Search
Security · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist. | eigent-ai/ | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | today |
| 2 | Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT. | NVIDIA/ | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 3 | A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. | jewbetcha/ | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 4 | Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns. | awarexone/ | 5.3k | 3 repos | ~4.5k | Automated safety check: Pass | MIT | today |
| 5 | 5.Fizz Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects. | pashov/ | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | 3 days ago |
| 6 | Guides building Flowsint enrichers and types: where definitions live, how the base class and vault work, and when a new type is warranted. | reconurge/ | 9.6k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 7 | A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails | payloadcms/ | 45k | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 8 | Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script. | nanocoai/ | 31k | — | ~1.1k | Automated safety check: Notes | MIT | 2 days ago |
| 9 | A skill your agent uses when the user is designing, prototyping, or rewriting a desktop app that must run on multiple OSes (macOS + Windows, optionally Linux) AND feel indistinguishable from a… | yetone/ | 1.9k | 1 repo | ~1.5k | Automated safety check: Pass | MIT | 4 mo ago |
| 10 | Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs. | microsoft/ | 22k | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 11 | Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation. | vercel-labs/ | 8.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 12 | 12.Code Audit Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 892 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 13 | Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works. | usestrix/ | 67k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 14 | Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages. | webhtv/ | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | yesterday |
| 15 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 16 | Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner. | vercel-labs/ | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 17 | 17.Reverse Flow Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts. | lingbol088-spec/ | 940 | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 18 | 18.X Ray Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)… | pashov/ | 1.2k | 1 repo | ~10k | Automated safety check: Pass | MIT | 3 days ago |
| 19 | Creates a Phorge code review diff for the current branch with arc diff, while applying public-repo confidentiality rules since Phorge content later lands verbatim on the public GitHub repo. | yugabyte/ | 11k | — | ~3.1k | Automated safety check: Pass | Unknown | today |
| 20 | Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments. | elastic/ | 21k | — | ~1.7k | Automated safety check: Pass | Unknown | today |
| 21 | Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core… | digoal/ | 8.6k | — | ~4k | Automated safety check: Pass | GPL-2.0 | today |
| 22 | Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows. | trailofbits/ | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 23 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | today |
| 24 | 24.Audit Skills 当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。 | RuoJi6/ | 1k | — | ~447 | Automated safety check: Pass | No licence | 3 mo ago |
| 25 | Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report. | ruvnet/ | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | today |
| 26 | 26.Fizz Convert Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes. | pashov/ | 1.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 3 days ago |
| 27 | A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability. | zhaoxuya520/ | 40k | 4 repos | ~953 | Automated safety check: Warn | MIT | 17 days ago |
| 28 | A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK. | vulnersCom/ | 376 | — | ~2.3k | Automated safety check: Pass | MIT | 10 days ago |
| 29 | Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter). | symfony/ | 31k | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 30 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 31 | 31.Solana Dev A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my… | solana-foundation/ | 574 | — | ~3.8k | Automated safety check: Pass | MIT | today |
| 32 | Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt. | samugit83/ | 3k | — | ~775 | Automated safety check: Pass | MIT | today |
| 33 | Polymarket integration for prediction market trading on Polygon. | Polymarket/ | 191 | 1 repo | ~2k | Automated safety check: Pass | No licence | 7 mo ago |
| 34 | Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts. | luongnv89/ | 42k | — | ~764 | Automated safety check: Pass | MIT | 8 days ago |
| 35 | Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. | mono/ | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | today |
| 36 | 36.Aisafetyhot Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service. | wuyoscar/ | 641 | — | ~1.4k | Automated safety check: Pass | Unknown | today |
| 37 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 38 | Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change. | SonarSource/ | 1.2k | — | ~833 | Automated safety check: Pass | Unknown | today |
| 39 | Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening. | symfony/ | 31k | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 40 | 40.Maven Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing. | skjolber/ | 569 | — | ~886 | Automated safety check: Pass | Apache-2.0 | today |
| 41 | Launch, see and drive a real game so an agent can test its own mods. | rehan-remade/ | 5.8k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 42 | Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code. | ZeroDeng01/ | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | today |
| 43 | Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues. | verdaccio/ | 18k | — | ~853 | Automated safety check: Pass | MIT | today |
| 44 | 44.Doc Comments Ensure that C and C++/CLI types are documented with XML comments and follow best practices for documentation. | MichaelGrafnetter/ | 2k | — | ~1.2k | Automated safety check: Pass | MIT | 27 days ago |
| 45 | 45.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 844 | — | ~581 | Automated safety check: Pass | Apache-2.0 | today |
| 46 | Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team. | tech-leads-club/ | 7k | — | ~2.1k | Automated safety check: Pass | CC-BY-4.0 | today |
| 47 | Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references. | LukasNiessen/ | 446 | — | ~1.2k | Automated safety check: Pass | MIT | 26 days ago |
| 48 | Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities. | context-labs/ | 1.1k | 2 repos | ~3k | Automated safety check: Pass | MIT | 4 days ago |