Search

Security · Authentication

67 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

jewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT4 mo ago
2

Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

ZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMITtoday
3

Verify that code changes do not introduce OAuth security vulnerabilities.

doorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT2 days ago
4

Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make…

justrach/kuri365—~1.3kAutomated safety check: NotesUnknown2 mo ago
5

Add an EAP authentication method (e.g. An agent skill from talkincode/toughradius.

talkincode/toughradius691—~802Automated safety check: PassMITtoday
6

Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis.

s0ld13rr/pentestcode828—~2.9kAutomated safety check: PassMIT7 days ago
7

Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.

elementalsouls/Claude-BugHunter4.8k—~4.5kAutomated safety check: PassMITyesterday
8

Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses

NeoTheCapt/RedteamAgent142—~1.3kAutomated safety check: PassNo licence2 mo ago
9

Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager.

romshark/datapages113—~1.1kAutomated safety check: PassMITyesterday
10

Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

BlkLeg/CircuitBreaker201—~2.1kAutomated safety check: PassMIT4 days ago
11

Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

vinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT3 mo ago
12

Documents the OmniRoute REST endpoints for creating, listing, updating, regenerating and deleting API keys, with per-key scopes, spending limits, expiry and device lists.

diegosouzapw/OmniRoute74k—~1.4kAutomated safety check: PassMITtoday
13

Documents how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard.

diegosouzapw/OmniRoute74k—~1.8kAutomated safety check: PassMITtoday
14

Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.

ADScanPro/Claude-AD211—~1.9kAutomated safety check: PassMIT1 mo ago
15

Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

revfactory/harness-1001.3k—~1.7kAutomated safety check: PassApache-2.06 mo ago
16

Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.

Jeffallan/claude-skills12k—~1.8kAutomated safety check: PassMIT6 days ago
17

Review Convex security audit patterns for authentication and authorization.

IgorWarzocha/Opencode-Workflows122—~3.1kAutomated safety check: PassNo licence8 mo ago
18

Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

affaan-m/ECC276k1 repo~4.3kAutomated safety check: NotesMIT4 days ago
19

Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
20

安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust…

telagod/code-abyss243—~712Automated safety check: PassMIT2 mo ago
21

Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection.

AgentSecOps/SecOpsAgentKit2201 repo~3.7kAutomated safety check: PassUnknown5 mo ago
22

Detect insecure JWT (JSON Web Token) implementations in a codebase using a two-phase approach: first map all JWT issuance and verification sites to understand the token lifecycle and signing…

utkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT6 mo ago
23

Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate generation and ssl module for TLS verification.

mukul975/Anthropic-Cybersecurity-Skills34k—~650Automated safety check: PassApache-2.01 mo ago
24

Deploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
25

Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify…

utkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT6 mo ago
26

Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains

NeoTheCapt/RedteamAgent142—~608Automated safety check: PassNo licence2 mo ago
27

Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface.

transilienceai/communitytools562—~1.4kAutomated safety check: PassMIT2 mo ago
28

Expert in secure backend coding practices specializing in input validation, authentication, and API security.

aiskillstore/marketplace4307 repos~2.6kAutomated safety check: PassNo licencetoday
29

Application security defense knowledge for builders. An agent skill from telagod/code-abyss.

telagod/code-abyss243—~777Automated safety check: PassMIT2 mo ago
30

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
31

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
32

Detects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event ID 4624 logon type 3 with NTLMSSP authentication, flagging IP-to-hostname mismatches, Responder/LLMNR poisoning signatures…

mukul975/Anthropic-Cybersecurity-Skills34k—~718Automated safety check: PassApache-2.01 mo ago
33

Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of…

mukul975/Anthropic-Cybersecurity-Skills34k—~858Automated safety check: PassApache-2.01 mo ago
34

A skill your agent uses when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based…

thedaviddias/Front-End-Checklist74k—~604Automated safety check: PassMIT3 days ago
35

Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

uphiago/recon-skills1.3k—~2kAutomated safety check: PassMIT1 mo ago
36

Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

uphiago/recon-skills1.3k—~2.6kAutomated safety check: PassMIT1 mo ago
37

Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.

rand/cc-polymath181—~1.9kAutomated safety check: PassMIT7 mo ago
38

Server-Side Request Forgery detection→internal-access→proof for web apps.

s0ld13rr/pentestcode828—~660Automated safety check: WarnMIT7 days ago
39

Deploys and configures Wazuh SIEM/XDR for endpoint detection, covering agent authentication and management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, rule testing…

mukul975/Anthropic-Cybersecurity-Skills34k—~582Automated safety check: PassApache-2.01 mo ago
40

When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model"…

shawnpang/startup-founder-skills342—~1.8kAutomated safety check: PassMIT6 mo ago
41

OWASP Top 10 security checklist, authentication patterns, input validation, and HTTP security headers reference.

modu-ai/moai-adk1.2k—~2.3kAutomated safety check: PassApache-2.0today
42

A skill your agent uses when conducting a frontend security review — static analysis (risky HTML patterns, env var exposure), authentication/authorization audit (token storage, route guards…

mizchi/skills359—~1.7kAutomated safety check: NotesNo licence7 days ago
43

Analyze session management implementations to identify security vulnerabilities in web applications.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: PassMITtoday
44

Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

elementalsouls/Claude-BugHunter4.8k—~8.2kAutomated safety check: PassMITyesterday
45

Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism.

jamditis/claude-skills-journalism417—~14kAutomated safety check: PassMIT5 days ago
46

Manage AWS accounts, organizations, IAM, and billing. An agent skill from hoodini/ai-agents-skills.

hoodini/ai-agents-skills282—~3.5kAutomated safety check: PassNo licence2 mo ago
47

Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP…

LeoYeAI/openclaw-master-skills2.2k—~6.1kAutomated safety check: NotesMIT2 mo ago
48

API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT1 mo ago