Search

Web application vulnerabilities

464 skills found, page 2.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…

LIDR-academy/AI4Devs-LTI-extended278—~4.3kAutomated safety check: NotesMIT4 mo ago
50

Security audit checklist based on OWASP Top 10 and best practices.

unxed/f4244—~5.4kAutomated safety check: NotesBSD-3-Clausetoday
51

Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

thomast1906/github-copilot-agent-skills202—~3.1kAutomated safety check: PassMIT3 days ago
52

Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

Encod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT1 mo ago
53

Security hardening toolkit for OpenClaw. An agent skill from adversa-ai/secureclaw.

adversa-ai/secureclaw3471 repo~193Automated safety check: PassMIT6 mo ago
54

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

zebbern/claude-code-guide4.7k8 repos~3.1kAutomated safety check: PassMITyesterday
55

Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

briiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT4 mo ago
56

A skill your agent uses when writing Playwright tests, fixing flaky tests, debugging failures, implementing Page Object Model, configuring CI/CD, optimizing performance, mocking APIs, handling…

sanity-io/sanity6.4k7 repos~6.4kAutomated safety check: PassMITyesterday
57

Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

AgriciDaniel/claude-cybersecurity228—~11kAutomated safety check: WarnMIT5 mo ago
58

Diagnose and repair OpenASE CLI access in local bootstrap mode.

PacificStudio/openase268—~778Automated safety check: PassApache-2.02 mo ago
59

Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis.

s0ld13rr/pentestcode828—~2.9kAutomated safety check: PassMIT8 days ago
60

初始化 OryxOS(或同类 JDK 21 + Spring Boot 3.x 企业级单体)的工程地基:Maven 多模块骨架、 结构化日志、Actuator + Prometheus 监控、Spring MVC + 虚拟线程、springdoc OpenAPI、 统一响应体与全局异常/错误码、Google 格式 + 阿里编码规约(Spotless + 阿里 P3C +…

oryx-labs/oryxos187—~1.6kAutomated safety check: PassApache-2.0today
61

Use before shipping to production. An agent skill from garagon/nanostack.

garagon/nanostack207—~3.7kAutomated safety check: NotesApache-2.01 mo ago
62

This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks"…

zebbern/claude-code-guide4.7k8 repos~6.1kAutomated safety check: PassMITyesterday
63

Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

deadlock-mod-manager/deadlock-mod-manager478—~1.8kAutomated safety check: PassCC-BY-SA-4.0yesterday
64

A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

ProgrammerAnthony/Expert-Coding-Harness235—~1.6kAutomated safety check: PassMIT5 mo ago
65

A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

jabrena/plinth447—~3.2kAutomated safety check: PassApache-2.03 days ago
66

This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through…

zebbern/claude-code-guide4.7k5 repos~2.9kAutomated safety check: PassMITyesterday
67

Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.

elementalsouls/Claude-BugHunter4.9k—~4.5kAutomated safety check: PassMITyesterday
68

Dual-model code review via Codex CLI. An agent skill from suyuan2022/suyuan-skill.

suyuan2022/suyuan-skill308—~3.5kAutomated safety check: WarnMIT1 mo ago
69

Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

Encod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT1 mo ago
70

CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。

0xShe/PHP-Code-Audit-Skill4021 repo~477Automated safety check: PassNo licence6 mo ago
71

Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses

NeoTheCapt/RedteamAgent143—~1.3kAutomated safety check: PassNo licence2 mo ago
72

A declarative routing engine that turns ticket / error attributes (reporter, label, project, area path, error class, environment) into a tag + AI agent + priority assignment, so cross-source…

aozyildirim/Agena103—~976Automated safety check: PassMIT2 days ago
73

Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.

xenitV1/Antigravity-Workflows1307 repos~1.8kAutomated safety check: NotesMIT8 mo ago
74

Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

cdxgen/cdxgen1.1k—~1.5kAutomated safety check: WarnApache-2.0today
75

A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

AratKruglik/claude-laravel1551 repo~1.1kAutomated safety check: NotesNo licence5 mo ago
76

AI 도구(Claude, ChatGPT, Cursor, Copilot)용 시큐어 코딩 프롬프트와 가이드를 생성합니다.

cdppcorp/KESE-KIT360—~1.3kAutomated safety check: PassMIT6 mo ago
77

Builds ASP.NET Core APIs, EF Core data access, gRPC, SignalR, and backend services with middleware, security (OAuth, JWT, OWASP), resilience, messaging, OpenAPI, .NET Aspire, Semantic Kernel…

novotnyllc/dotnet-artisan232—~1.6kAutomated safety check: PassMIT3 days ago
78

Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.

elementalsouls/Claude-BugHunter4.9k—~3.4kAutomated safety check: PassMITyesterday
79

Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for…

agutinbaigo28/financial-agent-api128—~2.7kAutomated safety check: PassNo licence27 days ago
80

Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3…

utkusen/sast-skills1.3k—~4.9kAutomated safety check: PassMIT6 mo ago
81

Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli.

kklimuk/docx-cli216—~1.7kAutomated safety check: PassMITtoday
82

Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.

awarexone/Agentic-Bug-Hunter5.3k3 repos~3.4kAutomated safety check: PassMITyesterday
83

Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

affaan-m/ECC277k5 repos~2kAutomated safety check: PassMITtoday
84

Run the full Spring Boot verification loop — Maven or Gradle build, SpotBugs, PMD, and Checkstyle static analysis, unit and Testcontainers integration tests with JaCoCo coverage, OWASP dependency…

affaan-m/ECC277k5 repos~1.5kAutomated safety check: PassMITtoday
85

Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager.

romshark/datapages114—~1.1kAutomated safety check: PassMITtoday
86

Perform a language-agnostic first-pass code review covering logic errors, bad practices, operation ordering, magic strings, pattern improvements, strict type checking, and SQL injection.

maiobarbero/my-ai-workflow140—~1.2kAutomated safety check: PassNo licence5 mo ago
87

Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.

bugbountywithmarco/bugbounty-disclosed-reports120—~550Automated safety check: PassNo licence2 mo ago
88

Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

SpecterOps/skills706—~2.4kAutomated safety check: PassApache-2.017 days ago
89

A skill your agent uses when the user asks to review, audit, or check the quality of ADVPL/TLPP code for TOTVS Protheus before merge or deploy -- covering best practices (RecLock/MsUnlock pairing…

thalysjuvenal/advpl-specialist186—~604Automated safety check: PassMIT26 days ago
90

A paranoid OWASP-Top-10-aware system prompt for AI code review that traces data flow, treats every input as malicious, maps each finding to an OWASP category, and outputs a structured Summary /…

aozyildirim/Agena103—~978Automated safety check: PassMIT2 days ago
91

当你需要开发/排查 HTTP 抓取、SSRF、Playwright 受控浏览器、本地字体增强截图,或判断 webfetch 与 browser 工作流如何选型时使用。

xrkseek/XRK-AGT138—~1.3kAutomated safety check: PassMIT10 days ago
92
92.Code SecurityOfficial

Security guidelines for writing secure code. An agent skill from semgrep/skills.

semgrep/skills324—~1.2kAutomated safety check: PassUnknown2 mo ago
93

Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

skrun-dev/skrun210—~1.3kAutomated safety check: PassMIT18 days ago
94

Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

vinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT3 mo ago
95
95.Auth Store DebugOfficial

Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCALREADONLY, Redis vs memory store, keyspace namespacing, and metadata shape migrations.

vercel-labs/vercel-openclaw-archived117—~465Automated safety check: PassMIT4 mo ago
96

Houndarr's pytest patterns. An agent skill from av1155/houndarr.

av1155/houndarr292—~1kAutomated safety check: PassAGPL-3.05 days ago