Search

Security · GitHub · For developers

81 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1
1.CodeqlOfficial

Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.

elastic/kibana21k—~1.7kAutomated safety check: PassUnknowntoday
2

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknownyesterday
3

A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

zhaoxuya520/reverse-skill40k4 repos~953Automated safety check: WarnMIT16 days ago
4

A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

asyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.03 days ago
5

Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.

symfony/symfony31k—~2.9kAutomated safety check: PassMITyesterday
6

Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

verdaccio/verdaccio18k—~853Automated safety check: PassMIT2 days ago
7

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

ParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0yesterday
8

Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

EpicenterHQ/epicenter4.8k—~896Automated safety check: PassUnknowntoday
9

Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation.

obot-platform/obot1.1k—~1.3kAutomated safety check: PassMITtoday
10
10.ReviewOfficial

Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the…

getsentry/sentry-react-native1.8k—~1.9kAutomated safety check: PassMITtoday
11

Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.

openplayerjs/openplayerjs649—~1kAutomated safety check: PassMIT3 days ago
12

Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.

slowmist/slowmist-agent-security508—~1.4kAutomated safety check: PassMIT5 mo ago
13

Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

RaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0today
14

Run a security scan on the kedro-plugins codebase or a pull request.

kedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.0yesterday
15

Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

Tommy-yw/RunbookHermes5463 repos~5kAutomated safety check: PassMIT4 mo ago
16
16.Handle CveOfficial

A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR.

DataDog/dd-trace-rb417—~2.6kAutomated safety check: PassUnknowntoday
17

Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

nanocoai/nanoclaw31k1 repo~856Automated safety check: PassMIT2 days ago
18

Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

vechain/x-app-template450—~1.2kAutomated safety check: PassMIT2 mo ago
19

Deep EVM smart contract security audit system. An agent skill from austintgriffith/ethskills.

austintgriffith/ethskills294—~829Automated safety check: PassNo licence1 mo ago
20
20.Docs

Update project documentation when features are added or changed.

boostsecurityio/poutine523—~336Automated safety check: PassApache-2.02 days ago
21

Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

trailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
22

Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

AgriciDaniel/claude-cybersecurity227—~11kAutomated safety check: WarnMIT5 mo ago
23
23.CoreOfficial

Status-first routing, bounded evidence collection, and safety guidance for issue-graph.

vercel-labs/issue-graph125—~2.6kAutomated safety check: PassApache-2.07 days ago
24

Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe…

openclaw/openclaw392k—~13kAutomated safety check: PassMITtoday
25

Creates a new Earl HCL template for a specific API, database, or shell command.

mathematic-inc/earl113—~2.8kAutomated safety check: PassApache-2.02 days ago
26

Perform a requested security review of a NemoClaw PR or a PR linked to an issue.

NVIDIA/NemoClaw23k—~1.1kAutomated safety check: PassApache-2.0today
27
27.Keel

A skill your agent uses for ANY new software project from idea to release — websites, WordPress/WooCommerce plugins, MCP servers, web apps, components, or libraries.

joseconti/declaracion-renta-espana190—~11kAutomated safety check: WarnGPL-3.0-or-later2 mo ago
28

Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works.

nanocoai/nanoclaw31k1 repo~598Automated safety check: PassMIT2 days ago
29

Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

InternationalColorConsortium/iccDEV183—~1.5kAutomated safety check: PassBSD-3-Clausetoday
30

Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

axelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0yesterday
31

Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the…

PentesterFlow/agent1.4k—~3.3kAutomated safety check: PassApache-2.01 mo ago
32

Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

boostsecurityio/poutine523—~214Automated safety check: PassApache-2.02 days ago
33

Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch.

cloudposse/atmos1.4k—~1.3kAutomated safety check: PassApache-2.0today
34

Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.

boostsecurityio/poutine523—~173Automated safety check: PassApache-2.02 days ago
35

Supply-chain security controls for the @cipherstash/stack monorepo.

cipherstash/stack157—~5.2kAutomated safety check: WarnMITtoday
36

Audit GitHub issues before implementation, including skeptical claim verification, safe reproduction, prompt-injection resistance, malicious-link and attachment handling, root-cause analysis…

akitaonrails/my-skills212—~4.1kAutomated safety check: PassNo licence15 days ago
37

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

awarexone/Agentic-Bug-Hunter5.3k2 repos~6.4kAutomated safety check: WarnMIT3 days ago
38
38.CodeqlOfficial

Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI.

github/awesome-copilot40k1 repo~3.4kAutomated safety check: PassMITtoday
39

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

github/awesome-copilot40k1 repo~2.4kAutomated safety check: PassMITtoday
40

Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation…

akitaonrails/my-skills212—~4.8kAutomated safety check: PassNo licence15 days ago
41

Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration.

github/gh-aw5.4k—~2.8kAutomated safety check: PassMITtoday
42

Human review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service.

sickn33/agentic-awesome-skills47k2 repos~1.1kAutomated safety check: PassMITyesterday
43

Automated code review and security linting integration for CI/CD pipelines using reviewdog.

AgentSecOps/SecOpsAgentKit2201 repo~3kAutomated safety check: PassUnknown5 mo ago
44

Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
45

Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
46

Implements secure API key generation with sufficient entropy, server-side hashing (SHA-256/bcrypt) instead of plaintext storage, per-key scoping to endpoints/IPs/rate limits, zero-downtime rotation…

mukul975/Anthropic-Cybersecurity-Skills34k—~4kAutomated safety check: PassApache-2.01 mo ago
47

Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.01 mo ago
48

Personally identifiable information (PII) leak prevention for EverClaw.

profbernardoj/everclaw-community-branches112—~921Automated safety check: PassMIT1 mo ago