Topic · Security
Best security review skills, page 8
Security review skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 337 | Harden OpenClaw self-hosted environments with baseline host controls, auth tightening, secret handling, network segmentation, and safe update/rollback workflows. | sickn33/ | 47k | 1 repo | ~1.2k | Automated safety check: Notes | MIT | today |
| 338 | Reference document for monopoly security-checklist. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~803 | Automated safety check: Pass | MIT | today |
| 339 | Cracks password hashes with Hashcat, covering hash-type identification, dictionary/brute-force/rule-based attack modes, custom rule creation, GPU benchmarking, and password-strength/compliance… | mukul975/ | 34k | — | ~893 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 340 | Manages core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment. | google/ | 21k | — | ~995 | Automated safety check: Pass | Apache-2.0 | today |
| 341 | Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. | Varnan-Tech/ | 674 | — | ~3k | Automated safety check: Notes | MIT | 1 mo ago |
| 342 | Audit a product or tech spec pull request diff for high-level security concerns (threat surface, authentication and authorization model, trust boundaries, sensitive data handling, secrets and key… | warpdotdev/ | 313 | 1 repo | ~2.6k | Automated safety check: Pass | MIT | 22 days ago |
| 343 | 343.Money Quality Code and product quality gates for shipping with confidence. | iamzifei/ | 1k | — | ~5.7k | Automated safety check: Pass | Unknown | 1 mo ago |
| 344 | 344.Security Audit A skill your agent uses when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying… | nicepkg/ | 194 | 1 repo | ~676 | Automated safety check: Pass | No licence | 7 mo ago |
| 345 | 345.Security Nextjs Review Next.js security audit patterns for App Router and Server Actions. | IgorWarzocha/ | 122 | — | ~1.5k | Automated safety check: Notes | No licence | 8 mo ago |
| 346 | 346.Security Review Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles. | affaan-m/ | 276k | — | ~3.4k | Automated safety check: Notes | MIT | 4 days ago |
| 347 | Validate security findings for exploitability, reachability, and real-world impact using Bug Hunter-native findings artifacts. | codexstar69/ | 519 | — | ~497 | Automated safety check: Pass | MIT | 1 mo ago |
| 348 | Run Azure compliance and security audits with azqr plus Key Vault expiration checks. | microsoft/ | 255 | 2 repos | ~997 | Automated safety check: Pass | MIT | today |
| 349 | A skill your agent uses when reviewing or writing code that handles user input, authentication, file I/O, network requests, or database queries. | aiming-lab/ | 3.5k | — | ~249 | Automated safety check: Pass | MIT | 4 mo ago |
| 350 | Hardens LDAP directory services against credential harvesting, LDAP injection, anonymous binding, and channel-binding bypass by enforcing LDAPS, channel binding, and LDAP signing. | mukul975/ | 34k | — | ~756 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 351 | Configures Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control, covering signal-based policy design, device compliance requirements, risk-based authentication… | mukul975/ | 34k | — | ~689 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 352 | Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 353 | Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 354 | Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 355 | Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 356 | Assess SSL/TLS server configurations using the sslyze Python scanning library to evaluate supported protocol versions, cipher suite strength, certificate chain validation, HSTS enforcement, OCSP… | mukul975/ | 34k | — | ~597 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 357 | Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 358 | A skill your agent uses when reviewing HTTP response headers for defense-in-depth security hardening on any web application. | thedaviddias/ | 74k | — | ~565 | Automated safety check: Pass | MIT | 3 days ago |
| 359 | 359.X Content Type A skill your agent uses when auditing HTTP response headers on any web server or CDN for security hardening. | thedaviddias/ | 74k | — | ~513 | Automated safety check: Pass | MIT | 3 days ago |
| 360 | Audit SillyTavern rolecard JSON, embedded HTML, regex replacements, Tavern Helper scripts, loaders, and related source for injection, dynamic execution, remote-code, wildcard messaging… | LiarMTTT/ | 153 | — | ~993 | Automated safety check: Pass | Unknown | 5 days ago |
| 361 | CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows). | pskoett/ | 314 | — | ~1.1k | Automated safety check: Pass | No licence | 4 days ago |
| 362 | Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management. | rand/ | 181 | — | ~1.9k | Automated safety check: Pass | MIT | 7 mo ago |
| 363 | Audit architecture, dead code, duplication, type confusion, and code smells across a codebase. | pedronauck/ | 634 | 1 repo | ~524 | Automated safety check: Pass | No licence | 25 days ago |
| 364 | 364.Security Audit Security scanning and vulnerability detection. An agent skill from ruvnet/ruflo. | ruvnet/ | 74k | — | ~229 | Automated safety check: Pass | MIT | today |
| 365 | A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including… | hyodotdev/ | 155 | — | ~766 | Automated safety check: Pass | MIT | today |
| 366 | PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). | tetherto/ | 683 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 367 | Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects. | romarayt/ | 149 | — | ~572 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 368 | Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. | c0x12c/ | 106 | — | ~1.6k | Automated safety check: Warn | No licence | 3 mo ago |
| 369 | Audit MCP (Model Context Protocol) server configurations for security issues. | github/ | 40k | — | ~3.1k | Automated safety check: Pass | MIT | today |
| 370 | 370.Security Review Perform a focused security review of pending git changes to identify high-confidence security vulnerabilities with real exploitation potential. | waybarrios/ | 533 | — | ~4.1k | Automated safety check: Pass | MIT | 3 days ago |
| 371 | 371.Security Review Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it… | trycompai/ | 2k | — | ~853 | Automated safety check: Pass | AGPL-3.0 | 2 days ago |
| 372 | This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. | mukul975/ | 34k | — | ~6.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 373 | Test pyramid strategy, coverage targets, test patterns, and quality metrics reference. | modu-ai/ | 1.2k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 374 | 374.Security Auditor Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. | aiskillstore/ | 430 | 6 repos | ~2.6k | Automated safety check: Pass | No licence | today |
| 375 | Create standardized report headers with metadata for all agent-generated reports. | maslennikov-ig/ | 260 | — | ~1.2k | Automated safety check: Pass | Unknown | 7 mo ago |
| 376 | 376.Secure By Design Run an enterprise security review of a system design or existing code before it ships. | ooiyeefei/ | 494 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 377 | Continuous security posture assessment. An agent skill from bolivian-peru/os-moda. | bolivian-peru/ | 119 | — | ~819 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 378 | Enforce output quality, evidence verification, and quality gates across security audits. | github/ | 40k | — | ~1k | Automated safety check: Pass | MIT | today |
| 379 | 379.Code Review Web Review web application code for bugs, security issues, performance problems, and stack-specific anti-patterns. | rampstackco/ | 941 | — | ~2.7k | Automated safety check: Pass | MIT | 2 days ago |
| 380 | 380.Security Secrets Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows. | IgorWarzocha/ | 122 | — | ~1.2k | Automated safety check: Notes | No licence | 8 mo ago |
| 381 | 381.Sec Check Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code. | waynesutton/ | 628 | — | ~753 | Automated safety check: Pass | MIT | 4 mo ago |
| 382 | 382.Review Code Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in… | tobihagemann/ | 409 | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 383 | A skill your agent uses when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. | vlinx-io/ | 275 | 1 repo | ~6.3k | Automated safety check: Pass | MIT | 2 days ago |
| 384 | UI polish and interface-completion reference: the small visual details — concentric border radius, optical alignment, shadow-vs-border, motion easing, typography smoothing, tabular numbers, icon… | modu-ai/ | 1.2k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | today |
Explore related skills
Category
More topics in Security
- Web application vulnerabilities468
- Vulnerability scanning305
- Static analysis and SAST284
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38