Search
GitHub · Security review
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | yesterday |
| 2 | Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot. | HezaoHezao/ | 249 | 5 repos | ~1.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 3 | Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening. | symfony/ | 31k | — | ~2.9k | Automated safety check: Pass | MIT | yesterday |
| 4 | Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues. | verdaccio/ | 18k | — | ~853 | Automated safety check: Pass | MIT | 2 days ago |
| 5 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | 3 days ago |
| 6 | Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. | EpicenterHQ/ | 4.8k | — | ~896 | Automated safety check: Pass | Unknown | 2 days ago |
| 7 | Run CodeRabbit CLI reviews, retrieve saved local or GitHub PR fix prompts, and interpret CodeRabbit authentication and review output. | coderabbitai/ | 187 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 8 | Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation. | obot-platform/ | 1.1k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 9 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 10 | 10.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 391 | — | ~660 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 11 | Run a security scan on the kedro-plugins codebase or a pull request. | kedro-org/ | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 12 | Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. | vechain/ | 450 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 13 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.5k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 14 | Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity. | AgriciDaniel/ | 228 | — | ~11k | Automated safety check: Warn | MIT | 5 mo ago |
| 15 | 15.Bugfix PR Treats bug-fix pull requests as invasive and untrusted. An agent skill from TanStack/ai. | TanStack/ | 3.2k | — | ~4.8k | Automated safety check: Pass | MIT | yesterday |
| 16 | Perform a requested security review of a NemoClaw PR or a PR linked to an issue. | NVIDIA/ | 23k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 17 | 17.Keel A skill your agent uses for ANY new software project from idea to release — websites, WordPress/WooCommerce plugins, MCP servers, web apps, components, or libraries. | joseconti/ | 190 | — | ~11k | Automated safety check: Warn | GPL-3.0-or-later | 2 mo ago |
| 18 | 18.Audit Scope Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. | forefy/ | 152 | — | ~2.3k | Automated safety check: Pass | MIT | 6 days ago |
| 19 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 20 | Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration. | github/ | 5.4k | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 21 | Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. | sickn33/ | 47k | 2 repos | ~2.1k | Automated safety check: Notes | MIT | yesterday |
| 22 | Human review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service. | sickn33/ | 47k | 2 repos | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 23 | Google Workspace administration via the gws CLI (github.com/googleworkspace/cli). | alirezarezvani/ | 28k | — | ~3k | Automated safety check: Notes | MIT | 1 mo ago |
| 24 | CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows). | pskoett/ | 315 | — | ~1.1k | Automated safety check: Pass | No licence | 5 days ago |
| 25 | A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including… | hyodotdev/ | 155 | — | ~766 | Automated safety check: Pass | MIT | today |
| 26 | PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). | tetherto/ | 685 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 27 | Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows. | IgorWarzocha/ | 122 | — | ~1.2k | Automated safety check: Notes | No licence | 8 mo ago |
| 28 | A skill your agent uses for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge… | hyodotdev/ | 155 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 29 | 29.Hunter 22 Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw… | aeonfun/ | 770 | — | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 30 | Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date. | ArabelaTso/ | 253 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. | Mathews-Tom/ | 329 | — | ~2.2k | Automated safety check: Pass | MIT | 5 days ago |
| 32 | 32.Release 发版自动化技能:CalVer 版本号 + 从 git log 生成 changelog + GitHub Releases。 | 312362115/ | 107 | — | ~874 | Automated safety check: Pass | MIT | 5 mo ago |
| 33 | Security review gate for MCP server installations. An agent skill from bobmatnyc/claude-mpm. | bobmatnyc/ | 156 | — | ~1.1k | Automated safety check: Pass | Unknown | 1 mo ago |
| 34 | Read-only GitHub Actions workflow security audit for one repository, a repository set, or a whole GitHub org. | apache/ | 114 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | today |