Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 337 | 337.Catalog Constructs catalog products (standard or limited), catalog orders, and account-credit enrollment, including product-then-credit scenes. | openqa-cn/ | 152 | — | ~514 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 338 | Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix. | codewhale-hq/ | 41k | — | ~844 | Automated safety check: Pass | MIT | today |
| 339 | Loads a missing environment variable or API key from the team's Infisical workspace into the current shell, or runs a command with all project secrets injected. | Devin-AXIS/ | 6.8k | 1 repo | ~516 | Automated safety check: Pass | Unknown | yesterday |
| 340 | Plans and builds full-stack features with frontend, backend and security handled together, including a written design and a security checklist before any code. | Jeffallan/ | 12k | — | ~1.5k | Automated safety check: Pass | MIT | 8 days ago |
| 341 | Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks. | Jeffallan/ | 12k | — | ~1.8k | Automated safety check: Pass | MIT | 8 days ago |
| 342 | Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review. | Jeffallan/ | 12k | — | ~1.3k | Automated safety check: Pass | MIT | 8 days ago |
| 343 | Maintain a Mira detection topic after user confirmation. An agent skill from vw2x/Mira. | vw2x/ | 105 | — | ~575 | Automated safety check: Pass | GPL-3.0 | 6 days ago |
| 344 | Check reburp's Montoya API coverage and detect when a Burp/Montoya upgrade added or changed APIs. | forefy/ | 117 | — | ~213 | Automated safety check: Pass | MIT | 6 days ago |
| 345 | 345.Update Vulndb Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository. | boostsecurityio/ | 523 | — | ~173 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 346 | A skill your agent uses when the user asks to create a NOWPayments crypto payment link, poll payment status, or execute a supported direct wallet payment through the AltLLM Portal CLI. | internet-court/ | 6.6k | 1 repo | ~563 | Automated safety check: Pass | ISC | 1 mo ago |
| 347 | 347.HTTP Evidence Turn a captured HTTP request/response into a bounded, redacted evidence pack with a stable request-ref using the mantishttpaudit MCP server, instead of pasting raw traffic into a finding | deonmenezes/ | 503 | — | ~455 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 348 | 348.Security Setup Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 349 | 349.Dep Security Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that… | tinyfish-io/ | 2.2k | — | ~2.4k | Automated safety check: Pass | MIT | 3 days ago |
| 350 | 350.Ghost Scan Deps Ghost Security - Software Composition Analysis (SCA) scanner. | ghostsecurity/ | 409 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | 13 days ago |
| 351 | Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste. | microsoft/ | 107 | — | ~1k | Automated safety check: Pass | MIT | yesterday |
| 352 | 352.Gate Run this project's verification — the full local CI mirror (ruff, mypy, import contract, pytest with PostgreSQL, coverage floors, dogfood, generated docs and site, the isolated example suites, the… | guardana/ | 259 | — | ~757 | Automated safety check: Pass | Apache-2.0 | today |
| 353 | 353.Django Security Django 安全最佳实践、认证、授权、CSRF 防护、SQL 注入预防、XSS 预防和安全部署配置. An agent skill from affaan-m/ECC. | affaan-m/ | 277k | 3 repos | ~3.7k | Automated safety check: Notes | MIT | today |
| 354 | 354.Security Review 在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。 | affaan-m/ | 277k | 3 repos | ~2.5k | Automated safety check: Notes | MIT | today |
| 355 | Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。 | affaan-m/ | 277k | 3 repos | ~1.6k | Automated safety check: Pass | MIT | today |
| 356 | Supply-chain security controls for the @cipherstash/stack monorepo. | cipherstash/ | 157 | — | ~5.2k | Automated safety check: Warn | MIT | yesterday |
| 357 | 357.Aster Config Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits. | Zfinix/ | 118 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 358 | 358.History Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive. | alpha-omega-security/ | 245 | — | ~2.9k | Automated safety check: Notes | MIT | today |
| 359 | Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works. | nanocoai/ | 31k | — | ~598 | Automated safety check: Pass | MIT | yesterday |
| 360 | Reviews code for security, performance, quality and maintainability, then reports findings in a fixed template with a rating, severity levels and suggested fixes. | luongnv89/ | 42k | — | ~474 | Automated safety check: Pass | MIT | today |
| 361 | 361.Webcrypt MCP Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography. | putervision/ | 50 | — | ~847 | Automated safety check: Pass | MIT | 8 days ago |
| 362 | Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments. | irahardianto/ | 156 | — | ~2.7k | Automated safety check: Notes | MIT | 6 days ago |
| 363 | Secure secrets in Google Cloud Secret Manager. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 3 repos | ~3.3k | Automated safety check: Pass | MIT | yesterday |
| 364 | 364.Security Hygiene Detecta riscos básicos de segurança em repositórios (segredos expostos, configurações perigosas, padrões inseguros) e gera recomendações com evidências. | glaucia86/ | 121 | — | ~819 | Automated safety check: Warn | MIT | 3 mo ago |
| 365 | 生成安全审计 skill。两种模式:(1) 项目模式——根据项目文档生成定制化审计 skill;(2) 通用模式——仅指定语言+框架,从参考资料库生成通用审计 skill。当用户想创建安全审计 skill、生成审计规则、或提到"生成安全审计skill"、"创建code review skill"、"生成 Java 审计 skill"时使用。 | xwtro0tk1t-cloud/ | 265 | — | ~5.7k | Automated safety check: Pass | No licence | 5 mo ago |
| 366 | Audit Entra ID app registration and service principal security posture. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | 3 days ago |
| 367 | Analyzes Solidity contract entry points to map attack surface. | alt-research2/ | 104 | — | ~959 | Automated safety check: Pass | Unknown | 4 mo ago |
| 368 | 368.Dependency Audit Dependency audit and cleanup workflow for maintaining healthy project dependencies. | bobmatnyc/ | 156 | — | ~3.5k | Automated safety check: Pass | Unknown | 1 mo ago |
| 369 | Performs security-focused differential review of code changes (PRs, commits, diffs). | waybarrios/ | 534 | 5 repos | ~1.6k | Automated safety check: Pass | MIT | 5 days ago |
| 370 | 370.Threat Model MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness. | ruvnet/ | 696 | — | ~637 | Automated safety check: Notes | MIT | yesterday |
| 371 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.5k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 372 | Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation. | trailofbits/ | 7.5k | — | ~4.6k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 373 | Annotates a codebase with unit, dimension and decimal-scaling comments to expose mismatches and formula bugs in DeFi, financial and scientific arithmetic. | trailofbits/ | 7.5k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 374 | Triages survived mutants and unnecessary test statements using Trailmark call-graph data, sorting them into false positives, missing unit tests and fuzzing targets. | trailofbits/ | 7.5k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 375 | Converts a Mermaid sequence diagram of a cryptographic protocol into a ProVerif model file ready for checking secrecy, authentication and forward secrecy. | trailofbits/ | 7.5k | — | ~4.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 376 | Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions. | trailofbits/ | 7.5k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 377 | Uses mutation testing on cryptographic implementations to find coverage gaps, then writes new test vectors for the uncovered paths and compares kill rates to show they help. | trailofbits/ | 7.5k | — | ~4.8k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 378 | 378.Iss Audit Audit GitHub issues before implementation, including skeptical claim verification, safe reproduction, prompt-injection resistance, malicious-link and attachment handling, root-cause analysis… | akitaonrails/ | 216 | — | ~4.1k | Automated safety check: Pass | No licence | 18 days ago |
| 379 | Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 380 | Manage cryptographic keys using Azure Key Vault Keys SDK for JavaScript (@azure/keyvault-keys). | microsoft/ | 3.1k | 5 repos | ~1.7k | Automated safety check: Pass | MIT | 2 days ago |
| 381 | Azure Key Vault Keys Java SDK for cryptographic key management. | microsoft/ | 3.1k | 5 repos | ~2.9k | Automated safety check: Pass | MIT | 2 days ago |
| 382 | Azure Key Vault Secrets Java SDK for secret management. An agent skill from microsoft/skills. | microsoft/ | 3.1k | 5 repos | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 383 | 383.Web Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用. An agent skill from MuWinds/BUUCTF_Agent. | MuWinds/ | 267 | — | ~463 | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 384 | 384.Get Call Paths Get a path in the call graph from a source function to a specified destination function in the codebase. | opensage-agent/ | 127 | — | ~272 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |