Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 289 | 289.Clusterfuzzlite Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan. | InternationalColorConsortium/ | 183 | — | ~1.5k | Automated safety check: Pass | BSD-3-Clause | yesterday |
| 290 | Builds and debugs Arcium encrypted computation apps on Solana: Arcis circuits, Anchor orchestration, encrypted inputs and the init, queue and callback flow. | sendaifun/ | 130 | — | ~2.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 291 | Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates. | AgentSecOps/ | 220 | 1 repo | ~4.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 292 | Documents the OmniRoute REST endpoints for creating, listing, updating, regenerating and deleting API keys, with per-key scopes, spending limits, expiry and device lists. | diegosouzapw/ | 75k | — | ~1.4k | Automated safety check: Pass | MIT | today |
| 293 | Documents how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard. | diegosouzapw/ | 75k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 294 | Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs… | aws/ | 103 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 295 | 295.Security Review Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy. | langfuse/ | 36k | — | ~1.4k | Automated safety check: Pass | Unknown | today |
| 296 | Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle… | axelixlabs/ | 148 | — | ~4.2k | Automated safety check: Pass | LGPL-3.0 | today |
| 297 | Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks. | maslennikov-ig/ | 260 | — | ~2k | Automated safety check: Pass | Unknown | 7 mo ago |
| 298 | 298.Nmap Recon Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools | CommonHuman-Lab/ | 157 | — | ~639 | Automated safety check: Pass | Unknown | 2 days ago |
| 299 | Database migration creation with mandatory RLS policies and ARCHitect approval workflow. Use when creating migrations, adding tables with RLS… | bybren-llc/ | 423 | — | ~1.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 300 | Build metric-driven Chimera/create-chimera-app stateful invariant testing campaigns for Solidity projects. | aviggiano/ | 144 | — | ~2.8k | Automated safety check: Pass | MIT | 25 days ago |
| 301 | Runs untrusted or AI-generated code in isolated Deno Sandbox microVMs using the @deno/sandbox SDK, with lifecycle, process and streaming guidance. | denoland/ | 100 | — | ~2.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 302 | 302.Container Sbom Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 303 | 303.Django Security Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 277k | 5 repos | ~4k | Automated safety check: Notes | MIT | today |
| 304 | 304.Security Guide OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation | jnMetaCode/ | 140 | — | ~644 | Automated safety check: Warn | Apache-2.0 | 12 days ago |
| 305 | Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by… | hardw00t/ | 105 | — | ~2.7k | Automated safety check: Pass | No licence | 5 mo ago |
| 306 | 306.Llvm Security Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation. | aftermathlabs/ | 438 | — | ~1.8k | Automated safety check: Pass | AGPL-3.0 | 8 days ago |
| 307 | Changing or adding a project setting / default value in RedAmon. | samugit83/ | 3k | — | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 308 | Route Mira detection findings into a reusable knowledge pipeline. | vw2x/ | 105 | — | ~1.1k | Automated safety check: Pass | GPL-3.0 | 6 days ago |
| 309 | 309.Takeover Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the… | PentesterFlow/ | 1.4k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 310 | 310.Enrich Ioc Enrich an IOC (IP, domain, hash, URL) with threat intelligence. | dandye/ | 127 | — | ~702 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 311 | 311.Snapshot Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions. | boostsecurityio/ | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 312 | 312.Apk Reversing 当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是… | zhaji2333/ | 115 | — | ~1.7k | Automated safety check: Pass | MIT | 26 days ago |
| 313 | Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. | OWASP/ | 188 | — | ~542 | Automated safety check: Pass | CC-BY-4.0 | 16 days ago |
| 314 | Shows, adds and removes the host directories that NanoClaw agent containers may access, recording each as read-only or read-write in an allowlist file. | nanocoai/ | 31k | — | ~474 | Automated safety check: Pass | MIT | yesterday |
| 315 | 315.OneCLI Gateway Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys. | nanocoai/ | 31k | — | ~856 | Automated safety check: Pass | MIT | yesterday |
| 316 | Code review covering security, performance, quality and maintainability, with a fixed report layout and two analysis scripts; the SKILL.md itself is in Ukrainian. | luongnv89/ | 42k | — | ~484 | Automated safety check: Pass | MIT | today |
| 317 | 317.TS Review TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura. | liuyanghejerry/ | 204 | — | ~166 | Automated safety check: Pass | MIT | 12 days ago |
| 318 | Finds exploitable application security vulnerabilities in code changes. | getsentry/ | 418 | — | ~1.8k | Automated safety check: Pass | Unknown | today |
| 319 | 319.Supply Chain Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops. | padamson/ | 159 | — | ~711 | Automated safety check: Pass | Apache-2.0 | today |
| 320 | Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself. | anthropics/ | 38k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 321 | 321.Repo Audit Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. | zebbern/ | 4.7k | — | ~831 | Automated safety check: Pass | MIT | yesterday |
| 322 | Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design. | revfactory/ | 1.3k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 323 | Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session. | avelikiy/ | 103 | — | ~884 | Automated safety check: Notes | MIT | today |
| 324 | Paid API marketplace for AI agents via Corbits. An agent skill from moonpay/skills. | moonpay/ | 113 | — | ~1.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 325 | 325.Sca AI Denoise SCA 漏洞 AI 降噪与风险优先级评估。对 Grype/Snyk/Xray 等 SCA 工具的漏洞发现进行多维度风险评估,按 P0-P3 分级,过滤噪音(DoS、本地提权、低影响信息泄露),聚焦真正可利用的高风险漏洞。当用户需要对 SCA 扫描结果降噪、漏洞优先级排序、或供应链风险评估时使用。 | xwtro0tk1t-cloud/ | 265 | — | ~787 | Automated safety check: Pass | No licence | 5 mo ago |
| 326 | Search and contribute to the shared AI-modding knowledge base, where field notes record how specific games were modded, decompiled or reverse-engineered (exact versions, route, engine facts… | rehan-remade/ | 6.5k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 327 | Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan. | kubernetes-sigs/ | 294 | — | ~818 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 328 | 328.AI Agent Posture Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | 2 days ago |
| 329 | Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch. | cloudposse/ | 1.4k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 330 | Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 331 | 331.Review Criteria Classify Datapages findings by reach and severity and write review-.md reports. | romshark/ | 114 | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 332 | Guides designing a layered permission pipeline for agent tools that decides which calls are allowed, need confirmation or are denied, with scopes and hooks. | simbajigege/ | 183 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 333 | Guides writing and improving fuzzing harnesses for C, C++ and Rust so random byte input gets translated into structured, reproducible test cases for the target code. | trailofbits/ | 7.5k | 1 repo | ~5.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 334 | 334.Crypto Bom Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts… | cdxgen/ | 1.1k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 335 | Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely. | Encod3d-Sec/ | 329 | — | ~1.6k | Automated safety check: Notes | MIT | 1 mo ago |
| 336 | 336.Review Review code quality, security, and maintainability before committing. | Thank-you-Linus/ | 211 | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |