Search
Security · For lawyers and compliance teams
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.X Ray Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)… | pashov/ | 1.2k | 1 repo | ~10k | Automated safety check: Pass | MIT | 5 days ago |
| 2 | 2.Solodit Search Solodit for similar smart contract security findings. | marchev/ | 159 | — | ~832 | Automated safety check: Pass | MIT | 5 mo ago |
| 3 | Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers. | CyberStrategyInstitute/ | 147 | — | ~1.2k | Automated safety check: Pass | Unknown | yesterday |
| 4 | 按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's… | jnMetaCode/ | 140 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 12 days ago |
| 5 | 5.Sail Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. | pillar-labs/ | 113 | — | ~5.1k | Automated safety check: Pass | Unknown | 3 mo ago |
| 6 | A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy… | SCStelz/ | 249 | — | ~3.8k | Automated safety check: Pass | MIT | 2 days ago |
| 7 | Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption. | wshobson/ | 40k | 11 repos | ~1.9k | Automated safety check: Pass | MIT | 6 days ago |
| 8 | A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview. | ccashwell/ | 131 | — | ~25k | Automated safety check: Pass | MIT | 11 days ago |
| 9 | Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Warn | Apache-2.0 | today |
| 10 | Senior ISMS Audit Expert for internal and external information security management system auditing. | davila7/ | 33k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | today |
| 11 | AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents | Hack23/ | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 12 | 12.Fp Check Systematic false positive verification for security findings. | vibeeval/ | 532 | — | ~1.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 13 | 安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex. | ReJeCtAll/ | 113 | — | ~780 | Automated safety check: Pass | MIT | 3 mo ago |
| 14 | Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and… | sangrokjung/ | 852 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 15 | Open source license compliance check for a dependency list, a single library, or outbound code. | anthropics/ | 9.6k | 3 repos | ~5k | Automated safety check: Pass | Apache-2.0 | 11 days ago |
| 16 | A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit. | ccashwell/ | 131 | — | ~1.4k | Automated safety check: Pass | MIT | 11 days ago |
| 17 | Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. | alirezarezvani/ | 28k | 1 repo | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 18 | 安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust… | telagod/ | 244 | — | ~712 | Automated safety check: Pass | MIT | 2 mo ago |
| 19 | Automate security workflows and remediation. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~1k | Automated safety check: Pass | MIT | yesterday |
| 20 | Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export. | GRCEngClub/ | 419 | — | ~2.4k | Automated safety check: Notes | Unknown | 7 days ago |
| 21 | Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks. | github/ | 40k | 1 repo | ~3k | Automated safety check: Pass | MIT | 2 days ago |
| 22 | Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence. | github/ | 5.4k | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 23 | A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU… | davila7/ | 33k | 1 repo | ~4.7k | Automated safety check: Pass | CC-BY-4.0 | yesterday |
| 24 | Admin account register: system, main and backup admin, seats, plan, 2FA, shared logins and access-review dates, as CSV, SQL, JSON Schema or Notion on request. | sickn33/ | 47k | 1 repo | ~4.2k | Automated safety check: Pass | MIT | 2 days ago |
| 25 | Mailbox and licence register: employee, account type, aliases, groups, tool, licence cost, 2FA and password policy state, and access-review dates. | sickn33/ | 47k | 1 repo | ~5k | Automated safety check: Pass | MIT | 2 days ago |
| 26 | Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 27 | Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC 2, and HIPAA. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering… | cdxgen/ | 1.1k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 30 | Audit and manage dependencies across multi-language projects. | alirezarezvani/ | 28k | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 31 | Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Deploy AWS Security Hub, backed by AWS Config, to aggregate findings from GuardDuty, Inspector, Macie, Firewall Manager, and Prowler across multi-account AWS Organizations, enable standards like CIS… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 33 | Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | Implements secure conduit architecture for OT remote access under the IEC 62443 zones-and-conduits model, deploying jump servers, MFA gateways, session recording, and approval-based workflows for… | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | Implements Delinea Secret Server for privileged access management, covering secret vault configuration, role-based access policies, automated password rotation, session recording, and Active… | mukul975/ | 34k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates, with automatic generation, lease management, and rotation to eliminate static secrets… | mukul975/ | 34k | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. | alirezarezvani/ | 28k | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 38 | Design identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML) automation, role mining, access requests… | mukul975/ | 34k | — | ~7.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | Designs and runs access review and certification campaigns-scoping, reviewer selection, risk-based prioritization, micro-certification, and remediation tracking-to verify user access matches job… | mukul975/ | 34k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 40 | Discovers and inventories privileged accounts across enterprise infrastructure, including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin… | mukul975/ | 34k | — | ~657 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 41 | Usar para generar Software Bill of Materials para cumplimiento del CRA. | 686f6c61/ | 117 | — | ~780 | Automated safety check: Pass | MIT | 1 mo ago |
| 42 | Audits all guest and external user access on the current SharePoint site. | pnp/ | 133 | — | ~2.3k | Automated safety check: Pass | MIT | yesterday |
| 43 | You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. | aiskillstore/ | 433 | 7 repos | ~490 | Automated safety check: Pass | No licence | yesterday |
| 44 | A skill your agent uses when the user says 'licensing', 'license audit', 'can I use this commercially', 'OSS license check', 'license compatibility', 'GPL', 'MIT', 'AGPL', 'copyleft'. | cwinvestments/ | 423 | — | ~3.5k | Automated safety check: Pass | Proprietary | 14 days ago |
| 45 | Generate comprehensive security audit reports for applications and systems. | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 46 | Audit a Python project's installed dependencies for known CVEs by wrapping pip-audit (PyPA's official vulnerability auditor) and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.3k | Automated safety check: Notes | MIT | yesterday |
| 47 | Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards. | jeremylongshore/ | 2.8k | — | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 48 | Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present. | jeremylongshore/ | 2.8k | — | ~2.1k | Automated safety check: Notes | MIT | yesterday |