Topic · Security
Best web application vulnerabilities skills for Claude Code, Codex and other agents.
- skills
- 467
- official
- 15
Web application vulnerabilities skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Hardens code against vulnerabilities. An agent skill from penpot/penpot. | penpot/ | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | today |
| 2 | Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist. | eigent-ai/ | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | today |
| 3 | A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. | jewbetcha/ | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 4 | Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept. | usestrix/ | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 5 | Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 893 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 6 | Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works. | usestrix/ | 67k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments. | awarexone/ | 5.3k | 2 repos | ~4.7k | Automated safety check: Pass | MIT | 3 days ago |
| 8 | A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol. | tradecatlabs/ | 17k | 2 repos | ~3.3k | Automated safety check: Pass | MIT | today |
| 9 | WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws… | tanweai/ | 1.8k | — | ~1.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 10 | Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept. | usestrix/ | 67k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 11 | Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet. | awarexone/ | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | 3 days ago |
| 12 | Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report. | ruvnet/ | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | today |
| 13 | Security code review for vulnerabilities. An agent skill from getsentry/skills. | getsentry/ | 1k | 4 repos | ~2.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 14 | OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews | nyldn/ | 4.2k | 1 repo | ~2.3k | Automated safety check: Pass | MIT | today |
| 15 | 15.Maven Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing. | skjolber/ | 568 | — | ~886 | Automated safety check: Pass | Apache-2.0 | today |
| 16 | Query 57 Indonesian government APIs and data sources — BPJPH halal certification, BPOM food safety, OJK financial legality, BPS statistics, BMKG weather/earthquakes, Bank Indonesia exchange rates… | suryast/ | 172 | — | ~997 | Automated safety check: Pass | MIT | today |
| 17 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 4 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 18 | Handles Laravel Cashier Stripe integration including subscriptions, webhooks, Stripe Checkout, invoices, charges, refunds, trials, coupons, metered billing, and payment failure handling. | luadotsh/ | 343 | 1 repo | ~1.2k | Automated safety check: Pass | MIT | 16 days ago |
| 19 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 22 days ago |
| 20 | Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization. | PentesterFlow/ | 1.4k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 21 | Reviews code for security vulnerabilities and guides secure implementation using OWASP Top 10:2025, ASVS 5.0, the OWASP Top 10 for LLM Applications (2026), and the OWASP Top 10 for Agentic… | agamm/ | 377 | — | ~3.5k | Automated safety check: Pass | MIT | 13 days ago |
| 22 | 22.Vibe Check Security audit for web apps, especially AI-built ("vibe coded") ones. | benavlabs/ | 118 | — | ~1.1k | Automated safety check: Notes | MIT | 19 days ago |
| 23 | Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. | jeremylongshore/ | 2.8k | 2 repos | ~1.3k | Automated safety check: Notes | MIT | today |
| 24 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 423 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 25 | Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. | gocronx-team/ | 808 | — | ~690 | Automated safety check: Pass | MIT | 5 days ago |
| 26 | Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. | EpicenterHQ/ | 4.8k | — | ~896 | Automated safety check: Pass | Unknown | today |
| 27 | Django access control and IDOR security review. An agent skill from getsentry/skills. | getsentry/ | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | 5 days ago |
| 28 | Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then… | Yikai-Liao/ | 189 | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 29 | 29.Secskills 渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。 | Arenbai/ | 251 | — | ~1.8k | Automated safety check: Notes | MIT | 9 days ago |
| 30 | Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn. | Encod3d-Sec/ | 329 | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 31 | Drive the AuthEndpoints HTTP API via the in-repo test host (cookie sessions, Identity bearer, Simple JWT, CSRF, ReAuth). | madeyoga/ | 121 | — | ~2.7k | Automated safety check: Pass | MIT | today |
| 32 | Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and… | discord-php/ | 1.1k | — | ~1.2k | Automated safety check: Notes | MIT | yesterday |
| 33 | 33.Kuri Agent Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make… | justrach/ | 365 | — | ~1.3k | Automated safety check: Notes | Unknown | 2 mo ago |
| 34 | Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged… | samugit83/ | 3k | — | ~1.4k | Automated safety check: Pass | MIT | today |
| 35 | Security-focused code review checklist and automated scanning patterns. | nicepkg/ | 192 | 1 repo | ~3.9k | Automated safety check: Pass | MIT | 7 mo ago |
| 36 | 36.Sail Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. | pillar-labs/ | 113 | — | ~5.1k | Automated safety check: Pass | Unknown | 3 mo ago |
| 37 | Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data. | addyosmani/ | 103k | 1 repo | ~4.4k | Automated safety check: Notes | MIT | 4 days ago |
| 38 | 38.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 281 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 39 | Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets. | Tencent/ | 6.8k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | today |
| 40 | Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration. | gdarko/ | 145 | — | ~668 | Automated safety check: Notes | MIT | 6 mo ago |
| 41 | Apply Rails security and multi-tenant safety practices including scoped queries, SSRF defenses, rate limiting, and tenant-scoped realtime updates. | marckohlbrugge/ | 724 | — | ~1.7k | Automated safety check: Pass | No licence | 4 mo ago |
| 42 | Runs and interprets Psalm security (taint) analysis on a Laravel project. | cachethq/ | 230 | — | ~4.7k | Automated safety check: Pass | Unknown | 2 days ago |
| 43 | Sentry-specific security review based on real vulnerability history. | getsentry/ | 46k | — | ~2.3k | Automated safety check: Notes | Unknown | today |
| 44 | A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own… | agentfront/ | 146 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 45 | Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or… | supercheck-io/ | 215 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | today |
| 46 | Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection. | zebbern/ | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 47 | Automate low-impact web vulnerability verification through Burp MCP. | langbyyi/ | 134 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | today |
| 48 | 48.API Design Backend API design specialist. An agent skill from selmakcby/claude-agents-skills. | selmakcby/ | 136 | — | ~1.1k | Automated safety check: Pass | MIT | 5 mo ago |
Questions, answered from the data.
What is the best web application vulnerabilities skill?
Security And Hardening from penpot/penpot ranks first of the 467 web application vulnerabilities skills listed here, with the highest score: its repository has 61k GitHub stars, 6 other GitHub owners carry a copy, its SKILL.md loads about 4.7k tokens and it has informational notes only in the automated safety check. Next come Security Auditor and Security Review.
Which web application vulnerabilities skills are official?
15 of the 467 web application vulnerabilities skills are official, published by the vendor's own GitHub organization: Security Review, Burp Suite Project Parser, Django Access Review, Sentry Security, Playwright Best Practices and 10 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
More topics in Security
- Security review636
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38