Search
Security · OAuth and OpenID Connect
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Verify that code changes do not introduce OAuth security vulnerabilities. | doorkeeper-gem/ | 5.5k | — | ~1.4k | Automated safety check: Pass | MIT | 2 days ago |
| 2 | Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. | EpicenterHQ/ | 4.8k | — | ~896 | Automated safety check: Pass | Unknown | 3 days ago |
| 3 | Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. | PrefectHQ/ | 28k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 4 | Documents how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard. | diegosouzapw/ | 75k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 5 | Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys. | nanocoai/ | 31k | — | ~856 | Automated safety check: Pass | MIT | yesterday |
| 6 | Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. | Gabson0x/ | 442 | — | ~11k | Automated safety check: Warn | No licence | 24 days ago |
| 7 | 7.AWS Iam Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 8 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 9 | Deploys Cloudflare Access with Cloudflare Tunnel for zero trust access to self-hosted apps, configuring identity-aware policies, device posture checks, and WARP client enrollment as a VPN replacement. | mukul975/ | 34k | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 10 | Signs and verifies container image provenance with Sigstore Cosign, covering key-based and keyless OIDC signing (Fulcio, Rekor transparency log), SLSA attestations, and enforcing signature… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 11 | Installs and configures HashiCorp Boundary as a default-deny, identity-aware proxy for infrastructure access, including controller/worker setup, Vault-backed credential brokering, session recording… | mukul975/ | 34k | — | ~3.9k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 12 | 12.Atmos CI Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs… | cloudposse/ | 1.4k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 13 | Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 15 | Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains | NeoTheCapt/ | 143 | — | ~608 | Automated safety check: Pass | No licence | 2 mo ago |
| 16 | 16.Bug Bounty Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling… | awarexone/ | 5.3k | — | ~20k | Automated safety check: Warn | MIT | 2 days ago |
| 17 | Application security defense knowledge for builders. An agent skill from telagod/code-abyss. | telagod/ | 244 | — | ~777 | Automated safety check: Pass | MIT | 2 mo ago |
| 18 | 18.Web Ssrf Server-Side Request Forgery detection→internal-access→proof for web apps. | s0ld13rr/ | 828 | — | ~660 | Automated safety check: Warn | MIT | 9 days ago |
| 19 | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. | aiskillstore/ | 433 | 6 repos | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 20 | Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise. | mukul975/ | 34k | — | ~584 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 21 | 21.Hunt Sqli Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.5k | Automated safety check: Pass | MIT | yesterday |
| 22 | 22.Secure Auth Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~14k | Automated safety check: Pass | MIT | 6 days ago |
| 23 | 安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。 | devcodex-labs/ | 439 | — | ~771 | Automated safety check: Pass | AGPL-3.0 | 24 days ago |
| 24 | OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 25 | Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 26 | Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls. | jeremylongshore/ | 2.8k | — | ~1k | Automated safety check: Pass | MIT | yesterday |
| 27 | Establish least-privilege OAuth, secret, webhook, data, card, and financial-write controls for a Ramp integration. | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |