Search
Security · Web application vulnerabilities
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Hardens code against vulnerabilities. An agent skill from penpot/penpot. | penpot/ | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | yesterday |
| 2 | Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist. | eigent-ai/ | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 3 | A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. | jewbetcha/ | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 4 | Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept. | usestrix/ | 68k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 5 | Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 892 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 6 | Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works. | usestrix/ | 68k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 7 | Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments. | awarexone/ | 5.3k | 2 repos | ~4.7k | Automated safety check: Pass | MIT | yesterday |
| 8 | A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol. | tradecatlabs/ | 17k | 2 repos | ~3.3k | Automated safety check: Pass | MIT | today |
| 9 | WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws… | tanweai/ | 1.8k | — | ~1.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 10 | Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept. | usestrix/ | 68k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 11 | Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet. | awarexone/ | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | yesterday |
| 12 | Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report. | ruvnet/ | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | today |
| 13 | Security code review for vulnerabilities. An agent skill from getsentry/skills. | getsentry/ | 1k | 4 repos | ~2.9k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 14 | OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews | nyldn/ | 4.2k | 1 repo | ~2.3k | Automated safety check: Pass | MIT | yesterday |
| 15 | 15.Maven Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing. | skjolber/ | 569 | — | ~886 | Automated safety check: Pass | Apache-2.0 | today |
| 16 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 25 days ago |
| 17 | Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization. | PentesterFlow/ | 1.4k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Reviews code for security vulnerabilities and guides secure implementation using OWASP Top 10:2025, ASVS 5.0, the OWASP Top 10 for LLM Applications (2026), and the OWASP Top 10 for Agentic… | agamm/ | 377 | — | ~3.5k | Automated safety check: Pass | MIT | 15 days ago |
| 19 | 19.Vibe Check Security audit for web apps, especially AI-built ("vibe coded") ones. | benavlabs/ | 118 | — | ~1.1k | Automated safety check: Notes | MIT | 21 days ago |
| 20 | Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. | jeremylongshore/ | 2.8k | 2 repos | ~1.3k | Automated safety check: Notes | MIT | today |
| 21 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 425 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 22 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.5k | 3 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 23 | Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. | gocronx-team/ | 801 | — | ~690 | Automated safety check: Pass | MIT | yesterday |
| 24 | Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. | EpicenterHQ/ | 4.8k | — | ~896 | Automated safety check: Pass | Unknown | 2 days ago |
| 25 | Django access control and IDOR security review. An agent skill from getsentry/skills. | getsentry/ | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 26 | 26.Secskills 渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。 | Arenbai/ | 253 | — | ~1.8k | Automated safety check: Notes | MIT | 11 days ago |
| 27 | Rates a threat against the OWASP Risk Rating Methodology, then rates it again counting only the mitigations that are implemented and verified, and again counting dated commitments, and shows the… | TracecatHQ/ | 3.8k | — | ~6.9k | Automated safety check: Pass | MIT | today |
| 28 | 28.Kuri Agent Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make… | justrach/ | 365 | — | ~1.3k | Automated safety check: Notes | Unknown | yesterday |
| 29 | Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged… | samugit83/ | 3k | — | ~1.4k | Automated safety check: Pass | MIT | 2 days ago |
| 30 | Security-focused code review checklist and automated scanning patterns. | nicepkg/ | 195 | 1 repo | ~3.9k | Automated safety check: Pass | MIT | 8 mo ago |
| 31 | Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data. | addyosmani/ | 104k | 1 repo | ~4.4k | Automated safety check: Notes | MIT | 7 days ago |
| 32 | 32.Sail Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. | pillar-labs/ | 113 | — | ~5.1k | Automated safety check: Pass | Unknown | 3 mo ago |
| 33 | 33.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 283 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 34 | Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets. | Tencent/ | 6.8k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 35 | Sentry-specific security review based on real vulnerability history. | getsentry/ | 46k | — | ~2.3k | Automated safety check: Notes | Unknown | today |
| 36 | Runs and interprets Psalm security (taint) analysis on a Laravel project. | cachethq/ | 230 | — | ~4.7k | Automated safety check: Pass | Unknown | 5 days ago |
| 37 | Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection. | zebbern/ | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 38 | Automate low-impact web vulnerability verification through Burp MCP. | langbyyi/ | 129 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 39 | A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a… | LIDR-academy/ | 278 | — | ~4.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 40 | Security audit checklist based on OWASP Top 10 and best practices. | unxed/ | 243 | — | ~5.4k | Automated safety check: Notes | BSD-3-Clause | today |
| 41 | Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity. | thomast1906/ | 202 | — | ~3.1k | Automated safety check: Pass | MIT | 3 days ago |
| 42 | Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 43 | 43.Secureclaw Security hardening toolkit for OpenClaw. An agent skill from adversa-ai/secureclaw. | adversa-ai/ | 347 | 1 repo | ~193 | Automated safety check: Pass | MIT | 6 mo ago |
| 44 | 44.Idor Testing This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"… | zebbern/ | 4.7k | 8 repos | ~3.1k | Automated safety check: Pass | MIT | today |
| 45 | Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity. | AgriciDaniel/ | 228 | — | ~11k | Automated safety check: Warn | MIT | 5 mo ago |
| 46 | Diagnose and repair OpenASE CLI access in local bootstrap mode. | PacificStudio/ | 268 | — | ~778 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 47 | Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis. | s0ld13rr/ | 828 | — | ~2.9k | Automated safety check: Pass | MIT | 8 days ago |
| 48 | 48.Security Use before shipping to production. An agent skill from garagon/nanostack. | garagon/ | 207 | — | ~3.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |