Topic · Security

Best web application vulnerabilities skills for Claude Code, Codex and other agents.

Skills that find and fix XSS, SQL injection, SSRF and other web application flaws.
skills
467
official
15

Web application vulnerabilities skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Web application vulnerabilities skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Hardens code against vulnerabilities. An agent skill from penpot/penpot.

penpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0today
2

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

eigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0today
3

A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

jewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT4 mo ago
4

Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

usestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0today
5

Professional code security audit skill covering 55+ vulnerability types.

3stoneBrother/code-audit8931 repo~2.7kAutomated safety check: PassNo licence7 mo ago
6

Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

usestrix/strix67k—~1.5kAutomated safety check: PassApache-2.0today
7

Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

awarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMIT3 days ago
8

A master set of ten grep command blocks that surface likely vulnerability classes in Solidity source within the first 30 minutes of auditing a new protocol.

tradecatlabs/vibe-coding-cn17k2 repos~3.3kAutomated safety check: PassMITtoday
9

WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

tanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassUnknown2 mo ago
10

Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept.

usestrix/strix67k—~1.6kAutomated safety check: PassApache-2.0today
11

Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

awarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT3 days ago
12

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

ruvnet/ruflo74k2 repos~823Automated safety check: PassMITtoday
13
13.Security ReviewOfficial

Security code review for vulnerabilities. An agent skill from getsentry/skills.

getsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.05 days ago
14

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

nyldn/claude-octopus4.2k1 repo~2.3kAutomated safety check: PassMITtoday
15

Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing.

skjolber/3d-bin-container-packing568—~886Automated safety check: PassApache-2.0today
16

Query 57 Indonesian government APIs and data sources — BPJPH halal certification, BPOM food safety, OJK financial legality, BPS statistics, BMKG weather/earthquakes, Bank Indonesia exchange rates…

suryast/indonesia-gov-apis172—~997Automated safety check: PassMITtoday
17

Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

trailofbits/skills7.4k4 repos~4.2kAutomated safety check: NotesCC-BY-SA-4.0today
18

Handles Laravel Cashier Stripe integration including subscriptions, webhooks, Stripe Checkout, invoices, charges, refunds, trials, coupons, metered billing, and payment failure handling.

luadotsh/lua3431 repo~1.2kAutomated safety check: PassMIT16 days ago
19

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

fengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT22 days ago
20

Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.

PentesterFlow/agent1.4k—~1.7kAutomated safety check: PassApache-2.01 mo ago
21

Reviews code for security vulnerabilities and guides secure implementation using OWASP Top 10:2025, ASVS 5.0, the OWASP Top 10 for LLM Applications (2026), and the OWASP Top 10 for Agentic…

agamm/claude-code-owasp377—~3.5kAutomated safety check: PassMIT13 days ago
22

Security audit for web apps, especially AI-built ("vibe coded") ones.

benavlabs/vibe-check118—~1.1kAutomated safety check: NotesMIT19 days ago
23

Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

jeremylongshore/tons-of-skills-marketplace2.8k2 repos~1.3kAutomated safety check: NotesMITtoday
24

Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

Pa55w0rd/secknowledge-skill423—~2.7kAutomated safety check: PassNo licence3 mo ago
25

Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

gocronx-team/gocron808—~690Automated safety check: PassMIT5 days ago
26

Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

EpicenterHQ/epicenter4.8k—~896Automated safety check: PassUnknowntoday
27

Django access control and IDOR security review. An agent skill from getsentry/skills.

getsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.05 days ago
28

Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

Yikai-Liao/symusic1891 repo~1.3kAutomated safety check: PassMIT1 mo ago
29

渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。

Arenbai/SecSkills251—~1.8kAutomated safety check: NotesMIT9 days ago
30

Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

Encod3d-Sec/TORCH3291 repo~1.8kAutomated safety check: PassMIT1 mo ago
31

Drive the AuthEndpoints HTTP API via the in-repo test host (cookie sessions, Identity bearer, Simple JWT, CSRF, ReAuth).

madeyoga/AuthEndpoints121—~2.7kAutomated safety check: PassMITtoday
32

Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…

discord-php/DiscordPHP1.1k—~1.2kAutomated safety check: NotesMITyesterday
33

Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make…

justrach/kuri365—~1.3kAutomated safety check: NotesUnknown2 mo ago
34

Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…

samugit83/redamon3k—~1.4kAutomated safety check: PassMITtoday
35

Security-focused code review checklist and automated scanning patterns.

nicepkg/auto-company1921 repo~3.9kAutomated safety check: PassMIT7 mo ago
36
36.Sail

Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.

pillar-labs/sail-skill113—~5.1kAutomated safety check: PassUnknown3 mo ago
37

Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

addyosmani/agent-skills103k1 repo~4.4kAutomated safety check: NotesMIT4 days ago
38

Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

Hainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT2 mo ago
39

Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets.

Tencent/AI-Infra-Guard6.8k—~1.5kAutomated safety check: NotesApache-2.0today
40

Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.

gdarko/laravel-vue-starter145—~668Automated safety check: NotesMIT6 mo ago
41

Apply Rails security and multi-tenant safety practices including scoped queries, SSRF defenses, rate limiting, and tenant-scoped realtime updates.

marckohlbrugge/37signals-skills724—~1.7kAutomated safety check: PassNo licence4 mo ago
42

Runs and interprets Psalm security (taint) analysis on a Laravel project.

cachethq/core230—~4.7kAutomated safety check: PassUnknown2 days ago
43
43.Sentry SecurityOfficial

Sentry-specific security review based on real vulnerability history.

getsentry/sentry46k—~2.3kAutomated safety check: NotesUnknowntoday
44

A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own…

agentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0yesterday
45

Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

supercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0today
46

Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

zebbern/claude-code-guide4.7k—~1.3kAutomated safety check: PassMITtoday
47

Automate low-impact web vulnerability verification through Burp MCP.

langbyyi/CyberStrikeAI-SRC134—~3.1kAutomated safety check: PassApache-2.0today
48

Backend API design specialist. An agent skill from selmakcby/claude-agents-skills.

selmakcby/claude-agents-skills136—~1.1kAutomated safety check: PassMIT5 mo ago

Questions, answered from the data.

What is the best web application vulnerabilities skill?

Security And Hardening from penpot/penpot ranks first of the 467 web application vulnerabilities skills listed here, with the highest score: its repository has 61k GitHub stars, 6 other GitHub owners carry a copy, its SKILL.md loads about 4.7k tokens and it has informational notes only in the automated safety check. Next come Security Auditor and Security Review.

Which web application vulnerabilities skills are official?

15 of the 467 web application vulnerabilities skills are official, published by the vendor's own GitHub organization: Security Review, Burp Suite Project Parser, Django Access Review, Sentry Security, Playwright Best Practices and 10 more.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.