Topic · Security
Best web application vulnerabilities skills, page 10
Web application vulnerabilities skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 433 | Audit codebase for security vulnerabilities, insecure patterns, and compliance gaps. | EmeaAppGbb/ | 100 | — | ~2.2k | Automated safety check: Notes | MIT | 5 mo ago |
| 434 | 基于 OWASP Top 10 (2021) 标准提供代码安全审查,逐项检查 SQL 注入、XSS、SSRF、访问控制、加密失败等常见漏洞,并给出具体的漏洞代码示例与修复方案。当用户需要代码安全审查、安全加固、渗透测试辅助,或提及 OWASP、安全检查、SQL 注入、XSS、代码审计、安全清单等关键词时触发此技能。 | rongxinzy/ | 154 | — | ~3k | Automated safety check: Pass | MIT | today |
| 435 | 435.Owasp Security Comprehensive OWASP-aligned security guidance across six standards - Top 10 (2021) for web apps, ASVS 5.0, MASVS v2.1.0 for mobile, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the… | davila7/ | 32k | — | ~7.4k | Automated safety check: Warn | MIT | today |
| 436 | Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment. | rsmdt/ | 551 | — | ~1.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 437 | 437.Security Review AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files. | danielvm-git/ | 257 | — | ~1.5k | Automated safety check: Pass | MIT | 16 days ago |
| 438 | 安全测试助手 - 专业的应用安全测试与防护专家。适用场景: (1) Web应用安全测试(OWASP Top 10漏洞检测) (2) API安全测试(认证/授权/数据泄露) (3) 安全测试用例设计与评审 (4) 渗透测试方案制定与执行指导 (5) 安全漏洞分析与风险评估 (6) 安全加固建议与最佳实践 (7) 安全合规检查(GDPR/等保) (8) 安全测试报告编写… | chendongqi/ | 125 | — | ~1.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 439 | 439.Hunt Ssrf Hunting skill for ssrf vulnerabilities. | sickn33/ | 47k | 1 repo | ~4.5k | Automated safety check: Warn | MIT | today |
| 440 | 440.Security Audit Security auditing and vulnerability assessment specialist. An agent skill from aiskillstore/marketplace. | aiskillstore/ | 430 | 1 repo | ~383 | Automated safety check: Pass | No licence | today |
| 441 | 441.Audit On-demand security and code quality audit. An agent skill from MadAppGang/claude-code. | MadAppGang/ | 284 | — | ~3.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 442 | 442.Security Auditor Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow. | dralgorhythm/ | 125 | — | ~496 | Automated safety check: Pass | No licence | 2 mo ago |
| 443 | 443.Go Review Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications. | SpecterOps/ | 702 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 14 days ago |
| 444 | 444.Phy Cors Audit CORS (Cross-Origin Resource Sharing) misconfiguration auditor. | LeoYeAI/ | 2.2k | — | ~6.7k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 445 | HTTP security header auditor that fetches response headers from any URL and grades them against OWASP, Mozilla Observatory, and Google standards. | LeoYeAI/ | 2.2k | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 446 | Java 源码认证与配置安全审计。当在 Java 白盒审计中需要检测认证绕过、权限缺陷或安全配置问题时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~888 | Automated safety check: Pass | No licence | 4 days ago |
| 447 | Java 源码前端安全类漏洞审计。当在 Java 白盒审计中需要检测前端安全漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~1.4k | Automated safety check: Pass | No licence | 4 days ago |
| 448 | Java 源码注入类漏洞审计。当在 Java 白盒审计中需要检测注入类漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~1.1k | Automated safety check: Pass | No licence | 4 days ago |
| 449 | PHP 源码认证、配置与逻辑类漏洞审计。当在 PHP 白盒审计中需要检测认证绕过、 权限控制、安全配置、密码学误用或业务逻辑漏洞时触发。 | wgpsec/ | 1.8k | — | ~704 | Automated safety check: Pass | No licence | 4 days ago |
| 450 | PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。 | wgpsec/ | 1.8k | — | ~767 | Automated safety check: Notes | No licence | 4 days ago |
| 451 | PHP 源码前端交互类漏洞审计。当在 PHP 白盒审计中需要检测前端安全相关漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~777 | Automated safety check: Pass | No licence | 4 days ago |
| 452 | PHP 源码注入类漏洞审计。当在 PHP 白盒审计中需要检测注入类漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~965 | Automated safety check: Pass | No licence | 4 days ago |
| 453 | 453.Idor Testing Insecure direct object reference testing for broken access control | NeoTheCapt/ | 142 | — | ~793 | Automated safety check: Pass | No licence | 2 mo ago |
| 454 | 覆盖工具 allow/ask/deny、四种 permission mode、审批持久化、Workspace/Hook Trust、敏感文件以及 Hook/Browser 网络边界。 | echoVic/ | 181 | — | ~1.8k | Automated safety check: Pass | MIT | 10 days ago |
| 455 | Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection. | majiayu000/ | 666 | 1 repo | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 456 | 456.Angular Security Harden Angular apps against XSS, CSP violations, and unauthorized access. | HoangNguyen0403/ | 571 | — | ~608 | Automated safety check: Pass | MIT | today |
| 457 | OWASP LLM Top 10 (2025) audit checklist for AI applications, agent tools, RAG pipelines, and prompt construction. | HoangNguyen0403/ | 571 | — | ~921 | Automated safety check: Pass | MIT | today |
| 458 | 458.Common Owasp OWASP Top 10 audit checklists for Web Applications (2021), APIs (2023), and Mobile (2024). | HoangNguyen0403/ | 571 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 459 | 459.Golang Security Secure Go backend services against common vulnerabilities. An agent skill from HoangNguyen0403/agent-skills-standard. | HoangNguyen0403/ | 571 | — | ~528 | Automated safety check: Pass | MIT | today |
| 460 | 460.React Security Prevent XSS, secure auth flows, and harden React client-side applications. | HoangNguyen0403/ | 571 | — | ~594 | Automated safety check: Pass | MIT | today |
| 461 | Secure server-side TypeScript input, auth tokens, and injection boundaries. | HoangNguyen0403/ | 571 | — | ~817 | Automated safety check: Notes | MIT | today |
| 462 | 462.Security Arsenal Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. | elementalsouls/ | 4.8k | — | ~7.2k | Automated safety check: Warn | MIT | today |
| 463 | 463.Azure Waf Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools). | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 464 | 浏览器交互式挖洞:登录态操作、双账号越权对比、SPA渲染取证、DOM XSS确认、验证码登录、前端隐藏功能绕过. An agent skill from langbyyi/CyberStrikeAI-SRC. | langbyyi/ | 134 | — | ~434 | Automated safety check: Pass | Apache-2.0 | today |
| 465 | 465.Security Auditor MASTER SECURITY: OWASP Top 10, SAST/DAST, PenTest. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI. | Dokhacgiakhoa/ | 507 | — | ~440 | Automated safety check: Pass | Unknown | 3 mo ago |
| 466 | Database security (encryption, access control, injection prevention), data governance (lineage, quality, MDM), and compliance frameworks (GDPR, CCPA, HIPAA) | nWave-ai/ | 617 | — | ~1.7k | Automated safety check: Pass | MIT | 21 days ago |
| 467 | Security design principles, STRIDE threat modeling, OWASP Top 10 architectural mitigations, and secure patterns. | nWave-ai/ | 617 | — | ~2.4k | Automated safety check: Pass | MIT | 21 days ago |
Explore related skills
More topics in Security
- Security review636
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38