Topic · Security
Best vulnerability scanning skills, page 3
Vulnerability scanning skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | Review a PR through the CodeReviewSecurityReview persona. An agent skill from eric-tramel/moraine. | eric-tramel/ | 117 | — | ~497 | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 98 | Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults. | Aedelon/ | 120 | — | ~1.6k | Automated safety check: Notes | Unknown | 7 mo ago |
| 99 | Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 100 | 100.Quarkus Security Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt… | affaan-m/ | 275k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | 3 days ago |
| 101 | Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix. | trailofbits/ | 7.4k | — | ~3.1k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 102 | Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 103 | Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents. | trailofbits/ | 7.4k | — | ~2.7k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 104 | Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. | trailofbits/ | 7.4k | — | ~3.2k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 105 | Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. | trailofbits/ | 7.4k | — | ~3.8k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 106 | 106.Dast Nuclei Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues across web… | AgentSecOps/ | 220 | 1 repo | ~4.1k | Automated safety check: Notes | Unknown | 5 mo ago |
| 107 | 107.Senior Secops Comprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. | davila7/ | 32k | 1 repo | ~1.1k | Automated safety check: Notes | MIT | today |
| 108 | 108.Security Audit Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening. | davila7/ | 32k | 4 repos | ~1.3k | Automated safety check: Pass | MIT | today |
| 109 | Configure code scanning in Harness pipelines using STO security scanners. | harness/ | 115 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 110 | 110.Senior Secops Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. | alirezarezvani/ | 28k | 1 repo | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 111 | 111.Security Scan Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes. | bagofwords1/ | 458 | — | ~1.7k | Automated safety check: Pass | Unknown | today |
| 112 | 112.Static Security Static security review for Flutter mobile apps and Dart code: hardcoded secrets, insecure storage, unsafe network calls, leaky logs, vulnerable dependencies. | VeryGoodOpenSource/ | 169 | — | ~4.4k | Automated safety check: Notes | MIT | 2 days ago |
| 113 | Agent skill for v3-security-architect - invoke with $agent-v3-security-architect | ruvnet/ | 74k | 2 repos | ~1.5k | Automated safety check: Pass | MIT | today |
| 114 | 114.Webvuln Web vulnerability hunting playbook. An agent skill from PentesterFlow/agent. | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 115 | 115.Cve Scan Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart). | softspark/ | 179 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 116 | 116.Cybersecurity Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e… | ohmyjahh/ | 276 | — | ~895 | Automated safety check: Pass | MIT | 8 days ago |
| 117 | 117.Security Audit Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology | RightNow-AI/ | 18k | — | ~858 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 118 | For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the… | lyonzin/ | 290 | — | ~2.3k | Automated safety check: Pass | MIT | 3 days ago |
| 119 | Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and… | hardw00t/ | 104 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 120 | 120.Sca Trivy Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license… | AgentSecOps/ | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 121 | Scan package manifests and lockfiles for outdated and vulnerable dependencies. | cobusgreyling/ | 11k | — | ~206 | Automated safety check: Pass | MIT | today |
| 122 | 122.Security Audit 全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -… | staruhub/ | 727 | — | ~1.3k | Automated safety check: Notes | MIT | 1 mo ago |
| 123 | 123.Sbom Syft Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives. | AgentSecOps/ | 220 | 1 repo | ~3.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 124 | 124.Webapp Nikto Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. | AgentSecOps/ | 220 | 1 repo | ~2.8k | Automated safety check: Pass | Unknown | 5 mo ago |
| 125 | KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. | SnailSploit/ | 7.3k | — | ~1.1k | Automated safety check: Notes | MIT | 18 days ago |
| 126 | A skill your agent uses when a user asks what the EU Cyber Resilience Act (CRA) means for their product, whether and when they must report a vulnerability or incident, or what a specific CVE… | davila7/ | 32k | 1 repo | ~4.5k | Automated safety check: Pass | CC-BY-4.0 | today |
| 127 | AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching… | github/ | 40k | 1 repo | ~2.3k | Automated safety check: Notes | MIT | today |
| 128 | 128.Golang Security Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory… | unxed/ | 241 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | today |
| 129 | Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 130 | Deploy DefectDojo as a centralized vulnerability management dashboard that ingests findings from 200+ security scanners, deduplicates results, tracks remediation metrics, and integrates with CI/CD… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 131 | Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 132 | Deploy and configure Rapid7 InsightVM Security Console and Scan Engines, including scan templates, credentialed scanning, and Insight Agent integration, for authenticated and unauthenticated… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 133 | Fetch and parse the CISA Known Exploited Vulnerabilities (KEV) catalog, enrich it with EPSS scores and CVSS metrics, and build a multi-factor prioritization engine and report that ranks CVE… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 134 | Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 135 | Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 136 | Scores Kubernetes resource manifests with Kubesec to flag misconfiguration and privilege-escalation risk before deployment, mapping each finding back to the securityContext change that fixes it. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 137 | Golang dependency management — go.mod, installing/upgrading packages, Minimal Version Selection, vulnerability scanning, binary size, Dependabot/Renovate, conflict resolution, go.work. | context-labs/ | 1.1k | — | ~2.4k | Automated safety check: Pass | MIT | 3 days ago |
| 138 | 138.Web Vuln Web vulnerability scanning workflow covering SQLi, XSS, template injection, and generic CVE detection using nuclei, sqlmap, dalfox, nikto, and jaeles | CommonHuman-Lab/ | 157 | — | ~896 | Automated safety check: Pass | Unknown | today |
| 139 | 139.Security Audit RLS validation, security audits, OWASP compliance, and vulnerability scanning. | bybren-llc/ | 421 | — | ~1.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 140 | Audit and manage dependencies across multi-language projects. | alirezarezvani/ | 28k | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 141 | Assess a reported security vulnerability in GAIA and fill a PSIRT / JIRA triage: decide if it is valid & exploitable, whether it needs a CVE + bulletin, and produce the CVSS 4.0 score, CWE, and CVE… | amd/ | 1.6k | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 142 | Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls. | sickn33/ | 47k | 1 repo | ~1k | Automated safety check: Notes | MIT | today |
| 143 | 143.Conducty Ship Pre-merge / pre-deploy gate. An agent skill from robertbarclayy/conducty. | robertbarclayy/ | 176 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 144 | Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38