Search
By cyberful
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence. | cyberful/ | 135 | — | ~649 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 2 | Audit Kubernetes admission and policy-as-code enforcement against local workload manifests, exception paths, namespace scope, and deployment evidence. | cyberful/ | 135 | — | ~610 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 3 | Audit PCI DSS penetration-test methodology, scope, internal and external reports, segmentation results, tester independence, remediation, retesting, retention, and multi-tenant support evidence. | cyberful/ | 135 | — | ~1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 4 | Design and interpret advanced content discovery with ffuf and complementary web fuzzers. | cyberful/ | 135 | — | ~1.5k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 5 | Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 6 | Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits. | cyberful/ | 135 | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 7 | Operate Syft, Grype, Trivy, Gitleaks, Retire.js, package-manager metadata, and build evidence for advanced software-supply-chain assessment. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 8 | Assemble reviewed compliance evidence into a versioned, traceable draft report for PCI DSS or GDPR. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 9 | Assess race conditions, transactional invariants, idempotency, retries, replay, rate and quota enforcement, algorithmic complexity, resource amplification, and cost abuse during authorized… | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 10 | Test native or language object reconstruction, polymorphic type selection, gadget reachability, schema bypass, mass object binding, and unsafe serializer configuration in authorized applications or… | cyberful/ | 135 | — | ~654 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 11 | Assess WebSocket, Server-Sent Events, webhook, event-stream, callback, and asynchronous integration security during authorized penetration tests or code audits. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 12 | Test executable smart-contract properties with deterministic, offline Foundry harnesses over a confined source snapshot. | cyberful/ | 135 | — | ~745 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 13 | Test authorized web-cache key construction, variation, partitioning, authenticated response handling, revalidation, poisoning, deception, purge, and TTL behavior. | cyberful/ | 135 | — | ~631 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 14 | Trace how clients, CDNs, proxies, protocol translators, gateways, frameworks, and origins derive HTTP message boundaries, authority, paths, queries, and trusted forwarding metadata. | cyberful/ | 135 | — | ~711 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 15 | Deterministically compare OpenAPI JSON operations with implementation and observation inventories to expose undocumented, unimplemented, unexercised, and security-declaration coverage gaps. | cyberful/ | 135 | — | ~585 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 16 | Audit local AI model, adapter, tokenizer, configuration, and packaging artifacts for provenance, integrity, dependency, serialization, license, and loading-risk evidence. | cyberful/ | 135 | — | ~535 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 17 | Test whether authorized direct or indirect untrusted content can alter an AI system's protected behavior, context use, memory, retrieval, output handling, or downstream capability. | cyberful/ | 135 | — | ~538 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 18 | Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects. | cyberful/ | 135 | — | ~549 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 19 | Reconstruct how instructions, retrieved content, memory, identities, approvals, tool schemas, arguments, outputs, delegation, and fallbacks propagate through an AI system. | cyberful/ | 135 | — | ~517 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 20 | Extract bounded, deterministic evidence from crash and sanitizer logs, including signals, sanitizer classes, memory-safety indicators, stack-frame hashes, and source provenance, while reserving… | cyberful/ | 135 | — | ~563 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 21 | Normalize and compare authorized fraud-control observations from local evidence, highlighting decision drift, coverage gaps, and conflicting outcomes without making a fraud or vulnerability verdict. | cyberful/ | 135 | — | ~649 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 22 | Parse bounded classic PCAP files offline into deterministic capture metadata, packet-length and timestamp summaries, link and network protocol counts, truncation indicators, and source digests… | cyberful/ | 135 | — | ~590 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 23 | Model fraud and abuse threats across actors, account states, value flows, controls, and monetization paths. | cyberful/ | 135 | — | ~716 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 24 | Coordinate a PCI DSS penetration-testing and CDE-scoping readiness assessment across methodology, scope, segmentation, execution evidence, remediation, and retesting. | cyberful/ | 135 | — | ~895 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 25 | Assess the security of a smart-contract system across protocol economics, trust roles, upgrade and governance paths, oracle and bridge dependencies, deployment state, and off-chain operators. | cyberful/ | 135 | — | ~651 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 26 | Audit application database access layers for query construction, authorization placement, tenant scoping, transaction boundaries, consistency, credential authority, and observable durable effects. | cyberful/ | 135 | — | ~599 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 27 | Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures. | cyberful/ | 135 | — | ~637 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 28 | Audit extracted embedded firmware for boot and update trust, credential and secret handling, service exposure, privilege boundaries, parsers, persistence, cryptography, hardening, recovery, and… | cyberful/ | 135 | — | ~644 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 29 | Audit security logging and telemetry from event creation through transport, storage, access, correlation, retention, and response use. | cyberful/ | 135 | — | ~597 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 30 | Audit smart-contract source and build evidence for authorization, accounting, state-machine, external-call, upgrade, signature, oracle, token-integration, and denial-of-service defects. | cyberful/ | 135 | — | ~650 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 31 | Plan an authorized PCI DSS penetration test around the cardholder data environment, critical systems, internal and external coverage, segmentation, tester independence, remediation, retesting, and… | cyberful/ | 135 | — | ~943 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 32 | Test browser capability transfer across postMessage, opener, frame, portal, worker, service-worker, BroadcastChannel, MessagePort, and extension messaging boundaries. | cyberful/ | 135 | — | ~583 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 33 | Test whether every segmentation and scope-reduction control isolates the cardholder data environment from claimed out-of-scope systems and differing security levels. | cyberful/ | 135 | — | ~928 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 34 | Test application email generation, recipient authority, template and header construction, link and token binding, inbound parsing, threading, reply handling, bounce processing, and tenant isolation. | cyberful/ | 135 | — | ~599 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 35 | Test payment decision and value-movement invariants with authorized synthetic instruments and reversible sandbox transactions. | cyberful/ | 135 | — | ~668 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 36 | Test service accounts, OAuth clients, workload federation, token exchange, audience binding, delegated actors, credential rotation, and machine-identity authorization. | cyberful/ | 135 | — | ~895 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 37 | Trace uploaded, imported, generated, archived, converted, scanned, rendered, and downloaded files across storage, naming, extraction, parser, sandbox, and cleanup boundaries. | cyberful/ | 135 | — | ~646 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 38 | Reconstruct how principal, actor, issuer, audience, assurance, scopes, and delegated authority change across requests, tokens, services, queues, and stored artifacts. | cyberful/ | 135 | — | ~730 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 39 | Reconstruct how tenant and organization context is authenticated, selected, routed, cached, queued, and bound to resources across distributed request paths. | cyberful/ | 135 | — | ~679 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 40 | Reconstruct transaction state across services, ledgers, queues, and compensations from local artifacts, identifying causal gaps, duplicate effects, and value mismatches without active traffic. | cyberful/ | 135 | — | ~635 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 41 | Build or challenge an application threat model from architecture, dataflows, identities, trust boundaries, business invariants, dependencies, and deployment context. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 42 | Route broad AI-agent security reviews to focused Cyberful skills across risk, model supply chain, context and capabilities, prompt injection, tool authorization, and RAG isolation. | cyberful/ | 135 | — | ~723 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 43 | Audit whether API handlers, gateways, serializers, validators, and generated clients implement the effective contract and its security invariants. | cyberful/ | 135 | — | ~666 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 44 | Coordinate a repository-wide white-box application security audit across architecture, source, configuration, dependencies, build, and deployment paths. | cyberful/ | 135 | — | ~774 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 45 | Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk. | cyberful/ | 135 | — | ~829 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 46 | Coordinate an authorized software-supply-chain audit from dependency resolution through build, artifact, release, deployment, and runtime trust. | cyberful/ | 135 | — | ~737 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 47 | 47.Cyberful Operate Cyberful as an authorized application-security control room. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0-only | 1 mo ago |
| 48 | Operate Ghidra headless analysis, radare2, platform binary utilities, decompilers, and targeted dynamic evidence for advanced native and bytecode security review. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |