Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 385 | 385.Iam AWS Identity and Access Management for users, roles, policies, and permissions. | itsmostafa/ | 1.2k | — | ~1.8k | Automated safety check: Pass | MIT | 6 days ago |
| 386 | Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. | Gabson0x/ | 442 | — | ~11k | Automated safety check: Warn | No licence | 24 days ago |
| 387 | Explains authorization in an Arandu Go application: write a Policy, get a security.Grant through security.Authorize, re-authorize each row, and keep tenant isolation. | arandu-io/ | 281 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 388 | Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator. | transilienceai/ | 563 | — | ~1.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 389 | Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run. | dralgorhythm/ | 125 | — | ~1.5k | Automated safety check: Pass | No licence | 2 mo ago |
| 390 | 390.Security Audit Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults. | Aedelon/ | 120 | — | ~1.6k | Automated safety check: Notes | Unknown | 7 mo ago |
| 391 | Insecure deserialization detection and gadget chain exploitation | NeoTheCapt/ | 143 | — | ~836 | Automated safety check: Pass | No licence | 2 mo ago |
| 392 | Steers C++ code toward C++20, C++23 and C++26 idioms such as smart pointers, concepts, std::expected and std::print, with a security focus. | trailofbits/ | 7.5k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 393 | 393.Security Django Review Django security audit patterns for settings and middleware. | IgorWarzocha/ | 122 | — | ~1.6k | Automated safety check: Notes | No licence | 8 mo ago |
| 394 | Guide to maintain creating modern and secure code while developing WordPress plugins. | duracelltomi/ | 174 | — | ~7.2k | Automated safety check: Pass | GPL-2.0-or-later | 2 days ago |
| 395 | 395.Secure Agent Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules. | mathematic-inc/ | 113 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 396 | Perform language and framework specific security best-practice reviews and suggest improvements. | trailofbits/ | 513 | 9 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 397 | Implementation details for EF Core scaffolding (reverse engineering). | dotnet/ | 15k | — | ~321 | Automated safety check: Pass | MIT | yesterday |
| 398 | 减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。 | index-login/ | 158 | — | ~242 | Automated safety check: Pass | MIT | yesterday |
| 399 | 399.Plan Turn a development task into one work file in .work/ — goal, decisions, lanes with exact files and verification, done-criteria. | guardana/ | 259 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 400 | 400.Security Scan AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。 | affaan-m/ | 277k | 2 repos | ~796 | Automated safety check: Pass | MIT | today |
| 401 | 401.Security Review 認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。 | affaan-m/ | 277k | 2 repos | ~2.5k | Automated safety check: Notes | MIT | today |
| 402 | 402.Security Review 인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요. | affaan-m/ | 277k | 2 repos | ~2.7k | Automated safety check: Notes | MIT | today |
| 403 | 403.Security Audit A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance. | jellydn/ | 123 | — | ~2.9k | Automated safety check: Notes | MIT | yesterday |
| 404 | 404.Web2 Recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis… | awarexone/ | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | 2 days ago |
| 405 | Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates. | awarexone/ | 5.3k | — | ~1.9k | Automated safety check: Warn | MIT | 2 days ago |
| 406 | Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation. | dslsdzc/ | 135 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 407 | 407.Ctf Forensics Provides digital forensics and signal analysis techniques for CTF challenges. | ljagiello/ | 3.4k | — | ~9.2k | Automated safety check: Warn | MIT | 27 days ago |
| 408 | Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. | trailofbits/ | 7.5k | — | ~3.6k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 409 | Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix. | trailofbits/ | 7.5k | — | ~3.1k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 410 | Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation. | trailofbits/ | 7.5k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 411 | Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay. | trailofbits/ | 7.5k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 412 | Sets up cargo-fuzz for a Cargo-based Rust project: nightly toolchain, fuzz targets, structured inputs, sanitizers, coverage and reproducing crashes. | trailofbits/ | 7.5k | — | ~2.9k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 413 | Scores a smart contract or blockchain codebase across 9 maturity categories with evidence, then delivers a scorecard and a priority-ordered improvement roadmap. | trailofbits/ | 7.5k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 414 | Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents. | trailofbits/ | 7.5k | — | ~2.7k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 415 | Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. | trailofbits/ | 7.5k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 416 | Builds fuzzing dictionaries of keywords, magic bytes and tokens and wires them into libFuzzer, AFL++ or cargo-fuzz so fuzzers get past input validation. | trailofbits/ | 7.5k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 417 | Patches checksums, hash checks, time-based seeds and other non-deterministic state out of fuzzing builds so the fuzzer reaches deeper code, with production behavior intact. | trailofbits/ | 7.5k | — | ~4k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 418 | Reviews a smart contract project against Trail of Bits development guidelines, covering documentation, architecture, upgradeability, implementation quality, dependencies and tests. | trailofbits/ | 7.5k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 419 | Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. | trailofbits/ | 7.5k | — | ~4.3k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 420 | Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally. | trailofbits/ | 7.5k | — | ~4.2k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 421 | Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language. | trailofbits/ | 7.5k | — | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 422 | Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. | trailofbits/ | 7.5k | — | ~3.8k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 423 | 423.Review Swarm Parallel read-only multi-agent review of a current git diff or explicit file scope to find behavioral regressions, security or privacy risks, performance or reliability issues, and contract or test… | Dimillian/ | 4k | — | ~1.6k | Automated safety check: Pass | MIT | 6 mo ago |
| 424 | 424.Django Security Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 277k | 1 repo | ~4.3k | Automated safety check: Notes | MIT | today |
| 425 | Verification loop for Quarkus projects: build, static analysis (Checkstyle, PMD, SpotBugs), tests with JaCoCo coverage, OWASP dependency and container security scans, GraalVM native compilation… | affaan-m/ | 277k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | today |
| 426 | 426.Web Sqli SQL injection detection→exploitation→proof for web apps and APIs. | s0ld13rr/ | 828 | — | ~710 | Automated safety check: Pass | MIT | 9 days ago |
| 427 | Azure Key Vault Keys SDK for .NET. An agent skill from microsoft/skills. | microsoft/ | 3.1k | 5 repos | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 428 | 428.Fuzz Generator Generates Foundry invariant tests and Echidna property-based fuzz tests for Solidity contracts. | alt-research2/ | 104 | — | ~763 | Automated safety check: Notes | Unknown | 4 mo ago |
| 429 | 429.R0crawl Skills 面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。 | manyuegong33/ | 312 | — | ~1.2k | Automated safety check: Pass | No licence | 21 days ago |
| 430 | A skill your agent uses when setting up an email inbox for an AI agent (Moltbot, Clawdbot, or similar) - configuring inbound email, webhooks, tunneling for local development, and implementing… | viclafouch/ | 110 | 2 repos | ~10k | Automated safety check: Warn | No licence | 6 mo ago |
| 431 | A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection. | openJiuwen-ai/ | 446 | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | today |
| 432 | Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |