Search
Security · Authorization and RBAC
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept. | usestrix/ | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2 | 2.Fedramp Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). | Sushegaad/ | 943 | 1 repo | ~4.4k | Automated safety check: Pass | MIT | 5 days ago |
| 3 | Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code. | ZeroDeng01/ | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | yesterday |
| 4 | Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries. | Tencent/ | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 5 | Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. | gocronx-team/ | 808 | — | ~690 | Automated safety check: Pass | MIT | 7 days ago |
| 6 | Django access control and IDOR security review. An agent skill from getsentry/skills. | getsentry/ | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | 7 days ago |
| 7 | Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants. | google/ | 21k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 8 | Add or retrofit Tenuo authorization for AI-agent tools and effects. | tenuo-ai/ | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 9 | Guide for writing eval conversation JSONs and running them through policy engines | open-bias/ | 143 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 10 | Sentry-specific security review based on real vulnerability history. | getsentry/ | 46k | — | ~2.3k | Automated safety check: Notes | Unknown | today |
| 11 | Create or delegate Tenuo warrants from natural-language authority requirements. | tenuo-ai/ | 103 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 12 | 12.Idor Testing This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"… | zebbern/ | 4.7k | 8 repos | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 13 | Manages who can reach Claude through a Discord channel: approve pairing codes, edit the allowlist and set direct-message and group policy. | anthropics/ | 38k | 1 repo | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 14 | Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without… | maddhruv/ | 218 | 1 repo | ~1.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 15 | Explains authorization in an Arandu Go application: write a Policy, get a security.Grant through security.Authorize, re-authorize each row, and keep tenant isolation. | arandu-io/ | 281 | — | ~1.4k | Automated safety check: Pass | MIT | 5 days ago |
| 16 | Worked bug bounty case study of a yield aggregator: target scoring, fund-flow mapping, prior audit triage and a verdict per bug class, with role misconfiguration in focus. | tradecatlabs/ | 17k | 2 repos | ~3.5k | Automated safety check: Pass | MIT | yesterday |
| 17 | 17.Tenuo Audit Audit, explain, or compare existing Tenuo warrants and delegation chains. | tenuo-ai/ | 103 | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 18 | 18.Auth Bypass Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses | NeoTheCapt/ | 142 | — | ~1.3k | Automated safety check: Pass | No licence | 2 mo ago |
| 19 | 19.Sast Idor Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3… | utkusen/ | 1.3k | — | ~4.9k | Automated safety check: Pass | MIT | 6 mo ago |
| 20 | Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority. | tenuo-ai/ | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 21 | Run Warden security scans in this repo using Sentry's warden-skills. | UsefulSoftwareCo/ | 4.1k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 22 | Analyzes authentication and authorization events for failed-login clustering, privilege-escalation chains, credential-stuffing patterns, and MFA-bypass indicators. | ahmadvh/ | 376 | — | ~1.3k | Automated safety check: Pass | Unknown | 1 mo ago |
| 23 | Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. | BlkLeg/ | 201 | — | ~2.1k | Automated safety check: Pass | MIT | 4 days ago |
| 24 | Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API… | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 25 | Documents the OmniRoute REST endpoints for creating, listing, updating, regenerating and deleting API keys, with per-key scopes, spending limits, expiry and device lists. | diegosouzapw/ | 74k | — | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 26 | Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy. | langfuse/ | 36k | — | ~1.4k | Automated safety check: Pass | Unknown | today |
| 27 | Database migration creation with mandatory RLS policies and ARCHitect approval workflow. Use when creating migrations, adding tables with RLS… | bybren-llc/ | 423 | — | ~1.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 28 | Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 276k | 5 repos | ~4k | Automated safety check: Notes | MIT | 5 days ago |
| 29 | 29.Cors Testing CORS misconfiguration testing for data theft and access control bypass | NeoTheCapt/ | 142 | — | ~904 | Automated safety check: Pass | No licence | 2 mo ago |
| 30 | Guides designing a layered permission pipeline for agent tools that decides which calls are allowed, need confirmation or are denied, with scopes and hooks. | simbajigege/ | 183 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix. | codewhale-hq/ | 41k | — | ~844 | Automated safety check: Pass | MIT | today |
| 32 | Review Convex security audit patterns for authentication and authorization. | IgorWarzocha/ | 122 | — | ~3.1k | Automated safety check: Pass | No licence | 8 mo ago |
| 33 | A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level… | makifbaysal/ | 112 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 34 | Analyzes Solidity contract entry points to map attack surface. | alt-research2/ | 104 | — | ~959 | Automated safety check: Pass | Unknown | 3 mo ago |
| 35 | 35.Iam AWS Identity and Access Management for users, roles, policies, and permissions. | itsmostafa/ | 1.2k | — | ~1.8k | Automated safety check: Pass | MIT | 4 days ago |
| 36 | A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance. | jellydn/ | 123 | — | ~2.9k | Automated safety check: Notes | MIT | today |
| 37 | Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 276k | 1 repo | ~4.3k | Automated safety check: Notes | MIT | 5 days ago |
| 38 | A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection. | openJiuwen-ai/ | 446 | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | today |
| 39 | 39.Hunt Core Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop… | Encod3d-Sec/ | 329 | — | ~3.5k | Automated safety check: Notes | MIT | 1 mo ago |
| 40 | Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition. | bbartling/ | 173 | — | ~2.2k | Automated safety check: Pass | Unknown | yesterday |
| 41 | Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~2.8k | Automated safety check: Notes | MIT | today |
| 42 | Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle). | totvs/ | 143 | — | ~3.5k | Automated safety check: Pass | MIT | 4 days ago |
| 43 | Security-focused code review mapped to OWASP Top 10 and ASVS. | OWASP/ | 187 | — | ~549 | Automated safety check: Pass | CC-BY-4.0 | 14 days ago |
| 44 | Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and… | hardw00t/ | 104 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 45 | Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection. | arpitg1304/ | 369 | — | ~7.8k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 46 | 46.Recon Nmap Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection. | AgentSecOps/ | 220 | 1 repo | ~4.6k | Automated safety check: Notes | Unknown | 5 mo ago |
| 47 | AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching… | github/ | 40k | 1 repo | ~2.3k | Automated safety check: Notes | MIT | yesterday |
| 48 | Deploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |