Search

Security · Git · For developers

50 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…

pashov/skills1.2k1 repo~10kAutomated safety check: PassMIT4 days ago
2

Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core…

digoal/blog8.6k—~4kAutomated safety check: PassGPL-2.0today
3

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

trailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.0yesterday
4

Security audit for web apps, especially AI-built ("vibe coded") ones.

benavlabs/vibe-check118—~1.1kAutomated safety check: NotesMIT20 days ago
5

Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix.

pretend1111/claude-desktop-app4961 repo~502Automated safety check: PassUnknown5 mo ago
6

Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity.

activepieces/activepieces25k—~3.6kAutomated safety check: PassUnknowntoday
7
7.ReviewOfficial

Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the…

getsentry/sentry-react-native1.8k—~1.9kAutomated safety check: PassMITtoday
8

Specialized in reverse-engineering compiled binaries (JARs, DLLs).

HacktronAI/skills115—~2.2kAutomated safety check: PassMIT4 mo ago
9

Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

RaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0today
10

Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.

openqa-cn/codexqa152—~2.6kAutomated safety check: PassApache-2.06 days ago
11
11.ReviewOfficial

Three-axis review of the branch diff — Standards (this repo's documented standards + public API surface), Spec (the originating Linear issue / PR), and Correctness (runtime bugs + the SDK threat…

getsentry/sentry-dart873—~1.3kAutomated safety check: PassMITtoday
12

Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.

ruby-git/ruby-git1.8k—~806Automated safety check: PassMIT7 days ago
13

Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli.

kklimuk/docx-cli216—~1.7kAutomated safety check: PassMITtoday
14

Automated triage and fixing of Dependabot security vulnerabilities (IN-1189).

linuxfoundation/insights280—~3.8kAutomated safety check: NotesMIT8 days ago
15

Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

mistralai/mistral-vibe5.1k—~1kAutomated safety check: PassApache-2.02 days ago
16
16.Auto

Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions.

guardana/guardana130—~788Automated safety check: PassApache-2.0today
17

Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

maslennikov-ig/claude-code-orchestrator-kit260—~2kAutomated safety check: PassUnknown7 mo ago
18

Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

luongnv89/skills131—~4.5kAutomated safety check: PassMITtoday
19
19.Claude SecurityOfficial

Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself.

anthropics/claude-plugins-official38k—~1.4kAutomated safety check: PassApache-2.0today
20

Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets.

zebbern/claude-code-guide4.7k—~831Automated safety check: PassMITtoday
21

Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch.

cloudposse/atmos1.4k—~1.3kAutomated safety check: PassApache-2.0today
22

Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.

trailofbits/skills7.4k—~1.1kAutomated safety check: NotesCC-BY-SA-4.0yesterday
23

Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

dralgorhythm/claude-agentic-framework125—~1.5kAutomated safety check: PassNo licence2 mo ago
24

Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.

trailofbits/skills7.4k—~1.8kAutomated safety check: NotesCC-BY-SA-4.0yesterday
25

Parallel read-only multi-agent review of a current git diff or explicit file scope to find behavioral regressions, security or privacy risks, performance or reliability issues, and contract or test…

Dimillian/Skills4k—~1.6kAutomated safety check: PassMIT6 mo ago
26

Behaviour-preserving restructuring and cleanup — splitting an oversized module, removing dead code, finished scripts, flags or documents, consolidating duplicates, tightening comments.

guardana/guardana130—~786Automated safety check: PassApache-2.0today
27

Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
28

Personally identifiable information (PII) leak prevention for EverClaw.

profbernardoj/everclaw-community-branches112—~921Automated safety check: PassMIT1 mo ago
29

Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

mukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.01 mo ago
30

PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

tetherto/qvac683—~2.5kAutomated safety check: PassApache-2.0today
31

Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification…

kubernetes-sigs/cloud-provider-azure294—~3.9kAutomated safety check: PassApache-2.0today
32

Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

uphiago/recon-skills1.3k—~2.8kAutomated safety check: NotesMIT1 mo ago
33

Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in…

tobihagemann/turbo409—~3.3kAutomated safety check: PassMITtoday
34

Mass scan for exposed env files, backups, and git configs. An agent skill from uphiago/recon-skills.

uphiago/recon-skills1.3k—~2.2kAutomated safety check: NotesMIT1 mo ago
35

Verify exact SillyTavern, Tavern Helper / JS-Slash-Runner, STScript, macro, prompt-injection, worldbook, EJS, MVU, and runtime-library capabilities before implementing or reviewing rolecard…

LiarMTTT/TavernWeave153—~2.4kAutomated safety check: PassUnknown5 days ago
36

Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit.

softspark/ai-toolkit179—~3.1kAutomated safety check: NotesApache-2.0yesterday
37

Probe a target for directories that return auto-generated index listings instead of denying or serving a specific file — exposes the full file tree under any reachable directory, including files the…

jeremylongshore/tons-of-skills-marketplace2.8k—~1.8kAutomated safety check: NotesMITtoday
38

Security review via Codex exec. An agent skill from sd0xdev/sd0x-harness.

sd0xdev/sd0x-harness192—~1.1kAutomated safety check: PassMITyesterday
39

Run a fast AWS Security Agent diff scan on only the changed code since a git ref.

aws/agent-toolkit-for-aws2.8k—~1kAutomated safety check: PassApache-2.0today
40

Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.

aws/agent-toolkit-for-aws2.8k—~2.9kAutomated safety check: PassApache-2.0today
41

Multi-dimensional LLM council review of an open PR (default) or a local feature branch (§ 8 branch mode, invoked via /gflow:branch-review).

ffroliva/gflow-cli266—~12kAutomated safety check: PassMITtoday
42

Build a read-only compromise timeline and evidence bundle from local Git history and public forge/archive records.

alpha-omega-security/scrutineer239—~2.1kAutomated safety check: NotesMITtoday
43

Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.

Mathews-Tom/armory328—~2.2kAutomated safety check: PassMIT3 days ago
44

CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式

wgpsec/AboutSecurity1.8k—~1.4kAutomated safety check: NotesNo licenceyesterday
45

A skill your agent uses when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.

openshift-eng/ai-helpers120—~4.5kAutomated safety check: PassApache-2.02 days ago
46
46.Security AuditOfficial

Focused security audit of code, calibrated to surface real exploitable bugs and suppress theoretical findings.

PostHog/posthog40k—~8.1kAutomated safety check: WarnUnknowntoday
47

Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing Harness pipeline to verify SBOM attestations and apply OPA SBOM policy sets.

harness/harness-skills115—~3.9kAutomated safety check: PassApache-2.02 days ago
48

AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files.

danielvm-git/bigpowers258—~1.5kAutomated safety check: PassMIT17 days ago