Search
Security · Rate limiting
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. | EpicenterHQ/ | 4.8k | — | ~896 | Automated safety check: Pass | Unknown | 3 days ago |
| 2 | Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus. | bugbountywithmarco/ | 120 | — | ~550 | Automated safety check: Pass | No licence | 2 mo ago |
| 3 | Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings… | waynesutton/ | 406 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 13 days ago |
| 4 | Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API… | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 5 | Design and interpret advanced content discovery with ffuf and complementary web fuzzers. | cyberful/ | 135 | — | ~1.5k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 6 | Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design. | revfactory/ | 1.3k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 7 | "보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요. | imgompanda/ | 140 | — | ~371 | Automated safety check: Notes | MIT | 6 mo ago |
| 8 | Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks. | Jeffallan/ | 12k | — | ~1.8k | Automated safety check: Pass | MIT | 7 days ago |
| 9 | Aggiunge a un sito/app un agente di difesa che rileva e blocca richieste malevole (SQL injection, XSS, path traversal, brute force, bot) con rate limiting, blocklist IP e modalità lockdown che… | ccplugins/ | 970 | — | ~781 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | 10.Dast Nuclei Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues across web… | AgentSecOps/ | 220 | 1 repo | ~4.1k | Automated safety check: Notes | Unknown | 5 mo ago |
| 11 | Comprehensive API security review against OWASP API Security Top 10 (2023). | OWASP/ | 188 | — | ~744 | Automated safety check: Pass | CC-BY-4.0 | 15 days ago |
| 12 | Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. | affaan-m/ | 277k | 1 repo | ~3.2k | Automated safety check: Notes | MIT | today |
| 13 | Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. | mukul975/ | 34k | — | ~581 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Detect API enumeration attacks (BOLA/IDOR, OWASP API1:2023) by writing SIEM detection rules that flag sequential or UUID identifier iteration, parameter tampering, and mixed 200/401/403 response… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Detect MITRE ATLAS AML.T0024 attacks (model stealing, inversion, membership inference) performed via inference-API abuse, by monitoring per-principal query volume/distribution, rate-limiting and… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Review the implementation source code of MCP (Model Context Protocol) servers, clients, and tool handlers against a security baseline — authentication, sessions, rate limiting, input-schema… | github/ | 40k | — | ~5.2k | Automated safety check: Pass | MIT | 2 days ago |
| 20 | DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning… | modu-ai/ | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 21 | API hardening for Express, FastAPI, and serverless. An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~12k | Automated safety check: Pass | MIT | 6 days ago |
| 22 | 22.Hunt API API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 23 | Cloudflare Workers security with authentication, CORS, rate limiting, input validation. | secondsky/ | 227 | — | ~1.9k | Automated safety check: Pass | MIT | 13 days ago |
| 24 | Run defensive pre-release security tests for Python web applications. | aiskillstore/ | 433 | — | ~1.2k | Automated safety check: Notes | MIT | yesterday |
| 25 | 25.Warden Audit Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. | jeremylongshore/ | 2.8k | — | ~910 | Automated safety check: Notes | MIT | yesterday |
| 26 | 26.Azure Waf Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools). | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |