Search
Web application vulnerabilities
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 193 | Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 194 | Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web application audit logging, tuning SecRuleEngine, SecAuditEngine, and CRS paranoia levels to reduce false positives, and writing… | mukul975/ | 34k | — | ~615 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 195 | Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 196 | Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, and payload obfuscation to smuggle SQL injection, XSS, and other exploit payloads… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 197 | Triages web application vulnerability findings from DAST/SAST scanners such as Burp Suite and ZAP, using the OWASP Risk Rating Methodology to confirm true positives, dismiss false positives, and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 198 | Implements defense-in-depth controls at an AI agent's tool-invocation boundary using tool allowlisting, least-privilege identity binding, NeMo Guardrails policy enforcement, human-in-the-loop… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 199 | Secures AWS API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, custom rate-limiting rules, bot control, IP reputation filtering, and WAF metric… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 200 | Audits and hardens process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments: Purdue-level network placement, interface access control, secure DMZ… | mukul975/ | 34k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 201 | Tests APIs for mass assignment (auto-binding), OWASP API3:2023, by identifying writable endpoints, adding undocumented fields to request bodies (role, isAdmin, price, balance), and checking whether… | mukul975/ | 34k | — | ~4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 202 | Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 203 | HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. | langbyyi/ | 129 | 1 repo | ~2.2k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 204 | Review the finished Worker against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report. | receptron/ | 237 | — | ~1.2k | Automated safety check: Notes | MIT | yesterday |
| 205 | 205.Swift Security A skill your agent uses when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM… | dpearson2699/ | 1.2k | — | ~3.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 206 | 206.API Spectral API specification linting and security validation using Stoplight's Spectral with support for OpenAPI, AsyncAPI, and Arazzo specifications. | AgentSecOps/ | 220 | 1 repo | ~5.6k | Automated safety check: Pass | Unknown | 5 mo ago |
| 207 | A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. | alirezarezvani/ | 28k | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 208 | 208.QA A skill your agent uses for paranoid, language-agnostic architectural code review — applies SOLID, DRY/KISS/YAGNI, decoupling, OWASP/NIST security, and quantitative complexity thresholds (cyclomatic… | openwpm/ | 1.4k | — | ~1.8k | Automated safety check: Pass | Unknown | 6 days ago |
| 209 | Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server, Oracle). | github/ | 40k | 1 repo | ~2.2k | Automated safety check: Pass | MIT | 2 days ago |
| 210 | 210.Security Audit Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. | decebals/ | 751 | — | ~3.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 211 | 211.Web Xxe XML External Entity injection detection→file-read/SSRF→proof for web apps. | s0ld13rr/ | 828 | — | ~585 | Automated safety check: Pass | MIT | 9 days ago |
| 212 | 212.Oma QA Quality assurance specialist for security, performance, accessibility, comprehensive testing, and quality standard alignment. | first-fluke/ | 1.3k | — | ~1.6k | Automated safety check: Pass | MIT | yesterday |
| 213 | 213.Sast Patterns Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. | vibeeval/ | 532 | — | ~4.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 214 | A skill your agent uses when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis. | sangrokjung/ | 852 | — | ~1k | Automated safety check: Notes | MIT | 1 mo ago |
| 215 | This skill provides guidance for implementing security features that span across Better Auth, including rate limiting, CSRF protection, session security, trusted origins, secret management, OAuth… | viclafouch/ | 110 | — | ~4.2k | Automated safety check: Pass | No licence | 6 mo ago |
| 216 | 216.Vc Security STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit. | withkynam/ | 1.1k | — | ~1.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 217 | 217.Security Audit Audits Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit authorization policies. | ThibautBaissac/ | 665 | — | ~846 | Automated safety check: Notes | MIT | 4 mo ago |
| 218 | Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP… | trilwu/ | 157 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 219 | Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills. | rampstackco/ | 945 | — | ~3k | Automated safety check: Pass | MIT | 4 days ago |
| 220 | Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 221 | 221.Hunt RAG Vector Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) | sickn33/ | 47k | 1 repo | ~3k | Automated safety check: Pass | MIT | 2 days ago |
| 222 | 222.Hunt Shadow API Hunt shadow / zombie / undocumented API surface (OWASP API9 Improper Inventory Management) | sickn33/ | 47k | 1 repo | ~2.5k | Automated safety check: Pass | MIT | 2 days ago |
| 223 | Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 224 | Laravel 框架特效安全审计工具。针对 Laravel 常见鉴权/CSRF/Session/模型填充/Blade 渲染等框架特性进行白盒静态审计,并将风险映射到你现有通用漏洞类型体系(AUTH/CSRF/LOGIC/XSS/CFG 等)。 | 0xShe/ | 402 | 1 repo | ~821 | Automated safety check: Pass | No licence | 6 mo ago |
| 225 | 225.Php Ssrf Audit PHP Web 源码 SSRF 审计工具。识别用户可控 URL/地址进入网络请求 Sink,追踪内网/协议/端口限制与回显,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~481 | Automated safety check: Pass | No licence | 6 mo ago |
| 226 | Symfony 框架特效安全审计工具。针对 Symfony 常见 security.yaml、CSRF、Twig/Twig raw、表达式与访问控制等框架机制做白盒静态审计,并将风险映射到通用漏洞类型体系(AUTH/CSRF/CFG/XSS/TPL/LOGIC 等)。 | 0xShe/ | 402 | 1 repo | ~599 | Automated safety check: Pass | No licence | 6 mo ago |
| 227 | ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。 | 0xShe/ | 402 | 1 repo | ~779 | Automated safety check: Pass | No licence | 6 mo ago |
| 228 | WordPress 框架特效安全审计工具。针对 WordPress 常见 nonce/capability/checkadminreferer、AJAX action、escape/sanitize、重定向、安全上传与远程请求等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/SQL/CFG/SSRF 等)。 | 0xShe/ | 402 | 1 repo | ~666 | Automated safety check: Pass | No licence | 6 mo ago |
| 229 | 229.Php Yii Audit Yii 框架特效安全审计工具。针对 Yii(通常指 Yii2)访问控制(AccessControl/RBAC)、CSRF、输入过滤规则、输出编码策略、URL/重定向安全等进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/CFG/LOGIC 等)。 | 0xShe/ | 402 | 1 repo | ~528 | Automated safety check: Pass | No licence | 6 mo ago |
| 230 | 230.Security Audit A skill your agent uses when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying… | nicepkg/ | 195 | 1 repo | ~676 | Automated safety check: Pass | No licence | 8 mo ago |
| 231 | 231.Security Review Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles. | affaan-m/ | 276k | — | ~3.4k | Automated safety check: Notes | MIT | yesterday |
| 232 | 232.Laravel Security Buenas prácticas de seguridad en Laravel para autenticación/autorización, validación, CSRF, asignación masiva, subida de archivos, secretos, limitación de velocidad y despliegue seguro. | affaan-m/ | 276k | — | ~2.1k | Automated safety check: Pass | MIT | yesterday |
| 233 | 233.Laravel Security Laravel セキュリティベストプラクティス:認証・認可、バリデーション、CSRF、一括割当、ファイルアップロード、シークレット管理、レート制限、安全なデプロイメント | affaan-m/ | 276k | — | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 234 | 234.Quarkus Security Buenas prácticas de seguridad en Quarkus para autenticación, autorización, JWT/OIDC, RBAC, validación de entrada, CSRF, gestión de secretos y seguridad de dependencias. | affaan-m/ | 276k | — | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 235 | 235.Quarkus Security Quarkus認証、認可、JWT/OIDC、RBAC、入力検証、CSRF、シークレット管理、依存関係セキュリティのセキュリティベストプラクティス。 | affaan-m/ | 276k | — | ~2.8k | Automated safety check: Pass | MIT | yesterday |
| 236 | 236.Quarkus Security Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security. | affaan-m/ | 276k | — | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 237 | Buenas prácticas de Spring Security para autenticación/autorización, validación, CSRF, secretos, cabeceras, limitación de velocidad y seguridad de dependencias en servicios Java Spring Boot. | affaan-m/ | 276k | — | ~2.1k | Automated safety check: Pass | MIT | yesterday |
| 238 | Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. | transilienceai/ | 563 | — | ~1.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 239 | 239.Bug Bounty Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling… | awarexone/ | 5.3k | — | ~20k | Automated safety check: Warn | MIT | yesterday |
| 240 | 240.Sapui5 This skill should be used when developing SAP UI5 applications, including creating freestyle apps, Fiori Elements apps, custom controls, testing, data binding, OData integration, routing, and… | secondsky/ | 462 | — | ~4.1k | Automated safety check: Pass | GPL-3.0 | 6 days ago |