Search
Security · Secrets management
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist. | eigent-ai/ | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 2 | Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge. | nanocoai/ | 31k | — | ~4.6k | Automated safety check: Notes | MIT | yesterday |
| 3 | Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script. | nanocoai/ | 31k | — | ~1.1k | Automated safety check: Notes | MIT | yesterday |
| 4 | Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized. | netdata/ | 81k | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | today |
| 5 | Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. | ktnyt/ | 675 | — | ~565 | Automated safety check: Pass | MIT | 7 mo ago |
| 6 | Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. | vechain/ | 450 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 7 | When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain | deonmenezes/ | 503 | — | ~510 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 8 | Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API… | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 9 | Lets the agent list and read the secrets a user has configured, such as API keys and tokens, through two tai tools instead of hardcoding credentials into code or commands. | YaoApp/ | 8.1k | — | ~415 | Automated safety check: Pass | Unknown | 3 days ago |
| 10 | Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys. | nanocoai/ | 31k | — | ~856 | Automated safety check: Pass | MIT | yesterday |
| 11 | 11.Repo Audit Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. | zebbern/ | 4.7k | — | ~831 | Automated safety check: Pass | MIT | yesterday |
| 12 | Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session. | avelikiy/ | 103 | — | ~884 | Automated safety check: Notes | MIT | today |
| 13 | Security-focused source code review and SAST. An agent skill from transilienceai/communitytools. | transilienceai/ | 563 | — | ~1.2k | Automated safety check: Notes | MIT | 2 mo ago |
| 14 | Loads a missing environment variable or API key from the team's Infisical workspace into the current shell, or runs a command with all project secrets injected. | Devin-AXIS/ | 6.8k | 1 repo | ~516 | Automated safety check: Pass | Unknown | yesterday |
| 15 | Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review. | Jeffallan/ | 12k | — | ~1.3k | Automated safety check: Pass | MIT | 7 days ago |
| 16 | Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works. | nanocoai/ | 31k | — | ~598 | Automated safety check: Pass | MIT | yesterday |
| 17 | Azure Key Vault Secrets Java SDK for secret management. An agent skill from microsoft/skills. | microsoft/ | 3.1k | 5 repos | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 18 | How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes. | ibuilder/ | 122 | — | ~1.7k | Automated safety check: Pass | MIT | 2 days ago |
| 19 | Azure Key Vault Keys SDK for .NET. An agent skill from microsoft/skills. | microsoft/ | 3.1k | 5 repos | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 20 | Working on RedAmon's supply-chain scanner (offline OSV + GuardDog + retire + trufflehog): the offline OSV database that the scan path does not bootstrap, the world-readable requirement for the… | samugit83/ | 3k | — | ~855 | Automated safety check: Pass | MIT | 2 days ago |
| 21 | Static security review for Flutter mobile apps and Dart code: hardcoded secrets, insecure storage, unsafe network calls, leaky logs, vulnerable dependencies. | VeryGoodOpenSource/ | 170 | — | ~4.4k | Automated safety check: Notes | MIT | 5 days ago |
| 22 | Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates. | utkusen/ | 1.3k | — | ~6.5k | Automated safety check: Notes | MIT | 6 mo ago |
| 23 | Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection. | arpitg1304/ | 369 | — | ~7.8k | Automated safety check: Warn | Apache-2.0 | 2 mo ago |
| 24 | 24.Sast Bandit Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. | AgentSecOps/ | 220 | 1 repo | ~2.6k | Automated safety check: Pass | Unknown | 5 mo ago |
| 25 | AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching… | github/ | 40k | 1 repo | ~2.3k | Automated safety check: Notes | MIT | 2 days ago |
| 26 | Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory… | unxed/ | 243 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | yesterday |
| 27 | Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | RLS validation, security audits, OWASP compliance, and vulnerability scanning. | bybren-llc/ | 423 | — | ~1.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 30 | Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold… | warpdotdev/ | 312 | 1 repo | ~2k | Automated safety check: Notes | MIT | 23 days ago |
| 31 | Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible-travel patterns, and credential-stuffing indicators using GuardDuty, Microsoft… | mukul975/ | 34k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 33 | Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates, with automatic generation, lease management, and rotation to eliminate static secrets… | mukul975/ | 34k | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills. | rampstackco/ | 945 | — | ~3k | Automated safety check: Pass | MIT | 4 days ago |
| 36 | Review Next.js security audit patterns for App Router and Server Actions. | IgorWarzocha/ | 122 | — | ~1.5k | Automated safety check: Notes | No licence | 8 mo ago |
| 37 | Run Azure compliance and security audits with azqr plus Key Vault expiration checks. | microsoft/ | 255 | 2 repos | ~997 | Automated safety check: Pass | MIT | yesterday |
| 38 | Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed… | mukul975/ | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints | uphiago/ | 1.3k | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 40 | Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management. | rand/ | 181 | — | ~1.9k | Automated safety check: Pass | MIT | 7 mo ago |
| 41 | Audit MCP (Model Context Protocol) server configurations for security issues. | github/ | 40k | — | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 42 | Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows. | IgorWarzocha/ | 122 | — | ~1.2k | Automated safety check: Notes | No licence | 8 mo ago |
| 43 | [omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and… | rlaope/ | 3.2k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 44 | Azure Key Vault SDK for Python. An agent skill from microsoft/skills. | microsoft/ | 3.1k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 45 | DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning… | modu-ai/ | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 46 | 46.Osint Open-source intelligence gathering - company repository enumeration, secret scanning, git history analysis, employee footprint, and code exposure discovery. | transilienceai/ | 563 | — | ~494 | Automated safety check: Notes | MIT | 2 mo ago |
| 47 | A skill your agent uses when the user says 'scan for secrets', 'check for leaked keys', 'secrets scanner', 'hardcoded credentials', 'API key leak', or needs to detect exposed secrets in source code. | cwinvestments/ | 423 | — | ~6k | Automated safety check: Notes | Proprietary | 14 days ago |
| 48 | ANALYSIS SKILL — Azure compliance and security auditing: best practices, Key Vault expiration monitoring, resource validation. | jonathan-vella/ | 217 | — | ~1.6k | Automated safety check: Pass | MIT | yesterday |