Search

Web application vulnerabilities

464 skills found, page 4.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
145

Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

ArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.01 mo ago
146

Security-focused review for frontend/Web3 code. An agent skill from hyperlane-xyz/hyperlane-explorer.

hyperlane-xyz/hyperlane-explorer102—~185Automated safety check: PassUnknownyesterday
147

Comprehensive API security review against OWASP API Security Top 10 (2023).

OWASP/secure-agent-playbook188—~744Automated safety check: PassCC-BY-4.015 days ago
148

Web vulnerability hunting playbook. An agent skill from PentesterFlow/agent.

PentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.01 mo ago
149

Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition.

bbartling/open-fdd173—~2.2kAutomated safety check: PassUnknowntoday
150

Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations.

affaan-m/ECC277k1 repo~6.7kAutomated safety check: NotesMITtoday
151

Black-box security audit of a DEPLOYED AI agent (not the MCP server behind it) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR…

awarexone/Agentic-Bug-Hunter5.3k—~1.1kAutomated safety check: PassMITyesterday
152

Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

ohmyjahh/xquads-squads277—~895Automated safety check: PassMIT12 days ago
153

Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection.

AgentSecOps/SecOpsAgentKit2201 repo~3.7kAutomated safety check: PassUnknown5 mo ago
154

Systematically reviews code for SQL injection, XSS, SSRF, broken access control, cryptographic failures, and other common OWASP Top 10 vulnerabilities, providing vulnerable code examples and…

zebbern/claude-code-guide4.7k—~4.7kAutomated safety check: PassMITyesterday
155

Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology

RightNow-AI/openfang18k—~858Automated safety check: PassApache-2.03 mo ago
156

Suede AI findings-only code review with full context: changed files, callers, contracts, and deploy surface.

JasonColapietro/suede-creator-skills127—~7.1kAutomated safety check: PassMITyesterday
157

Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle).

totvs/engpro-advpl-tlpp-skills143—~3.5kAutomated safety check: PassMIT5 days ago
158

Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies…

eser/stack128—~598Automated safety check: PassUnknown7 days ago
159

Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署. An agent skill from affaan-m/ECC.

affaan-m/ECC277k1 repo~1.3kAutomated safety check: PassMITtoday
160

Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

affaan-m/ECC277k1 repo~3.2kAutomated safety check: NotesMITtoday
161

API design conventions, namespace coordinate system, RBAC roles, ClawHub compatibility layer, OpenAPI contract sync rules, and CSRF/session handling.

iflytek/skillhub5.2k—~1.3kAutomated safety check: PassApache-2.0yesterday
162

Security-focused code review mapped to OWASP Top 10 and ASVS.

OWASP/secure-agent-playbook188—~549Automated safety check: PassCC-BY-4.015 days ago
163

Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks.

github/awesome-copilot40k1 repo~3kAutomated safety check: PassMIT2 days ago
164

Quality standards for Salesforce Lightning Web Components (LWC), Aura components, and Visualforce pages.

github/awesome-copilot40k1 repo~2.4kAutomated safety check: PassMIT2 days ago
165

Deep security scanning for .NET applications across 6 layers: vulnerable packages, secrets detection, OWASP code patterns, auth configuration, CORS policy, and data protection.

codewithmukesh/dotnet-claude-kit7561 repo~1.3kAutomated safety check: PassMIT2 mo ago
166

Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from…

elementalsouls/Claude-BugHunter4.8k—~2.6kAutomated safety check: PassMITyesterday
167

全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…

staruhub/ClaudeSkills728—~1.3kAutomated safety check: NotesMIT1 mo ago
168

Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

AgentSecOps/SecOpsAgentKit2201 repo~2.6kAutomated safety check: PassUnknown5 mo ago
169

Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions.

AgentSecOps/SecOpsAgentKit2201 repo~2.8kAutomated safety check: PassUnknown5 mo ago
170

Automated SQL injection detection and exploitation tool for web application security testing.

AgentSecOps/SecOpsAgentKit2201 repo~3.2kAutomated safety check: PassUnknown5 mo ago
171
171.007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

sickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMIT2 days ago
172
172.Security ReviewOfficial

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

github/awesome-copilot40k1 repo~2.3kAutomated safety check: NotesMIT2 days ago
173

Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

unxed/f42432 repos~3.6kAutomated safety check: PassMITyesterday
174

Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
175

Integrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
176

Web vulnerability scanning workflow covering SQLi, XSS, template injection, and generic CVE detection using nuclei, sqlmap, dalfox, nikto, and jaeles

CommonHuman-Lab/nyxstrike157—~896Automated safety check: PassUnknownyesterday
177

RLS validation, security audits, OWASP compliance, and vulnerability scanning.

bybren-llc/safe-agentic-workflow423—~1.4kAutomated safety check: PassMIT2 mo ago
178

Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering…

cdxgen/cdxgen1.1k—~2.5kAutomated safety check: PassApache-2.0yesterday
179

IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

Encod3d-Sec/TORCH329—~2.6kAutomated safety check: PassMIT1 mo ago
180

A skill your agent uses for security reviews of VoxBento code.

fossasia/eventyay-interpretation1.6k—~1.3kAutomated safety check: PassApache-2.06 days ago
181

A skill your agent uses when the user needs to build, choose the pattern for, or optimize a SQL query against Protheus ERP tables -- covering Workarea (DbSelectArea/DbSeek) vs Embedded SQL vs…

thalysjuvenal/advpl-specialist186—~594Automated safety check: PassMIT27 days ago
182

检查 SQL 注入、XSS、硬编码密钥

liuyanghejerry/Clausura204—~106Automated safety check: PassMIT12 days ago
183

Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

dzhalaevd/Donatello135—~5.1kAutomated safety check: NotesApache-2.07 days ago
184

Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

sickn33/agentic-awesome-skills47k1 repo~1.5kAutomated safety check: PassMIT2 days ago
185

Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts.

mukul975/Anthropic-Cybersecurity-Skills34k—~581Automated safety check: PassApache-2.01 mo ago
186

Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
187

Detect API enumeration attacks (BOLA/IDOR, OWASP API1:2023) by writing SIEM detection rules that flag sequential or UUID identifier iteration, parameter tampering, and mixed 200/401/403 response…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.01 mo ago
188

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization (BOPLA), covering excessive data exposure in API responses and mass assignment via injected request-body properties.

mukul975/Anthropic-Cybersecurity-Skills34k—~4kAutomated safety check: PassApache-2.01 mo ago
189

Implements API security testing on the 42Crunch platform, combining API Audit for static analysis of OpenAPI definitions, API Conformance Scan for dynamic vulnerability testing, and API Protect for…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
190

Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
191

Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
192

Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago