Topic · Security
Best vulnerability scanning skills, page 4
Vulnerability scanning skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 145 | Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 146 | Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 147 | Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 148 | Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis, providing asset visibility, behavioral anomaly detection, protocol-aware monitoring, and vulnerability assessment… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 149 | Audits container and pod configuration for escape-enabling misconfiguration using the Kubernetes Python client - privileged flags, dangerous capability grants, host path mounts, shared namespaces… | mukul975/ | 34k | — | ~648 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 150 | Perform OT vulnerability assessments using the Claroty xDome platform for asset discovery, risk scoring, and vulnerability correlation, combining passive traffic-based identification and active safe… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 151 | Conducts a sector-specific threat landscape assessment (financial, healthcare, energy, government, etc.) by profiling targeting threat actors, mapping attack vectors and MITRE ATT&CK TTPs with the… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 152 | Hardens serverless compute platforms (AWS Lambda, Azure Functions, Google Cloud Functions): least-privilege IAM roles, dependency vulnerability scanning, secrets management integration, input… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 153 | Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 154 | 154.Dependency Audit Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. | briiirussell/ | 413 | — | ~3.2k | Automated safety check: Warn | MIT | 4 mo ago |
| 155 | 155.Pii Guard Personally identifiable information (PII) leak prevention for EverClaw. | profbernardoj/ | 112 | — | ~921 | Automated safety check: Pass | MIT | 1 mo ago |
| 156 | 156.Recon Osint A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover… | hypnguyen1209/ | 388 | — | ~2.2k | Automated safety check: Pass | MIT | 11 days ago |
| 157 | A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. | alirezarezvani/ | 28k | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 158 | 158.Chimera A skill your agent uses for post-session code quality review of files added or modified during a WrongStack session. | WrongStack/ | 370 | — | ~3.2k | Automated safety check: Pass | MIT | today |
| 159 | 159.Analyze Cve Full Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers. | openshift-eng/ | 120 | — | ~2k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 160 | Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories. | alt-research2/ | 104 | — | ~1.6k | Automated safety check: Notes | Unknown | 3 mo ago |
| 161 | A skill your agent uses when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis. | sangrokjung/ | 852 | — | ~1k | Automated safety check: Notes | MIT | 1 mo ago |
| 162 | Scan systems and dependencies for CVEs and security vulnerabilities. | sickn33/ | 47k | 1 repo | ~2.8k | Automated safety check: Pass | MIT | today |
| 163 | Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 164 | Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents. | mukul975/ | 34k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 165 | This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 166 | Tenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network infrastructure including servers, workstations, network devices, and operating systems. | mukul975/ | 34k | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 167 | Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. | Varnan-Tech/ | 674 | — | ~3k | Automated safety check: Notes | MIT | 1 mo ago |
| 168 | 168.Security Audit A skill your agent uses when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying… | nicepkg/ | 194 | 1 repo | ~676 | Automated safety check: Pass | No licence | 7 mo ago |
| 169 | 当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。 | zhaji2333/ | 114 | — | ~688 | Automated safety check: Warn | MIT | 24 days ago |
| 170 | Application security defense knowledge for builders. An agent skill from telagod/code-abyss. | telagod/ | 243 | — | ~777 | Automated safety check: Pass | MIT | 2 mo ago |
| 171 | Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 172 | Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library over the Greenbone Management Protocol (GMP) to connect via Unix socket or TLS, create scan targets and… | mukul975/ | 34k | — | ~778 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 173 | Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed… | mukul975/ | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 174 | Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 175 | Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across network… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 176 | Performs advanced network recon using Nmap's Scripting Engine (NSE), timing controls, firewall/IDS evasion, and structured output parsing to discover hosts, enumerate service versions, detect… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 177 | 177.Dep Triage Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context). | epam/ | 504 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 178 | Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management. | rand/ | 181 | — | ~1.9k | Automated safety check: Pass | MIT | 7 mo ago |
| 179 | Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification… | kubernetes-sigs/ | 294 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | today |
| 180 | A skill your agent uses when asked to generate a vulnerability and exposure management report, assess security posture, or review CVEs, security configurations, and attack paths. | SCStelz/ | 250 | — | ~15k | Automated safety check: Pass | MIT | today |
| 181 | 181.Cveapi CVE lookup via MITRE + NVD: severity, CVSS, affected products, refs | taracodlabs/ | 851 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 25 days ago |
| 182 | Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps. | google/ | 21k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | today |
| 183 | 183.Security Auditor Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. | aiskillstore/ | 430 | 6 repos | ~2.6k | Automated safety check: Pass | No licence | today |
| 184 | Run osv-scanner via the mantisosvscanner MCP server for SCA (vulnerable dependency) findings | deonmenezes/ | 504 | — | ~298 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 185 | Inventories project dependencies and runtimes across ecosystems and reports known CVEs, supply-chain risks and a prioritized upgrade plan. | criptogus/ | 288 | — | ~974 | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 186 | 186.Security Audit RLS validation, security audits, OWASP compliance, and vulnerability scanning. | bybren-llc/ | 423 | — | ~1.4k | Automated safety check: Notes | MIT | 2 mo ago |
| 187 | 187.Dependency Check Scan project dependencies for known vulnerabilities and CVEs. | ruvnet/ | 74k | — | ~258 | Automated safety check: Pass | MIT | today |
| 188 | 188.Security Scanner A skill your agent uses when scanning code or configuration for security vulnerabilities. | WrongStack/ | 370 | — | ~2.1k | Automated safety check: Pass | MIT | today |
| 189 | 189.Network Scanner Run authorized network reconnaissance with Nmap on Windows (or Linux). | ptn1411/ | 220 | — | ~1.4k | Automated safety check: Notes | No licence | 17 days ago |
| 190 | You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. | aiskillstore/ | 430 | 7 repos | ~490 | Automated safety check: Pass | No licence | today |
| 191 | You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. | aiskillstore/ | 430 | 7 repos | ~563 | Automated safety check: Pass | No licence | today |
| 192 | 192.Cve Source Check Audit CVE/vulnerability source coverage for a technology stack. | notque/ | 439 | — | ~1.4k | Automated safety check: Notes | MIT | 6 days ago |
Explore related skills
More topics in Security
- Security review637
- Web application vulnerabilities468
- Static analysis and SAST284
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38