Search
Security · Cloud networking
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging. | wshobson/ | 40k | 9 repos | ~588 | Automated safety check: Pass | MIT | 4 days ago |
| 2 | Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. | BlkLeg/ | 201 | — | ~2.1k | Automated safety check: Pass | MIT | 4 days ago |
| 3 | Passive domain reconnaissance using Python stdlib. An agent skill from Tommy-yw/RunbookHermes. | Tommy-yw/ | 546 | 1 repo | ~1.1k | Automated safety check: Pass | MIT | 4 mo ago |
| 4 | Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection. | AgentSecOps/ | 220 | 1 repo | ~4.6k | Automated safety check: Notes | Unknown | 5 mo ago |
| 5 | Configures and deploys Palo Alto Networks next-generation firewalls end-to-end, covering App-ID application-aware policies, User-ID identity-based enforcement, zone-based security rules, SSL… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 6 | Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. | mukul975/ | 34k | — | ~581 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 7 | Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. | mukul975/ | 34k | — | ~745 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 8 | Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxypass) and Apache (modrewrite), deriving filter rules from a Malleable C2 profile, layering Let's Encrypt TLS, and applying OPSEC… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 9 | Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Configure TLS certificates and encryption for secure communications. | ancoleman/ | 526 | — | ~3.6k | Automated safety check: Notes | MIT | 10 mo ago |
| 12 | Guidance for Azure Firewall — managed cloud-native L3-L7 stateful network firewall for centralised egress, east-west, and ingress control. | vinayaklatthe/ | 175 | — | ~1.7k | Automated safety check: Pass | MIT | 3 mo ago |
| 13 | Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs. | forefy/ | 152 | — | ~3.1k | Automated safety check: Pass | MIT | 5 days ago |
| 14 | Queries Arkime (formerly Moloch) full packet capture via its API to search sessions, download PCAPs, detect C2 beaconing through connection interval/jitter stats, spot DNS tunneling via query-length… | mukul975/ | 34k | — | ~557 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Automates the full SSL/TLS certificate lifecycle, including generating Certificate Signing Requests, issuing, deploying, monitoring, renewing, and revoking X.509 certificates, using Python and ACME… | mukul975/ | 34k | — | ~867 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. | mukul975/ | 34k | — | ~644 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. | mukul975/ | 34k | — | ~4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 20 | Detects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-header mismatches in proxy logs and inspecting TLS certificate discrepancies with pyOpenSSL. | mukul975/ | 34k | — | ~695 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 21 | Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 22 | Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 23 | This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. | mukul975/ | 34k | — | ~6.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 24 | 24.Domain Intel Passive recon of subdomains, SSL certs, WHOIS, and DNS. An agent skill from Luciole-Studio/Misaka-Agent. | Luciole-Studio/ | 158 | 1 repo | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 25 | Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2). | google/ | 21k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 26 | A skill your agent uses when protected HTTP routes return 401 or 403. | uphiago/ | 1.3k | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 27 | Discover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs. | uphiago/ | 1.3k | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 28 | Discover hidden virtual hosts via Host header fuzzing and SSL certificate parsing. | uphiago/ | 1.3k | — | ~1.4k | Automated safety check: Notes | MIT | 1 mo ago |
| 29 | Probe a target for directories that return auto-generated index listings instead of denying or serving a specific file — exposes the full file tree under any reachable directory, including files the… | jeremylongshore/ | 2.8k | — | ~1.8k | Automated safety check: Notes | MIT | today |
| 30 | Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards. | jeremylongshore/ | 2.8k | — | ~1.7k | Automated safety check: Pass | MIT | today |
| 31 | Test authorized web-cache key construction, variation, partitioning, authenticated response handling, revalidation, poisoning, deception, purge, and TTL behavior. | cyberful/ | 135 | — | ~631 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 32 | Infrastructure tech-stack identification — cloud providers, CDN/WAF, DNS services, TLS/CT, DevOps tooling, plus asset discovery (domains, subdomains, IPs). | transilienceai/ | 562 | — | ~462 | Automated safety check: Pass | MIT | 2 mo ago |
| 33 | Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging. | automateyournetwork/ | 676 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 34 | AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource… | LeoYeAI/ | 2.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 35 | Route HTTP intermediary testing across request normalization, web-cache behavior, and offline traffic evidence. | cyberful/ | 135 | — | ~630 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |