Search

Security · For developers

1,199 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

eigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0today
2
2.Skill InspectorOfficial

Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

NVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0today
3

A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

jewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT4 mo ago
4

Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

awarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMITtoday
5

Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

pashov/skills1.2k2 repos~11kAutomated safety check: PassMIT3 days ago
6

Guides building Flowsint enrichers and types: where definitions live, how the base class and vault work, and when a new type is warranted.

reconurge/flowsint9.6k—~2.6kAutomated safety check: PassApache-2.06 days ago
7

A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

payloadcms/payload45k—~2.8kAutomated safety check: PassMITtoday
8

Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.

nanocoai/nanoclaw31k—~1.1kAutomated safety check: NotesMIT2 days ago
9

A skill your agent uses when the user is designing, prototyping, or rewriting a desktop app that must run on multiple OSes (macOS + Windows, optionally Linux) AND feel indistinguishable from a…

yetone/native-feel-skill1.9k1 repo~1.5kAutomated safety check: PassMIT4 mo ago
10

Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.

microsoft/onnxruntime22k—~3.3kAutomated safety check: PassMITtoday
11

Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.

vercel-labs/deepsec8.1k—~1.2kAutomated safety check: PassApache-2.010 days ago
12

Professional code security audit skill covering 55+ vulnerability types.

3stoneBrother/code-audit8921 repo~2.7kAutomated safety check: PassNo licence7 mo ago
13

Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

usestrix/strix67k—~1.5kAutomated safety check: PassApache-2.0today
14

Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

webhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0yesterday
15

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0yesterday
16

Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

vercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.010 days ago
17

Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

lingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT2 mo ago
18

Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…

pashov/skills1.2k1 repo~10kAutomated safety check: PassMIT3 days ago
19

Creates a Phorge code review diff for the current branch with arc diff, while applying public-repo confidentiality rules since Phorge content later lands verbatim on the public GitHub repo.

yugabyte/yugabyte-db11k—~3.1kAutomated safety check: PassUnknowntoday
20
20.CodeqlOfficial

Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.

elastic/kibana21k—~1.7kAutomated safety check: PassUnknowntoday
21

Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core…

digoal/blog8.6k—~4kAutomated safety check: PassGPL-2.0today
22

Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

trailofbits/skills7.4k—~1.7kAutomated safety check: PassCC-BY-SA-4.0yesterday
23

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknowntoday
24

当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。

RuoJi6/audit-skills1k—~447Automated safety check: PassNo licence3 mo ago
25

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

ruvnet/ruflo74k2 repos~823Automated safety check: PassMITtoday
26

Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

pashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT3 days ago
27

A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

zhaoxuya520/reverse-skill40k4 repos~953Automated safety check: WarnMIT17 days ago
28

A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

vulnersCom/api376—~2.3kAutomated safety check: PassMIT10 days ago
29

Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter).

symfony/symfony31k—~2.6kAutomated safety check: PassMITtoday
30

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

trailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.0yesterday
31

A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

solana-foundation/solana-dev-skill574—~3.8kAutomated safety check: PassMITtoday
32

Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

samugit83/redamon3k—~775Automated safety check: PassMITtoday
33

Polymarket integration for prediction market trading on Polygon.

Polymarket/agent-skills1911 repo~2kAutomated safety check: PassNo licence7 mo ago
34

Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

luongnv89/claude-howto42k—~764Automated safety check: PassMIT8 days ago
35

Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

mono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMITtoday
36

Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.

wuyoscar/AISafetyHot-Hub641—~1.4kAutomated safety check: PassUnknowntoday
37

A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

asyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.04 days ago
38

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

SonarSource/sonar-java1.2k—~833Automated safety check: PassUnknowntoday
39

Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.

symfony/symfony31k—~2.9kAutomated safety check: PassMITtoday
40

Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing.

skjolber/3d-bin-container-packing569—~886Automated safety check: PassApache-2.0today
41

Launch, see and drive a real game so an agent can test its own mods.

rehan-remade/universal-modder5.8k—~1.9kAutomated safety check: PassMITtoday
42

Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

ZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMITtoday
43

Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

verdaccio/verdaccio18k—~853Automated safety check: PassMITtoday
44

Ensure that C and C++/CLI types are documented with XML comments and follow best practices for documentation.

MichaelGrafnetter/DSInternals2k—~1.2kAutomated safety check: PassMIT27 days ago
45

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos844—~581Automated safety check: PassApache-2.0today
46

Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

tech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0today
47

Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

LukasNiessen/kubernetes-skill446—~1.2kAutomated safety check: PassMIT26 days ago
48

Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.

context-labs/whip1.1k2 repos~3kAutomated safety check: PassMIT4 days ago