Search
Web application vulnerabilities
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 337 | 337.Security Fuzzing Essential fuzzing payloads: SQL injection, command injection, special characters. | Ch1nfo/ | 114 | 1 repo | ~329 | Automated safety check: Pass | MIT | 19 days ago |
| 338 | 338.Ghost Scan Code Ghost Security - SAST code scanner. An agent skill from aAAaqwq/AGI-Super-Team. | aAAaqwq/ | 105 | 1 repo | ~1.4k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 339 | 339.Sast Ssrf Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to destinations in parallel… | utkusen/ | 1.3k | — | ~6.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 340 | 340.Sast Xss Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 341 | 341.Mobile Security Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC… | transilienceai/ | 563 | — | ~2.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 342 | 342.Server Side Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection. | transilienceai/ | 563 | — | ~484 | Automated safety check: Pass | MIT | 2 mo ago |
| 343 | 343.Security Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries… | telagod/ | 244 | — | ~907 | Automated safety check: Pass | MIT | 2 mo ago |
| 344 | Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for… | forcedotcom/ | 1.1k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 345 | Activate an Enhanced MessagingChannel (WhatsApp/Apple/Facebook/SMS/RCS) by PATCHing MessagingChannelUsage.DeploymentStatus from Disabled to Provisioning via the REST sobject endpoint. | forcedotcom/ | 1.1k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 346 | A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data… | NoobyGains/ | 109 | — | ~2.4k | Automated safety check: Notes | MIT | 7 mo ago |
| 347 | 对前端代码进行安全审计,检测 XSS、CSRF 等漏洞。当用户请求代码审查或询问代码安全性时使用. An agent skill from TencentBlueKing/bk-bcs. | TencentBlueKing/ | 840 | — | ~216 | Automated safety check: Pass | Unknown | 2 days ago |
| 348 | Application security covering input validation, auth, headers, secrets management, and dependency auditing | rohitg00/ | 2.7k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | 5 mo ago |
| 349 | WordPress security code review and vulnerability detection. An agent skill from jorgerosal/wordpress-skills. | jorgerosal/ | 103 | — | ~6.4k | Automated safety check: Pass | MIT | 4 mo ago |
| 350 | A skill your agent uses when closing a patch cycle with rigorous stress LAST on the Railway hub, bensbench x86 fieldbus → MQTTS, CSV/synth59/Creekside/gate 19, B100 Railway-only, light OWASP ZAP… | bbartling/ | 173 | — | ~1.2k | Automated safety check: Pass | Unknown | yesterday |
| 351 | Cloudflare Workers security with authentication, CORS, rate limiting, input validation. | secondsky/ | 227 | — | ~1.9k | Automated safety check: Pass | MIT | 13 days ago |
| 352 | 352.Webapp Review Web application security testing workflow and checklist generation. | SpecterOps/ | 706 | — | ~1k | Automated safety check: Pass | Apache-2.0 | 17 days ago |
| 353 | 353.Hunt Csrf Hunting skill for csrf vulnerabilities. | sickn33/ | 47k | 1 repo | ~7.1k | Automated safety check: Pass | MIT | 2 days ago |
| 354 | Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 355 | Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 356 | Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 357 | Comprehensive code security audit with AI-powered vulnerability detection. | LeoYeAI/ | 2.2k | — | ~3.7k | Automated safety check: Notes | MIT | 2 mo ago |
| 358 | Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash… | trilwu/ | 157 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 359 | 359.Hardening Siti Applica regole di sicurezza (hardening) ogni volta che si costruisce, modifica o revisiona un sito web o un'app. | ccplugins/ | 970 | — | ~875 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 360 | 360.Security Build and harden Phoenix auth and security — OAuth login, password hashing, sessions, RBAC, rate limiting, CSRF, XSS, SQL injection, secrets. | oliver-kriska/ | 565 | — | ~1k | Automated safety check: Pass | MIT | 5 days ago |
| 361 | 361.Security Security audit workflow - vulnerability scan → verification. An agent skill from parcadei/Continuous-Claude-v3. | parcadei/ | 3.9k | — | ~1.5k | Automated safety check: Pass | MIT | 8 mo ago |
| 362 | 362.Senior Secops SecOps for application security, vulnerability management, compliance, and secure development. | borghei/ | 891 | — | ~1.7k | Automated safety check: Pass | MIT | 4 days ago |
| 363 | 扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。 | rongxinzy/ | 154 | — | ~868 | Automated safety check: Pass | MIT | yesterday |
| 364 | Entry P1 category router for injection testing. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~570 | Automated safety check: Pass | MIT | 28 days ago |
| 365 | 365.Auth Sec Entry P1 category router for authentication and authorization. | yaklang/ | 2.4k | — | ~591 | Automated safety check: Pass | MIT | 28 days ago |
| 366 | 366.Dt Sec Insights Query and analyze Dynatrace security data in security.events with DQL: vulnerabilities, threat detections, compliance posture, and scan coverage. | Dynatrace/ | 163 | — | ~7.2k | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 367 | 367.Cso Chief Security Officer mode. An agent skill from mr-daedalium/ostack-saas. | mr-daedalium/ | 114 | — | ~7.4k | Automated safety check: Notes | MIT | 6 mo ago |
| 368 | 368.Security Scan A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 180 | — | ~2.8k | Automated safety check: Notes | MIT | yesterday |
| 369 | 369.Prompt Injection AI/LLM 间接 Prompt 注入攻击。当目标 AI 系统会处理外部数据源(网页、文档、邮件、数据库、API 返回)时使用。覆盖间接注入、工具链劫持、RAG 投毒、数据外泄等技术。OWASP LLM Top 10 1 漏洞类别 | wgpsec/ | 1.8k | — | ~704 | Automated safety check: Notes | No licence | yesterday |
| 370 | 370.Sqli Testing Detect and exploit SQL injection vulnerabilities in web application parameters | NeoTheCapt/ | 143 | — | ~1.2k | Automated safety check: Pass | No licence | 2 mo ago |
| 371 | 371.Ssrf Testing Detect and exploit server-side request forgery to access internal resources and cloud metadata | NeoTheCapt/ | 143 | — | ~768 | Automated safety check: Pass | No licence | 2 mo ago |
| 372 | 372.Xss Testing Detect and exploit cross-site scripting vulnerabilities in web applications | NeoTheCapt/ | 143 | — | ~1.4k | Automated safety check: Pass | No licence | 2 mo ago |
| 373 | 373.Xxe Testing XML external entity injection for file read, SSRF, and DoS. An agent skill from NeoTheCapt/RedteamAgent. | NeoTheCapt/ | 143 | — | ~1k | Automated safety check: Pass | No licence | 2 mo ago |
| 374 | Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. | giuseppe-trisciuoglio/ | 357 | — | ~2.4k | Automated safety check: Notes | MIT | 1 mo ago |
| 375 | Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable… | Goldziher/ | 159 | — | ~250 | Automated safety check: Pass | MIT | yesterday |
| 376 | 当未授权/零身份测试但路径不在主站 JS、禁止依赖登录 Network 截图、独立 H5/旧域名 NXDOMAIN/品牌迁域、兄弟域或同 IP Host 漏路径、网关 405 或 data 空数组、getRsaKey/JSEncrypt/前端加密被当成鉴权时调用。负责零身份公开面还原路径与密钥、响应指纹分流、加密证伪、迁域复查。JS 拆包见 recon-js-analysis;角色/IDOR… | zhaji2333/ | 115 | — | ~1.4k | Automated safety check: Pass | MIT | 26 days ago |
| 377 | 当payload被拦截、请求被WAF/过滤/403拒绝、连续多次payload失败、需要绕过黑名单/白名单/正则/语义分析防御时调用。负责编码/变形/逻辑/协议层绕过、换入口、组合利用与时间维度攻击的完整升级路径。 | zhaji2333/ | 115 | — | ~620 | Automated safety check: Pass | MIT | 26 days ago |
| 378 | 当目标存在评论/昵称/富文本/私信/工单/搜索反射/Markdown解析/AI输出渲染/前端DOM操作/postMessage/跨域配置等功能时调用。负责反射型/存储型/DOM XSS、AI/Markdown 渲染型存储 XSS、CSRF、CORS错误配置、Clickjacking 的深度挖掘与绕过。命中跳转页/开放重定向/target 参数驱动 location 跳转时优先测试跳转型… | zhaji2333/ | 115 | — | ~2.1k | Automated safety check: Pass | MIT | 26 days ago |
| 379 | 379.Client Side Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution. | transilienceai/ | 563 | — | ~374 | Automated safety check: Pass | MIT | 2 mo ago |
| 380 | 380.Audit On-demand security and code quality audit. An agent skill from MadAppGang/claude-code. | MadAppGang/ | 285 | — | ~3.3k | Automated safety check: Pass | MIT | 7 mo ago |
| 381 | 381.Aurakit Sonnet Amplified fullstack engine. An agent skill from davepoon/buildwithclaude. | davepoon/ | 3.6k | — | ~469 | Automated safety check: Pass | MIT | 2 days ago |
| 382 | 382.Security Audit Deep security audit covering OWASP Top 10, authentication, authorization, data protection, dependency vulnerabilities, and secrets scanning. | davepoon/ | 3.6k | — | ~442 | Automated safety check: Pass | MIT | 2 days ago |
| 383 | 383.Laravel Security Harden Laravel apps with Policies for model authorization, Gate-based RBAC, validated mass assignment, and CSRF protection. | HoangNguyen0403/ | 572 | — | ~887 | Automated safety check: Pass | MIT | yesterday |
| 384 | 384.Nestjs Security Implement JWT authentication, RBAC guards, Helmet hardening, and Argon2 hashing in NestJS. | HoangNguyen0403/ | 572 | — | ~778 | Automated safety check: Notes | MIT | yesterday |