Search
Security · Node.js
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 2 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 24 days ago |
| 3 | A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a… | LIDR-academy/ | 278 | — | ~4.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 4 | Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus. | bugbountywithmarco/ | 122 | — | ~524 | Automated safety check: Pass | No licence | 2 mo ago |
| 5 | A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance. | jellydn/ | 123 | — | ~2.9k | Automated safety check: Notes | MIT | today |
| 6 | Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 7 | Zero friction. An agent skill from HKUDS/CLI-Anything. | HKUDS/ | 52k | — | ~360 | Automated safety check: Pass | Apache-2.0 | 17 days ago |
| 8 | Periodic dependency review for Node.js/pnpm projects — outdated package triage, security audit, update batching strategy (patch/minor/major), validation checklist. | mizchi/ | 359 | — | ~1.8k | Automated safety check: Pass | No licence | 7 days ago |
| 9 | Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.5k | Automated safety check: Notes | MIT | today |
| 10 | 10.Sast Ssti Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user… | utkusen/ | 1.3k | — | ~7.5k | Automated safety check: Pass | MIT | 6 mo ago |
| 11 | Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust. | borghei/ | 886 | — | ~1.8k | Automated safety check: Pass | MIT | 2 days ago |
| 12 | OpenClaw 多模式安全巡检工具:默认本地离线扫描,可选联网威胁情报上报. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~2.5k | Automated safety check: Notes | MIT | 2 mo ago |
| 13 | Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills. | jwynia/ | 169 | — | ~1.7k | Automated safety check: Pass | MIT | 7 mo ago |
| 14 | CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式 | wgpsec/ | 1.8k | — | ~1.4k | Automated safety check: Notes | No licence | today |
| 15 | Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. | giuseppe-trisciuoglio/ | 356 | — | ~2.4k | Automated safety check: Notes | MIT | 29 days ago |
| 16 | XSS attack prevention with input sanitization, output encoding, Content Security Policy. | secondsky/ | 227 | — | ~1.5k | Automated safety check: Pass | MIT | 11 days ago |
| 17 | 17.Re Electron Electron 桌面应用逆向:asar 解包、主/渲染进程 JS、V8 字节码(.jsc)边界、CDP 动态调试、反调试对抗。 | dslsdzc/ | 130 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 18 | 容器安全CVE漏洞修复验证引擎。从容器漏扫报告(Excel)自动提取漏洞,生成修复计划, SSH到测试环境验证OS包(apt/yum/apk)、Python(pip)、Node.js(npm)、Java(JAR)四种包类型的 修复方案,产出修复验证报告。不涉及主机层漏洞修复、不处理容器编排层安全配置。 | infometa/ | 346 | — | ~779 | Automated safety check: Notes | Apache-2.0 | today |