Search

Security · Authorization and RBAC

127 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

usestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0yesterday
2

Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repo~4.4kAutomated safety check: PassMIT5 days ago
3

Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

ZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMITyesterday
4

Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.

Tencent/AI-Infra-Guard6.8k—~753Automated safety check: PassApache-2.0yesterday
5

Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

gocronx-team/gocron808—~690Automated safety check: PassMIT7 days ago
6

Django access control and IDOR security review. An agent skill from getsentry/skills.

getsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.07 days ago
7

Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

google/skills21k—~3.2kAutomated safety check: PassApache-2.0yesterday
8

Add or retrofit Tenuo authorization for AI-agent tools and effects.

tenuo-ai/tenuo103—~2.3kAutomated safety check: PassApache-2.0yesterday
9

Guide for writing eval conversation JSONs and running them through policy engines

open-bias/open-bias143—~1.5kAutomated safety check: PassApache-2.02 days ago
10
10.Sentry SecurityOfficial

Sentry-specific security review based on real vulnerability history.

getsentry/sentry46k—~2.3kAutomated safety check: NotesUnknowntoday
11

Create or delegate Tenuo warrants from natural-language authority requirements.

tenuo-ai/tenuo103—~4.9kAutomated safety check: PassApache-2.0yesterday
12

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

zebbern/claude-code-guide4.7k8 repos~3.1kAutomated safety check: PassMITyesterday
13

Manages who can reach Claude through a Discord channel: approve pairing codes, edit the allowlist and set direct-message and group policy.

anthropics/claude-plugins-official38k1 repo~1.1kAutomated safety check: PassApache-2.0yesterday
14

Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without…

maddhruv/absolute2181 repo~1.2kAutomated safety check: PassMIT3 mo ago
15

Explains authorization in an Arandu Go application: write a Policy, get a security.Grant through security.Authorize, re-authorize each row, and keep tenant isolation.

arandu-io/arandu281—~1.4kAutomated safety check: PassMIT5 days ago
16

Worked bug bounty case study of a yield aggregator: target scoring, fund-flow mapping, prior audit triage and a verdict per bug class, with role misconfiguration in focus.

tradecatlabs/vibe-coding-cn17k2 repos~3.5kAutomated safety check: PassMITyesterday
17

Audit, explain, or compare existing Tenuo warrants and delegation chains.

tenuo-ai/tenuo103—~3.6kAutomated safety check: PassApache-2.0yesterday
18

Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses

NeoTheCapt/RedteamAgent142—~1.3kAutomated safety check: PassNo licence2 mo ago
19

Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3…

utkusen/sast-skills1.3k—~4.9kAutomated safety check: PassMIT6 mo ago
20

Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority.

tenuo-ai/tenuo103—~2.3kAutomated safety check: PassApache-2.0yesterday
21

Run Warden security scans in this repo using Sentry's warden-skills.

UsefulSoftwareCo/executor4.1k—~1.3kAutomated safety check: PassMITtoday
22

Analyzes authentication and authorization events for failed-login clustering, privilege-escalation chains, credential-stuffing patterns, and MFA-bypass indicators.

ahmadvh/octochains376—~1.3kAutomated safety check: PassUnknown1 mo ago
23

Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

BlkLeg/CircuitBreaker201—~2.1kAutomated safety check: PassMIT4 days ago
24

Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

vinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT3 mo ago
25

Documents the OmniRoute REST endpoints for creating, listing, updating, regenerating and deleting API keys, with per-key scopes, spending limits, expiry and device lists.

diegosouzapw/OmniRoute74k—~1.4kAutomated safety check: PassMITyesterday
26

Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

langfuse/langfuse36k—~1.4kAutomated safety check: PassUnknowntoday
27

Database migration creation with mandatory RLS policies and ARCHitect approval workflow. Use when creating migrations, adding tables with RLS…

bybren-llc/safe-agentic-workflow423—~1.3kAutomated safety check: PassMIT2 mo ago
28

Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

affaan-m/ECC276k5 repos~4kAutomated safety check: NotesMIT5 days ago
29

CORS misconfiguration testing for data theft and access control bypass

NeoTheCapt/RedteamAgent142—~904Automated safety check: PassNo licence2 mo ago
30

Guides designing a layered permission pipeline for agent tools that decides which calls are allowed, need confirmation or are denied, with scopes and hooks.

simbajigege/book2skills183—~2.1kAutomated safety check: PassApache-2.01 mo ago
31

Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix.

codewhale-hq/Codewhale41k—~844Automated safety check: PassMITtoday
32

Review Convex security audit patterns for authentication and authorization.

IgorWarzocha/Opencode-Workflows122—~3.1kAutomated safety check: PassNo licence8 mo ago
33

A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level…

makifbaysal/tasktrooper112—~1.7kAutomated safety check: PassApache-2.0yesterday
34

Analyzes Solidity contract entry points to map attack surface.

alt-research2/SolidityGuard104—~959Automated safety check: PassUnknown3 mo ago
35
35.Iam

AWS Identity and Access Management for users, roles, policies, and permissions.

itsmostafa/aws-agent-skills1.2k—~1.8kAutomated safety check: PassMIT4 days ago
36

A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

jellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMITtoday
37

Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

affaan-m/ECC276k1 repo~4.3kAutomated safety check: NotesMIT5 days ago
38

A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.

openJiuwen-ai/agent-core446—~1.7kAutomated safety check: NotesApache-2.0today
39

Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop…

Encod3d-Sec/TORCH329—~3.5kAutomated safety check: NotesMIT1 mo ago
40

Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition.

bbartling/open-fdd173—~2.2kAutomated safety check: PassUnknownyesterday
41

Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~2.8kAutomated safety check: NotesMITtoday
42

Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle).

totvs/engpro-advpl-tlpp-skills143—~3.5kAutomated safety check: PassMIT4 days ago
43

Security-focused code review mapped to OWASP Top 10 and ASVS.

OWASP/secure-agent-playbook187—~549Automated safety check: PassCC-BY-4.014 days ago
44

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

hardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNo licence5 mo ago
45

Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.

arpitg1304/robotics-agent-skills369—~7.8kAutomated safety check: WarnApache-2.01 mo ago
46

Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.

AgentSecOps/SecOpsAgentKit2201 repo~4.6kAutomated safety check: NotesUnknown5 mo ago
47
47.Security ReviewOfficial

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

github/awesome-copilot40k1 repo~2.3kAutomated safety check: NotesMITyesterday
48

Deploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago