Search
Security · Git · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.X Ray Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)… | pashov/ | 1.2k | 1 repo | ~10k | Automated safety check: Pass | MIT | 4 days ago |
| 2 | Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core… | digoal/ | 8.6k | — | ~4k | Automated safety check: Pass | GPL-2.0 | today |
| 3 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 4 | Security audit for web apps, especially AI-built ("vibe coded") ones. | benavlabs/ | 118 | — | ~1.1k | Automated safety check: Notes | MIT | 20 days ago |
| 5 | Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix. | pretend1111/ | 496 | 1 repo | ~502 | Automated safety check: Pass | Unknown | 5 mo ago |
| 6 | Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity. | activepieces/ | 25k | — | ~3.6k | Automated safety check: Pass | Unknown | today |
| 7 | Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the… | getsentry/ | 1.8k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 8 | Specialized in reverse-engineering compiled binaries (JARs, DLLs). | HacktronAI/ | 115 | — | ~2.2k | Automated safety check: Pass | MIT | 4 mo ago |
| 9 | 9.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 | today |
| 10 | Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis. | openqa-cn/ | 152 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 11 | Three-axis review of the branch diff — Standards (this repo's documented standards + public API surface), Spec (the originating Linear issue / PR), and Correctness (runtime bugs + the SDK threat… | getsentry/ | 873 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 12 | Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages. | ruby-git/ | 1.8k | — | ~806 | Automated safety check: Pass | MIT | 7 days ago |
| 13 | Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli. | kklimuk/ | 216 | — | ~1.7k | Automated safety check: Pass | MIT | today |
| 14 | 14.Fix Vulns Automated triage and fixing of Dependabot security vulnerabilities (IN-1189). | linuxfoundation/ | 280 | — | ~3.8k | Automated safety check: Notes | MIT | 8 days ago |
| 15 | Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. | mistralai/ | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 16 | 16.Auto Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions. | guardana/ | 130 | — | ~788 | Automated safety check: Pass | Apache-2.0 | today |
| 17 | Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks. | maslennikov-ig/ | 260 | — | ~2k | Automated safety check: Pass | Unknown | 7 mo ago |
| 18 | Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 19 | Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself. | anthropics/ | 38k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 20 | 20.Repo Audit Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. | zebbern/ | 4.7k | — | ~831 | Automated safety check: Pass | MIT | today |
| 21 | Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch. | cloudposse/ | 1.4k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 22 | Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions. | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 23 | Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run. | dralgorhythm/ | 125 | — | ~1.5k | Automated safety check: Pass | No licence | 2 mo ago |
| 24 | Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 25 | 25.Review Swarm Parallel read-only multi-agent review of a current git diff or explicit file scope to find behavioral regressions, security or privacy risks, performance or reliability issues, and contract or test… | Dimillian/ | 4k | — | ~1.6k | Automated safety check: Pass | MIT | 6 mo ago |
| 26 | 26.Refactor Behaviour-preserving restructuring and cleanup — splitting an oversized module, removing dead code, finished scripts, flags or documents, consolidating duplicates, tightening comments. | guardana/ | 130 | — | ~786 | Automated safety check: Pass | Apache-2.0 | today |
| 27 | Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | 28.Pii Guard Personally identifiable information (PII) leak prevention for EverClaw. | profbernardoj/ | 112 | — | ~921 | Automated safety check: Pass | MIT | 1 mo ago |
| 29 | Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed… | mukul975/ | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). | tetherto/ | 683 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 31 | Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification… | kubernetes-sigs/ | 294 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | today |
| 32 | Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect | uphiago/ | 1.3k | — | ~2.8k | Automated safety check: Notes | MIT | 1 mo ago |
| 33 | 33.Review Code Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in… | tobihagemann/ | 409 | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 34 | Mass scan for exposed env files, backups, and git configs. An agent skill from uphiago/recon-skills. | uphiago/ | 1.3k | — | ~2.2k | Automated safety check: Notes | MIT | 1 mo ago |
| 35 | Verify exact SillyTavern, Tavern Helper / JS-Slash-Runner, STScript, macro, prompt-injection, worldbook, EJS, MVU, and runtime-library capabilities before implementing or reviewing rolecard… | LiarMTTT/ | 153 | — | ~2.4k | Automated safety check: Pass | Unknown | 5 days ago |
| 36 | 36.Review Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit. | softspark/ | 179 | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 37 | Probe a target for directories that return auto-generated index listings instead of denying or serving a specific file — exposes the full file tree under any reachable directory, including files the… | jeremylongshore/ | 2.8k | — | ~1.8k | Automated safety check: Notes | MIT | today |
| 38 | Security review via Codex exec. An agent skill from sd0xdev/sd0x-harness. | sd0xdev/ | 192 | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 39 | Run a fast AWS Security Agent diff scan on only the changed code since a git ref. | aws/ | 2.8k | — | ~1k | Automated safety check: Pass | Apache-2.0 | today |
| 40 | Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. | aws/ | 2.8k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | today |
| 41 | Multi-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review). | ffroliva/ | 266 | — | ~12k | Automated safety check: Pass | MIT | today |
| 42 | 42.Forensics Build a read-only compromise timeline and evidence bundle from local Git history and public forge/archive records. | alpha-omega-security/ | 239 | — | ~2.1k | Automated safety check: Notes | MIT | today |
| 43 | Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. | Mathews-Tom/ | 328 | — | ~2.2k | Automated safety check: Pass | MIT | 3 days ago |
| 44 | CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式 | wgpsec/ | 1.8k | — | ~1.4k | Automated safety check: Notes | No licence | yesterday |
| 45 | A skill your agent uses when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field. | openshift-eng/ | 120 | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 46 | Focused security audit of code, calibrated to surface real exploitable bugs and suppress theoretical findings. | PostHog/ | 40k | — | ~8.1k | Automated safety check: Warn | Unknown | today |
| 47 | 47.Enforce Sbom Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing Harness pipeline to verify SBOM attestations and apply OPA SBOM policy sets. | harness/ | 115 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 48 | AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files. | danielvm-git/ | 258 | — | ~1.5k | Automated safety check: Pass | MIT | 17 days ago |