Topic · Security
Best security review skills, page 2
Security review skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files. | HarnessMD/ | 8.6k | — | ~350 | Automated safety check: Notes | MIT | today |
| 50 | Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge. | Gabson0x/ | 443 | — | ~3.7k | Automated safety check: Pass | No licence | 21 days ago |
| 51 | 51.Skillkit Toolkit for creating and validating skills and subagents. An agent skill from rfxlamia/skillkit. | rfxlamia/ | 102 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 52 | Security audit of Solidity code while you develop. An agent skill from pashov/skills. | pashov/ | 1.2k | 1 repo | ~9.9k | Automated safety check: Pass | MIT | 2 days ago |
| 53 | Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge. | TheDecipherist/ | 550 | — | ~1.3k | Automated safety check: Notes | MIT | 5 mo ago |
| 54 | 54.Myrqen Run an authorized, local-first application security assessment on the current project using this agent's own reasoning. | stijnswapped/ | 137 | — | ~2.1k | Automated safety check: Pass | Unknown | 1 mo ago |
| 55 | Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more. | Rain-kl/ | 288 | — | ~2.3k | Automated safety check: Notes | MIT | today |
| 56 | A skill your agent uses when scanning code for security vulnerabilities. | tanviet12/ | 287 | — | ~5.3k | Automated safety check: Notes | MIT | 10 days ago |
| 57 | Run a pre-deployment security compliance checklist based on KISA guidelines. | cdppcorp/ | 361 | — | ~1.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 58 | Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation. | obot-platform/ | 1.1k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 59 | 59.Audit Flow Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. | zebbern/ | 4.7k | — | ~4.2k | Automated safety check: Pass | MIT | today |
| 60 | Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams. | rfc-st/ | 379 | — | ~3.7k | Automated safety check: Pass | MIT | today |
| 61 | 61.Cyberowlai Check if recent cybersecurity alerts from 10 international CERTs affect your current project. | karimhabush/ | 263 | — | ~2.5k | Automated safety check: Pass | MIT | today |
| 62 | Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware. | tihanyin/ | 107 | — | ~5.1k | Automated safety check: Pass | MIT | 14 days ago |
| 63 | Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps. | zereight/ | 2k | 1 repo | ~859 | Automated safety check: Notes | MIT | 2 days ago |
| 64 | GitHub Actions security review for workflow exploitation vulnerabilities. | getsentry/ | 1k | 3 repos | ~2.2k | Automated safety check: Notes | Apache-2.0 | 5 days ago |
| 65 | 65.Openqodex Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex. | openqodex/ | 303 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 66 | 66.Kuri Agent Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make… | justrach/ | 365 | — | ~1.3k | Automated safety check: Notes | Unknown | 2 mo ago |
| 67 | A skill your agent uses to perform a security-focused audit of the codebase to identify vulnerabilities, sandbox escapes, and logic flaws. | ziggy42/ | 439 | — | ~924 | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 68 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 69 | 69.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 | today |
| 70 | Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks. | telagod/ | 243 | — | ~552 | Automated safety check: Notes | MIT | 2 mo ago |
| 71 | Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. | ktnyt/ | 675 | — | ~565 | Automated safety check: Pass | MIT | 7 mo ago |
| 72 | Run a security scan on the kedro-plugins codebase or a pull request. | kedro-org/ | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | today |
| 73 | Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results. | block/ | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 74 | Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers. | CyberStrategyInstitute/ | 146 | — | ~1.2k | Automated safety check: Pass | Unknown | today |
| 75 | 75.Gmgn Token Research any crypto or meme token by address — real-time price, market cap, liquidity, holder list, trader list, top Smart Money and KOL positions, security audit (honeypot, rug pull risk, dev… | GMGNAI/ | 604 | 1 repo | ~10k | Automated safety check: Notes | MIT | 9 days ago |
| 76 | A skill your agent uses when scanning code for security vulnerabilities. | tanviet12/ | 287 | — | ~6.8k | Automated safety check: Notes | MIT | 10 days ago |
| 77 | Routes a whole-product security request to the right Strix test per asset, source code, a live app, an API or a CI pipeline, then turns results into one ranked remediation plan. | usestrix/ | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 78 | Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work. | LUC4N3X/ | 531 | — | ~2k | Automated safety check: Pass | GPL-3.0 | today |
| 79 | Check and apply security updates across the photofield project (api/Go, ui/npm, docs/npm, e2e/npm). | SmilyOrg/ | 608 | — | ~808 | Automated safety check: Pass | MIT | 1 mo ago |
| 80 | Enable, configure, and query Elasticsearch security audit logs. | aspectrr/ | 405 | — | ~1.7k | Automated safety check: Pass | MIT | 5 mo ago |
| 81 | Security best practices, vulnerability review, and full security audits for LLM Gateway. | theopenco/ | 1.7k | — | ~1.8k | Automated safety check: Pass | Unknown | today |
| 82 | Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects. | microsoft/ | 22k | — | ~737 | Automated safety check: Pass | MIT | today |
| 83 | 83.Audit A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures. | vigolium/ | 140 | — | ~8.7k | Automated safety check: Pass | MIT | 18 days ago |
| 84 | Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report. | marketcalls/ | 2.8k | — | ~1.9k | Automated safety check: Pass | AGPL-3.0 | today |
| 85 | Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files. | ZaxbyHub/ | 490 | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 86 | 86.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 281 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 87 | Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled. | garrytan/ | 136k | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 88 | Review a change (a PR, the current branch diff, or a set of files) or audit a Symfony UX package or the whole src/ tree for missing or incorrect security hardening. | symfony/ | 1.1k | — | ~2.9k | Automated safety check: Pass | MIT | yesterday |
| 89 | Runs and interprets Psalm security (taint) analysis on a Laravel project. | cachethq/ | 230 | — | ~4.7k | Automated safety check: Pass | Unknown | 2 days ago |
| 90 | 90.Codeql Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF. | waybarrios/ | 533 | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 2 days ago |
| 91 | Sentry-specific security review based on real vulnerability history. | getsentry/ | 46k | — | ~2.3k | Automated safety check: Notes | Unknown | today |
| 92 | Review code for quality, correctness, and security vulnerabilities. | hiroshiyui/ | 135 | — | ~1.6k | Automated safety check: Pass | GPL-3.0 | 10 days ago |
| 93 | Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk. | GitbookIO/ | 131 | — | ~1.2k | Automated safety check: Pass | No licence | today |
| 94 | Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script. | ptn1411/ | 219 | — | ~830 | Automated safety check: Notes | No licence | 16 days ago |
| 95 | Token-efficient smart contract security auditing via Behavioral State Analysis (BSA). | quillai-network/ | 129 | — | ~1.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 96 | Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection. | zebbern/ | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | today |
Explore related skills
More topics in Security
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38