Search
Security · GitHub · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.Release Cut a new AperiSolve release — bump the version, commit "chore(release): X.Y.Z", tag it, push, and publish a GitHub Release whose notes are computed from the commits since the last tag. | Zeecka/ | 850 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 2 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 3 | Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized. | netdata/ | 81k | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | today |
| 4 | Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING… | MidnightBSD/ | 114 | — | ~2.2k | Automated safety check: Pass | Unknown | 4 days ago |
| 5 | Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs. | eclipse-ankaios/ | 125 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 6 | Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. | vechain/ | 450 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 7 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 8 | A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability… | openclaw/ | 142 | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 9 | Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images. | warpdotdev/ | 65k | 1 repo | ~2.1k | Automated safety check: Pass | AGPL-3.0 | today |
| 10 | 10.Fix Issues A skill your agent uses when fixing compiler warnings, static analyzer findings (clang-tidy, etc.), or runtime errors/crashes in the libYSE codebase. | yvanvds/ | 238 | — | ~3k | Automated safety check: Pass | MIT | 8 days ago |
| 11 | Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe… | openclaw/ | 392k | — | ~13k | Automated safety check: Pass | MIT | today |
| 12 | Creates a new Earl HCL template for a specific API, database, or shell command. | mathematic-inc/ | 113 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 13 | 13.Cve Doctor Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix. | getlago/ | 163 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 14 | Handle confidential GitHub Security Advisory response for Paperclip. | paperclipai/ | 99k | — | ~2k | Automated safety check: Pass | MIT | today |
| 15 | Turn a vulnerability report into a publication-ready GitHub Security Advisory. | frappe/ | 146 | — | ~1.3k | Automated safety check: Pass | No licence | 8 days ago |
| 16 | Find new skills on GitHub or check a specific skill before installing. | khendzel/ | 123 | — | ~1.6k | Automated safety check: Pass | MIT | 8 days ago |
| 17 | 17.Snapshot Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions. | boostsecurityio/ | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 18 | 18.Audit Scope Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. | forefy/ | 152 | — | ~2.3k | Automated safety check: Pass | MIT | 3 days ago |
| 19 | GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL). | secondsky/ | 227 | — | ~4k | Automated safety check: Notes | MIT | 10 days ago |
| 20 | 20.Public Issue File a low-severity finding as an ordinary public GitHub issue after explicit analyst confirmation. | alpha-omega-security/ | 231 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 21 | Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. | sickn33/ | 47k | 2 repos | ~2.1k | Automated safety check: Notes | MIT | today |
| 22 | Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 23 | Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 24 | 24.Analyze Cve Full Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers. | openshift-eng/ | 120 | — | ~2k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 25 | Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows. | IgorWarzocha/ | 122 | — | ~1.2k | Automated safety check: Notes | No licence | 8 mo ago |
| 26 | High-precision Google dorks for exposed configs, secrets, and credentials -- real-world validated | uphiago/ | 1.3k | — | ~1.1k | Automated safety check: Notes | MIT | 1 mo ago |
| 27 | Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. | tobihagemann/ | 407 | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 28 | A skill your agent uses when auditing an authorized website, SaaS, API, AI app, local code path, GitHub repo, staging URL, or owned runtime for security risks, vulnerability checklist scoring… | yaojingang/ | 1.3k | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 29 | 29.Hunter 22 Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw… | aeonfun/ | 767 | — | ~1.7k | Automated safety check: Pass | MIT | today |
| 30 | 30.Re Evasion 检测规避/EDR 对抗分析:AMSI/ETW 绕过、无文件、lolbin 链. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 125 | 1 repo | ~1.6k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 31 | 31.Disclosure Drive responsible disclosure of a proven finding to a CVE. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~686 | Automated safety check: Pass | MIT | 1 mo ago |
| 32 | 32.Fork Stage a scanned repository into a private repo in the configured GitHub organisation. | alpha-omega-security/ | 231 | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 33 | File a finding on the upstream repository through GitHub's private vulnerability reporting, request the temporary private fork, and push the proposed patch to it when available. | alpha-omega-security/ | 231 | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 34 | Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables | Microck/ | 403 | 1 repo | ~2.7k | Automated safety check: Notes | Unknown | 1 mo ago |
| 35 | Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support | Hack23/ | 239 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 36 | Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. | Mathews-Tom/ | 328 | — | ~2.2k | Automated safety check: Pass | MIT | 2 days ago |
| 37 | Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot. | ccplugins/ | 968 | — | ~486 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 38 | Ingest a CVE writeup, blog post, advisory, or GitHub repo into the wiki - fetch, dedup via sources:, update the right technique/tool page(s), re-index. | Encod3d-Sec/ | 329 | — | ~572 | Automated safety check: Pass | MIT | 1 mo ago |
| 39 | A skill your agent uses when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field. | openshift-eng/ | 120 | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 40 | CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100. | revfactory/ | 1.3k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 41 | Find leaked API keys, tokens, and credentials in public GitHub repositories. | uphiago/ | 1.3k | — | ~1.8k | Automated safety check: Warn | MIT | 1 mo ago |
| 42 | GitHub 安全研究方法论:搜索 GitHub 上的免杀/Loader/C2 技术仓库,分析代码模式,提取新技术入库。当知识库中没有针对当前检测环境的免杀技术时使用——先搜索 GitHub 高星仓库,分析代码后写入 evasion-techniques-db.json 或 loader-components-db.json 入库 | wgpsec/ | 1.8k | — | ~432 | Automated safety check: Pass | No licence | 4 days ago |
| 43 | A skill your agent uses when opening or updating a GitHub pull request after Phase 5 of /compliance:analyze-cve has applied and verified a CVE fix locally. | openshift-eng/ | 120 | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 44 | This skill should be used when the user asks to "triage security findings", "fix an Aikido finding", "review Aikido issues", "dismiss a false positive", "check SAST/IaC alerts", or needs to work… | bitwarden/ | 154 | — | ~2.2k | Automated safety check: Pass | Unknown | today |
| 45 | Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. | aiskillstore/ | 430 | — | ~3.2k | Automated safety check: Pass | No licence | yesterday |