Search
Security · Pull requests
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Creates a Phorge code review diff for the current branch with arc diff, while applying public-repo confidentiality rules since Phorge content later lands verbatim on the public GitHub repo. | yugabyte/ | 11k | — | ~3.1k | Automated safety check: Pass | Unknown | yesterday |
| 2 | Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues. | verdaccio/ | 18k | — | ~853 | Automated safety check: Pass | MIT | 2 days ago |
| 3 | Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects. | codexstar69/ | 520 | — | ~5k | Automated safety check: Pass | MIT | 1 mo ago |
| 4 | Runs trace-mcp security, quality-gate and antipattern checks before a commit or pull request, and builds a symbol-level diff for the PR description. | nikolai-vysotskyi/ | 189 | — | ~565 | Automated safety check: Pass | MIT | today |
| 5 | Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in… | malloydata/ | 116 | — | ~5.1k | Automated safety check: Pass | MIT | today |
| 6 | A skill your agent uses when the user has concrete failing cases in code or a guardrail/classifier/filter/prompt/API they own — a red-team failure catalogue OR a CI/CD test-failure report (failing… | gaasher/ | 174 | — | ~3.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 7 | Run the full Spring Boot verification loop — Maven or Gradle build, SpotBugs, PMD, and Checkstyle static analysis, unit and Testcontainers integration tests with JaCoCo coverage, OWASP dependency… | affaan-m/ | 276k | 5 repos | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 8 | Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle… | axelixlabs/ | 148 | — | ~4.2k | Automated safety check: Pass | LGPL-3.0 | today |
| 9 | Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks. | maslennikov-ig/ | 260 | — | ~2k | Automated safety check: Pass | Unknown | 7 mo ago |
| 10 | Code review covering security, performance, quality and maintainability, with a fixed report layout and two analysis scripts; the SKILL.md itself is in Ukrainian. | luongnv89/ | 42k | — | ~484 | Automated safety check: Pass | MIT | 10 days ago |
| 11 | Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself. | anthropics/ | 38k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 12 | Search and contribute to the shared AI-modding knowledge base, where field notes record how specific games were modded, decompiled or reverse-engineered (exact versions, route, engine facts… | rehan-remade/ | 6.1k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 13 | Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions. | trailofbits/ | 7.5k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 14 | Analyze code changes for security vulnerabilities using LLM reasoning and threat model patterns. | Factory-AI/ | 111 | — | ~2.3k | Automated safety check: Pass | No licence | 3 days ago |
| 15 | Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. | trailofbits/ | 7.5k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 16 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 17 | 17.PR Audit Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation… | akitaonrails/ | 216 | — | ~4.8k | Automated safety check: Pass | No licence | 17 days ago |
| 18 | Security-focused code review mapped to OWASP Top 10 and ASVS. | OWASP/ | 188 | — | ~549 | Automated safety check: Pass | CC-BY-4.0 | 15 days ago |
| 19 | 19.Reviewdog Automated code review and security linting integration for CI/CD pipelines using reviewdog. | AgentSecOps/ | 220 | 1 repo | ~3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 20 | Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold… | warpdotdev/ | 312 | 1 repo | ~2k | Automated safety check: Notes | MIT | 23 days ago |
| 21 | Audit a product or tech spec pull request diff for high-level security concerns (threat surface, authentication and authorization model, trust boundaries, sensitive data handling, secrets and key… | warpdotdev/ | 312 | 1 repo | ~2.6k | Automated safety check: Pass | MIT | 23 days ago |
| 22 | Ten minute security pass over a Convex backend: public functions that should be internal, missing auth checks, unvalidated args, IDs from the client trusted without ownership checks, secrets in code. | waynesutton/ | 406 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 12 days ago |
| 23 | Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 24 | Screen a pull request from an outside contributor for hidden, obfuscated, or supply-chain-risky changes before any of its code runs. | different-ai/ | 24k | — | ~939 | Automated safety check: Warn | Unknown | today |
| 25 | CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows). | pskoett/ | 315 | — | ~1.1k | Automated safety check: Pass | No licence | 5 days ago |
| 26 | A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including… | hyodotdev/ | 155 | — | ~766 | Automated safety check: Pass | MIT | today |
| 27 | PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). | tetherto/ | 685 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 28 | Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks. | foryourhealth111-pixel/ | 3.6k | — | ~1.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 29 | A skill your agent uses for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge… | hyodotdev/ | 155 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 30 | 30.Purple Team A skill your agent uses when the user wants to automatically harden a guardrail, classifier, content filter, prompt, or API they own by running attack and defense together as a closed loop, not just… | gaasher/ | 174 | — | ~2.6k | Automated safety check: Pass | MIT | 3 mo ago |
| 31 | 31.Review Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit. | softspark/ | 179 | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 32 | Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF… | LUC4N3X/ | 590 | — | ~2.3k | Automated safety check: Pass | GPL-3.0 | today |
| 33 | Code review using Codex exec. An agent skill from sd0xdev/sd0x-harness. | sd0xdev/ | 192 | — | ~9.8k | Automated safety check: Pass | MIT | 3 days ago |
| 34 | Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline. | trilwu/ | 157 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 35 | Configure and audit security review capabilities as one layer in a defense-in-depth pull-request program. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 36 | Reviews a design or change for security before it ships — authentication and authorization, data handling, secrets, dependencies, and the secure-development practices around it. | cbrock84/ | 2k | — | ~1.1k | Automated safety check: Pass | MIT | 23 days ago |
| 37 | Generate an AI SBOM declaration for a PR description. An agent skill from openshift-eng/ai-helpers. | openshift-eng/ | 120 | — | ~874 | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 38 | Perform evidence-driven security code reviews across application repositories, services, libraries, and pull requests. | SpecterOps/ | 706 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 17 days ago |
| 39 | Review application and infrastructure changes for exploitable security risks by tracing assets, trust boundaries, attacker-controlled input, authorization, sensitive data, and dangerous sinks. | hashgraph-online/ | 1.3k | — | ~601 | Automated safety check: Pass | Apache-2.0 | yesterday |