Topic · Security
Best vulnerability scanning skills for Claude Code, Codex and other agents.
- skills
- 303
- official
- 22
Vulnerability scanning skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist. | eigent-ai/ | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | today |
| 2 | Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review. | trufflesecurity/ | 28k | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | today |
| 3 | Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT. | NVIDIA/ | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 4 | A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails | payloadcms/ | 45k | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 5 | Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation. | vercel-labs/ | 8.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 6 | Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 893 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 7 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 8 | Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner. | vercel-labs/ | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 9 | Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report. | ruvnet/ | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | today |
| 10 | 当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro… | SummerSec/ | 2.6k | — | ~945 | Automated safety check: Pass | MIT | 4 mo ago |
| 11 | A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK. | vulnersCom/ | 375 | — | ~2.3k | Automated safety check: Pass | MIT | 8 days ago |
| 12 | Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck. | rundeck/ | 6.3k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | today |
| 13 | Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter). | symfony/ | 31k | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 14 | OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews | nyldn/ | 4.2k | 1 repo | ~2.3k | Automated safety check: Pass | MIT | today |
| 15 | Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. | mono/ | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | today |
| 16 | Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities. | context-labs/ | 1.1k | 2 repos | ~3k | Automated safety check: Pass | MIT | 2 days ago |
| 17 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 22 days ago |
| 18 | 18.Forensify Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 187 | — | ~2.5k | Automated safety check: Notes | Unknown | 10 days ago |
| 19 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 423 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 20 | Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. | gocronx-team/ | 808 | — | ~690 | Automated safety check: Pass | MIT | 5 days ago |
| 21 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | 9 days ago |
| 22 | Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE. | evdenis/ | 138 | — | ~2.5k | Automated safety check: Pass | GPL-3.0 | 5 days ago |
| 23 | Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge. | TheDecipherist/ | 550 | — | ~1.3k | Automated safety check: Notes | MIT | 5 mo ago |
| 24 | Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings. | tradecatlabs/ | 17k | 1 repo | ~738 | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 25 | A skill your agent uses when scanning code for security vulnerabilities. | tanviet12/ | 287 | — | ~5.3k | Automated safety check: Notes | MIT | 9 days ago |
| 26 | 26.Secskills 渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。 | Arenbai/ | 249 | — | ~1.8k | Automated safety check: Notes | MIT | 8 days ago |
| 27 | Triage Apache Roller security reports, maintain private case tracking, prepare CVE records, coordinate fixes and reporter review, and prepare disclosure with a release. | apache/ | 133 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 28 | 28.Cyberowlai Check if recent cybersecurity alerts from 10 international CERTs affect your current project. | karimhabush/ | 263 | — | ~2.5k | Automated safety check: Pass | MIT | yesterday |
| 29 | Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps. | zereight/ | 2k | 1 repo | ~859 | Automated safety check: Notes | MIT | yesterday |
| 30 | 30.Audit Fix Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree. | openplayerjs/ | 649 | — | ~1k | Automated safety check: Pass | MIT | 2 days ago |
| 31 | Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files… | livesession/ | 114 | — | ~2k | Automated safety check: Pass | MIT | 15 days ago |
| 32 | Triage a security finding in a Symfony UX package into a disposition: a private CVE (coordinated disclosure through the Symfony security process), a public hardening PR (fix in the open, no CVE), or… | symfony/ | 1.1k | — | ~3.2k | Automated safety check: Pass | MIT | yesterday |
| 33 | Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills. | aliyun/ | 148 | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 34 | 34.Chaitin CLI A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability… | chaitin/ | 114 | — | ~15k | Automated safety check: Notes | GPL-3.0 | 8 days ago |
| 35 | Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results. | block/ | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 36 | A skill your agent uses when scanning code for security vulnerabilities. | tanviet12/ | 287 | — | ~6.8k | Automated safety check: Notes | MIT | 9 days ago |
| 37 | Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING… | MidnightBSD/ | 114 | — | ~2.2k | Automated safety check: Pass | Unknown | 3 days ago |
| 38 | Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs. | eclipse-ankaios/ | 125 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 39 | 39.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 281 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 40 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 219 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 41 | Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled. | garrytan/ | 136k | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 42 | Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。 | aliyun/ | 148 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 43 | Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection. | zebbern/ | 4.6k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 44 | 44.Docs Update project documentation when features are added or changed. | boostsecurityio/ | 522 | — | ~336 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 45 | Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths. | Tencent/ | 6.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 46 | A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a… | LIDR-academy/ | 278 | — | ~4.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 47 | Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images. | warpdotdev/ | 65k | 1 repo | ~2.1k | Automated safety check: Pass | AGPL-3.0 | today |
| 48 | This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware"… | zebbern/ | 4.6k | 7 repos | ~3.4k | Automated safety check: Notes | MIT | today |
Questions, answered from the data.
What is the best vulnerability scanning skill?
Security Auditor from eigent-ai/eigent ranks first of the 303 vulnerability scanning skills listed here, with the highest score: its repository has 15k GitHub stars, its SKILL.md loads about 1.8k tokens and it has informational notes only in the automated safety check. Next come Dep Updates and Skill Inspector.
Which vulnerability scanning skills are official?
22 of the 303 vulnerability scanning skills are official, published by the vendor's own GitHub organization: Skill Inspector, Deepsec Vulnerability Scanner, CodeQL Security Scan, Deepsec Documentation Guide, CodeCrucible Security Scans and 17 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
More topics in Security
- Security review611
- Web application vulnerabilities460
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34