Search
Security · Backend development
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Django access control and IDOR security review. An agent skill from getsentry/skills. | getsentry/ | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 2 | Runs and interprets Psalm security (taint) analysis on a Laravel project. | cachethq/ | 230 | — | ~4.7k | Automated safety check: Pass | Unknown | 5 days ago |
| 3 | 3.Ssti Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or… | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 4 | Run the full Spring Boot verification loop — Maven or Gradle build, SpotBugs, PMD, and Checkstyle static analysis, unit and Testcontainers integration tests with JaCoCo coverage, OWASP dependency… | affaan-m/ | 276k | 5 repos | ~1.5k | Automated safety check: Pass | MIT | today |
| 5 | Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 276k | 5 repos | ~4k | Automated safety check: Notes | MIT | today |
| 6 | Django 安全最佳实践、认证、授权、CSRF 防护、SQL 注入预防、XSS 预防和安全部署配置. An agent skill from affaan-m/ECC. | affaan-m/ | 276k | 3 repos | ~3.7k | Automated safety check: Notes | MIT | today |
| 7 | Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。 | affaan-m/ | 276k | 3 repos | ~1.6k | Automated safety check: Pass | MIT | today |
| 8 | Review Django security audit patterns for settings and middleware. | IgorWarzocha/ | 122 | — | ~1.6k | Automated safety check: Notes | No licence | 8 mo ago |
| 9 | Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 276k | 1 repo | ~4.3k | Automated safety check: Notes | MIT | today |
| 10 | NVIDIA's runtime safety framework for LLM applications. An agent skill from Orchestra-Research/AI-Research-SKILLs. | Orchestra-Research/ | 13k | 2 repos | ~1.9k | Automated safety check: Warn | MIT | 3 mo ago |
| 11 | 11.Web Ssti Server-Side Template Injection detection→engine-fingerprint→RCE for web apps. | s0ld13rr/ | 828 | — | ~621 | Automated safety check: Pass | MIT | 8 days ago |
| 12 | Detects and exploits Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Audits Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit authorization policies. | ThibautBaissac/ | 665 | — | ~846 | Automated safety check: Notes | MIT | 4 mo ago |
| 15 | Laravel 框架特效安全审计工具。针对 Laravel 常见鉴权/CSRF/Session/模型填充/Blade 渲染等框架特性进行白盒静态审计,并将风险映射到你现有通用漏洞类型体系(AUTH/CSRF/LOGIC/XSS/CFG 等)。 | 0xShe/ | 402 | 1 repo | ~821 | Automated safety check: Pass | No licence | 6 mo ago |
| 16 | Buenas prácticas de Spring Security para autenticación/autorización, validación, CSRF, secretos, cabeceras, limitación de velocidad y seguridad de dependencias en servicios Java Spring Boot. | affaan-m/ | 276k | — | ~2.1k | Automated safety check: Pass | MIT | today |
| 17 | Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | 18.Web Ssrf Server-Side Request Forgery detection→internal-access→proof for web apps. | s0ld13rr/ | 828 | — | ~660 | Automated safety check: Warn | MIT | 8 days ago |
| 19 | Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows. | IgorWarzocha/ | 122 | — | ~1.2k | Automated safety check: Notes | No licence | 8 mo ago |
| 20 | Identify CMS, frameworks, and server technology stacks on live hosts. | uphiago/ | 1.3k | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 21 | Security auditor for Laravel applications. An agent skill from aiskillstore/marketplace. | aiskillstore/ | 433 | 4 repos | ~1.1k | Automated safety check: Notes | No licence | yesterday |
| 22 | Analyze session management implementations to identify security vulnerabilities in web applications. | jeremylongshore/ | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 23 | Review Vite security audit patterns for SPA and dev server security. | IgorWarzocha/ | 122 | — | ~1.2k | Automated safety check: Notes | No licence | 8 mo ago |
| 24 | Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.7k | Automated safety check: Pass | MIT | yesterday |
| 25 | 25.Hunt Sqli Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.5k | Automated safety check: Pass | MIT | yesterday |
| 26 | API hardening for Express, FastAPI, and serverless. An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~12k | Automated safety check: Pass | MIT | 6 days ago |
| 27 | Deploys Llama Guard 3 safety classification, NeMo Guardrails programmable dialogue rails, and LLM Guard input/output scanner pipelines as complementary runtime defenses that inspect and constrain… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 28 | Advanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasses, and detection techniques. | yaklang/ | 2.4k | — | ~2.8k | Automated safety check: Pass | MIT | 27 days ago |
| 29 | 29.Sast Ssrf Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to destinations in parallel… | utkusen/ | 1.3k | — | ~6.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 30 | 30.Sast Ssti Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user… | utkusen/ | 1.3k | — | ~7.5k | Automated safety check: Pass | MIT | 6 mo ago |
| 31 | 31.Server Side Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection. | transilienceai/ | 563 | — | ~484 | Automated safety check: Pass | MIT | 2 mo ago |
| 32 | Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for… | forcedotcom/ | 1.1k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 33 | Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash… | trilwu/ | 157 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 34 | Run defensive pre-release security tests for Python web applications. | aiskillstore/ | 433 | — | ~1.2k | Automated safety check: Notes | MIT | yesterday |
| 35 | 35.Ssrf Testing Detect and exploit server-side request forgery to access internal resources and cloud metadata | NeoTheCapt/ | 143 | — | ~768 | Automated safety check: Pass | No licence | 2 mo ago |
| 36 | Provides AWS Key Management Service (KMS) patterns using AWS SDK for Java 2.x. | giuseppe-trisciuoglio/ | 357 | — | ~3.6k | Automated safety check: Notes | MIT | 1 mo ago |
| 37 | Backend tech-stack identification — web servers, runtimes, languages, frameworks, databases, APIs, and CMS via HTTP headers, cookies, error pages, and API discovery. | transilienceai/ | 563 | — | ~381 | Automated safety check: Pass | MIT | 2 mo ago |
| 38 | 38.Php Security PHP-only security standards for database access, password handling, and input validation. | HoangNguyen0403/ | 572 | — | ~604 | Automated safety check: Pass | MIT | yesterday |
| 39 | Spring Boot 服务的 Spring Security 身份验证/授权、验证、CSRF、密钥、响应头、速率限制和依赖项安全最佳实践。 | xu-xiang/ | 2k | — | ~703 | Automated safety check: Pass | MIT | 7 mo ago |
| 40 | Spring Boot 服务的身份验证/授权、校验、CSRF、机密管理、响应头、速率限制及依赖安全的 Spring Security 最佳实践。 | xu-xiang/ | 2k | — | ~1.7k | Automated safety check: Pass | MIT | 7 mo ago |
| 41 | Assess server-side URL retrieval and network egress during authorized penetration tests or code audits. | cyberful/ | 135 | — | ~867 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 42 | PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。 | wgpsec/ | 1.8k | — | ~767 | Automated safety check: Notes | No licence | today |
| 43 | 43.Ssti Testing Server-side template injection detection, engine identification, and RCE | NeoTheCapt/ | 143 | — | ~748 | Automated safety check: Pass | No licence | 2 mo ago |
| 44 | Secure server-side TypeScript input, auth tokens, and injection boundaries. | HoangNguyen0403/ | 572 | — | ~817 | Automated safety check: Notes | MIT | yesterday |