Search

Security · Security review

550 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

eigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0yesterday
2

A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

jewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT4 mo ago
3

Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

usestrix/strix68k—~1.1kAutomated safety check: PassApache-2.0today
4

Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.

vercel-labs/deepsec8.1k—~1.2kAutomated safety check: PassApache-2.012 days ago
5

Professional code security audit skill covering 55+ vulnerability types.

3stoneBrother/code-audit8921 repo~2.7kAutomated safety check: PassNo licence8 mo ago
6

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0yesterday
7

Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

vercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.012 days ago
8

WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

tanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassUnknown2 mo ago
9

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknown2 days ago
10

Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

kubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0yesterday
11

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

trailofbits/skills7.5k—~3.4kAutomated safety check: PassCC-BY-SA-4.0yesterday
12

A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

solana-foundation/solana-dev-skill573—~3.8kAutomated safety check: PassMIT2 days ago
13

Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

awarexone/Agentic-Bug-Hunter5.3k1 repo~2.4kAutomated safety check: PassMITyesterday
14
14.Security ReviewOfficial

Security code review for vulnerabilities. An agent skill from getsentry/skills.

getsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0yesterday
15

Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

luongnv89/claude-howto42k—~764Automated safety check: PassMITtoday
16

Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

mono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMITyesterday
17

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

nyldn/claude-octopus4.2k1 repo~2.3kAutomated safety check: PassMITtoday
18

Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.

symfony/symfony31k—~2.9kAutomated safety check: PassMITtoday
19

Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

ZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMIT2 days ago
20

Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

verdaccio/verdaccio18k—~853Automated safety check: PassMIT2 days ago
21

Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

tech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.02 days ago
22

Verify that code changes do not introduce OAuth security vulnerabilities.

doorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMITyesterday
23

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

ruvnet/ruflo74k1 repo~823Automated safety check: PassMITtoday
24

Security audit for web apps, especially AI-built ("vibe coded") ones.

benavlabs/vibe-check118—~1.1kAutomated safety check: NotesMIT22 days ago
25

Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

jeremylongshore/tons-of-skills-marketplace2.8k2 repos~1.3kAutomated safety check: NotesMITtoday
26

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

zebbern/claude-code-guide4.7k—~4.2kAutomated safety check: PassMITyesterday
27

Apply modern web development best practices for security, compatibility, and code quality.

midudev/100cosas.dev1143 repos~3kAutomated safety check: PassMIT12 days ago
28

Operates Flounder, an autonomous white-hat security auditor.

adshao/flounder518—~9.2kAutomated safety check: PassAGPL-3.05 days ago
29

Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

trailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0yesterday
30
30.Review SecurityOfficial

Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.

pydantic/monty8.6k—~852Automated safety check: PassMITtoday
31

Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

gocronx-team/gocron801—~690Automated safety check: PassMITyesterday
32

Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.

codexstar69/bug-hunter520—~5kAutomated safety check: PassMIT1 mo ago
33

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

ParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0yesterday
34

Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

EpicenterHQ/epicenter4.8k—~896Automated safety check: PassUnknown3 days ago
35

Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

Fangcun-AI/SkillWard143—~2.9kAutomated safety check: PassUnknown2 mo ago
36

Django access control and IDOR security review. An agent skill from getsentry/skills.

getsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0yesterday
37

Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files.

HarnessMD/munder-difflin8.6k—~350Automated safety check: NotesMITyesterday
38

Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

Gabson0x/bountyforge442—~3.7kAutomated safety check: PassNo licence24 days ago
39

Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

TheDecipherist/claude-code-mastery551—~1.3kAutomated safety check: NotesMIT5 mo ago
40

Run an authorized, local-first application security assessment on the current project using this agent's own reasoning.

stijnswapped/Myrqen137—~2.1kAutomated safety check: PassUnknown1 mo ago
41

A skill your agent uses when scanning code for security vulnerabilities.

tanviet12/vbsec289—~5.3kAutomated safety check: NotesMIT13 days ago
42

Run a pre-deployment security compliance checklist based on KISA guidelines.

cdppcorp/KESE-KIT360—~1.3kAutomated safety check: PassMIT6 mo ago
43

Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation.

obot-platform/obot1.1k—~1.3kAutomated safety check: PassMITtoday
44

A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…

agentlas-ai/Agentlas-OS1.6k—~822Automated safety check: PassApache-2.0today
45

Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.

rfc-st/humble379—~3.7kAutomated safety check: PassMITyesterday
46

Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

karimhabush/cyberowl263—~2.5kAutomated safety check: PassMITtoday
47

Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.

tihanyin/REx-skill108—~5.1kAutomated safety check: PassMIT17 days ago
48

Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

zereight/gitlab-mcp2k1 repo~859Automated safety check: NotesMITtoday