Search
Security · SQL
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 424 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 2 | 渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。 | Arenbai/ | 251 | — | ~1.8k | Automated safety check: Notes | MIT | 10 days ago |
| 3 | PHP Web 全链路白盒代码安全审计流水线(多文件版编排)。作为总编排参考,按 Sink 类型调用各子审计 skill(php-route-mapper/php-auth-audit/php-route-tracer/php--audit),并复用统一输出与分级标准。 | 0xShe/ | 402 | 1 repo | ~4.9k | Automated safety check: Pass | No licence | 6 mo ago |
| 4 | 对 jar-analyzer-engine 构建的 SQLite 数据库执行安全审计分析查询。支持方法调用搜索、调用链追踪、Spring 组件分析、字符串搜索、漏洞模式检测等。 | jar-analyzer/ | 141 | — | ~2.5k | Automated safety check: Pass | No licence | 6 mo ago |
| 5 | A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code… | ProgrammerAnthony/ | 235 | — | ~1.6k | Automated safety check: Pass | MIT | 5 mo ago |
| 6 | CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。 | 0xShe/ | 402 | 1 repo | ~477 | Automated safety check: Pass | No licence | 6 mo ago |
| 7 | A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. | AratKruglik/ | 155 | 1 repo | ~1.1k | Automated safety check: Notes | No licence | 5 mo ago |
| 8 | Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura. | liuyanghejerry/ | 204 | — | ~164 | Automated safety check: Pass | MIT | 10 days ago |
| 9 | TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura. | liuyanghejerry/ | 204 | — | ~166 | Automated safety check: Pass | MIT | 10 days ago |
| 10 | SCA 漏洞 AI 降噪与风险优先级评估。对 Grype/Snyk/Xray 等 SCA 工具的漏洞发现进行多维度风险评估,按 P0-P3 分级,过滤噪音(DoS、本地提权、低影响信息泄露),聚焦真正可利用的高风险漏洞。当用户需要对 SCA 扫描结果降噪、漏洞优先级排序、或供应链风险评估时使用。 | xwtro0tk1t-cloud/ | 265 | — | ~787 | Automated safety check: Pass | No licence | 5 mo ago |
| 11 | Django 安全最佳实践、认证、授权、CSRF 防护、SQL 注入预防、XSS 预防和安全部署配置. An agent skill from affaan-m/ECC. | affaan-m/ | 276k | 3 repos | ~3.7k | Automated safety check: Notes | MIT | 4 days ago |
| 12 | 在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。 | affaan-m/ | 276k | 3 repos | ~2.5k | Automated safety check: Notes | MIT | 4 days ago |
| 13 | Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 14 | 14.Web Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用. An agent skill from MuWinds/BUUCTF_Agent. | MuWinds/ | 267 | — | ~463 | Automated safety check: Pass | Apache-2.0 | today |
| 15 | Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults. | Aedelon/ | 120 | — | ~1.6k | Automated safety check: Notes | Unknown | 7 mo ago |
| 16 | Review Django security audit patterns for settings and middleware. | IgorWarzocha/ | 122 | — | ~1.6k | Automated safety check: Notes | No licence | 8 mo ago |
| 17 | 認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。 | affaan-m/ | 276k | 2 repos | ~2.5k | Automated safety check: Notes | MIT | 4 days ago |
| 18 | 18.Web Sqli SQL injection detection→exploitation→proof for web apps and APIs. | s0ld13rr/ | 828 | — | ~710 | Automated safety check: Pass | MIT | 7 days ago |
| 19 | 19.Rust Review Rust 服务审查:panic、SQL 注入、密钥、错误吞没、遗留标记 | liuyanghejerry/ | 204 | — | ~180 | Automated safety check: Pass | MIT | 10 days ago |
| 20 | Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle). | totvs/ | 143 | — | ~3.5k | Automated safety check: Pass | MIT | 4 days ago |
| 21 | 全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -… | staruhub/ | 727 | — | ~1.3k | Automated safety check: Notes | MIT | 1 mo ago |
| 22 | SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases. | AgentSecOps/ | 220 | 1 repo | ~4.9k | Automated safety check: Notes | Unknown | 5 mo ago |
| 23 | Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory… | unxed/ | 241 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | today |
| 24 | Admin account register: system, main and backup admin, seats, plan, 2FA, shared logins and access-review dates, as CSV, SQL, JSON Schema or Notion on request. | sickn33/ | 47k | 1 repo | ~4.2k | Automated safety check: Pass | MIT | today |
| 25 | Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | 检查 SQL 注入、XSS、硬编码密钥 | liuyanghejerry/ | 204 | — | ~106 | Automated safety check: Pass | MIT | 10 days ago |
| 27 | Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents or AWS Athena SQL over S3-delivered logs, filtering on suspicious user agents, source IPs, and event names to… | mukul975/ | 34k | — | ~845 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Cross-chain relayer bridge audit register: message hash verifications, replay protection nonces, validator quorum, and withdrawal proofs. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Pass | MIT | today |
| 31 | Soroban smart contract security audit register: authorization checks, panic pathways, integer overflows, and storage footprint verification for Stellar. | sickn33/ | 47k | 1 repo | ~1.4k | Automated safety check: Pass | MIT | today |
| 32 | Automated market maker liquidity pool register: constant-product invariant curves, swap fee tiers, and LP token shares for Soroban DeFi. | sickn33/ | 47k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | today |
| 33 | DeFi price oracle integration and safety audit register: heartbeat bounds, stale price threshold reversion, and TWAP medianizer validation. | sickn33/ | 47k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | today |
| 34 | Soroban ledger state rent and TTL extension register: live state tracking, bump thresholds, rent fee reserves, and archive boundaries. | sickn33/ | 47k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | today |
| 35 | Soroban SEP-41 token contract architecture register: admin control, supply caps, metadata standard, and transfer event emissions on Stellar. | sickn33/ | 47k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | today |
| 36 | Zero-knowledge cryptographic verification pipeline register: proving system, circuit verification keys, public inputs, and gas costs. | sickn33/ | 47k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | today |
| 37 | ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。 | 0xShe/ | 402 | 1 repo | ~779 | Automated safety check: Pass | No licence | 6 mo ago |
| 38 | WordPress 框架特效安全审计工具。针对 WordPress 常见 nonce/capability/checkadminreferer、AJAX action、escape/sanitize、重定向、安全上传与远程请求等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/SQL/CFG/SSRF 等)。 | 0xShe/ | 402 | 1 repo | ~666 | Automated safety check: Pass | No licence | 6 mo ago |
| 39 | Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles. | affaan-m/ | 276k | — | ~3.4k | Automated safety check: Notes | MIT | 4 days ago |
| 40 | 当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。 | zhaji2333/ | 114 | — | ~688 | Automated safety check: Warn | MIT | 24 days ago |
| 41 | Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 42 | Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills. | uphiago/ | 1.3k | — | ~3.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 43 | Mass scan for exposed env files, backups, and git configs. An agent skill from uphiago/recon-skills. | uphiago/ | 1.3k | — | ~2.2k | Automated safety check: Notes | MIT | 1 mo ago |
| 44 | 44.SQL Security SQL injection screening for host code (MoonBit / TS / Rust) plus secretlint setup notes. | mizchi/ | 359 | — | ~1.4k | Automated safety check: Pass | No licence | 7 days ago |
| 45 | Detect and analyze SQL injection vulnerabilities in application code and database queries. | jeremylongshore/ | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | today |
| 46 | A skill your agent uses when handling database errors in Frappe/ERPNext. | Impertio-Studio/ | 188 | — | ~3.9k | Automated safety check: Pass | MIT | 22 days ago |
| 47 | A skill your agent uses when code touches user input, tokens, redirects, raw SQL, or logging — injection, XSS, atom exhaustion, timing attacks, audit tooling. | j-morgan6/ | 166 | — | ~2k | Automated safety check: Pass | MIT | 3 mo ago |
| 48 | 48.Sast Sqli Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |