Search

Security · Vulnerability scanning

286 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

eigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0yesterday
2
2.Skill InspectorOfficial

Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

NVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0yesterday
3

A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

payloadcms/payload45k—~2.8kAutomated safety check: PassMITyesterday
4

Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.

vercel-labs/deepsec8.1k—~1.2kAutomated safety check: PassApache-2.011 days ago
5

Professional code security audit skill covering 55+ vulnerability types.

3stoneBrother/code-audit8921 repo~2.7kAutomated safety check: PassNo licence8 mo ago
6

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0yesterday
7

Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

vercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.011 days ago
8

当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

SummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT4 mo ago
9

A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

vulnersCom/api376—~2.3kAutomated safety check: PassMIT12 days ago
10

Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

rundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0yesterday
11

Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter).

symfony/symfony31k—~2.6kAutomated safety check: PassMITtoday
12

Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

mono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMITyesterday
13

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

nyldn/claude-octopus4.2k1 repo~2.3kAutomated safety check: PassMITtoday
14

Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.

context-labs/whip1.1k2 repos~3kAutomated safety check: PassMIT6 days ago
15

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

fengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT25 days ago
16

Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

alexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesUnknown14 days ago
17

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

ruvnet/ruflo74k1 repo~823Automated safety check: PassMITtoday
18

Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and…

activepieces/activepieces25k—~2.9kAutomated safety check: PassUnknowntoday
19

Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

Pa55w0rd/secknowledge-skill425—~2.7kAutomated safety check: PassNo licence3 mo ago
20

Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

gocronx-team/gocron801—~690Automated safety check: PassMITyesterday
21

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

ParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0today
22

Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

evdenis/cvehound138—~2.5kAutomated safety check: PassGPL-3.02 days ago
23

Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

TheDecipherist/claude-code-mastery551—~1.3kAutomated safety check: NotesMIT5 mo ago
24

Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

tradecatlabs/vibe-coding-cn17k1 repo~738Automated safety check: PassApache-2.0yesterday
25

Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity.

activepieces/activepieces25k—~3.6kAutomated safety check: PassUnknowntoday
26

A skill your agent uses when scanning code for security vulnerabilities.

tanviet12/vbsec289—~5.3kAutomated safety check: NotesMIT13 days ago
27

渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。

Arenbai/SecSkills253—~1.8kAutomated safety check: NotesMIT12 days ago
28

Triage Apache Roller security reports, maintain private case tracking, prepare CVE records, coordinate fixes and reporter review, and prepare disclosure with a release.

apache/roller133—~1.9kAutomated safety check: PassApache-2.0today
29

Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

karimhabush/cyberowl263—~2.5kAutomated safety check: PassMITtoday
30

Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

zereight/gitlab-mcp2k1 repo~859Automated safety check: NotesMITtoday
31

Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.

openplayerjs/openplayerjs649—~1kAutomated safety check: PassMIT5 days ago
32

Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

garrytan/gstack136k—~4.5kAutomated safety check: PassMITtoday
33

Triage a security finding in a Symfony UX package into a disposition: a private CVE (coordinated disclosure through the Symfony security process), a public hardening PR (fix in the open, no CVE), or…

symfony/ux1.1k—~3.2kAutomated safety check: PassMITtoday
34

Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

aliyun/alibabacloud-ecs-troubleshoot-skills148—~2.4kAutomated safety check: NotesApache-2.01 mo ago
35

A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

chaitin/chaitin-cli115—~15kAutomated safety check: NotesGPL-3.012 days ago
36

Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

block/codecrucible117—~1.2kAutomated safety check: PassApache-2.04 days ago
37
37.Handle CveOfficial

A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR.

DataDog/dd-trace-rb417—~2.6kAutomated safety check: PassUnknownyesterday
38

A skill your agent uses when scanning code for security vulnerabilities.

tanviet12/vbsec289—~6.8kAutomated safety check: NotesMIT13 days ago
39

Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…

MidnightBSD/src114—~2.2kAutomated safety check: PassUnknownyesterday
40

Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

eclipse-ankaios/ankaios125—~1.5kAutomated safety check: PassApache-2.0yesterday
41

Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

Hainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT2 mo ago
42

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassUnknown5 mo ago
43

Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

aliyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.01 mo ago
44

Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

zebbern/claude-code-guide4.7k—~1.3kAutomated safety check: PassMITyesterday
45
45.Docs

Update project documentation when features are added or changed.

boostsecurityio/poutine523—~336Automated safety check: PassApache-2.0yesterday
46

Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.

Tencent/AI-Infra-Guard6.8k—~1.8kAutomated safety check: PassApache-2.0yesterday
47

A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…

LIDR-academy/AI4Devs-LTI-extended278—~4.3kAutomated safety check: NotesMIT4 mo ago
48

This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware"…

zebbern/claude-code-guide4.7k8 repos~3.4kAutomated safety check: NotesMITyesterday