Search
Security · GitHub · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments. | elastic/ | 21k | — | ~1.7k | Automated safety check: Pass | Unknown | today |
| 2 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | yesterday |
| 3 | A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability. | zhaoxuya520/ | 40k | 4 repos | ~953 | Automated safety check: Warn | MIT | 16 days ago |
| 4 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 5 | Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening. | symfony/ | 31k | — | ~2.9k | Automated safety check: Pass | MIT | yesterday |
| 6 | Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues. | verdaccio/ | 18k | — | ~853 | Automated safety check: Pass | MIT | 2 days ago |
| 7 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 8 | Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. | EpicenterHQ/ | 4.8k | — | ~896 | Automated safety check: Pass | Unknown | today |
| 9 | Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation. | obot-platform/ | 1.1k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 10 | Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the… | getsentry/ | 1.8k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 11 | 11.Audit Fix Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree. | openplayerjs/ | 649 | — | ~1k | Automated safety check: Pass | MIT | 3 days ago |
| 12 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 13 | 13.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 | today |
| 14 | Run a security scan on the kedro-plugins codebase or a pull request. | kedro-org/ | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 15 | Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. | Tommy-yw/ | 546 | 3 repos | ~5k | Automated safety check: Pass | MIT | 4 mo ago |
| 16 | A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR. | DataDog/ | 417 | — | ~2.6k | Automated safety check: Pass | Unknown | today |
| 17 | Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys. | nanocoai/ | 31k | 1 repo | ~856 | Automated safety check: Pass | MIT | 2 days ago |
| 18 | Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. | vechain/ | 450 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 19 | 19.Audit Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills. | austintgriffith/ | 294 | — | ~829 | Automated safety check: Pass | No licence | 1 mo ago |
| 20 | 20.Docs Update project documentation when features are added or changed. | boostsecurityio/ | 523 | — | ~336 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 21 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 22 | Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity. | AgriciDaniel/ | 227 | — | ~11k | Automated safety check: Warn | MIT | 5 mo ago |
| 23 | Status-first routing, bounded evidence collection, and safety guidance for issue-graph. | vercel-labs/ | 125 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 24 | Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe… | openclaw/ | 392k | — | ~13k | Automated safety check: Pass | MIT | today |
| 25 | Creates a new Earl HCL template for a specific API, database, or shell command. | mathematic-inc/ | 113 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 26 | Perform a requested security review of a NemoClaw PR or a PR linked to an issue. | NVIDIA/ | 23k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 27 | 27.Keel A skill your agent uses for ANY new software project from idea to release — websites, WordPress/WooCommerce plugins, MCP servers, web apps, components, or libraries. | joseconti/ | 190 | — | ~11k | Automated safety check: Warn | GPL-3.0-or-later | 2 mo ago |
| 28 | Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works. | nanocoai/ | 31k | 1 repo | ~598 | Automated safety check: Pass | MIT | 2 days ago |
| 29 | Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan. | InternationalColorConsortium/ | 183 | — | ~1.5k | Automated safety check: Pass | BSD-3-Clause | today |
| 30 | Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle… | axelixlabs/ | 148 | — | ~4.2k | Automated safety check: Pass | LGPL-3.0 | yesterday |
| 31 | 31.Takeover Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the… | PentesterFlow/ | 1.4k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | 32.Snapshot Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions. | boostsecurityio/ | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 33 | Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch. | cloudposse/ | 1.4k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 34 | Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository. | boostsecurityio/ | 523 | — | ~173 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 35 | Supply-chain security controls for the @cipherstash/stack monorepo. | cipherstash/ | 157 | — | ~5.2k | Automated safety check: Warn | MIT | today |
| 36 | 36.Iss Audit Audit GitHub issues before implementation, including skeptical claim verification, safe reproduction, prompt-injection resistance, malicious-link and attachment handling, root-cause analysis… | akitaonrails/ | 212 | — | ~4.1k | Automated safety check: Pass | No licence | 15 days ago |
| 37 | 37.Web2 Recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis… | awarexone/ | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | 3 days ago |
| 38 | Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. | github/ | 40k | 1 repo | ~3.4k | Automated safety check: Pass | MIT | today |
| 39 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 40 | 40.PR Audit Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation… | akitaonrails/ | 212 | — | ~4.8k | Automated safety check: Pass | No licence | 15 days ago |
| 41 | Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration. | github/ | 5.4k | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 42 | Human review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service. | sickn33/ | 47k | 2 repos | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 43 | 43.Reviewdog Automated code review and security linting integration for CI/CD pipelines using reviewdog. | AgentSecOps/ | 220 | 1 repo | ~3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 44 | Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 45 | Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 46 | Implements secure API key generation with sufficient entropy, server-side hashing (SHA-256/bcrypt) instead of plaintext storage, per-key scoping to endpoints/IPs/rate limits, zero-downtime rotation… | mukul975/ | 34k | — | ~4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 47 | Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 48 | 48.Pii Guard Personally identifiable information (PII) leak prevention for EverClaw. | profbernardoj/ | 112 | — | ~921 | Automated safety check: Pass | MIT | 1 mo ago |