Topic · Security
Best security review skills, page 7
Security review skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 289 | Comprehensive Snowflake development assistant covering SQL best practices, data pipeline design (Dynamic Tables, Streams, Tasks, Snowpipe), Cortex AI functions, Cortex Agents, Snowpark Python, dbt… | sickn33/ | 47k | 2 repos | ~2.1k | Automated safety check: Pass | MIT | today |
| 290 | Human review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service. | sickn33/ | 47k | 2 repos | ~1.1k | Automated safety check: Pass | MIT | today |
| 291 | 291.Report Generator Generates professional security audit reports from findings. | alt-research2/ | 104 | — | ~1k | Automated safety check: Pass | Unknown | 3 mo ago |
| 292 | AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching… | github/ | 40k | 1 repo | ~2.3k | Automated safety check: Notes | MIT | today |
| 293 | Guides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption. | mukul975/ | 34k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 294 | Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 295 | Runs Docker Bench for Security, the open-source CIS Docker Benchmark audit script, across host configuration, daemon settings, images, and runtime configuration, then interprets pass/fail/warn… | mukul975/ | 34k | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 296 | Assesses the security posture of the etcd cluster backing Kubernetes: encryption at rest, TLS peer and client transport, access control, backup encryption, and network isolation. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 297 | 297.Security Audit RLS validation, security audits, OWASP compliance, and vulnerability scanning. | bybren-llc/ | 423 | — | ~1.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 298 | 298.Audit Prep A skill your agent uses when preparing a codebase for security audit. | ccashwell/ | 131 | — | ~1.4k | Automated safety check: Pass | MIT | 9 days ago |
| 299 | Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies. | rileyhilliard/ | 130 | — | ~1.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 300 | Google Workspace administration via the gws CLI (github.com/googleworkspace/cli). | alirezarezvani/ | 28k | — | ~3k | Automated safety check: Notes | MIT | 1 mo ago |
| 301 | 301.Security Audit A skill your agent uses for security reviews of VoxBento code. | fossasia/ | 1.6k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 302 | 302.Security How to handle GRIDA-SEC-<id security boundaries in the Grida repo. | gridaco/ | 2.7k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 303 | 303.Security Review 检查 SQL 注入、XSS、硬编码密钥 | liuyanghejerry/ | 204 | — | ~106 | Automated safety check: Pass | MIT | 10 days ago |
| 304 | Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold… | warpdotdev/ | 313 | 1 repo | ~2k | Automated safety check: Notes | MIT | 22 days ago |
| 305 | Assess a reported security vulnerability in GAIA and fill a PSIRT / JIRA triage: decide if it is valid & exploitable, whether it needs a CVE + bulletin, and produce the CVSS 4.0 score, CWE, and CVE… | amd/ | 1.6k | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 306 | 306.Security Fastapi Review FastAPI security audit patterns for dependencies and middleware. | IgorWarzocha/ | 122 | — | ~893 | Automated safety check: Pass | No licence | 8 mo ago |
| 307 | Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries. | dzhalaevd/ | 135 | — | ~5.1k | Automated safety check: Notes | Apache-2.0 | 6 days ago |
| 308 | Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation). | OWASP/ | 187 | — | ~694 | Automated safety check: Pass | CC-BY-4.0 | 14 days ago |
| 309 | Pre-production audit, hardening, and go-live checklists for FrontMCP servers. | agentfront/ | 146 | — | ~6.5k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 310 | Audit authorized codebases for exploitable vulnerabilities using scoped reconnaissance, adversarial review, validation, and structured reporting. | sickn33/ | 47k | 1 repo | ~3.3k | Automated safety check: Pass | MIT | today |
| 311 | Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls. | sickn33/ | 47k | 1 repo | ~1k | Automated safety check: Notes | MIT | today |
| 312 | 312.Email Security Authorized email security review: phishing analysis, SPF/DKIM/DMARC header authentication, BEC pattern investigation, and mailbox token abuse research. | sickn33/ | 47k | 1 repo | ~603 | Automated safety check: Pass | MIT | today |
| 313 | 313.Wifi Wireless Authorized wireless security assessment: Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauthentication testing. | sickn33/ | 47k | 1 repo | ~589 | Automated safety check: Pass | MIT | today |
| 314 | Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 315 | Audit Azure Storage accounts for public blob containers, missing encryption, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 316 | Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 317 | Conduct cybersecurity assessments of upstream, midstream, and downstream oil and gas operations, covering pipeline SCADA, refinery DCS, safety instrumented systems, and remote wellhead RTUs, and… | mukul975/ | 34k | — | ~4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 318 | Conduct cybersecurity assessments of power grid infrastructure spanning generation, transmission substations, distribution, and EMS control centers, covering NERC CIP compliance verification, IEC… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 319 | Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. | google/ | 21k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 320 | Internal PostHog developer frontend/browser QA skill. An agent skill from PostHog/posthog. | PostHog/ | 40k | — | ~5.9k | Automated safety check: Notes | Unknown | today |
| 321 | Design optimal agent team compositions with sizing heuristics, preset configurations, and agent type selection. | wshobson/ | 40k | — | ~2k | Automated safety check: Pass | MIT | 4 days ago |
| 322 | Audit an application's credentials, authorization, integrations and data handling, with proof and a fix for every finding. | myICOR/ | 307 | — | ~273 | Automated safety check: Pass | MIT | 3 days ago |
| 323 | Operating production Kubernetes clusters effectively with resource management, advanced scheduling, networking, storage, security hardening, and autoscaling. | ancoleman/ | 526 | — | ~3.6k | Automated safety check: Pass | MIT | 10 mo ago |
| 324 | Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles. | ancoleman/ | 526 | — | ~3.5k | Automated safety check: Pass | MIT | 10 mo ago |
| 325 | Run a read-only audit for missing, weak, stale, or mis-scoped test coverage. | github/ | 40k | — | ~3.4k | Automated safety check: Pass | MIT | today |
| 326 | 326.Security Audit Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. | decebals/ | 751 | — | ~3.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 327 | A skill your agent uses when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. | vlinx-io/ | 275 | 1 repo | ~2.1k | Automated safety check: Pass | MIT | 2 days ago |
| 328 | 328.Validation A skill your agent uses when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. | vlinx-io/ | 275 | 1 repo | ~3.2k | Automated safety check: Pass | MIT | 2 days ago |
| 329 | 329.Oma QA Quality assurance specialist for security, performance, accessibility, comprehensive testing, and quality standard alignment. | first-fluke/ | 1.3k | — | ~1.6k | Automated safety check: Pass | MIT | today |
| 330 | 330.Autoresearch Autonomous goal-directed iteration loop: modify, verify, keep/discard against a metric or a checkable success predicate, with bounded cycles, plateau/ceiling backstops, safety-screened commands, and… | leo-kuang-ai/ | 107 | — | ~2.2k | Automated safety check: Pass | MIT | yesterday |
| 331 | Review Maple security across authentication, account isolation, local persistence, Tauri IPC and capabilities, OAuth and deep links, the Local OpenAI Proxy, Agent Mode tools and permissions, MCP… | MaplePrivacyLabs/ | 100 | — | ~7.1k | Automated safety check: Pass | MIT | today |
| 332 | 332.Vc Security STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit. | withkynam/ | 1.1k | — | ~1.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 333 | 333.Wordpress Complete WordPress development workflow covering theme development, plugin creation, WooCommerce integration, performance optimization, and security hardening. | sickn33/ | 47k | 2 repos | ~348 | Automated safety check: Pass | MIT | today |
| 334 | 334.Security Audit Audits Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit authorization policies. | ThibautBaissac/ | 665 | — | ~846 | Automated safety check: Notes | MIT | 4 mo ago |
| 335 | Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills. | rampstackco/ | 941 | — | ~3k | Automated safety check: Pass | MIT | 2 days ago |
| 336 | 336.Code Audit Authorized source-code security review and SAST workflows: Semgrep and CodeQL pattern hunting, dangerous API identification, and fix verification. | sickn33/ | 47k | 1 repo | ~480 | Automated safety check: Pass | MIT | today |
Explore related skills
Category
More topics in Security
- Web application vulnerabilities468
- Vulnerability scanning305
- Static analysis and SAST284
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38