Topic · Security
Best web application vulnerabilities skills, page 2
Web application vulnerabilities skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Compose AuthEndpoints 3.x in an ASP.NET Core host — AddAuthEndpoints, UseAuthEndpoints, MapAuthEndpoints, cookie vs Identity bearer vs Simple JWT, passkeys, CSRF, ReAuth, and production options. | madeyoga/ | 121 | — | ~3.1k | Automated safety check: Pass | MIT | today |
| 50 | A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a… | LIDR-academy/ | 278 | — | ~4.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 51 | Security audit checklist based on OWASP Top 10 and best practices. | unxed/ | 241 | — | ~5.4k | Automated safety check: Notes | BSD-3-Clause | today |
| 52 | Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity. | thomast1906/ | 202 | — | ~3.1k | Automated safety check: Pass | MIT | today |
| 53 | 53.Secureclaw Security hardening toolkit for OpenClaw. An agent skill from adversa-ai/secureclaw. | adversa-ai/ | 348 | 1 repo | ~193 | Automated safety check: Pass | MIT | 5 mo ago |
| 54 | 54.Idor Testing This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"… | zebbern/ | 4.7k | 8 repos | ~3.1k | Automated safety check: Pass | MIT | today |
| 55 | 55.API Audit Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023). | briiirussell/ | 413 | — | ~2.8k | Automated safety check: Notes | MIT | 4 mo ago |
| 56 | A skill your agent uses when writing Playwright tests, fixing flaky tests, debugging failures, implementing Page Object Model, configuring CI/CD, optimizing performance, mocking APIs, handling… | sanity-io/ | 6.4k | 7 repos | ~6.4k | Automated safety check: Pass | MIT | today |
| 57 | Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity. | AgriciDaniel/ | 227 | — | ~11k | Automated safety check: Warn | MIT | 5 mo ago |
| 58 | Diagnose and repair OpenASE CLI access in local bootstrap mode. | PacificStudio/ | 268 | — | ~778 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 59 | Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. | elementalsouls/ | 4.8k | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 60 | Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs. | deadlock-mod-manager/ | 574 | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 61 | Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis. | s0ld13rr/ | 827 | — | ~2.9k | Automated safety check: Pass | MIT | 5 days ago |
| 62 | 62.Oryxos Init 初始化 OryxOS(或同类 JDK 21 + Spring Boot 3.x 企业级单体)的工程地基:Maven 多模块骨架、 结构化日志、Actuator + Prometheus 监控、Spring MVC + 虚拟线程、springdoc OpenAPI、 统一响应体与全局异常/错误码、Google 格式 + 阿里编码规约(Spotless + 阿里 P3C +… | oryx-labs/ | 186 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 63 | 63.Security Use before shipping to production. An agent skill from garagon/nanostack. | garagon/ | 207 | — | ~3.7k | Automated safety check: Notes | Apache-2.0 | 27 days ago |
| 64 | A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16. | Impertio-Studio/ | 187 | 1 repo | ~4k | Automated safety check: Pass | MIT | 20 days ago |
| 65 | This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks"… | zebbern/ | 4.7k | 8 repos | ~6.1k | Automated safety check: Pass | MIT | today |
| 66 | A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code… | ProgrammerAnthony/ | 235 | — | ~1.6k | Automated safety check: Pass | MIT | 4 mo ago |
| 67 | A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning… | jabrena/ | 446 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | today |
| 68 | 68.Hunt Ato Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. | elementalsouls/ | 4.8k | — | ~3.4k | Automated safety check: Pass | MIT | today |
| 69 | This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through… | zebbern/ | 4.7k | 5 repos | ~2.9k | Automated safety check: Pass | MIT | today |
| 70 | 70.Hunt Idor IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and… | Encod3d-Sec/ | 329 | 1 repo | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 71 | 71.Codex Review Dual-model code review via Codex CLI. An agent skill from suyuan2022/suyuan-skill. | suyuan2022/ | 276 | — | ~3.5k | Automated safety check: Warn | MIT | 1 mo ago |
| 72 | CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。 | 0xShe/ | 402 | 1 repo | ~477 | Automated safety check: Pass | No licence | 6 mo ago |
| 73 | 73.Auth Bypass Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses | NeoTheCapt/ | 142 | — | ~1.3k | Automated safety check: Pass | No licence | 2 mo ago |
| 74 | Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows. | xenitV1/ | 130 | 7 repos | ~1.8k | Automated safety check: Notes | MIT | 8 mo ago |
| 75 | A declarative routing engine that turns ticket / error attributes (reporter, label, project, area path, error class, environment) into a tag + AI agent + priority assignment, so cross-source… | aozyildirim/ | 101 | — | ~976 | Automated safety check: Pass | MIT | 2 mo ago |
| 76 | Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Warn | Apache-2.0 | today |
| 77 | A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. | AratKruglik/ | 155 | 1 repo | ~1.1k | Automated safety check: Notes | No licence | 5 mo ago |
| 78 | AI 도구(Claude, ChatGPT, Cursor, Copilot)용 시큐어 코딩 프롬프트와 가이드를 생성합니다. | cdppcorp/ | 361 | — | ~1.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 79 | 79.Dotnet API Builds ASP.NET Core APIs, EF Core data access, gRPC, SignalR, and backend services with middleware, security (OAuth, JWT, OWASP), resilience, messaging, OpenAPI, .NET Aspire, Semantic Kernel… | novotnyllc/ | 233 | — | ~1.6k | Automated safety check: Pass | MIT | today |
| 80 | Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for… | agutinbaigo28/ | 128 | — | ~2.7k | Automated safety check: Pass | No licence | 23 days ago |
| 81 | 81.Sast Idor Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3… | utkusen/ | 1.3k | — | ~4.9k | Automated safety check: Pass | MIT | 6 mo ago |
| 82 | Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli. | kklimuk/ | 216 | — | ~1.7k | Automated safety check: Pass | MIT | 12 days ago |
| 83 | Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early. | awarexone/ | 5.3k | 3 repos | ~3.4k | Automated safety check: Pass | MIT | 2 days ago |
| 84 | Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services. | affaan-m/ | 275k | 5 repos | ~2k | Automated safety check: Pass | MIT | 3 days ago |
| 85 | Run the full Spring Boot verification loop — Maven or Gradle build, SpotBugs, PMD, and Checkstyle static analysis, unit and Testcontainers integration tests with JaCoCo coverage, OWASP dependency… | affaan-m/ | 275k | 5 repos | ~1.5k | Automated safety check: Pass | MIT | 3 days ago |
| 86 | Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager. | romshark/ | 113 | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 87 | 87.Code Review Perform a language-agnostic first-pass code review covering logic errors, bad practices, operation ordering, magic strings, pattern improvements, strict type checking, and SQL injection. | maiobarbero/ | 140 | — | ~1.2k | Automated safety check: Pass | No licence | 5 mo ago |
| 88 | Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus. | bugbountywithmarco/ | 122 | — | ~550 | Automated safety check: Pass | No licence | 2 mo ago |
| 89 | Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema… | SpecterOps/ | 702 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 14 days ago |
| 90 | A skill your agent uses when the user asks to review, audit, or check the quality of ADVPL/TLPP code for TOTVS Protheus before merge or deploy -- covering best practices (RecLock/MsUnlock pairing… | thalysjuvenal/ | 186 | — | ~604 | Automated safety check: Pass | MIT | 23 days ago |
| 91 | A paranoid OWASP-Top-10-aware system prompt for AI code review that traces data flow, treats every input as malicious, maps each finding to an OWASP category, and outputs a structured Summary /… | aozyildirim/ | 101 | — | ~978 | Automated safety check: Pass | MIT | 2 mo ago |
| 92 | 92.Xrk Crawl 当你需要开发/排查 HTTP 抓取、SSRF、Playwright 受控浏览器、本地字体增强截图,或判断 webfetch 与 browser 工作流如何选型时使用。 | xrkseek/ | 140 | — | ~1.3k | Automated safety check: Pass | MIT | 7 days ago |
| 93 | Security guidelines for writing secure code. An agent skill from semgrep/skills. | semgrep/ | 322 | — | ~1.2k | Automated safety check: Pass | Unknown | 2 mo ago |
| 94 | Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. | skrun-dev/ | 210 | — | ~1.3k | Automated safety check: Pass | MIT | 15 days ago |
| 95 | Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API… | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 96 | Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCALREADONLY, Redis vs memory store, keyspace namespacing, and metadata shape migrations. | vercel-labs/ | 117 | — | ~465 | Automated safety check: Pass | MIT | 4 mo ago |
Explore related skills
More topics in Security
- Security review636
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38