Search

Security · GitHub

113 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

j3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT2 mo ago
2
2.CodeqlOfficial

Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.

elastic/kibana21k—~1.7kAutomated safety check: PassUnknowntoday
3

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknowntoday
4

A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

zhaoxuya520/reverse-skill40k4 repos~953Automated safety check: WarnMIT16 days ago
5

Cut a new AperiSolve release — bump the version, commit "chore(release): X.Y.Z", tag it, push, and publish a GitHub Release whose notes are computed from the commits since the last tag.

Zeecka/AperiSolve850—~1.9kAutomated safety check: PassMITtoday
6

A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

asyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.02 days ago
7

Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.

symfony/symfony31k—~2.9kAutomated safety check: PassMITtoday
8

Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

verdaccio/verdaccio18k—~853Automated safety check: PassMITyesterday
9

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

ParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0today
10

Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

EpicenterHQ/epicenter4.8k—~896Automated safety check: PassUnknowntoday
11

Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation.

obot-platform/obot1.1k—~1.3kAutomated safety check: PassMITtoday
12
12.ReviewOfficial

Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the…

getsentry/sentry-react-native1.8k—~1.9kAutomated safety check: PassMITtoday
13

Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.

openplayerjs/openplayerjs649—~1kAutomated safety check: PassMIT2 days ago
14

Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

netdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0today
15

Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.

slowmist/slowmist-agent-security508—~1.4kAutomated safety check: PassMIT5 mo ago
16

Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

RaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0today
17

Run a security scan on the kedro-plugins codebase or a pull request.

kedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.0today
18

Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

Tommy-yw/RunbookHermes5463 repos~5kAutomated safety check: PassMIT4 mo ago
19
19.Handle CveOfficial

A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR.

DataDog/dd-trace-rb417—~2.6kAutomated safety check: PassUnknowntoday
20

Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…

MidnightBSD/src114—~2.2kAutomated safety check: PassUnknown4 days ago
21

Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

eclipse-ankaios/ankaios125—~1.5kAutomated safety check: PassApache-2.0today
22

Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

nanocoai/nanoclaw31k1 repo~856Automated safety check: PassMITyesterday
23

Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

vechain/x-app-template450—~1.2kAutomated safety check: PassMIT2 mo ago
24

Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills.

austintgriffith/ethskills294—~829Automated safety check: PassNo licence1 mo ago
25
25.Docs

Update project documentation when features are added or changed.

boostsecurityio/poutine523—~336Automated safety check: PassApache-2.0yesterday
26

Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

trailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0today
27

A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…

openclaw/clawscan142—~1.1kAutomated safety check: PassMITtoday
28

Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

warpdotdev/warp65k1 repo~2.1kAutomated safety check: PassAGPL-3.0today
29

A skill your agent uses when fixing compiler warnings, static analyzer findings (clang-tidy, etc.), or runtime errors/crashes in the libYSE codebase.

yvanvds/yse-soundengine238—~3kAutomated safety check: PassMIT8 days ago
30

Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

AgriciDaniel/claude-cybersecurity227—~11kAutomated safety check: WarnMIT5 mo ago
31
31.CoreOfficial

Status-first routing, bounded evidence collection, and safety guidance for issue-graph.

vercel-labs/issue-graph125—~2.6kAutomated safety check: PassApache-2.07 days ago
32

Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe…

openclaw/openclaw392k—~13kAutomated safety check: PassMITtoday
33

Creates a new Earl HCL template for a specific API, database, or shell command.

mathematic-inc/earl113—~2.8kAutomated safety check: PassApache-2.0yesterday
34

Perform a requested security review of a NemoClaw PR or a PR linked to an issue.

NVIDIA/NemoClaw23k—~1.1kAutomated safety check: PassApache-2.0today
35

Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.

getlago/lago-front163—~2.9kAutomated safety check: PassMITtoday
36

Handle confidential GitHub Security Advisory response for Paperclip.

paperclipai/paperclip99k—~2kAutomated safety check: PassMITtoday
37
37.Keel

A skill your agent uses for ANY new software project from idea to release — websites, WordPress/WooCommerce plugins, MCP servers, web apps, components, or libraries.

joseconti/declaracion-renta-espana190—~11kAutomated safety check: WarnGPL-3.0-or-later2 mo ago
38

Turn a vulnerability report into a publication-ready GitHub Security Advisory.

frappe/skills146—~1.3kAutomated safety check: PassNo licence7 days ago
39

Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works.

nanocoai/nanoclaw31k1 repo~598Automated safety check: PassMITyesterday
40

Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

InternationalColorConsortium/iccDEV183—~1.5kAutomated safety check: PassBSD-3-Clausetoday
41

Find new skills on GitHub or check a specific skill before installing.

khendzel/skills-janitor123—~1.6kAutomated safety check: PassMIT8 days ago
42

Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

axelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0today
43

Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the…

PentesterFlow/agent1.4k—~3.3kAutomated safety check: PassApache-2.01 mo ago
44

Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

boostsecurityio/poutine523—~214Automated safety check: PassApache-2.0yesterday
45

Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch.

cloudposse/atmos1.4k—~1.3kAutomated safety check: PassApache-2.0today
46

Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.

boostsecurityio/poutine523—~173Automated safety check: PassApache-2.0yesterday
47

Supply-chain security controls for the @cipherstash/stack monorepo.

cipherstash/stack157—~5.2kAutomated safety check: WarnMITtoday
48

Audit GitHub issues before implementation, including skeptical claim verification, safe reproduction, prompt-injection resistance, malicious-link and attachment handling, root-cause analysis…

akitaonrails/my-skills212—~4.1kAutomated safety check: PassNo licence14 days ago