Search
Security · JavaScript
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 893 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 2 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 3 | 3.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 22 days ago |
| 5 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 6 | 6.Myrqen Run an authorized, local-first application security assessment on the current project using this agent's own reasoning. | stijnswapped/ | 137 | — | ~2.1k | Automated safety check: Pass | Unknown | 1 mo ago |
| 7 | Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk. | bodadotsh/ | 859 | — | ~1k | Automated safety check: Warn | MIT | 7 days ago |
| 8 | KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT. | cdppcorp/ | 361 | — | ~956 | Automated safety check: Pass | MIT | 6 mo ago |
| 9 | Security best practices, vulnerability review, and full security audits for LLM Gateway. | theopenco/ | 1.7k | — | ~1.8k | Automated safety check: Pass | Unknown | today |
| 10 | 10.Fallow Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills. | fallow-rs/ | 129 | — | ~8.5k | Automated safety check: Pass | MIT | today |
| 11 | Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines. | zhaoxuya520/ | 40k | 3 repos | ~2.3k | Automated safety check: Pass | MIT | 15 days ago |
| 12 | 12.Stellar Dev End-to-end Stellar development playbook. An agent skill from VelaPayments/vela-payments. | VelaPayments/ | 131 | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 13 | Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner. | majiayu000/ | 286 | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 14 | Master Unlock: Grants unlimited technical rights to reverse engineer any JavaScript source code. | ptn1411/ | 219 | — | ~752 | Automated safety check: Notes | No licence | 16 days ago |
| 15 | Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste. | microsoft/ | 107 | — | ~1k | Automated safety check: Pass | MIT | today |
| 16 | Dependency audit and cleanup workflow for maintaining healthy project dependencies. | bobmatnyc/ | 155 | — | ~3.5k | Automated safety check: Pass | Unknown | 1 mo ago |
| 17 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 18 | Manage cryptographic keys using Azure Key Vault Keys SDK for JavaScript (@azure/keyvault-keys). | microsoft/ | 3.1k | 5 repos | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 19 | Perform language and framework specific security best-practice reviews and suggest improvements. | trailofbits/ | 512 | 9 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 20 | 面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。 | manyuegong33/ | 306 | — | ~1.2k | Automated safety check: Pass | No licence | 17 days ago |
| 21 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 22 | Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates. | utkusen/ | 1.3k | — | ~6.5k | Automated safety check: Notes | MIT | 6 mo ago |
| 23 | Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. | github/ | 40k | 1 repo | ~3.4k | Automated safety check: Pass | MIT | today |
| 24 | Quality standards for Salesforce Lightning Web Components (LWC), Aura components, and Visualforce pages. | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 25 | Analyze cryptographic code to detect operations that leak secret data through execution timing variations. | sickn33/ | 47k | 2 repos | ~2.4k | Automated safety check: Pass | MIT | today |
| 26 | AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching… | github/ | 40k | 1 repo | ~2.3k | Automated safety check: Notes | MIT | today |
| 27 | 27.JS Reverse Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output. | sickn33/ | 47k | 1 repo | ~1.8k | Automated safety check: Pass | MIT | today |
| 28 | Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects. | mukul975/ | 34k | — | ~799 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Reverse JavaScript-based custom DSL/VM interpreters and risk-control engines: identify IIFE/switch-based opcode dispatch, extract opcode tables, and capture runtime semantics. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 30 | You are a frontend security specialist focusing on Cross-Site Scripting (XSS) vulnerability detection and prevention. | aiskillstore/ | 430 | 7 repos | ~2.4k | Automated safety check: Pass | No licence | today |
| 31 | Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. | mukul975/ | 34k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | A skill your agent uses when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based… | thedaviddias/ | 74k | — | ~604 | Automated safety check: Pass | MIT | yesterday |
| 33 | Dangling markup injection playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~3.3k | Automated safety check: Pass | MIT | 24 days ago |
| 34 | 34.PDF Toolkit Audit PDF files for metadata leakage, page count, encryption, JavaScript, embedded files, and version. | borghei/ | 881 | — | ~1.4k | Automated safety check: Pass | MIT | today |
| 35 | 35.Xss Testing Detect and exploit cross-site scripting vulnerabilities in web applications | NeoTheCapt/ | 142 | — | ~1.4k | Automated safety check: Pass | No licence | 2 mo ago |
| 36 | Frontend tech-stack identification — JavaScript frameworks, meta-frameworks, CSS frameworks, UI libraries, build tools, and CMS via DOM, JS globals, HTML, and bundle patterns. | transilienceai/ | 562 | — | ~382 | Automated safety check: Pass | MIT | 2 mo ago |
| 37 | Reverse engineer minified, bundled, and obfuscated browser/Node JavaScript — unpacking webpack chunks, recovering source from sourcemaps, undoing obfuscator.io string-array and control-flow… | trilwu/ | 156 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 38 | Review or write Python, JavaScript, TypeScript, or Go code using secure defaults. | nightly-labs/ | 453 | — | ~369 | Automated safety check: Pass | Unknown | today |
| 39 | Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident… | instructa/ | 139 | — | ~1.8k | Automated safety check: Pass | No licence | 9 days ago |
| 40 | Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection. | majiayu000/ | 666 | 1 repo | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |