Search
Security
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 385 | 385.Misc 杂项技术,包括隐写术、流量分析、编码转换、取证分析、AI 安全等非传统 CTF 分类. An agent skill from MuWinds/BUUCTF_Agent. | MuWinds/ | 267 | — | ~504 | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 386 | Review Hermes settings for security risks. An agent skill from OnlyTerp/hermes-optimization-guide. | OnlyTerp/ | 688 | — | ~1.1k | Automated safety check: Notes | MIT | 17 days ago |
| 387 | Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption. | wshobson/ | 40k | 11 repos | ~1.9k | Automated safety check: Pass | MIT | 6 days ago |
| 388 | 388.Update Updating Add an entry to the UPDATING file at the repository root. An agent skill from MidnightBSD/src. | MidnightBSD/ | 114 | — | ~1.6k | Automated safety check: Pass | Unknown | 2 days ago |
| 389 | 389.Triage Self-validates a bug bounty report draft before submission. An agent skill from yeswehack/claude-kit. | yeswehack/ | 110 | — | ~1k | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 390 | Display Hak5 WiFi Pineapple recon scan data as a formatted table. | sneakerhax/ | 112 | — | ~298 | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 391 | 391.Do Analyze 对 jar-analyzer-engine 构建的 SQLite 数据库执行安全审计分析查询。支持方法调用搜索、调用链追踪、Spring 组件分析、字符串搜索、漏洞模式检测等。 | jar-analyzer/ | 141 | — | ~2.5k | Automated safety check: Pass | No licence | 6 mo ago |
| 392 | 392.Security Use before shipping to production. An agent skill from garagon/nanostack. | garagon/ | 207 | — | ~3.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 393 | 393.Deobf String Decrypt and recover obfuscated strings from binaries by analyzing encryption patterns and generating decryption scripts | P4nda0s/ | 140 | — | ~876 | Automated safety check: Pass | No licence | 4 mo ago |
| 394 | A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings… | villith/ | 156 | — | ~7.5k | Automated safety check: Pass | MIT | 16 days ago |
| 395 | Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 396 | OpenClaw 安全检测工具,基于安全实践指南验证配置安全、权限隔离、网络策略、日志审计和运行时完整性. An agent skill from jd-opensource/JoySafeter. | jd-opensource/ | 314 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 397 | Manages who can reach Claude through a Discord channel: approve pairing codes, edit the allowlist and set direct-message and group policy. | anthropics/ | 38k | 1 repo | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 398 | Update copyright year references across the project at the beginning of each calendar year. | MichaelGrafnetter/ | 2k | — | ~404 | Automated safety check: Pass | MIT | 29 days ago |
| 399 | This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks"… | zebbern/ | 4.7k | 8 repos | ~6.1k | Automated safety check: Pass | MIT | yesterday |
| 400 | Systematic static analysis of ELF firmware binaries using command-line tools (file, strings, readelf, objdump, xxd). | OrbitCurve/ | 216 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 401 | 401.Mod Any Game Mod a PC game the user owns, taking an idea to working in the real game and recorded. | rehan-remade/ | 6.5k | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 402 | Recovers internal keys from legacy ZipCrypto-protected ZIP archives in CTF challenges through a known-plaintext method, instead of brute force. | zhaoxuya520/ | 41k | 1 repo | ~1.5k | Automated safety check: Pass | MIT | 19 days ago |
| 403 | Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence. | zhaoxuya520/ | 41k | 1 repo | ~1k | Automated safety check: Pass | MIT | 19 days ago |
| 404 | Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis. | trilwu/ | 157 | — | ~3.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 405 | Runs trace-mcp security, quality-gate and antipattern checks before a commit or pull request, and builds a symbol-level diff for the PR description. | nikolai-vysotskyi/ | 189 | — | ~565 | Automated safety check: Pass | MIT | today |
| 406 | Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report. | forefy/ | 152 | — | ~1.4k | Automated safety check: Pass | MIT | 6 days ago |
| 407 | Perform post-implementation security review on recent code changes and produce prioritized hardening recommendations with file evidence and fix guidance. | Bald0Wang/ | 187 | — | ~694 | Automated safety check: Pass | No licence | 7 mo ago |
| 408 | Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related… | microsoft/ | 984 | — | ~3k | Automated safety check: Notes | MIT | yesterday |
| 409 | A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability… | openclaw/ | 143 | — | ~1.9k | Automated safety check: Pass | MIT | 4 days ago |
| 410 | 410.Security Review Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs. | deadlock-mod-manager/ | 478 | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 411 | Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis. | trailofbits/ | 7.5k | 3 repos | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 412 | 412.Bom Explore Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences… | cdxgen/ | 1.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 413 | Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures. | Encod3d-Sec/ | 329 | — | ~611 | Automated safety check: Pass | MIT | 1 mo ago |
| 414 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.5k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 415 | Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings. | seb1n/ | 206 | — | ~2.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 416 | Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe… | openclaw/ | 392k | — | ~14k | Automated safety check: Pass | MIT | today |
| 417 | 417.Create Template Creates a new Earl HCL template for a specific API, database, or shell command. | mathematic-inc/ | 113 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 418 | 418.Breach Patterns Learn from public breach disclosures — extract the audit question each one implies and check your own stack. | briiirussell/ | 413 | — | ~3.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 419 | 419.Php Cmd Audit PHP Web 源码命令注入审计工具。识别命令执行 Sink(exec/system/shellexec 等),追踪用户输入进入命令拼接,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~465 | Automated safety check: Pass | No licence | 6 mo ago |
| 420 | 420.MCP Server Tools Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token. | samugit83/ | 3k | — | ~1.8k | Automated safety check: Pass | MIT | 2 days ago |
| 421 | A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code… | ProgrammerAnthony/ | 235 | — | ~1.6k | Automated safety check: Pass | MIT | 5 mo ago |
| 422 | Generate prioritized CVE watchlists and actionable security recommendations for repositories. | ArabelaTso/ | 253 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 423 | Close a case or alert with proper reason and documentation. An agent skill from dandye/ai-runbooks. | dandye/ | 127 | — | ~615 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 424 | Perform a requested security review of a NemoClaw PR or a PR linked to an issue. | NVIDIA/ | 23k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 425 | 425.Absolute Audit Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without… | maddhruv/ | 219 | 1 repo | ~1.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 426 | 426.Cve Doctor Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix. | getlago/ | 163 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 427 | 427.Gstack Cso Security audit workflow for OPC code, providers, plugins, Electron surfaces, local HTTP bridges, filesystem access, and command execution. | LING71671/ | 963 | — | ~321 | Automated safety check: Notes | Unknown | 2 mo ago |
| 428 | Reference for ten classes of DeFi smart contract bugs, each with root cause, vulnerable code, fix, grep patterns and paid examples, for audits and bug bounty reviews. | tradecatlabs/ | 17k | 2 repos | ~10k | Automated safety check: Pass | MIT | yesterday |
| 429 | Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup. | tradecatlabs/ | 17k | 2 repos | ~9.9k | Automated safety check: Pass | MIT | yesterday |
| 430 | Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting. | tradecatlabs/ | 17k | 2 repos | ~7.7k | Automated safety check: Pass | MIT | yesterday |
| 431 | Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. | Eyadkelleh/ | 389 | — | ~636 | Automated safety check: Pass | No licence | 4 mo ago |
| 432 | 432.Ctf Key Recovery Reconstruct CTF key, serial, and flag verifiers using known plaintext, repeating XOR, encoded constants, bytecode replacement, hash constraints, SMT, and bounded brute force. | manyuegong33/ | 312 | — | ~434 | Automated safety check: Pass | No licence | 21 days ago |