Search
Security · Java
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 893 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 2 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 3 | 当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。 | RuoJi6/ | 1k | — | ~447 | Automated safety check: Pass | No licence | 3 mo ago |
| 4 | Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change. | SonarSource/ | 1.2k | — | ~833 | Automated safety check: Pass | Unknown | today |
| 5 | 5.Maven Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing. | skjolber/ | 568 | — | ~886 | Automated safety check: Pass | Apache-2.0 | today |
| 6 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 4 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 7 | 7.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | today |
| 8 | Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization. | PentesterFlow/ | 1.4k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 9 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 10 | Reverse-engineer missing or incomplete OpenFastTrace system requirements and arc42-style design documentation from a project's user guide, existing documentation, tests, and code. | itsallcode/ | 198 | — | ~2.9k | Automated safety check: Pass | GPL-3.0 | today |
| 11 | Triage Apache Roller security reports, maintain private case tracking, prepare CVE records, coordinate fixes and reporter review, and prepare disclosure with a release. | apache/ | 133 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 12 | A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI… | jabrena/ | 446 | — | ~874 | Automated safety check: Pass | Apache-2.0 | today |
| 13 | 13.Build DB 使用 jar-analyzer-engine 从 JAR/WAR/Class 文件构建 SQLite 分析数据库。这是进行 Java 代码安全审计、方法调用分析的第一步。 | jar-analyzer/ | 141 | — | ~898 | Automated safety check: Pass | No licence | 6 mo ago |
| 14 | Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify… | nvuillam/ | 248 | — | ~1.9k | Automated safety check: Notes | MIT | 4 days ago |
| 15 | A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning… | jabrena/ | 446 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | today |
| 16 | 16.Ssti Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or… | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | 当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是… | zhaji2333/ | 113 | — | ~1.7k | Automated safety check: Pass | MIT | 23 days ago |
| 18 | 18.Crypto Bom Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts… | cdxgen/ | 1.1k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 19 | Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。 | affaan-m/ | 275k | 3 repos | ~1.6k | Automated safety check: Pass | MIT | 3 days ago |
| 20 | 生成安全审计 skill。两种模式:(1) 项目模式——根据项目文档生成定制化审计 skill;(2) 通用模式——仅指定语言+框架,从参考资料库生成通用审计 skill。当用户想创建安全审计 skill、生成审计规则、或提到"生成安全审计skill"、"创建code review skill"、"生成 Java 审计 skill"时使用。 | xwtro0tk1t-cloud/ | 265 | — | ~5.7k | Automated safety check: Pass | No licence | 5 mo ago |
| 21 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 22 | Azure Key Vault Keys Java SDK for cryptographic key management. | microsoft/ | 3.1k | 5 repos | ~2.9k | Automated safety check: Pass | MIT | yesterday |
| 23 | Azure Key Vault Secrets Java SDK for secret management. An agent skill from microsoft/skills. | microsoft/ | 3.1k | 5 repos | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 24 | Insecure deserialization detection and gadget chain exploitation | NeoTheCapt/ | 142 | — | ~836 | Automated safety check: Pass | No licence | 2 mo ago |
| 25 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. | github/ | 40k | 1 repo | ~3.4k | Automated safety check: Pass | MIT | today |
| 27 | 27.Sca Trivy Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license… | AgentSecOps/ | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 28 | Analyze cryptographic code to detect operations that leak secret data through execution timing variations. | sickn33/ | 47k | 2 repos | ~2.4k | Automated safety check: Pass | MIT | today |
| 29 | AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching… | github/ | 40k | 1 repo | ~2.3k | Automated safety check: Notes | MIT | today |
| 30 | Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. | decebals/ | 751 | — | ~3.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 31 | Buenas prácticas de Spring Security para autenticación/autorización, validación, CSRF, secretos, cabeceras, limitación de velocidad y seguridad de dependencias en servicios Java Spring Boot. | affaan-m/ | 275k | — | ~2.1k | Automated safety check: Pass | MIT | 3 days ago |
| 32 | Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination… | mukul975/ | 34k | — | ~620 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 33 | XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. | langbyyi/ | 134 | 1 repo | ~3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 34 | Decompile Java applications (JAR/WAR/APK/class) — extract archives, detect obfuscators, decompile bytecode to source, analyse license logic and secrets. | ptn1411/ | 219 | — | ~788 | Automated safety check: Notes | No licence | 16 days ago |
| 35 | Defensive audit of a license/entitlement/activation mechanism on software you own or are authorized to test. | ptn1411/ | 219 | — | ~1k | Automated safety check: Notes | No licence | 16 days ago |
| 36 | Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy… | mukul975/ | 34k | — | ~754 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Provides AWS Key Management Service (KMS) patterns using AWS SDK for Java 2.x. | giuseppe-trisciuoglio/ | 355 | 1 repo | ~3.6k | Automated safety check: Notes | MIT | 28 days ago |
| 38 | A skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products… | jabrena/ | 446 | — | ~3k | Automated safety check: Pass | Apache-2.0 | today |
| 39 | Scan a source tree for weak cryptographic primitives: MD5 / SHA-1 used for security purposes, DES / 3DES / RC4 ciphers, ECB block mode, custom-built crypto (XOR loops, hand-rolled HMAC), hardcoded… | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 40 | A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing… | jabrena/ | 446 | — | ~885 | Automated safety check: Pass | Apache-2.0 | today |
| 41 | A skill your agent uses when you need to write or review programmatic JDBC with Spring — including JdbcClient (Spring Framework 7+) as the default API, JdbcTemplate only where batch/streaming APIs… | jabrena/ | 446 | — | ~975 | Automated safety check: Pass | Apache-2.0 | today |
| 42 | Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 43 | AI驱动的Java代码安全审计技能,实现系统化、高覆盖率的漏洞挖掘。使用场景: (1) 审计Java/Kotlin项目寻找安全漏洞(0day挖掘、代码审计、安全评估) (2) 企业级代码库的安全审计(支持大型项目) (3) 需要高质量、低幻觉率的安全审计报告 (4) CI/CD集成的前期漏洞发现 触发关键词:Java审计、代码审计、安全审计、漏洞挖掘、0day、安全评估、Java… | LeoYeAI/ | 2.2k | — | ~3.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 44 | 44.Sast Ssti Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user… | utkusen/ | 1.3k | — | ~7.5k | Automated safety check: Pass | MIT | 6 mo ago |
| 45 | 45.Sast Xxe Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 46 | A skill your agent uses when you add or change an endpoint, an auth check, a query by id, an outbound call to a user-supplied URL, file handling, or anything touching credentials — the OWASP API Top… | makifbaysal/ | 109 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 47 | CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式 | wgpsec/ | 1.8k | — | ~1.4k | Automated safety check: Notes | No licence | 4 days ago |
| 48 | 48.Spring AI Diagnose and operate Spring AI projects with version-aware Maven or Gradle checks for ChatClient, advisors, retrieval, conversation memory, tool/MCP boundaries, streaming, configuration, and… | magnus919/ | 113 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |