Search
Penetration testing
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 98 | Simulates ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risk and validate Dynamic ARP… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 99 | Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 100 | Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, and payload obfuscation to smuggle SQL injection, XSS, and other exploit payloads… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 101 | Hardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 102 | Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 103 | Triages and prioritizes vulnerabilities with CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree, weighing exploitation status (via the CISA KEV catalog and FIRST EPSS… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 104 | A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. | alirezarezvani/ | 28k | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 105 | 105.Nmap Parse Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills. | SpecterOps/ | 706 | — | ~738 | Automated safety check: Pass | Apache-2.0 | 17 days ago |
| 106 | Cracks password hashes with Hashcat, covering hash-type identification, dictionary/brute-force/rule-based attack modes, custom rule creation, GPU benchmarking, and password-strength/compliance… | mukul975/ | 34k | — | ~893 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 107 | Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains | NeoTheCapt/ | 143 | — | ~608 | Automated safety check: Pass | No licence | 2 mo ago |
| 108 | A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before… | hypnguyen1209/ | 388 | — | ~660 | Automated safety check: Pass | MIT | 13 days ago |
| 109 | Application security defense knowledge for builders. An agent skill from telagod/code-abyss. | telagod/ | 244 | — | ~777 | Automated safety check: Pass | MIT | 2 mo ago |
| 110 | Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom protocols to reverse-engineer beacon patterns, command structures, data encoding, and infrastructure (primary servers, fallback… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 111 | Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 112 | Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 113 | Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 114 | Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning… | mukul975/ | 34k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 115 | Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 116 | Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 117 | Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 118 | Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 119 | Performs advanced network recon using Nmap's Scripting Engine (NSE), timing controls, firewall/IDS evasion, and structured output parsing to discover hosts, enumerate service versions, detect… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 120 | Audit SillyTavern rolecard JSON, embedded HTML, regex replacements, Tavern Helper scripts, loaders, and related source for injection, dynamic execution, remote-code, wildcard messaging… | LiarMTTT/ | 154 | — | ~993 | Automated safety check: Pass | Unknown | 7 days ago |
| 121 | This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp ... | aiskillstore/ | 433 | 4 repos | ~2.7k | Automated safety check: Pass | No licence | yesterday |
| 122 | 122.Secure By Design Run an enterprise security review of a system design or existing code before it ships. | ooiyeefei/ | 495 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 123 | Discover hidden parameters, test values, and identify input handling anomalies | NeoTheCapt/ | 143 | — | ~944 | Automated safety check: Pass | No licence | 2 mo ago |
| 124 | Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's… | mukul975/ | 34k | — | ~963 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 125 | 125.File Inclusion Detect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution | NeoTheCapt/ | 143 | — | ~988 | Automated safety check: Warn | No licence | 2 mo ago |
| 126 | 126.Network Scanner Run authorized network reconnaissance with Nmap on Windows (or Linux). | ptn1411/ | 219 | — | ~1.4k | Automated safety check: Notes | No licence | 19 days ago |
| 127 | 127.Offensive Wifi Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. | SnailSploit/ | 7.4k | — | ~2.8k | Automated safety check: Notes | MIT | 21 days ago |
| 128 | 128.Screenshot Burp Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 129 | AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and… | modu-ai/ | 1.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 130 | A skill your agent uses when conducting a frontend security review — static analysis (risky HTML patterns, env var exposure), authentication/authorization audit (token storage, route guards… | mizchi/ | 360 | — | ~1.7k | Automated safety check: Notes | No licence | 9 days ago |
| 131 | 131.Port Scanning Discover open ports, running services, and their versions on a target | NeoTheCapt/ | 143 | — | ~634 | Automated safety check: Pass | No licence | 2 mo ago |
| 132 | Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill. | ptn1411/ | 219 | — | ~1.1k | Automated safety check: Pass | No licence | 19 days ago |
| 133 | Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 134 | Read findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable- grade markdown vulnerability report with per-finding sections (title… | jeremylongshore/ | 2.8k | — | ~1.9k | Automated safety check: Notes | MIT | yesterday |
| 135 | Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report. | jeremylongshore/ | 2.8k | — | ~2.2k | Automated safety check: Notes | MIT | yesterday |
| 136 | 136.Securing Systems Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research. | telagod/ | 244 | — | ~581 | Automated safety check: Pass | MIT | 2 mo ago |
| 137 | CORS misconfiguration testing playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.4k | Automated safety check: Pass | MIT | 28 days ago |
| 138 | Subdomain takeover detection and exploitation playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.6k | Automated safety check: Pass | MIT | 28 days ago |
| 139 | Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. | SnailSploit/ | 7.4k | — | ~5k | Automated safety check: Pass | MIT | 21 days ago |
| 140 | Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. | aws/ | 2.8k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 141 | 141.Hunt Burp Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)… | Encod3d-Sec/ | 329 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 142 | 142.Metasploit Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup… | Encod3d-Sec/ | 329 | — | ~1k | Automated safety check: Pass | MIT | 1 mo ago |
| 143 | 143.Cryptography Cryptanalysis techniques — lattice attacks, padding oracles, weak-RNG exploitation, signature forgery, secret-sharing recovery. | transilienceai/ | 563 | — | ~465 | Automated safety check: Pass | MIT | 2 mo ago |
| 144 | 144.Security Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries… | telagod/ | 244 | — | ~907 | Automated safety check: Pass | MIT | 2 mo ago |