Topic · Security
Best vulnerability scanning skills, page 2
Vulnerability scanning skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths. | Tencent/ | 6.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 50 | A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a… | LIDR-academy/ | 278 | — | ~4.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 51 | This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware"… | zebbern/ | 4.7k | 8 repos | ~3.4k | Automated safety check: Notes | MIT | today |
| 52 | Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images. | warpdotdev/ | 65k | 1 repo | ~2.1k | Automated safety check: Pass | AGPL-3.0 | today |
| 53 | Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages. | ruby-git/ | 1.8k | — | ~806 | Automated safety check: Pass | MIT | 6 days ago |
| 54 | Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify… | nvuillam/ | 248 | — | ~1.9k | Automated safety check: Notes | MIT | 4 days ago |
| 55 | Generate prioritized CVE watchlists and actionable security recommendations for repositories. | ArabelaTso/ | 253 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 56 | 56.Cve Doctor Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix. | getlago/ | 163 | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 57 | Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without… | maddhruv/ | 218 | 1 repo | ~1.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 58 | Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks. | unional/ | 133 | — | ~1.4k | Automated safety check: Warn | MIT | today |
| 59 | 59.Dep Scan Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema. | epam/ | 504 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 60 | A skill your agent uses when asked to generate a "no way to prevent this" / no-way-to-prevent-this satire post for a memory-safety CVE (out-of-bounds write/read, buffer/heap overflow… | Xe/ | 732 | — | ~816 | Automated safety check: Pass | Zlib | 2 days ago |
| 61 | Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in… | malloydata/ | 116 | — | ~5.1k | Automated safety check: Pass | MIT | today |
| 62 | 62.Spec Pov Give a decisive, project-grounded verdict on an external input — judged against the current project, not in the abstract. | leo-kuang-ai/ | 107 | — | ~4.5k | Automated safety check: Pass | MIT | 13 days ago |
| 63 | Audit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline. | mono/ | 5.6k | — | ~5.7k | Automated safety check: Pass | MIT | today |
| 64 | Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows. | xenitV1/ | 130 | 7 repos | ~1.8k | Automated safety check: Notes | MIT | 8 mo ago |
| 65 | Handle confidential GitHub Security Advisory response for Paperclip. | paperclipai/ | 99k | — | ~2k | Automated safety check: Pass | MIT | today |
| 66 | 66.Onvifscan ONVIF device security scanner for testing authentication and brute-forcing credentials. | BrownFineSecurity/ | 858 | 1 repo | ~608 | Automated safety check: Pass | MIT | 4 mo ago |
| 67 | Remediate security vulnerabilities found by Grype or pnpm audit. | stacklok/ | 170 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | today |
| 68 | Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds. | AgentSecOps/ | 220 | 1 repo | ~2.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 69 | Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the… | kubernetes-sigs/ | 294 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 70 | Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner. | majiayu000/ | 286 | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 71 | Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. | alirezarezvani/ | 777 | — | ~1.2k | Automated safety check: Notes | MIT | 3 mo ago |
| 72 | A skill your agent uses when asked to sweep, clean up, or revisit pnpm overrides and minimumReleaseAge exclusions in platform/pnpm-workspace.yaml — unwinding a matured temporary CVE pin once its fix… | archestra-ai/ | 4.4k | — | ~1.4k | Automated safety check: Pass | Unknown | today |
| 73 | Run a security vulnerability assessment based on KISA guidelines. | cdppcorp/ | 361 | — | ~2.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 74 | Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. | skrun-dev/ | 210 | — | ~1.3k | Automated safety check: Pass | MIT | 15 days ago |
| 75 | Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. | getknit/ | 131 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 3 days ago |
| 76 | 76.Cis Controls Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection… | Sushegaad/ | 942 | 1 repo | ~4.2k | Automated safety check: Pass | MIT | 3 days ago |
| 77 | Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle… | axelixlabs/ | 148 | — | ~4.2k | Automated safety check: Pass | LGPL-3.0 | today |
| 78 | Scan systems and dependencies for CVEs and security vulnerabilities. | BagelHole/ | 1.1k | — | ~2.4k | Automated safety check: Pass | MIT | 4 mo ago |
| 79 | Run or install repo security leak checks with BetterLeaks and Trivy. | instructa/ | 139 | — | ~557 | Automated safety check: Pass | No licence | 9 days ago |
| 80 | 80.Snapshot Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions. | boostsecurityio/ | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 81 | Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself. | anthropics/ | 38k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 82 | Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan. | kubernetes-sigs/ | 294 | — | ~818 | Automated safety check: Pass | Apache-2.0 | today |
| 83 | Security-focused source code review and SAST. An agent skill from transilienceai/communitytools. | transilienceai/ | 562 | — | ~1.2k | Automated safety check: Notes | MIT | 2 mo ago |
| 84 | Tests a target AI agent for sensitive information disclosure, such as its system prompt, credentials, personal data and internal configuration, using escalating dialogue probes. | Tencent/ | 6.8k | — | ~954 | Automated safety check: Pass | Apache-2.0 | today |
| 85 | Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review. | Jeffallan/ | 12k | — | ~1.3k | Automated safety check: Pass | MIT | 4 days ago |
| 86 | Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository. | boostsecurityio/ | 523 | — | ~173 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 87 | Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop. | cobusgreyling/ | 11k | — | ~300 | Automated safety check: Pass | MIT | today |
| 88 | 88.Dep Security Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that… | tinyfish-io/ | 2.2k | — | ~2.4k | Automated safety check: Pass | MIT | 6 days ago |
| 89 | Ghost Security - Software Composition Analysis (SCA) scanner. | ghostsecurity/ | 408 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | 9 days ago |
| 90 | Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste. | microsoft/ | 107 | — | ~1k | Automated safety check: Pass | MIT | today |
| 91 | Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans. | AgentSecOps/ | 220 | 1 repo | ~3.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 92 | Build, run, debug, and operate applications on AWS Lambda MicroVMs — Firecracker-isolated, snapshot-resumable serverless compute environments that run inside a container with up to 8-hour lifetimes. | awslabs/ | 915 | 1 repo | ~4.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 93 | Turn a plain-English description ("a node that runs on the kernel and does XGBoost predictions", "a node that trims whitespace", "an ML clustering node") into a correct single-file Flowfile custom… | Edwardvaneechoud/ | 373 | — | ~8.6k | Automated safety check: Pass | MIT | today |
| 94 | Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 95 | Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 96 | A skill your agent uses when adding, updating, or removing CVE/GHSA suppressions in .openvex.json — the OpenVEX document consumed by the weekly image vulnerability scan workflow. | NVIDIA/ | 439 | — | ~5.9k | Automated safety check: Pass | Apache-2.0 | today |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38