Search
Security · Git
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.X Ray Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)… | pashov/ | 1.2k | 1 repo | ~10k | Automated safety check: Pass | MIT | 3 days ago |
| 2 | Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core… | digoal/ | 8.6k | — | ~4k | Automated safety check: Pass | GPL-2.0 | 11 days ago |
| 3 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 4 | Security audit for web apps, especially AI-built ("vibe coded") ones. | benavlabs/ | 118 | — | ~1.1k | Automated safety check: Notes | MIT | 20 days ago |
| 5 | Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix. | pretend1111/ | 494 | 1 repo | ~502 | Automated safety check: Pass | Unknown | 5 mo ago |
| 6 | Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity. | activepieces/ | 25k | — | ~3.6k | Automated safety check: Pass | Unknown | yesterday |
| 7 | Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the… | getsentry/ | 1.8k | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 8 | Specialized in reverse-engineering compiled binaries (JARs, DLLs). | HacktronAI/ | 115 | — | ~2.2k | Automated safety check: Pass | MIT | 4 mo ago |
| 9 | Checks each shell command for destructive patterns such as recursive deletes, force pushes and dropped tables, and asks before letting them run. | garrytan/ | 136k | — | ~931 | Automated safety check: Notes | MIT | today |
| 10 | 10.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 | today |
| 11 | Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis. | openqa-cn/ | 152 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 12 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 220 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 13 | Three-axis review of the branch diff — Standards (this repo's documented standards + public API surface), Spec (the originating Linear issue / PR), and Correctness (runtime bugs + the SDK threat… | getsentry/ | 873 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 14 | A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally… | sandgardenhq/ | 137 | 3 repos | ~970 | Automated safety check: Pass | Unknown | 18 days ago |
| 15 | Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context. | codexstar69/ | 519 | — | ~629 | Automated safety check: Pass | MIT | 1 mo ago |
| 16 | Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages. | ruby-git/ | 1.8k | — | ~806 | Automated safety check: Pass | MIT | 7 days ago |
| 17 | 17.Cc Review 结构化代码审查工作流,适用于显式 quick/full/security review;不负责普通实现或 bug 修复流程。 | doccker/ | 1.1k | — | ~541 | Automated safety check: Pass | Unknown | 1 mo ago |
| 18 | 18.Review Swarm Parallel read-only multi-agent review of a current git diff or explicit file scope to find behavioral regressions, security or privacy risks, performance or reliability issues, and contract or test… | Dimillian/ | 4k | 1 repo | ~1.6k | Automated safety check: Pass | MIT | 6 mo ago |
| 19 | Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli. | kklimuk/ | 216 | — | ~1.7k | Automated safety check: Pass | MIT | 13 days ago |
| 20 | 20.Fix Vulns Automated triage and fixing of Dependabot security vulnerabilities (IN-1189). | linuxfoundation/ | 280 | — | ~3.8k | Automated safety check: Notes | MIT | 7 days ago |
| 21 | Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. | mistralai/ | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 22 | Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks. | maslennikov-ig/ | 260 | — | ~2k | Automated safety check: Pass | Unknown | 7 mo ago |
| 23 | Security audit skill. An agent skill from blueberrycongee/termcanvas. | blueberrycongee/ | 406 | — | ~966 | Automated safety check: Notes | MIT | 4 mo ago |
| 24 | Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 25 | Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself. | anthropics/ | 38k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 26 | 26.Repo Audit Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. | zebbern/ | 4.7k | — | ~831 | Automated safety check: Pass | MIT | yesterday |
| 27 | 27.Dependencies Run git-pkgs list and sbom against the repository and emit one envelope with per-section status. | alpha-omega-security/ | 231 | — | ~596 | Automated safety check: Pass | MIT | yesterday |
| 28 | 28.Auto Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions. | guardana/ | 129 | — | ~792 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 29 | Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch. | cloudposse/ | 1.4k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 30 | Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions. | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 31 | Publishes CycloneDX BOMs to Dependency-Track or a TEA (Transparency Exchange API) server from cdxgen, and runs cdxgen in HTTP server mode to generate BOMs on demand for local paths, Git URLs, or… | cdxgen/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 32 | Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run. | dralgorhythm/ | 125 | — | ~1.5k | Automated safety check: Pass | No licence | 2 mo ago |
| 33 | Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 34 | Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | 35.Pii Guard Personally identifiable information (PII) leak prevention for EverClaw. | profbernardoj/ | 112 | — | ~921 | Automated safety check: Pass | MIT | 1 mo ago |
| 36 | 36.Refactor Behaviour-preserving restructuring and cleanup — splitting an oversized module, removing dead code, finished scripts, flags or documents, consolidating duplicates, tightening comments. | guardana/ | 129 | — | ~827 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 37 | 37.Sbom Generate a CycloneDX SBOM for the repository via git-pkgs sbom. | alpha-omega-security/ | 231 | — | ~290 | Automated safety check: Pass | MIT | yesterday |
| 38 | Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed… | mukul975/ | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). | tetherto/ | 681 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 40 | Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification… | kubernetes-sigs/ | 294 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | today |
| 41 | Perform a focused security review of pending git changes to identify high-confidence security vulnerabilities with real exploitation potential. | waybarrios/ | 533 | — | ~4.1k | Automated safety check: Pass | MIT | 2 days ago |
| 42 | Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect | uphiago/ | 1.3k | — | ~2.8k | Automated safety check: Notes | MIT | 1 mo ago |
| 43 | 43.Review Code Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in… | tobihagemann/ | 407 | — | ~3.2k | Automated safety check: Pass | MIT | yesterday |
| 44 | Mass scan for exposed env files, backups, and git configs. An agent skill from uphiago/recon-skills. | uphiago/ | 1.3k | — | ~2.2k | Automated safety check: Notes | MIT | 1 mo ago |
| 45 | Verify exact SillyTavern, Tavern Helper / JS-Slash-Runner, STScript, macro, prompt-injection, worldbook, EJS, MVU, and runtime-library capabilities before implementing or reviewing rolecard… | LiarMTTT/ | 150 | — | ~2.4k | Automated safety check: Pass | Unknown | 4 days ago |
| 46 | 46.Security Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks. | notque/ | 438 | — | ~2.6k | Automated safety check: Notes | MIT | 5 days ago |
| 47 | 47.Review Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit. | softspark/ | 179 | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 48 | Probe a target for directories that return auto-generated index listings instead of denying or serving a specific file — exposes the full file tree under any reachable directory, including files the… | jeremylongshore/ | 2.8k | — | ~1.8k | Automated safety check: Notes | MIT | today |