Search
Security · Authentication
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. | jewbetcha/ | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 2 | Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code. | ZeroDeng01/ | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | today |
| 3 | Verify that code changes do not introduce OAuth security vulnerabilities. | doorkeeper-gem/ | 5.5k | — | ~1.4k | Automated safety check: Pass | MIT | 2 days ago |
| 4 | Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make… | justrach/ | 365 | — | ~1.3k | Automated safety check: Notes | Unknown | 2 mo ago |
| 5 | Add an EAP authentication method (e.g. An agent skill from talkincode/toughradius. | talkincode/ | 691 | — | ~802 | Automated safety check: Pass | MIT | today |
| 6 | Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis. | s0ld13rr/ | 828 | — | ~2.9k | Automated safety check: Pass | MIT | 7 days ago |
| 7 | Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. | elementalsouls/ | 4.8k | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 8 | Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses | NeoTheCapt/ | 142 | — | ~1.3k | Automated safety check: Pass | No licence | 2 mo ago |
| 9 | Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager. | romshark/ | 113 | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 10 | Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. | BlkLeg/ | 201 | — | ~2.1k | Automated safety check: Pass | MIT | 4 days ago |
| 11 | Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API… | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 12 | Documents the OmniRoute REST endpoints for creating, listing, updating, regenerating and deleting API keys, with per-key scopes, spending limits, expiry and device lists. | diegosouzapw/ | 74k | — | ~1.4k | Automated safety check: Pass | MIT | today |
| 13 | Documents how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard. | diegosouzapw/ | 74k | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 14 | Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. | ADScanPro/ | 211 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 15 | Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design. | revfactory/ | 1.3k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 16 | Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks. | Jeffallan/ | 12k | — | ~1.8k | Automated safety check: Pass | MIT | 6 days ago |
| 17 | Review Convex security audit patterns for authentication and authorization. | IgorWarzocha/ | 122 | — | ~3.1k | Automated safety check: Pass | No licence | 8 mo ago |
| 18 | Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 276k | 1 repo | ~4.3k | Automated safety check: Notes | MIT | 4 days ago |
| 19 | Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 20 | 安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust… | telagod/ | 243 | — | ~712 | Automated safety check: Pass | MIT | 2 mo ago |
| 21 | 21.Dast Zap Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection. | AgentSecOps/ | 220 | 1 repo | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 22 | 22.Sast JWT Detect insecure JWT (JSON Web Token) implementations in a codebase using a two-phase approach: first map all JWT issuance and verification sites to understand the token lifecycle and signing… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 23 | Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification. | mukul975/ | 34k | — | ~650 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 24 | Deploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 25 | Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 26 | Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains | NeoTheCapt/ | 142 | — | ~608 | Automated safety check: Pass | No licence | 2 mo ago |
| 27 | Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. | transilienceai/ | 562 | — | ~1.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 28 | Expert in secure backend coding practices specializing in input validation, authentication, and API security. | aiskillstore/ | 430 | 7 repos | ~2.6k | Automated safety check: Pass | No licence | today |
| 29 | Application security defense knowledge for builders. An agent skill from telagod/code-abyss. | telagod/ | 243 | — | ~777 | Automated safety check: Pass | MIT | 2 mo ago |
| 30 | Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Detects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event ID 4624 logon type 3 with NTLMSSP authentication, flagging IP-to-hostname mismatches, Responder/LLMNR poisoning signatures… | mukul975/ | 34k | — | ~718 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 33 | Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of… | mukul975/ | 34k | — | ~858 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | A skill your agent uses when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based… | thedaviddias/ | 74k | — | ~604 | Automated safety check: Pass | MIT | 3 days ago |
| 35 | Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing. | uphiago/ | 1.3k | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 36 | Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints | uphiago/ | 1.3k | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 37 | Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management. | rand/ | 181 | — | ~1.9k | Automated safety check: Pass | MIT | 7 mo ago |
| 38 | 38.Web Ssrf Server-Side Request Forgery detection→internal-access→proof for web apps. | s0ld13rr/ | 828 | — | ~660 | Automated safety check: Warn | MIT | 7 days ago |
| 39 | Deploys and configures Wazuh SIEM/XDR for endpoint detection, covering agent authentication and management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, rule testing… | mukul975/ | 34k | — | ~582 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 40 | When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model"… | shawnpang/ | 342 | — | ~1.8k | Automated safety check: Pass | MIT | 6 mo ago |
| 41 | OWASP Top 10 security checklist, authentication patterns, input validation, and HTTP security headers reference. | modu-ai/ | 1.2k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 42 | A skill your agent uses when conducting a frontend security review — static analysis (risky HTML patterns, env var exposure), authentication/authorization audit (token storage, route guards… | mizchi/ | 359 | — | ~1.7k | Automated safety check: Notes | No licence | 7 days ago |
| 43 | Analyze session management implementations to identify security vulnerabilities in web applications. | jeremylongshore/ | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 44 | Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~8.2k | Automated safety check: Pass | MIT | yesterday |
| 45 | 45.Secure Auth Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 417 | — | ~14k | Automated safety check: Pass | MIT | 5 days ago |
| 46 | Manage AWS accounts, organizations, IAM, and billing. An agent skill from hoodini/ai-agents-skills. | hoodini/ | 282 | — | ~3.5k | Automated safety check: Pass | No licence | 2 mo ago |
| 47 | 47.Clerk Auth Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP… | LeoYeAI/ | 2.2k | — | ~6.1k | Automated safety check: Notes | MIT | 2 mo ago |
| 48 | 48.Hunt API API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |