Search

Security · Java

64 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Professional code security audit skill covering 55+ vulnerability types.

3stoneBrother/code-audit8931 repo~2.7kAutomated safety check: PassNo licence7 mo ago
2

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0today
3

当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。

RuoJi6/audit-skills1k—~447Automated safety check: PassNo licence3 mo ago
4

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

SonarSource/sonar-java1.2k—~833Automated safety check: PassUnknowntoday
5

Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing.

skjolber/3d-bin-container-packing568—~886Automated safety check: PassApache-2.0today
6

Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

trailofbits/skills7.4k4 repos~4.2kAutomated safety check: NotesCC-BY-SA-4.0today
7

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~581Automated safety check: PassApache-2.0today
8

Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.

PentesterFlow/agent1.4k—~1.7kAutomated safety check: PassApache-2.01 mo ago
9

Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~545Automated safety check: PassApache-2.0today
10

Reverse-engineer missing or incomplete OpenFastTrace system requirements and arc42-style design documentation from a project's user guide, existing documentation, tests, and code.

itsallcode/openfasttrace198—~2.9kAutomated safety check: PassGPL-3.0today
11

Triage Apache Roller security reports, maintain private case tracking, prepare CVE records, coordinate fixes and reporter review, and prepare disclosure with a release.

apache/roller133—~1.9kAutomated safety check: PassApache-2.0today
12

A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

jabrena/plinth446—~874Automated safety check: PassApache-2.0today
13

使用 jar-analyzer-engine 从 JAR/WAR/Class 文件构建 SQLite 分析数据库。这是进行 Java 代码安全审计、方法调用分析的第一步。

jar-analyzer/jar-analyzer-claude141—~898Automated safety check: PassNo licence6 mo ago
14

Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

nvuillam/npm-groovy-lint248—~1.9kAutomated safety check: NotesMIT4 days ago
15

A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

jabrena/plinth446—~3.2kAutomated safety check: PassApache-2.0today
16
16.Ssti

Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or…

PentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.01 mo ago
17

当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

zhaji2333/CkSKILLS113—~1.7kAutomated safety check: PassMIT23 days ago
18

Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts…

cdxgen/cdxgen1.1k—~1.4kAutomated safety check: PassApache-2.0today
19

Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。

affaan-m/ECC275k3 repos~1.6kAutomated safety check: PassMIT3 days ago
20

生成安全审计 skill。两种模式:(1) 项目模式——根据项目文档生成定制化审计 skill;(2) 通用模式——仅指定语言+框架,从参考资料库生成通用审计 skill。当用户想创建安全审计 skill、生成审计规则、或提到"生成安全审计skill"、"创建code review skill"、"生成 Java 审计 skill"时使用。

xwtro0tk1t-cloud/harness265—~5.7kAutomated safety check: PassNo licence5 mo ago
21

Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

trailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0today
22

Azure Key Vault Keys Java SDK for cryptographic key management.

microsoft/skills3.1k5 repos~2.9kAutomated safety check: PassMITyesterday
23

Azure Key Vault Secrets Java SDK for secret management. An agent skill from microsoft/skills.

microsoft/skills3.1k5 repos~3.1kAutomated safety check: PassMITyesterday
24

Insecure deserialization detection and gadget chain exploitation

NeoTheCapt/RedteamAgent142—~836Automated safety check: PassNo licence2 mo ago
25

Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

ArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.01 mo ago
26
26.CodeqlOfficial

Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI.

github/awesome-copilot40k1 repo~3.4kAutomated safety check: PassMITtoday
27

Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

AgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassUnknown5 mo ago
28

Analyze cryptographic code to detect operations that leak secret data through execution timing variations.

sickn33/agentic-awesome-skills47k2 repos~2.4kAutomated safety check: PassMITtoday
29
29.Security ReviewOfficial

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

github/awesome-copilot40k1 repo~2.3kAutomated safety check: NotesMITtoday
30

Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding.

decebals/claude-code-java751—~3.7kAutomated safety check: NotesMIT1 mo ago
31

Buenas prácticas de Spring Security para autenticación/autorización, validación, CSRF, secretos, cabeceras, limitación de velocidad y seguridad de dependencias en servicios Java Spring Boot.

affaan-m/ECC275k—~2.1kAutomated safety check: PassMIT3 days ago
32

Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination…

mukul975/Anthropic-Cybersecurity-Skills34k—~620Automated safety check: PassApache-2.01 mo ago
33

XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.

langbyyi/CyberStrikeAI-SRC1341 repo~3kAutomated safety check: PassApache-2.0yesterday
34

Decompile Java applications (JAR/WAR/APK/class) — extract archives, detect obfuscators, decompile bytecode to source, analyse license logic and secrets.

ptn1411/skill219—~788Automated safety check: NotesNo licence16 days ago
35

Defensive audit of a license/entitlement/activation mechanism on software you own or are authorized to test.

ptn1411/skill219—~1kAutomated safety check: NotesNo licence16 days ago
36

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy…

mukul975/Anthropic-Cybersecurity-Skills34k—~754Automated safety check: PassApache-2.01 mo ago
37

Provides AWS Key Management Service (KMS) patterns using AWS SDK for Java 2.x.

giuseppe-trisciuoglio/developer-kit3551 repo~3.6kAutomated safety check: NotesMIT28 days ago
38

A skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products…

jabrena/plinth446—~3kAutomated safety check: PassApache-2.0today
39

Scan a source tree for weak cryptographic primitives: MD5 / SHA-1 used for security purposes, DES / 3DES / RC4 ciphers, ECB block mode, custom-built crypto (XOR loops, hand-rolled HMAC), hardcoded…

jeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMITtoday
40

A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…

jabrena/plinth446—~885Automated safety check: PassApache-2.0today
41

A skill your agent uses when you need to write or review programmatic JDBC with Spring — including JdbcClient (Spring Framework 7+) as the default API, JdbcTemplate only where batch/streaming APIs…

jabrena/plinth446—~975Automated safety check: PassApache-2.0today
42

Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node.

Encod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT1 mo ago
43

AI驱动的Java代码安全审计技能,实现系统化、高覆盖率的漏洞挖掘。使用场景: (1) 审计Java/Kotlin项目寻找安全漏洞(0day挖掘、代码审计、安全评估) (2) 企业级代码库的安全审计(支持大型项目) (3) 需要高质量、低幻觉率的安全审计报告 (4) CI/CD集成的前期漏洞发现 触发关键词:Java审计、代码审计、安全审计、漏洞挖掘、0day、安全评估、Java…

LeoYeAI/openclaw-master-skills2.2k—~3.1kAutomated safety check: PassMIT2 mo ago
44

Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user…

utkusen/sast-skills1.3k—~7.5kAutomated safety check: PassMIT6 mo ago
45

Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to…

utkusen/sast-skills1.3k—~7.2kAutomated safety check: PassMIT6 mo ago
46

A skill your agent uses when you add or change an endpoint, an auth check, a query by id, an outbound call to a user-supplied URL, file handling, or anything touching credentials — the OWASP API Top…

makifbaysal/tasktrooper109—~1.6kAutomated safety check: PassApache-2.0today
47

CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式

wgpsec/AboutSecurity1.8k—~1.4kAutomated safety check: NotesNo licence4 days ago
48

Diagnose and operate Spring AI projects with version-aware Maven or Gradle checks for ChatClient, advisors, retrieval, conversation memory, tool/MCP boundaries, streaming, configuration, and…

magnus919/agent-skills113—~1.2kAutomated safety check: PassMITyesterday