Topic · Security

Best vulnerability scanning skills, page 2

Skills #49–96 of 304, ranked by score.

Vulnerability scanning skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Vulnerability scanning skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.

Tencent/AI-Infra-Guard6.8k—~1.8kAutomated safety check: PassApache-2.0today
50

A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…

LIDR-academy/AI4Devs-LTI-extended278—~4.3kAutomated safety check: NotesMIT4 mo ago
51

This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware"…

zebbern/claude-code-guide4.7k8 repos~3.4kAutomated safety check: NotesMITtoday
52

Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

warpdotdev/warp65k1 repo~2.1kAutomated safety check: PassAGPL-3.0today
53

Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.

ruby-git/ruby-git1.8k—~806Automated safety check: PassMIT6 days ago
54

Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

nvuillam/npm-groovy-lint248—~1.9kAutomated safety check: NotesMIT4 days ago
55

Generate prioritized CVE watchlists and actionable security recommendations for repositories.

ArabelaTso/Skills-4-SE253—~1.7kAutomated safety check: PassApache-2.01 mo ago
56

Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.

getlago/lago-front163—~2.9kAutomated safety check: PassMITtoday
57

Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without…

maddhruv/absolute2181 repo~1.2kAutomated safety check: PassMIT3 mo ago
58

Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

unional/typescript-blackbook133—~1.4kAutomated safety check: WarnMITtoday
59

Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.

epam/ai-dial-chat504—~1.2kAutomated safety check: PassApache-2.0today
60

A skill your agent uses when asked to generate a "no way to prevent this" / no-way-to-prevent-this satire post for a memory-safety CVE (out-of-bounds write/read, buffer/heap overflow…

Xe/site732—~816Automated safety check: PassZlib2 days ago
61

Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

malloydata/publisher116—~5.1kAutomated safety check: PassMITtoday
62

Give a decisive, project-grounded verdict on an external input — judged against the current project, not in the abstract.

leo-kuang-ai/spec-first107—~4.5kAutomated safety check: PassMIT13 days ago
63

Audit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline.

mono/SkiaSharp5.6k—~5.7kAutomated safety check: PassMITtoday
64

Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.

xenitV1/Antigravity-Workflows1307 repos~1.8kAutomated safety check: NotesMIT8 mo ago
65

Handle confidential GitHub Security Advisory response for Paperclip.

paperclipai/paperclip99k—~2kAutomated safety check: PassMITtoday
66

ONVIF device security scanner for testing authentication and brute-forcing credentials.

BrownFineSecurity/iothackbot8581 repo~608Automated safety check: PassMIT4 mo ago
67

Remediate security vulnerabilities found by Grype or pnpm audit.

stacklok/toolhive-studio170—~2.3kAutomated safety check: NotesApache-2.0today
68

Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

AgentSecOps/SecOpsAgentKit2201 repo~2.5kAutomated safety check: PassUnknown5 mo ago
69

Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…

kubernetes-sigs/cloud-provider-azure294—~2.5kAutomated safety check: PassApache-2.0today
70

Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

majiayu000/spellbook286—~1.5kAutomated safety check: PassMITtoday
71

Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.

alirezarezvani/claude-code-tresor777—~1.2kAutomated safety check: NotesMIT3 mo ago
72

A skill your agent uses when asked to sweep, clean up, or revisit pnpm overrides and minimumReleaseAge exclusions in platform/pnpm-workspace.yaml — unwinding a matured temporary CVE pin once its fix…

archestra-ai/archestra4.4k—~1.4kAutomated safety check: PassUnknowntoday
73

Run a security vulnerability assessment based on KISA guidelines.

cdppcorp/KESE-KIT361—~2.3kAutomated safety check: PassMIT6 mo ago
74

Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

skrun-dev/skrun210—~1.3kAutomated safety check: PassMIT15 days ago
75

Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.

getknit/knit131—~1.2kAutomated safety check: PassGPL-3.03 days ago
76

Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~4.2kAutomated safety check: PassMIT3 days ago
77

Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

axelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0today
78

Scan systems and dependencies for CVEs and security vulnerabilities.

BagelHole/DevOps-Security-Agent-Skills1.1k—~2.4kAutomated safety check: PassMIT4 mo ago
79

Run or install repo security leak checks with BetterLeaks and Trivy.

instructa/agent-skills139—~557Automated safety check: PassNo licence9 days ago
80

Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

boostsecurityio/poutine523—~214Automated safety check: PassApache-2.0yesterday
81
81.Claude SecurityOfficial

Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself.

anthropics/claude-plugins-official38k—~1.4kAutomated safety check: PassApache-2.0today
82
82.Fix Image CvesOfficial

Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan.

kubernetes-sigs/cloud-provider-azure294—~818Automated safety check: PassApache-2.0today
83

Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

transilienceai/communitytools562—~1.2kAutomated safety check: NotesMIT2 mo ago
84

Tests a target AI agent for sensitive information disclosure, such as its system prompt, credentials, personal data and internal configuration, using escalating dialogue probes.

Tencent/AI-Infra-Guard6.8k—~954Automated safety check: PassApache-2.0today
85

Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

Jeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT4 days ago
86

Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.

boostsecurityio/poutine523—~173Automated safety check: PassApache-2.0yesterday
87

Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop.

cobusgreyling/loop-engineering11k—~300Automated safety check: PassMITtoday
88

Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…

tinyfish-io/tinyfish-cookbook2.2k—~2.4kAutomated safety check: PassMIT6 days ago
89

Ghost Security - Software Composition Analysis (SCA) scanner.

ghostsecurity/skills408—~1.3kAutomated safety check: NotesApache-2.09 days ago
90

Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.

microsoft/haste107—~1kAutomated safety check: PassMITtoday
91

Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans.

AgentSecOps/SecOpsAgentKit2201 repo~3.3kAutomated safety check: PassUnknown5 mo ago
92

Build, run, debug, and operate applications on AWS Lambda MicroVMs — Firecracker-isolated, snapshot-resumable serverless compute environments that run inside a container with up to 8-hour lifetimes.

awslabs/agent-plugins9151 repo~4.1kAutomated safety check: PassApache-2.02 days ago
93

Turn a plain-English description ("a node that runs on the kernel and does XGBoost predictions", "a node that trims whitespace", "an ML clustering node") into a correct single-file Flowfile custom…

Edwardvaneechoud/Flowfile373—~8.6kAutomated safety check: PassMITtoday
94

Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only.

trailofbits/skills7.4k—~1.8kAutomated safety check: PassCC-BY-SA-4.0today
95

Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
96

A skill your agent uses when adding, updating, or removing CVE/GHSA suppressions in .openvex.json — the OpenVEX document consumed by the weekly image vulnerability scan workflow.

NVIDIA/aicr439—~5.9kAutomated safety check: PassApache-2.0today