Search

Security · Web application vulnerabilities

405 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Hardens code against vulnerabilities. An agent skill from penpot/penpot.

penpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0yesterday
2

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

eigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0yesterday
3

A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

jewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT4 mo ago
4

Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

usestrix/strix68k—~1.1kAutomated safety check: PassApache-2.0yesterday
5

Professional code security audit skill covering 55+ vulnerability types.

3stoneBrother/code-audit8921 repo~2.7kAutomated safety check: PassNo licence7 mo ago
6

Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

usestrix/strix68k—~1.5kAutomated safety check: PassApache-2.0yesterday
7

Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

awarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMITyesterday
8

A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.

tradecatlabs/vibe-coding-cn17k2 repos~3.3kAutomated safety check: PassMITtoday
9

WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

tanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassUnknown2 mo ago
10

Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept.

usestrix/strix68k—~1.6kAutomated safety check: PassApache-2.0yesterday
11

Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

awarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMITyesterday
12

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

ruvnet/ruflo74k2 repos~823Automated safety check: PassMITtoday
13
13.Security ReviewOfficial

Security code review for vulnerabilities. An agent skill from getsentry/skills.

getsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0yesterday
14

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

nyldn/claude-octopus4.2k1 repo~2.3kAutomated safety check: PassMITyesterday
15

Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing.

skjolber/3d-bin-container-packing569—~886Automated safety check: PassApache-2.0today
16

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

fengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT25 days ago
17

Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.

PentesterFlow/agent1.4k—~1.7kAutomated safety check: PassApache-2.01 mo ago
18

Reviews code for security vulnerabilities and guides secure implementation using OWASP Top 10:2025, ASVS 5.0, the OWASP Top 10 for LLM Applications (2026), and the OWASP Top 10 for Agentic…

agamm/claude-code-owasp377—~3.5kAutomated safety check: PassMIT15 days ago
19

Security audit for web apps, especially AI-built ("vibe coded") ones.

benavlabs/vibe-check118—~1.1kAutomated safety check: NotesMIT21 days ago
20

Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

jeremylongshore/tons-of-skills-marketplace2.8k2 repos~1.3kAutomated safety check: NotesMITtoday
21

Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

Pa55w0rd/secknowledge-skill425—~2.7kAutomated safety check: PassNo licence3 mo ago
22

Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

trailofbits/skills7.5k3 repos~4.2kAutomated safety check: NotesCC-BY-SA-4.0today
23

Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

gocronx-team/gocron801—~690Automated safety check: PassMITyesterday
24

Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

EpicenterHQ/epicenter4.8k—~896Automated safety check: PassUnknown2 days ago
25

Django access control and IDOR security review. An agent skill from getsentry/skills.

getsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0yesterday
26

渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。

Arenbai/SecSkills253—~1.8kAutomated safety check: NotesMIT11 days ago
27

Rates a threat against the OWASP Risk Rating Methodology, then rates it again counting only the mitigations that are implemented and verified, and again counting dated commitments, and shows the…

TracecatHQ/tracecat3.8k—~6.9kAutomated safety check: PassMITtoday
28

Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make…

justrach/kuri365—~1.3kAutomated safety check: NotesUnknownyesterday
29

Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…

samugit83/redamon3k—~1.4kAutomated safety check: PassMIT2 days ago
30

Security-focused code review checklist and automated scanning patterns.

nicepkg/auto-company1951 repo~3.9kAutomated safety check: PassMIT8 mo ago
31

Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

addyosmani/agent-skills104k1 repo~4.4kAutomated safety check: NotesMIT7 days ago
32
32.Sail

Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.

pillar-labs/sail-skill113—~5.1kAutomated safety check: PassUnknown3 mo ago
33

Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

Hainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT2 mo ago
34

Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets.

Tencent/AI-Infra-Guard6.8k—~1.5kAutomated safety check: NotesApache-2.0yesterday
35
35.Sentry SecurityOfficial

Sentry-specific security review based on real vulnerability history.

getsentry/sentry46k—~2.3kAutomated safety check: NotesUnknowntoday
36

Runs and interprets Psalm security (taint) analysis on a Laravel project.

cachethq/core230—~4.7kAutomated safety check: PassUnknown5 days ago
37

Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

zebbern/claude-code-guide4.7k—~1.3kAutomated safety check: PassMITtoday
38

Automate low-impact web vulnerability verification through Burp MCP.

langbyyi/CyberStrikeAI-SRC129—~3.1kAutomated safety check: PassApache-2.03 days ago
39

A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…

LIDR-academy/AI4Devs-LTI-extended278—~4.3kAutomated safety check: NotesMIT4 mo ago
40

Security audit checklist based on OWASP Top 10 and best practices.

unxed/f4243—~5.4kAutomated safety check: NotesBSD-3-Clausetoday
41

Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

thomast1906/github-copilot-agent-skills202—~3.1kAutomated safety check: PassMIT3 days ago
42

Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

Encod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT1 mo ago
43

Security hardening toolkit for OpenClaw. An agent skill from adversa-ai/secureclaw.

adversa-ai/secureclaw3471 repo~193Automated safety check: PassMIT6 mo ago
44

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

zebbern/claude-code-guide4.7k8 repos~3.1kAutomated safety check: PassMITtoday
45

Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

AgriciDaniel/claude-cybersecurity228—~11kAutomated safety check: WarnMIT5 mo ago
46

Diagnose and repair OpenASE CLI access in local bootstrap mode.

PacificStudio/openase268—~778Automated safety check: PassApache-2.02 mo ago
47

Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis.

s0ld13rr/pentestcode828—~2.9kAutomated safety check: PassMIT8 days ago
48

Use before shipping to production. An agent skill from garagon/nanostack.

garagon/nanostack207—~3.7kAutomated safety check: NotesApache-2.01 mo ago