Topic · Security
Best web application vulnerabilities skills, page 3
Web application vulnerabilities skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | Houndarr's pytest patterns. An agent skill from av1155/houndarr. | av1155/ | 292 | — | ~1k | Automated safety check: Pass | AGPL-3.0 | 2 days ago |
| 98 | Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy. | langfuse/ | 36k | — | ~1.4k | Automated safety check: Pass | Unknown | today |
| 99 | Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 275k | 5 repos | ~4k | Automated safety check: Notes | MIT | 3 days ago |
| 100 | 100.AI Governance AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents | Hack23/ | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 101 | 101.Crypto Audit Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation. | briiirussell/ | 413 | — | ~2.8k | Automated safety check: Notes | MIT | 4 mo ago |
| 102 | 102.Cors Testing CORS misconfiguration testing for data theft and access control bypass | NeoTheCapt/ | 142 | — | ~904 | Automated safety check: Pass | No licence | 2 mo ago |
| 103 | 103.TS Review TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura. | liuyanghejerry/ | 204 | — | ~166 | Automated safety check: Pass | MIT | 9 days ago |
| 104 | Finds exploitable application security vulnerabilities in code changes. | getsentry/ | 414 | — | ~1.8k | Automated safety check: Pass | Unknown | 7 days ago |
| 105 | Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design. | revfactory/ | 1.3k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 106 | 106.Security Testing Scans for security vulnerabilities including XSS, SQL injection, CSRF, and auth flaws using OWASP Top 10 methodology. | proffesor-for-testing/ | 494 | — | ~2.7k | Automated safety check: Notes | MIT | 4 days ago |
| 107 | 107.Security Arsenal Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection… | Gabson0x/ | 443 | — | ~8.5k | Automated safety check: Warn | No licence | 21 days ago |
| 108 | Security-focused source code review and SAST. An agent skill from transilienceai/communitytools. | transilienceai/ | 562 | — | ~1.2k | Automated safety check: Notes | MIT | 2 mo ago |
| 109 | Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks. | Jeffallan/ | 12k | — | ~1.8k | Automated safety check: Pass | MIT | 5 days ago |
| 110 | 110.Csrf Testing Cross-site request forgery testing for state-changing operations | NeoTheCapt/ | 142 | — | ~791 | Automated safety check: Pass | No licence | 2 mo ago |
| 111 | 111.Cso Chief Security Officer mode. An agent skill from no-session/pstack. | no-session/ | 134 | — | ~12k | Automated safety check: Notes | MIT | 6 mo ago |
| 112 | 112.Security Convex Review Convex security audit patterns for authentication and authorization. | IgorWarzocha/ | 122 | — | ~3.1k | Automated safety check: Pass | No licence | 8 mo ago |
| 113 | 113.Django Security Django 安全最佳实践、认证、授权、CSRF 防护、SQL 注入预防、XSS 预防和安全部署配置. An agent skill from affaan-m/ECC. | affaan-m/ | 275k | 3 repos | ~3.7k | Automated safety check: Notes | MIT | 3 days ago |
| 114 | 114.Laravel Security Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment. | affaan-m/ | 275k | 3 repos | ~2k | Automated safety check: Pass | MIT | 3 days ago |
| 115 | 115.Security Review 在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。 | affaan-m/ | 275k | 3 repos | ~2.5k | Automated safety check: Notes | MIT | 3 days ago |
| 116 | Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。 | affaan-m/ | 275k | 3 repos | ~1.6k | Automated safety check: Pass | MIT | 3 days ago |
| 117 | Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities | davila7/ | 32k | 8 repos | ~5.8k | Automated safety check: Pass | MIT | today |
| 118 | 118.ffuf Web Fuzzer Runs ffuf for DAST work: directory and file discovery, GET and POST parameter fuzzing, virtual host enumeration and filtered, recursive scans. | AgentSecOps/ | 220 | 1 repo | ~3.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 119 | 119.Web Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用. An agent skill from MuWinds/BUUCTF_Agent. | MuWinds/ | 267 | — | ~463 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 120 | 120.Difesa Attacchi Aggiunge a un sito/app un agente di difesa che rileva e blocca richieste malevole (SQL injection, XSS, path traversal, brute force, bot) con rate limiting, blocklist IP e modalità lockdown che… | ccplugins/ | 968 | — | ~781 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 121 | Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. | Gabson0x/ | 443 | — | ~11k | Automated safety check: Warn | No licence | 21 days ago |
| 122 | 122.Security Review AI-powered security vulnerability detection. An agent skill from selmakcby/claude-agents-skills. | selmakcby/ | 136 | — | ~963 | Automated safety check: Pass | MIT | 5 mo ago |
| 123 | 123.Security Audit Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults. | Aedelon/ | 120 | — | ~1.6k | Automated safety check: Notes | Unknown | 7 mo ago |
| 124 | 124.Security Django Review Django security audit patterns for settings and middleware. | IgorWarzocha/ | 122 | — | ~1.6k | Automated safety check: Notes | No licence | 8 mo ago |
| 125 | Guide to maintain creating modern and secure code while developing WordPress plugins. | duracelltomi/ | 174 | — | ~7.2k | Automated safety check: Pass | GPL-2.0-or-later | today |
| 126 | Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework. | OWASP/ | 187 | — | ~876 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 127 | 127.Web Coder Expert 10x engineer with comprehensive knowledge of web development, internet protocols, and web standards. | boshi-xixixi/ | 275 | 1 repo | ~5.2k | Automated safety check: Pass | MIT | 4 mo ago |
| 128 | 128.Security Review 認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。 | affaan-m/ | 275k | 2 repos | ~2.5k | Automated safety check: Notes | MIT | 3 days ago |
| 129 | 129.Security Review 인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요. | affaan-m/ | 275k | 2 repos | ~2.7k | Automated safety check: Notes | MIT | 3 days ago |
| 130 | 130.Web App Scanner Authorized web application testing from the CLI, including local pre-deploy source/config audits, subdomain enumeration, passive recon, non-destructive active vulnerability checks, and guarded SQL… | ptn1411/ | 219 | — | ~3.2k | Automated safety check: Notes | No licence | 16 days ago |
| 131 | 当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM… | zhaji2333/ | 113 | — | ~4.7k | Automated safety check: Warn | MIT | 23 days ago |
| 132 | 132.Security Audit A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance. | jellydn/ | 123 | — | ~2.9k | Automated safety check: Notes | MIT | today |
| 133 | Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates. | awarexone/ | 5.3k | — | ~1.9k | Automated safety check: Warn | MIT | 3 days ago |
| 134 | 134.Django Security Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. | affaan-m/ | 275k | 1 repo | ~4.3k | Automated safety check: Notes | MIT | 3 days ago |
| 135 | Verification loop for Quarkus projects: build, static analysis (Checkstyle, PMD, SpotBugs), tests with JaCoCo coverage, OWASP dependency and container security scans, GraalVM native compilation… | affaan-m/ | 275k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | 3 days ago |
| 136 | 136.Dast Nuclei Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues across web… | AgentSecOps/ | 220 | 1 repo | ~4.1k | Automated safety check: Notes | Unknown | 5 mo ago |
| 137 | 137.Web Sqli SQL injection detection→exploitation→proof for web apps and APIs. | s0ld13rr/ | 827 | — | ~710 | Automated safety check: Pass | MIT | 6 days ago |
| 138 | 138.Security Audit Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening. | davila7/ | 32k | 4 repos | ~1.3k | Automated safety check: Pass | MIT | today |
| 139 | 139.Expert Security 安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex. | ReJeCtAll/ | 113 | — | ~780 | Automated safety check: Pass | MIT | 3 mo ago |
| 140 | 140.Security Auditor Perform comprehensive security audit of a repository with detailed findings and step-by-step PoCs. | commercetools/ | 154 | — | ~3.3k | Automated safety check: Notes | MIT | 5 days ago |
| 141 | Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP. | Encod3d-Sec/ | 329 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 142 | 142.Gotchas Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps. | yeswehack/ | 107 | — | ~4.3k | Automated safety check: Warn | GPL-3.0 | 1 mo ago |
| 143 | 143.Senior Secops Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. | alirezarezvani/ | 28k | 1 repo | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 144 | Detect unsafe file handling and path traversal in upload/save/extract flows. | Tencent/ | 6.8k | — | ~789 | Automated safety check: Pass | Apache-2.0 | today |
Explore related skills
Category
More topics in Security
- Security review636
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38