Search
Security · Linux · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses when the user is designing, prototyping, or rewriting a desktop app that must run on multiple OSes (macOS + Windows, optionally Linux) AND feel indistinguishable from a… | yetone/ | 1.9k | 1 repo | ~1.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 2 | Launch, see and drive a real game so an agent can test its own mods. | rehan-remade/ | 6.5k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 3 | Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills. | aliyun/ | 148 | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 4 | Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。 | aliyun/ | 148 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 5 | Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills. | ljagiello/ | 3.4k | — | ~11k | Automated safety check: Notes | MIT | 27 days ago |
| 6 | Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts… | cdxgen/ | 1.1k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~2.8k | Automated safety check: Notes | MIT | yesterday |
| 8 | Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 9 | SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases. | AgentSecOps/ | 220 | 1 repo | ~4.9k | Automated safety check: Notes | Unknown | 5 mo ago |
| 10 | 10.Bumblebee Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs. | sickn33/ | 47k | 1 repo | ~2.5k | Automated safety check: Notes | MIT | 2 days ago |
| 11 | Detect privilege escalation attempts across Windows and Linux, including access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse. | mukul975/ | 34k | — | ~922 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Detects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry… | mukul975/ | 34k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 14 | Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements. | mukul975/ | 34k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 15 | Configure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks malicious, phishing, and cryptojacking domains via real-time threat intelligence, detects DNS rebinding and CNAME… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 16 | Invoke for 等保2.0 full-lifecycle assessment on corporate networks on Kali Linux: classification, gap analysis, baseline audit, vuln scanning, penetration testing, and compliance reporting per GB/T… | openocta/ | 167 | — | ~6.3k | Automated safety check: Notes | MIT | 3 mo ago |
| 17 | Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. | mukul975/ | 34k | — | ~631 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. | mukul975/ | 34k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 19 | Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 20 | Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 21 | Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images. | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 22 | Analyze Linux, SteamOS, Steam Deck, Wine, or Proton game-security boundaries. | gmh5225/ | 3.6k | — | ~220 | Automated safety check: Pass | MIT | yesterday |
| 23 | Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. | mukul975/ | 34k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 24 | Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 25 | Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification… | kubernetes-sigs/ | 294 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 27 | Run authorized network reconnaissance with Nmap on Windows (or Linux). | ptn1411/ | 219 | — | ~1.4k | Automated safety check: Notes | No licence | 19 days ago |
| 28 | 28.Audit Skills Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~1.6k | Automated safety check: Warn | MIT | 2 days ago |
| 29 | Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 30 | Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.5k | Automated safety check: Pass | MIT | 27 days ago |
| 31 | Systematically map and remove malware, backdoors, and attacker persistence mechanisms (registry Run keys, scheduled tasks, WMI subscriptions, services, cron/init.d) from infected Windows and Linux… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 32 | Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 33 | Provisions, connects, migrates, and operates Amazon RDS for Db2. | aws/ | 2.8k | — | ~6.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 34 | Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures. | cyberful/ | 135 | — | ~637 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 35 | CTF 数字取证与信号分析技术。当挑战提供磁盘镜像(.dd/.E01)、内存 dump(.raw/.vmem)、网络抓包(.pcap/.pcapng)、隐写图片/音频、Windows 事件日志(.evtx)时使用。覆盖 Volatility 内存分析、Wireshark 流量还原、binwalk 隐写提取、文件系统恢复等取证全链路 | wgpsec/ | 1.8k | — | ~878 | Automated safety check: Notes | No licence | yesterday |
| 36 | 36.Log Evasion 日志分析与日志逃逸方法论。理解蓝队如何通过日志追踪攻击行为(SIEM/Event Log/Syslog),以及红队如何规避日志记录或精准清除痕迹。当需要设计无痕操作或分析日志监控覆盖范围时使用 | wgpsec/ | 1.8k | — | ~1.2k | Automated safety check: Pass | No licence | yesterday |
| 37 | ELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 38 | 固件仿真:QEMU 用户态/全系统. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 39 | 硬件接口:JTAG/UART/flash 读取. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 40 | 40.Re Lldb lldb 调试(macOS/iOS):attach、expr、image. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | 6 days ago |
| 41 | 41.Re Nim Nim 编译产物逆向:运行时识别、NimString 结构、异常与 GC 路径. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 42 | 42.Re Stego 隐写术检测与提取:文件尾附加、图片 LSB、音频与其他载体、提取验证. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 43 | 43.Re Tracing 系统调用/函数调用跟踪:strace/ltrace/dtruss. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~940 | Automated safety check: Notes | Apache-2.0 | 6 days ago |
| 44 | 44.Re Arm ARM 架构逆向(非 Android):Cortex-M/A 向量表、Thumb/ARM 切换、AAPCS 调用约定、位置相关代码重定位、MMIO 外设寄存器交叉。 | dslsdzc/ | 135 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 45 | 崩溃/漏洞样本分析:确定性复现、ASAN/UBSAN 报告解读、输入最小化 (afl-tmin/cmin)、gdb 回溯定位、rr 录制重放、PoC 产出。 | dslsdzc/ | 135 | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | 6 days ago |
| 46 | 磁盘/文件系统取证:删除恢复、时间线、可疑文件定位. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 47 | 47.Re Electron Electron 桌面应用逆向:asar 解包、主/渲染进程 JS、V8 字节码(.jsc)边界、CDP 动态调试、反调试对抗。 | dslsdzc/ | 135 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 48 | 固件提取与解包:binwalk/unblob、magic 扫描、字节序. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 135 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 6 days ago |