologies, security architecture review, and risk assessment. | davila7/ | 33k | 8 repos | ~529 | Automated safety check: Pass | MIT | today |
| 268 | A skill your agent uses when adding, updating, or removing CVE/GHSA suppressions in .openvex.json — the OpenVEX document consumed by the weekly image vulnerability scan workflow. | NVIDIA/ | 440 | — | ~5.9k | Automated safety check: Pass | Apache-2.0 | today |
| 269 | Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 270 | Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits. | cyberful/ | 135 | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 271 | Review a PR through the CodeReviewSecurityReview persona. An agent skill from eric-tramel/moraine. | eric-tramel/ | 117 | — | ~497 | Automated safety check: Pass | Apache-2.0 | today |
| 272 | Azure Key Vault Secrets Java SDK for secret management. An agent skill from microsoft/skills. | microsoft/ | 3.1k | 5 repos | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 273 | 273.Iam AWS Identity and Access Management for users, roles, policies, and permissions. | itsmostafa/ | 1.2k | — | ~1.8k | Automated safety check: Pass | MIT | 5 days ago |
| 274 | 274.Fabric Intelligent pattern selection for Fabric CLI. An agent skill from ynulihao/AgentSkillOS. | ynulihao/ | 618 | 1 repo | ~3.4k | Automated safety check: Pass | No licence | 7 mo ago |
| 275 | Publishes CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and runs cdxgen in HTTP server mode to generate BOMs on demand for local paths, Git URLs, or… | cdxgen/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 276 | How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes. | ibuilder/ | 122 | — | ~1.7k | Automated safety check: Pass | MIT | 2 days ago |
| 277 | 277.Security Review Run a focused STRIDE-based security review using Bug Hunter-native artifacts. | codexstar69/ | 520 | — | ~567 | Automated safety check: Pass | MIT | 1 mo ago |
| 278 | Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk. | seb1n/ | 206 | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 279 | PHP Web 源码任意文件读取/路径穿越审计工具。识别文件读取 Sink,追踪路径来源与校验逻辑,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~558 | Automated safety check: Pass | No licence | 6 mo ago |
| 280 | Bootstrap a development environment and configure the corporate package mirror | cisco-ai-defense/ | 2.6k | — | ~126 | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 281 | Complete Tier 1 triage workflow. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 282 | 282.Msp Helpdesk A skill your agent uses for anything about how your MSP runs day-to-day support: setting or questioning a ticket's priority, response and resolution targets, "the client says everything is down"… | RTFM-IT-Services-LLC/ | 115 | — | ~3.3k | Automated safety check: Pass | Unknown | 8 days ago |
| 283 | Chris Sherwood / Crosstalk Solutions 视角 — UBNT-native 实战派的代表 YouTuber (475K+ 订阅, 1000+ 视频, UI Toolkit 作者). | swaylq/ | 148 | — | ~5.2k | Automated safety check: Notes | MIT | 1 mo ago |
| 284 | Analyze code changes for security vulnerabilities using LLM reasoning and threat model patterns. | Factory-AI/ | 111 | — | ~2.3k | Automated safety check: Pass | No licence | today |
| 285 | GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL). | secondsky/ | 227 | — | ~4k | Automated safety check: Notes | MIT | 13 days ago |
| 286 | Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. | trailofbits/ | 513 | 9 repos | ~1.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 mo ago |
| 287 | Create an OpenTaint test project with positive/negative samples for verifying a rule or approximation. | seqra/ | 163 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 288 | 288.Sast Fileupload Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel… | utkusen/ | 1.3k | — | ~7.3k | Automated safety check: Pass | MIT | 6 mo ago |