Topic · Security
Best security review skills, page 11
Security review skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 481 | WordPress security code review and vulnerability detection. An agent skill from jorgerosal/wordpress-skills. | jorgerosal/ | 102 | — | ~6.4k | Automated safety check: Pass | MIT | 4 mo ago |
| 482 | 482.Repomix Guide for using Repomix - a powerful tool that packs entire repositories into single, AI-friendly files. | einverne/ | 121 | — | ~2.5k | Automated safety check: Notes | GPL-3.0 | 1 mo ago |
| 483 | 483.Security Pass Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth… | cyanheads/ | 156 | — | ~6.4k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 484 | Run a third-party / vendor security review and assign a risk tier with required controls. | mohitagw15856/ | 1.4k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 485 | 485.Recon Map distinct externally reachable input-processing subsystems into focus areas for the threat-model skill to carry into later security audits. | alpha-omega-security/ | 239 | — | ~951 | Automated safety check: Pass | MIT | today |
| 486 | Comprehensive code security audit with AI-powered vulnerability detection. | LeoYeAI/ | 2.2k | — | ~3.7k | Automated safety check: Notes | MIT | 2 mo ago |
| 487 | OpenClaw 多模式安全巡检工具:默认本地离线扫描,可选联网威胁情报上报. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~2.5k | Automated safety check: Notes | MIT | 2 mo ago |
| 488 | OpenClaw 安全巡检工具,一键执行系统安全扫描并生成通俗易懂的报告. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~2k | Automated safety check: Notes | MIT | 2 mo ago |
| 489 | Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline. | trilwu/ | 157 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 490 | 490.Phx Deps Vet Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner. | oliver-kriska/ | 565 | — | ~1.5k | Automated safety check: Pass | MIT | 4 days ago |
| 491 | 491.Phx Deps Vet Record vetted Hex versions after security review. An agent skill from oliver-kriska/claude-elixir-phoenix. | oliver-kriska/ | 565 | — | ~1.5k | Automated safety check: Pass | MIT | 4 days ago |
| 492 | 492.Phx Deps Vet Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner. | oliver-kriska/ | 565 | — | ~1.5k | Automated safety check: Pass | MIT | 4 days ago |
| 493 | 493.Pair Programming 结对编程搭档。当用户要求"边写边审"、"结对编程"、"写完自己 review 一遍"、"高可靠地实现",或明确希望代码交付时附带自我审查意见时使用。交付代码的同时输出结构化审查(正确性/安全/性能/可读性/健壮性五维度),重点捕捉 AI 生成代码的特有缺陷。不用于:对已有 PR 的正式评审(用 code review 流程)、安全专项扫描(用 security-audit)、10… | staruhub/ | 727 | — | ~482 | Automated safety check: Pass | MIT | 1 mo ago |
| 494 | 解决方案架构师助手。当用户要设计新系统架构、评审现有架构、做技术选型决策、诊断性能/可扩展性/可用性问题、规划架构演进或重构时使用。覆盖微服务、事件驱动、云原生等架构模式,技术趋势通过实时搜索获取而非依赖内置知识。不用于:具体功能的代码实现、安全漏洞审计(用security-audit)、产品需求分析(用product-manager)、只需一句话回答的技术常识问题。 | staruhub/ | 727 | — | ~670 | Automated safety check: Pass | MIT | 1 mo ago |
| 495 | 495.Security Planner Create a prioritized security remediation plan from security assessment findings. | EmeaAppGbb/ | 100 | — | ~2.5k | Automated safety check: Pass | MIT | 5 mo ago |
| 496 | Review Abridge deployment controls across data handling, identity, devices, EHR workflows, support, auditability, and incident response. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 497 | Review a Bright Data integration for least privilege, public-data authorization, secret containment, and controlled use. | jeremylongshore/ | 2.8k | — | ~922 | Automated safety check: Pass | MIT | yesterday |
| 498 | Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls. | jeremylongshore/ | 2.8k | — | ~1k | Automated safety check: Pass | MIT | yesterday |
| 499 | Configure and audit security review capabilities as one layer in a defense-in-depth pull-request program. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 500 | Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation. | jeremylongshore/ | 2.8k | — | ~2.3k | Automated safety check: Notes | MIT | yesterday |
| 501 | Apply Deepgram security best practices for API key management and data protection. | jeremylongshore/ | 2.8k | — | ~2.2k | Automated safety check: Pass | MIT | yesterday |
| 502 | Harden Fireflies bearer authentication, GraphQL selections, webhook signatures, logs, and privileged mutations against secret and meeting-data exposure. | jeremylongshore/ | 2.8k | — | ~1k | Automated safety check: Pass | MIT | yesterday |
| 503 | Analyze and harden Flexport credentials, tokens, webhook verification, data exposure, and mutation controls. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 504 | Implement security best practices for Lindy agents and integrations. | jeremylongshore/ | 2.8k | — | ~2.3k | Automated safety check: Pass | MIT | yesterday |
| 505 | Threat-model a Navan integration across identity, travel, expense, payment, file, and downstream systems. | jeremylongshore/ | 2.8k | — | ~963 | Automated safety check: Pass | MIT | yesterday |
| 506 | Pre-production readiness checklist for OCI — backup policies, security audit, key rotation, encryption, and Cloud Guard. | jeremylongshore/ | 2.8k | — | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 507 | Harden Persona API keys, identity data, inquiry sessions, webhook verification, and destructive redaction. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 508 | Establish least-privilege OAuth, secret, webhook, data, card, and financial-write controls for a Ramp integration. | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 509 | Review RemoFirst account, group, report, connector, and worker-data controls. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 510 | Apply Shopify security best practices for API credentials, webhook HMAC validation, and access scope management. | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Notes | MIT | yesterday |
| 511 | Threat-model a WebContainer or StackBlitz embed across host, runtime, user-code, filesystem, dependency, network, preview, secret, and persistence boundaries. | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Notes | MIT | yesterday |
| 512 | Enforce organizational governance for Supabase projects: shared RLS policy library with reusable templates, table and column naming conventions, migration review process with CI checks, cost alert… | jeremylongshore/ | 2.8k | — | ~2.8k | Automated safety check: Pass | MIT | yesterday |
| 513 | Apply Supabase security best practices: anon vs servicerole key separation, RLS enforcement, policy patterns, JWT verification, and API hardening. | jeremylongshore/ | 2.8k | — | ~3.1k | Automated safety check: Notes | MIT | yesterday |
| 514 | Apply Vercel security best practices for secrets, headers, and access control. | jeremylongshore/ | 2.8k | — | ~1.9k | Automated safety check: Notes | MIT | yesterday |
| 515 | Audit MCP (Model Context Protocol) server configurations for security issues. | boshi-xixixi/ | 275 | — | ~2.2k | Automated safety check: Pass | MIT | 5 mo ago |
| 516 | 516.Threat Modeling Identifies what could go wrong in a system before it is built or changed — the assets worth attacking, the entry points, the trust boundaries, and the controls that actually address the realistic… | cbrock84/ | 2k | — | ~841 | Automated safety check: Pass | MIT | 22 days ago |
| 517 | Orchestrate multiple Antigravity skills through guided workflows for SaaS MVP delivery, security audits, AI agent builds, and browser QA. | aiskillstore/ | 430 | 2 repos | ~636 | Automated safety check: Pass | No licence | today |
| 518 | 518.Security Security audit workflow - vulnerability scan → verification. An agent skill from parcadei/Continuous-Claude-v3. | parcadei/ | 3.9k | — | ~1.5k | Automated safety check: Pass | MIT | 8 mo ago |
| 519 | Microsoft 365 tenant administration for Global Administrators. | borghei/ | 886 | — | ~1.8k | Automated safety check: Pass | MIT | 2 days ago |
| 520 | 520.Senior Secops SecOps for application security, vulnerability management, compliance, and secure development. | borghei/ | 886 | — | ~1.7k | Automated safety check: Pass | MIT | 2 days ago |
| 521 | Audit or harden a defined application-security attack surface when the user explicitly requests a security audit, vulnerability investigation, or scoped security-hardening pass. | swyxio/ | 175 | — | ~962 | Automated safety check: Pass | MIT | 5 days ago |
| 522 | 522.Hack Entry P0 primary router and operating doctrine for HackSkills. | yaklang/ | 2.4k | — | ~4.7k | Automated safety check: Notes | MIT | 26 days ago |
| 523 | A skill your agent uses when someone wants an Amazon EKS cluster graded against best practices. | aws/ | 102 | — | ~3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 524 | Run defensive pre-release security tests for Python web applications. | aiskillstore/ | 430 | — | ~1.2k | Automated safety check: Notes | MIT | today |
| 525 | Read-only audit of MCP definition language across an existing surface — tools, resources, prompts, server instructions. | cyanheads/ | 156 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 526 | Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments | Hack23/ | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 527 | 527.Security Scan A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 174 | — | ~2.8k | Automated safety check: Notes | MIT | 2 days ago |
| 528 | 528.Wordpress A skill your agent uses when building or hardening WordPress sites or WooCommerce stores and treating WordPress as the product rather than just writing PHP — block themes with theme.json, plugins… | ericrisco/ | 174 | — | ~3k | Automated safety check: Pass | MIT | 2 days ago |
Explore related skills
Category
More topics in Security
- Web application vulnerabilities468
- Vulnerability scanning305
- Static analysis and SAST284
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38