Search

Security · Java · For developers

54 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Professional code security audit skill covering 55+ vulnerability types.

3stoneBrother/code-audit8921 repo~2.7kAutomated safety check: PassNo licence7 mo ago
2

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.02 days ago
3

当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。

RuoJi6/audit-skills1k—~447Automated safety check: PassNo licence3 mo ago
4

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

SonarSource/sonar-java1.2k—~833Automated safety check: PassUnknowntoday
5

Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing.

skjolber/3d-bin-container-packing569—~886Automated safety check: PassApache-2.0today
6

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos844—~581Automated safety check: PassApache-2.0today
7

Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

duriantaco/skylos844—~545Automated safety check: PassApache-2.0today
8

Reverse-engineer missing or incomplete OpenFastTrace system requirements and arc42-style design documentation from a project's user guide, existing documentation, tests, and code.

itsallcode/openfasttrace197—~2.9kAutomated safety check: PassGPL-3.0yesterday
9

A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

jabrena/plinth447—~874Automated safety check: PassApache-2.02 days ago
10

使用 jar-analyzer-engine 从 JAR/WAR/Class 文件构建 SQLite 分析数据库。这是进行 Java 代码安全审计、方法调用分析的第一步。

jar-analyzer/jar-analyzer-claude141—~898Automated safety check: PassNo licence6 mo ago
11

Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

nvuillam/npm-groovy-lint248—~1.9kAutomated safety check: NotesMITyesterday
12

A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

jabrena/plinth447—~3.2kAutomated safety check: PassApache-2.02 days ago
13
13.Ssti

Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or…

PentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.01 mo ago
14

当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

zhaji2333/CkSKILLS114—~1.7kAutomated safety check: PassMIT24 days ago
15

Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts…

cdxgen/cdxgen1.1k—~1.4kAutomated safety check: PassApache-2.0yesterday
16

Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。

affaan-m/ECC276k3 repos~1.6kAutomated safety check: PassMIT4 days ago
17

生成安全审计 skill。两种模式:(1) 项目模式——根据项目文档生成定制化审计 skill;(2) 通用模式——仅指定语言+框架,从参考资料库生成通用审计 skill。当用户想创建安全审计 skill、生成审计规则、或提到"生成安全审计skill"、"创建code review skill"、"生成 Java 审计 skill"时使用。

xwtro0tk1t-cloud/harness265—~5.7kAutomated safety check: PassNo licence5 mo ago
18

Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

trailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.02 days ago
19

Azure Key Vault Keys Java SDK for cryptographic key management.

microsoft/skills3.1k5 repos~2.9kAutomated safety check: PassMITtoday
20

Azure Key Vault Secrets Java SDK for secret management. An agent skill from microsoft/skills.

microsoft/skills3.1k5 repos~3.1kAutomated safety check: PassMITtoday
21

Insecure deserialization detection and gadget chain exploitation

NeoTheCapt/RedteamAgent142—~836Automated safety check: PassNo licence2 mo ago
22

Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

dslsdzc/rev-skills130—~2kAutomated safety check: PassApache-2.04 days ago
23

Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

ArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.01 mo ago
24
24.CodeqlOfficial

Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI.

github/awesome-copilot40k1 repo~3.4kAutomated safety check: PassMITtoday
25

Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

AgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassUnknown5 mo ago
26

Analyze cryptographic code to detect operations that leak secret data through execution timing variations.

sickn33/agentic-awesome-skills47k2 repos~2.4kAutomated safety check: PassMITtoday
27
27.Security ReviewOfficial

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

github/awesome-copilot40k1 repo~2.3kAutomated safety check: NotesMITtoday
28

Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding.

decebals/claude-code-java751—~3.7kAutomated safety check: NotesMIT1 mo ago
29

Buenas prácticas de Spring Security para autenticación/autorización, validación, CSRF, secretos, cabeceras, limitación de velocidad y seguridad de dependencias en servicios Java Spring Boot.

affaan-m/ECC276k—~2.1kAutomated safety check: PassMIT4 days ago
30

Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination…

mukul975/Anthropic-Cybersecurity-Skills34k—~620Automated safety check: PassApache-2.01 mo ago
31

XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.

langbyyi/CyberStrikeAI-SRC1351 repo~3kAutomated safety check: PassApache-2.02 days ago
32

Decompile Java applications (JAR/WAR/APK/class) — extract archives, detect obfuscators, decompile bytecode to source, analyse license logic and secrets.

ptn1411/skill220—~788Automated safety check: NotesNo licence17 days ago
33

Defensive audit of a license/entitlement/activation mechanism on software you own or are authorized to test.

ptn1411/skill220—~1kAutomated safety check: NotesNo licence17 days ago
34

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy…

mukul975/Anthropic-Cybersecurity-Skills34k—~754Automated safety check: PassApache-2.01 mo ago
35

A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…

jabrena/plinth447—~885Automated safety check: PassApache-2.02 days ago
36

A skill your agent uses when you need to write or review programmatic JDBC with Spring — including JdbcClient (Spring Framework 7+) as the default API, JdbcTemplate only where batch/streaming APIs…

jabrena/plinth447—~975Automated safety check: PassApache-2.02 days ago
37

Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node.

Encod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT1 mo ago
38

AI驱动的Java代码安全审计技能,实现系统化、高覆盖率的漏洞挖掘。使用场景: (1) 审计Java/Kotlin项目寻找安全漏洞(0day挖掘、代码审计、安全评估) (2) 企业级代码库的安全审计(支持大型项目) (3) 需要高质量、低幻觉率的安全审计报告 (4) CI/CD集成的前期漏洞发现 触发关键词:Java审计、代码审计、安全审计、漏洞挖掘、0day、安全评估、Java…

LeoYeAI/openclaw-master-skills2.2k—~3.1kAutomated safety check: PassMIT2 mo ago
39

Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user…

utkusen/sast-skills1.3k—~7.5kAutomated safety check: PassMIT6 mo ago
40

CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式

wgpsec/AboutSecurity1.8k—~1.4kAutomated safety check: NotesNo licenceyesterday
41

Provides AWS Key Management Service (KMS) patterns using AWS SDK for Java 2.x.

giuseppe-trisciuoglio/developer-kit356—~3.6kAutomated safety check: NotesMIT29 days ago
42

Diagnose and operate Spring AI projects with version-aware Maven or Gradle checks for ChatClient, advisors, retrieval, conversation memory, tool/MCP boundaries, streaming, configuration, and…

magnus919/agent-skills116—~1.2kAutomated safety check: PassMITyesterday
43

Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.

LeoYeAI/openclaw-master-skills2.2k—~5.1kAutomated safety check: PassApache-2.02 mo ago
44

Code vulnerability pattern database. An agent skill from revfactory/harness-100.

revfactory/harness-1001.3k—~1.5kAutomated safety check: PassApache-2.06 mo ago
45

Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills.

dslsdzc/rev-skills130—~1.2kAutomated safety check: PassApache-2.04 days ago
46

当拿到源码、代码片段、反编译产物,或用户要求代码审计时调用。负责输入点→传播链→危险函数Sink的静态审计,跨语言(PHP/Java/Python/Node/Go)危险函数速查,输出可疑调用链与缺陷触发条件。

zhaji2333/CkSKILLS114—~409Automated safety check: PassMIT24 days ago
47

Java 源码认证与配置安全审计。当在 Java 白盒审计中需要检测认证绕过、权限缺陷或安全配置问题时触发. An agent skill from wgpsec/AboutSecurity.

wgpsec/AboutSecurity1.8k—~888Automated safety check: PassNo licenceyesterday
48

Java 框架特定漏洞源码审计。当在 Java 白盒审计中需要检测框架层面的已知漏洞模式时触发. An agent skill from wgpsec/AboutSecurity.

wgpsec/AboutSecurity1.8k—~1.3kAutomated safety check: PassNo licenceyesterday