Topic · Security
Best security review skills, page 6
Security review skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 241 | 241.Replica Backend Builds the backend of an app clone: auth, database migrations and access rules, payments with Stripe, email, background jobs and third-party integrations through official APIs only, plus a security… | Jakeschincariol/ | 1.2k | — | ~997 | Automated safety check: Notes | MIT | 6 days ago |
| 242 | 242.Security Audit Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening. | davila7/ | 32k | 4 repos | ~1.3k | Automated safety check: Pass | MIT | today |
| 243 | Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking. | fabricioctelles/ | 106 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 244 | A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection. | openJiuwen-ai/ | 446 | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | today |
| 245 | 245.Audit Scope Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. | forefy/ | 152 | — | ~2.3k | Automated safety check: Pass | MIT | 4 days ago |
| 246 | 246.Security Auditor Perform comprehensive security audit of a repository with detailed findings and step-by-step PoCs. | commercetools/ | 154 | — | ~3.3k | Automated safety check: Notes | MIT | 6 days ago |
| 247 | A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit. | ccashwell/ | 131 | — | ~1.4k | Automated safety check: Pass | MIT | 9 days ago |
| 248 | Performs comprehensive C/C++ security review for memory corruption, integer overflows, race conditions, and platform-specific vulnerabilities. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 249 | 249.Best Practices Apply modern web development best practices for security, compatibility, and code quality. | tech-leads-club/ | 7k | — | ~3.2k | Automated safety check: Pass | MIT | yesterday |
| 250 | Configure code scanning in Harness pipelines using STO security scanners. | harness/ | 115 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 251 | 251.Senior Backend Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening. | alirezarezvani/ | 28k | 1 repo | ~3.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 252 | 252.Senior Secops Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. | alirezarezvani/ | 28k | 1 repo | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 253 | 253.Yao Doctor Skill Audit local and OpenClaw skill libraries for privacy theft, credential theft, stealthy exfiltration, unsafe execution chains, deceptive instructions, and persistence behavior, then generate a visual… | yaojingang/ | 1.3k | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 254 | Security-focused review for frontend/Web3 code. An agent skill from hyperlane-xyz/hyperlane-explorer. | hyperlane-xyz/ | 102 | — | ~185 | Automated safety check: Pass | Unknown | yesterday |
| 255 | 255.Security Scan Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes. | bagofwords1/ | 459 | — | ~1.7k | Automated safety check: Pass | Unknown | today |
| 256 | Comprehensive API security review against OWASP API Security Top 10 (2023). | OWASP/ | 187 | — | ~744 | Automated safety check: Pass | CC-BY-4.0 | 14 days ago |
| 257 | 257.Static Security Static security review for Flutter mobile apps and Dart code: hardcoded secrets, insecure storage, unsafe network calls, leaky logs, vulnerable dependencies. | VeryGoodOpenSource/ | 170 | — | ~4.4k | Automated safety check: Notes | MIT | 3 days ago |
| 258 | Implements authentication, authorization, encryption, secrets management, and security hardening patterns. | CloudAI-X/ | 1.4k | — | ~3.6k | Automated safety check: Notes | MIT | 3 days ago |
| 259 | Flag only new security issues introduced by this diff. An agent skill from different-ai/openwork. | different-ai/ | 24k | — | ~1.2k | Automated safety check: Pass | Unknown | today |
| 260 | Language-agnostic workflow for code reviews and security audits against Clean Code/SOLID principles, generating formal refactoring plans. | GulajavaMinistudio/ | 139 | — | ~1.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 261 | Black-box security audit of a DEPLOYED AI agent (not the MCP server behind it) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR… | awarexone/ | 5.3k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 262 | Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges… | github/ | 40k | 1 repo | ~3.6k | Automated safety check: Notes | MIT | today |
| 263 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 264 | 审计 Terraform / IaC 代码安全(AWS 基础设施)。检测硬编码凭据、过宽 Security Group(0.0.0.0/0)、IAM 权限过大(Action/Resource )、S3 公开访问、RDS 未加密/公开、State 文件泄露、ECS/EKS 容器特权、CloudTrail/VPC FlowLog 缺失、不安全 Provider/Module 引用等。当审计… | xwtro0tk1t-cloud/ | 265 | — | ~4.4k | Automated safety check: Pass | No licence | 5 mo ago |
| 265 | Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. | zebbern/ | 4.7k | — | ~2k | Automated safety check: Pass | MIT | today |
| 266 | Systematically reviews code for SQL injection, XSS, SSRF, broken access control, cryptographic failures, and other common OWASP Top 10 vulnerabilities, providing vulnerable code examples and… | zebbern/ | 4.7k | — | ~4.7k | Automated safety check: Pass | MIT | today |
| 267 | 267.Security Audit Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology | RightNow-AI/ | 18k | — | ~858 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 268 | 268.Deps Vet Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner. | oliver-kriska/ | 565 | — | ~1.5k | Automated safety check: Pass | MIT | 4 days ago |
| 269 | Performs comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes. | trailofbits/ | 7.4k | — | ~11k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 270 | Query token security audit to detect scams, honeypots, and malicious contracts before trading. | npc-live/ | 156 | 1 repo | ~1.6k | Automated safety check: Pass | No licence | 3 mo ago |
| 271 | Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies… | eser/ | 128 | — | ~598 | Automated safety check: Pass | Unknown | 5 days ago |
| 272 | 272.Security Review Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. | affaan-m/ | 276k | 1 repo | ~3.2k | Automated safety check: Notes | MIT | 4 days ago |
| 273 | Generates edge case, failure mode, and spec-driven test cases. | ash1794/ | 163 | — | ~1.4k | Automated safety check: Pass | MIT | 2 days ago |
| 274 | A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit. | ccashwell/ | 131 | — | ~1.6k | Automated safety check: Pass | MIT | 9 days ago |
| 275 | Security review: (1) vet an untrusted SKILL.md or .mcp.json BEFORE installing it — the injection/exfiltration scanner; CRITICAL blocks the install; (2) audit code on an untrusted-input path (a… | redhat-et/ | 2.4k | — | ~2.8k | Automated safety check: Warn | Apache-2.0 | today |
| 276 | 276.Proactive Agent Transform AI agents from task-followers into proactive partners. | LeoYeAI/ | 2.2k | — | ~4.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 277 | Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting. | bitwarden/ | 154 | — | ~1.8k | Automated safety check: Pass | Unknown | today |
| 278 | Perform a comprehensive security audit of all project files in the current working directory. | LaravelDaily/ | 136 | — | ~1.9k | Automated safety check: Notes | No licence | 5 mo ago |
| 279 | 279.Security Express Review Express.js security audit patterns for middleware and routes. | IgorWarzocha/ | 122 | — | ~1.8k | Automated safety check: Pass | No licence | 8 mo ago |
| 280 | Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection. | arpitg1304/ | 369 | — | ~7.8k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 281 | Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration. | github/ | 5.4k | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 282 | 282.Security Scan Deep security scanning for .NET applications across 6 layers: vulnerable packages, secrets detection, OWASP code patterns, auth configuration, CORS policy, and data protection. | codewithmukesh/ | 755 | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 283 | 283.Security Audit 全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -… | staruhub/ | 727 | — | ~1.3k | Automated safety check: Notes | MIT | 1 mo ago |
| 284 | 284.Recon Nmap Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection. | AgentSecOps/ | 220 | 1 repo | ~4.6k | Automated safety check: Notes | Unknown | 5 mo ago |
| 285 | 285.Sast Bandit Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. | AgentSecOps/ | 220 | 1 repo | ~2.6k | Automated safety check: Pass | Unknown | 5 mo ago |
| 286 | 286.Webapp Nikto Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. | AgentSecOps/ | 220 | 1 repo | ~2.8k | Automated safety check: Pass | Unknown | 5 mo ago |
| 287 | 287.007 Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project. | sickn33/ | 47k | 2 repos | ~410 | Automated safety check: Pass | MIT | today |
| 288 | Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. | sickn33/ | 47k | 2 repos | ~2.1k | Automated safety check: Notes | MIT | today |
Explore related skills
Category
More topics in Security
- Web application vulnerabilities468
- Vulnerability scanning305
- Static analysis and SAST284
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38