Topic · Security
Best security review skills, page 4
Security review skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 145 | Builds attack trees that map how an attacker could reach a goal, with AND and OR nodes and cost, time, skill and detection ratings, to find defense gaps. | wshobson/ | 40k | 8 repos | ~623 | Automated safety check: Pass | MIT | 3 days ago |
| 146 | Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation. | wshobson/ | 40k | 8 repos | ~742 | Automated safety check: Pass | MIT | 3 days ago |
| 147 | Runs a phased pre-PR and pre-deploy check on a Django project: environment, linting, migrations, tests with coverage, security scans and settings review. | affaan-m/ | 275k | 7 repos | ~2.9k | Automated safety check: Pass | MIT | 3 days ago |
| 148 | 148.Codex Review Dual-model code review via Codex CLI. An agent skill from suyuan2022/suyuan-skill. | suyuan2022/ | 276 | — | ~3.5k | Automated safety check: Warn | MIT | 1 mo ago |
| 149 | 149.Threat Modeling Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks. | dralgorhythm/ | 125 | — | ~581 | Automated safety check: Pass | No licence | 2 mo ago |
| 150 | 150.Nuclei Scan Run a Nuclei security scan against the target URL and report findings by severity. | MigoXLab/ | 232 | — | ~846 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 151 | Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries. | nordstjernen-web/ | 116 | — | ~920 | Automated safety check: Pass | GPL-3.0 | 2 days ago |
| 152 | 152.Security Audit Audit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline. | mono/ | 5.6k | — | ~5.7k | Automated safety check: Pass | MIT | today |
| 153 | Senior ISMS Audit Expert for internal and external information security management system auditing. | davila7/ | 32k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | today |
| 154 | 154.Healthcheck Host security hardening and risk-tolerance configuration for OpenClaw deployments. | trpc-group/ | 1.8k | 9 repos | ~2.6k | Automated safety check: Pass | Apache-2.0 | today |
| 155 | Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure. | CyberStrategyInstitute/ | 146 | — | ~2.7k | Automated safety check: Pass | Unknown | today |
| 156 | A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. | AratKruglik/ | 155 | 1 repo | ~1.1k | Automated safety check: Notes | No licence | 5 mo ago |
| 157 | 157.Audit Security audit and code review for Solidity smart contracts. | sablier-labs/ | 353 | — | ~1.8k | Automated safety check: Pass | Unknown | yesterday |
| 158 | 158.Audit Prep Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project… | PlamenTSV/ | 303 | — | ~3.7k | Automated safety check: Pass | MIT | 12 days ago |
| 159 | 159.Zhin Audit Audit Zhin.js changes for security, performance, lifecycle, and architecture regressions. | zhinjs/ | 137 | — | ~596 | Automated safety check: Notes | MIT | 15 days ago |
| 160 | 160.Keel A skill your agent uses for ANY new software project from idea to release — websites, WordPress/WooCommerce plugins, MCP servers, web apps, components, or libraries. | joseconti/ | 190 | — | ~11k | Automated safety check: Warn | GPL-3.0-or-later | 2 mo ago |
| 161 | Expert workflow for reviewing Tauri 2 desktop app security. An agent skill from mukiwu/tempo-term. | mukiwu/ | 228 | — | ~2.8k | Automated safety check: Notes | Apache-2.0 | 8 days ago |
| 162 | Remediate security vulnerabilities found by Grype or pnpm audit. | stacklok/ | 170 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 163 | Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit. | microsoft/ | 110 | — | ~356 | Automated safety check: Pass | MIT | 20 days ago |
| 164 | Find bugs, security vulnerabilities, and code quality issues in local branch changes. | getsentry/ | 1k | 9 repos | ~708 | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 165 | Runs a parallel security audit with three vulnerability hunters and two proof-of-concept engineers, rating each finding by whether it is actually exploitable. | code-yeongyu/ | 70k | — | ~1.9k | Automated safety check: Pass | Unknown | today |
| 166 | 166.Security Review Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli. | kklimuk/ | 216 | — | ~1.7k | Automated safety check: Pass | MIT | 13 days ago |
| 167 | 167.Audit Full Single-pass codebase analysis leveraging a 1M-token context window for comprehensive security scanning, architecture review, and dependency auditing. | yonatangross/ | 289 | — | ~3.5k | Automated safety check: Notes | MIT | today |
| 168 | 168.Security Scan Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. | affaan-m/ | 275k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | 3 days ago |
| 169 | Run Claude programmatically against collections of files in the codebase. | imbue-ai/ | 236 | — | ~308 | Automated safety check: Pass | MIT | yesterday |
| 170 | Run Warden security scans in this repo using Sentry's warden-skills. | UsefulSoftwareCo/ | 4.1k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 171 | 171.Fix Vulns Automated triage and fixing of Dependabot security vulnerabilities (IN-1189). | linuxfoundation/ | 280 | — | ~3.8k | Automated safety check: Notes | MIT | 7 days ago |
| 172 | Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. | microsoft/ | 972 | — | ~3.2k | Automated safety check: Notes | MIT | today |
| 173 | Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. | BlkLeg/ | 201 | — | ~2.1k | Automated safety check: Pass | MIT | 3 days ago |
| 174 | Security guidelines for writing secure code. An agent skill from semgrep/skills. | semgrep/ | 322 | — | ~1.2k | Automated safety check: Pass | Unknown | 2 mo ago |
| 175 | Maps the state-changing entry points of a smart contract codebase and sorts them by access level, producing a structured audit report that leaves out read-only functions. | trailofbits/ | 7.4k | 1 repo | ~2.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 176 | Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots. | trailofbits/ | 7.4k | 1 repo | ~4.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 177 | Verification loop for Laravel projects: env checks, linting, static analysis, tests with coverage, security scans, and deployment readiness. | affaan-m/ | 275k | 4 repos | ~1.1k | Automated safety check: Notes | MIT | 3 days ago |
| 178 | Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings… | waynesutton/ | 404 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 179 | 179.Code Audit A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification. | zhaoxuya520/ | 40k | 2 repos | ~374 | Automated safety check: Warn | MIT | 16 days ago |
| 180 | 180.Email Security A skill your agent uses for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research. | zhaoxuya520/ | 40k | 2 repos | ~259 | Automated safety check: Warn | MIT | 16 days ago |
| 181 | 181.Wifi Wireless A skill your agent uses for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing. | zhaoxuya520/ | 40k | 2 repos | ~255 | Automated safety check: Warn | MIT | 16 days ago |
| 182 | This skill should be used when the user asks to "verify code", "run verification", "check quality", "validate changes", or before creating a PR. | Galaxy-Dawn/ | 5.7k | 1 repo | ~888 | Automated safety check: Pass | MIT | 15 days ago |
| 183 | One-click deployment Skill for Windows security policies, daily security audits, behavior auditing, file baselines, logging and nightly audit task management | SafeAI-Lab-X/ | 1k | — | ~2.1k | Automated safety check: Pass | No licence | 1 mo ago |
| 184 | 184.Bugfix PR Treats bug-fix pull requests as invasive and untrusted. An agent skill from TanStack/ai. | TanStack/ | 3.2k | — | ~4.8k | Automated safety check: Pass | MIT | today |
| 185 | 185.Security Review Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy. | langfuse/ | 36k | — | ~1.4k | Automated safety check: Pass | Unknown | today |
| 186 | Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks. | maslennikov-ig/ | 260 | — | ~2k | Automated safety check: Pass | Unknown | 7 mo ago |
| 187 | 187.Security Audit Security audit skill. An agent skill from blueberrycongee/termcanvas. | blueberrycongee/ | 406 | — | ~966 | Automated safety check: Notes | MIT | 4 mo ago |
| 188 | Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules… | redis/ | 165 | 1 repo | ~918 | Automated safety check: Pass | MIT | 1 mo ago |
| 189 | 189.Security Setup Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 190 | Code review covering security, performance, quality and maintainability, with a fixed report layout and two analysis scripts; the SKILL.md itself is in Ukrainian. | luongnv89/ | 42k | — | ~484 | Automated safety check: Pass | MIT | 8 days ago |
| 191 | Finds exploitable application security vulnerabilities in code changes. | getsentry/ | 414 | — | ~1.8k | Automated safety check: Pass | Unknown | 8 days ago |
| 192 | 192.Ghost Report Ghost Security — combined security report. An agent skill from ghostsecurity/skills. | ghostsecurity/ | 408 | — | ~1.4k | Automated safety check: Notes | Apache-2.0 | 10 days ago |
Explore related skills
More topics in Security
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38