Search

Vulnerability scanning

305 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

eigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0today
2

Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

trufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0yesterday
3
3.Skill InspectorOfficial

Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

NVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0today
4

A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

payloadcms/payload45k—~2.8kAutomated safety check: PassMITtoday
5

Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.

vercel-labs/deepsec8.1k—~1.2kAutomated safety check: PassApache-2.010 days ago
6

Professional code security audit skill covering 55+ vulnerability types.

3stoneBrother/code-audit8921 repo~2.7kAutomated safety check: PassNo licence7 mo ago
7

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.02 days ago
8

Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

vercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.010 days ago
9

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

ruvnet/ruflo74k2 repos~823Automated safety check: PassMITtoday
10

当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

SummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT4 mo ago
11

A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

vulnersCom/api376—~2.3kAutomated safety check: PassMIT10 days ago
12

Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

rundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0today
13

Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter).

symfony/symfony31k—~2.6kAutomated safety check: PassMITtoday
14

Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

mono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMITtoday
15

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

nyldn/claude-octopus4.2k1 repo~2.3kAutomated safety check: PassMITtoday
16

Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.

context-labs/whip1.1k2 repos~3kAutomated safety check: PassMIT4 days ago
17

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

fengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT24 days ago
18

Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

alexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesUnknown12 days ago
19

Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and…

activepieces/activepieces25k—~2.9kAutomated safety check: PassUnknowntoday
20

Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

Pa55w0rd/secknowledge-skill424—~2.7kAutomated safety check: PassNo licence3 mo ago
21

Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

gocronx-team/gocron808—~690Automated safety check: PassMIT7 days ago
22

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

ParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.02 days ago
23

Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

evdenis/cvehound138—~2.5kAutomated safety check: PassGPL-3.0today
24

Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

TheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT5 mo ago
25

Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

tradecatlabs/vibe-coding-cn17k1 repo~738Automated safety check: PassApache-2.0today
26

Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity.

activepieces/activepieces25k—~3.6kAutomated safety check: PassUnknowntoday
27

A skill your agent uses when scanning code for security vulnerabilities.

tanviet12/vbsec287—~5.3kAutomated safety check: NotesMIT11 days ago
28

渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。

Arenbai/SecSkills251—~1.8kAutomated safety check: NotesMIT10 days ago
29

Triage Apache Roller security reports, maintain private case tracking, prepare CVE records, coordinate fixes and reporter review, and prepare disclosure with a release.

apache/roller133—~1.9kAutomated safety check: PassApache-2.0today
30

Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

karimhabush/cyberowl263—~2.5kAutomated safety check: PassMITtoday
31

Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

zereight/gitlab-mcp2k1 repo~859Automated safety check: NotesMITtoday
32

Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.

openplayerjs/openplayerjs649—~1kAutomated safety check: PassMIT4 days ago
33

Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

livesession/xyd114—~2kAutomated safety check: PassMITyesterday
34

Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

garrytan/gstack136k—~4.5kAutomated safety check: PassMITtoday
35

Triage a security finding in a Symfony UX package into a disposition: a private CVE (coordinated disclosure through the Symfony security process), a public hardening PR (fix in the open, no CVE), or…

symfony/ux1.1k—~3.2kAutomated safety check: PassMITyesterday
36

Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

aliyun/alibabacloud-ecs-troubleshoot-skills148—~2.4kAutomated safety check: NotesApache-2.01 mo ago
37

A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

chaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.010 days ago
38

Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

block/codecrucible117—~1.2kAutomated safety check: PassApache-2.02 days ago
39
39.Handle CveOfficial

A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR.

DataDog/dd-trace-rb417—~2.6kAutomated safety check: PassUnknowntoday
40

A skill your agent uses when scanning code for security vulnerabilities.

tanviet12/vbsec287—~6.8kAutomated safety check: NotesMIT11 days ago
41

Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…

MidnightBSD/src114—~2.2kAutomated safety check: PassUnknown5 days ago
42

Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

eclipse-ankaios/ankaios125—~1.5kAutomated safety check: PassApache-2.0yesterday
43

Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

Hainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT2 mo ago
44

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassUnknown5 mo ago
45

Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

aliyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.01 mo ago
46

Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

zebbern/claude-code-guide4.7k—~1.3kAutomated safety check: PassMITtoday
47
47.Docs

Update project documentation when features are added or changed.

boostsecurityio/poutine523—~336Automated safety check: PassApache-2.0today
48

Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.

Tencent/AI-Infra-Guard6.8k—~1.8kAutomated safety check: PassApache-2.0today