Search
Java · Web application vulnerabilities
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 893 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 2 | 2.Maven Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing. | skjolber/ | 568 | — | ~886 | Automated safety check: Pass | Apache-2.0 | today |
| 3 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 4 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 4 | Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization. | PentesterFlow/ | 1.4k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 5 | 初始化 OryxOS(或同类 JDK 21 + Spring Boot 3.x 企业级单体)的工程地基:Maven 多模块骨架、 结构化日志、Actuator + Prometheus 监控、Spring MVC + 虚拟线程、springdoc OpenAPI、 统一响应体与全局异常/错误码、Google 格式 + 阿里编码规约(Spotless + 阿里 P3C +… | oryx-labs/ | 186 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 6 | A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning… | jabrena/ | 446 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 7 | Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services. | affaan-m/ | 275k | 5 repos | ~2k | Automated safety check: Pass | MIT | 3 days ago |
| 8 | Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。 | affaan-m/ | 275k | 3 repos | ~1.6k | Automated safety check: Pass | MIT | 3 days ago |
| 9 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching… | github/ | 40k | 1 repo | ~2.3k | Automated safety check: Notes | MIT | today |
| 11 | Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. | decebals/ | 751 | — | ~3.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 12 | Buenas prácticas de Spring Security para autenticación/autorización, validación, CSRF, secretos, cabeceras, limitación de velocidad y seguridad de dependencias en servicios Java Spring Boot. | affaan-m/ | 275k | — | ~2.1k | Automated safety check: Pass | MIT | 3 days ago |
| 13 | XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. | langbyyi/ | 134 | 1 repo | ~3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 14 | A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing… | jabrena/ | 446 | — | ~885 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 15 | A skill your agent uses when you need to write or review programmatic JDBC with Spring — including JdbcClient (Spring Framework 7+) as the default API, JdbcTemplate only where batch/streaming APIs… | jabrena/ | 446 | — | ~975 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 16 | A skill your agent uses when you add or change an endpoint, an auth check, a query by id, an outbound call to a user-supplied URL, file handling, or anything touching credentials — the OWASP API Top… | makifbaysal/ | 109 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 17 | Code vulnerability pattern database. An agent skill from revfactory/harness-100. | revfactory/ | 1.3k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 18 | Java 源码认证与配置安全审计。当在 Java 白盒审计中需要检测认证绕过、权限缺陷或安全配置问题时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~888 | Automated safety check: Pass | No licence | 4 days ago |
| 19 | Java 源码前端安全类漏洞审计。当在 Java 白盒审计中需要检测前端安全漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~1.4k | Automated safety check: Pass | No licence | 4 days ago |
| 20 | Java 源码注入类漏洞审计。当在 Java 白盒审计中需要检测注入类漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~1.1k | Automated safety check: Pass | No licence | 4 days ago |