Topic · Security
Best web application vulnerabilities skills, page 4
Web application vulnerabilities skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 145 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 146 | 146.Traffic Capture Working on the HTTP capture proxy and its replay/fuzz path: the egress guard that stops the proxy becoming an SSRF pivot, why it checks the resolved IP, and keeping capture off the scan's critical… | samugit83/ | 3k | — | ~771 | Automated safety check: Pass | MIT | yesterday |
| 147 | Security-focused review for frontend/Web3 code. An agent skill from hyperlane-xyz/hyperlane-explorer. | hyperlane-xyz/ | 102 | — | ~185 | Automated safety check: Pass | Unknown | 10 days ago |
| 148 | Comprehensive API security review against OWASP API Security Top 10 (2023). | OWASP/ | 187 | — | ~744 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 149 | 149.Webvuln Web vulnerability hunting playbook. An agent skill from PentesterFlow/agent. | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 150 | 150.Laravel Security Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations. | affaan-m/ | 275k | 1 repo | ~6.6k | Automated safety check: Notes | MIT | 3 days ago |
| 151 | Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition. | bbartling/ | 172 | — | ~2.2k | Automated safety check: Pass | Unknown | today |
| 152 | 152.Hunt RAG Vector Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from… | elementalsouls/ | 4.8k | — | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 153 | Black-box security audit of a DEPLOYED AI agent (not the MCP server behind it) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR… | awarexone/ | 5.3k | — | ~1.1k | Automated safety check: Pass | MIT | 3 days ago |
| 154 | 154.Cybersecurity Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e… | ohmyjahh/ | 276 | — | ~895 | Automated safety check: Pass | MIT | 9 days ago |
| 155 | 155.Dast Zap Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection. | AgentSecOps/ | 220 | 1 repo | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 156 | Systematically reviews code for SQL injection, XSS, SSRF, broken access control, cryptographic failures, and other common OWASP Top 10 vulnerabilities, providing vulnerable code examples and… | zebbern/ | 4.7k | — | ~4.7k | Automated safety check: Pass | MIT | today |
| 157 | 157.Security Audit Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology | RightNow-AI/ | 18k | — | ~858 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 158 | Suede AI findings-only code review with full context: changed files, callers, contracts, and deploy surface. | JasonColapietro/ | 127 | — | ~7.1k | Automated safety check: Pass | MIT | yesterday |
| 159 | 159.SQL Code Review Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle). | totvs/ | 143 | — | ~3.5k | Automated safety check: Pass | MIT | 3 days ago |
| 160 | 160.Laravel Security Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署. An agent skill from affaan-m/ECC. | affaan-m/ | 275k | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 3 days ago |
| 161 | 161.Security Review Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. | affaan-m/ | 275k | 1 repo | ~3.2k | Automated safety check: Notes | MIT | 3 days ago |
| 162 | Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies… | eser/ | 128 | — | ~598 | Automated safety check: Pass | Unknown | 4 days ago |
| 163 | API design conventions, namespace coordinate system, RBAC roles, ClawHub compatibility layer, OpenAPI contract sync rules, and CSRF/session handling. | iflytek/ | 5.2k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 164 | Security-focused code review mapped to OWASP Top 10 and ASVS. | OWASP/ | 187 | — | ~549 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 165 | Review the finished Worker against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report. | receptron/ | 236 | — | ~1.2k | Automated safety check: Notes | MIT | today |
| 166 | Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks. | github/ | 40k | 1 repo | ~3k | Automated safety check: Pass | MIT | today |
| 167 | Quality standards for Salesforce Lightning Web Components (LWC), Aura components, and Visualforce pages. | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 168 | 168.Security Scan Deep security scanning for .NET applications across 6 layers: vulnerable packages, secrets detection, OWASP code patterns, auth configuration, CORS policy, and data protection. | codewithmukesh/ | 751 | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 169 | 169.Security Audit 全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -… | staruhub/ | 727 | — | ~1.3k | Automated safety check: Notes | MIT | 1 mo ago |
| 170 | 170.007 Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project. | sickn33/ | 47k | 2 repos | ~410 | Automated safety check: Pass | MIT | yesterday |
| 171 | 171.Sast Bandit Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. | AgentSecOps/ | 220 | 1 repo | ~2.6k | Automated safety check: Pass | Unknown | 5 mo ago |
| 172 | 172.Webapp Nikto Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. | AgentSecOps/ | 220 | 1 repo | ~2.8k | Automated safety check: Pass | Unknown | 5 mo ago |
| 173 | 173.Webapp Sqlmap Automated SQL injection detection and exploitation tool for web application security testing. | AgentSecOps/ | 220 | 1 repo | ~3.2k | Automated safety check: Pass | Unknown | 5 mo ago |
| 174 | AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching… | github/ | 40k | 1 repo | ~2.3k | Automated safety check: Notes | MIT | today |
| 175 | 175.Golang Security Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory… | unxed/ | 241 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | today |
| 176 | Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 177 | Integrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 178 | 178.Web Vuln Web vulnerability scanning workflow covering SQLi, XSS, template injection, and generic CVE detection using nuclei, sqlmap, dalfox, nikto, and jaeles | CommonHuman-Lab/ | 157 | — | ~896 | Automated safety check: Pass | Unknown | yesterday |
| 179 | 179.Security Audit RLS validation, security audits, OWASP compliance, and vulnerability scanning. | bybren-llc/ | 421 | — | ~1.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 180 | 180.Sbom Generate Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering… | cdxgen/ | 1.1k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 181 | 181.Security Audit A skill your agent uses for security reviews of VoxBento code. | fossasia/ | 1.6k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 182 | 182.Query Builder A skill your agent uses when the user needs to build, choose the pattern for, or optimize a SQL query against Protheus ERP tables -- covering Workarea (DbSelectArea/DbSeek) vs Embedded SQL vs… | thalysjuvenal/ | 186 | — | ~594 | Automated safety check: Pass | MIT | 24 days ago |
| 183 | 183.Security Review 检查 SQL 注入、XSS、硬编码密钥 | liuyanghejerry/ | 204 | — | ~106 | Automated safety check: Pass | MIT | 9 days ago |
| 184 | 184.Mobile Reverse Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP… | sickn33/ | 47k | 1 repo | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 185 | HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. | langbyyi/ | 134 | 1 repo | ~2.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 186 | Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries. | dzhalaevd/ | 135 | — | ~5.1k | Automated safety check: Notes | Apache-2.0 | 5 days ago |
| 187 | Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. | mukul975/ | 34k | — | ~581 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 188 | Wires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 189 | Detect API enumeration attacks (BOLA/IDOR, OWASP API1:2023) by writing SIEM detection rules that flag sequential or UUID identifier iteration, parameter tampering, and mixed 200/401/403 response… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 190 | Detect and test for OWASP API3:2023 Broken Object Property Level Authorization (BOPLA), covering excessive data exposure in API responses and mass assignment via injected request-body properties. | mukul975/ | 34k | — | ~4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 191 | Implements API security testing on the 42Crunch platform, combining API Audit for static analysis of OpenAPI definitions, API Conformance Scan for dynamic vulnerability testing, and API Protect for… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 192 | Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
Explore related skills
Category
More topics in Security
- Security review636
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38