Topic · Security
Best web application vulnerabilities skills, page 5
Web application vulnerabilities skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 193 | Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 194 | Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 195 | Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 196 | Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web application audit logging, tuning SecRuleEngine, SecAuditEngine, and CRS paranoia levels to reduce false positives, and writing… | mukul975/ | 34k | — | ~615 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 197 | Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 198 | Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, and payload obfuscation to smuggle SQL injection, XSS, and other exploit payloads… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 199 | Triages web application vulnerability findings from DAST/SAST scanners such as Burp Suite and ZAP, using the OWASP Risk Rating Methodology to confirm true positives, dismiss false positives, and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 200 | Implements defense-in-depth controls at an AI agent's tool-invocation boundary using tool allowlisting, least-privilege identity binding, NeMo Guardrails policy enforcement, human-in-the-loop… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 201 | Secures AWS API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, custom rate-limiting rules, bot control, IP reputation filtering, and WAF metric… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 202 | Audits and hardens process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments: Purdue-level network placement, interface access control, secure DMZ… | mukul975/ | 34k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 203 | Tests APIs for mass assignment (auto-binding), OWASP API3:2023, by identifying writable endpoints, adding undocumented fields to request bodies (role, isAdmin, price, balance), and checking whether… | mukul975/ | 34k | — | ~4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 204 | 204.Swift Security A skill your agent uses when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM… | dpearson2699/ | 1.2k | — | ~3.2k | Automated safety check: Pass | MIT | 2 mo ago |
| 205 | 205.API Spectral API specification linting and security validation using Stoplight's Spectral with support for OpenAPI, AsyncAPI, and Arazzo specifications. | AgentSecOps/ | 220 | 1 repo | ~5.6k | Automated safety check: Pass | Unknown | 5 mo ago |
| 206 | A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. | alirezarezvani/ | 28k | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 207 | 207.QA A skill your agent uses for paranoid, language-agnostic architectural code review — applies SOLID, DRY/KISS/YAGNI, decoupling, OWASP/NIST security, and quantitative complexity thresholds (cyclomatic… | openwpm/ | 1.4k | — | ~1.8k | Automated safety check: Pass | Unknown | 3 days ago |
| 208 | Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server, Oracle). | github/ | 40k | 1 repo | ~2.2k | Automated safety check: Pass | MIT | today |
| 209 | 209.Security Audit Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. | decebals/ | 751 | — | ~3.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 210 | 210.Web Xxe XML External Entity injection detection→file-read/SSRF→proof for web apps. | s0ld13rr/ | 827 | — | ~585 | Automated safety check: Pass | MIT | 6 days ago |
| 211 | 211.Hunt LLM AI Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). | elementalsouls/ | 4.8k | — | ~4k | Automated safety check: Warn | MIT | yesterday |
| 212 | 212.Sast Patterns Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. | vibeeval/ | 531 | — | ~4.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 213 | 213.Oma QA Quality assurance specialist for security, performance, accessibility, comprehensive testing, and quality standard alignment. | first-fluke/ | 1.3k | — | ~1.6k | Automated safety check: Pass | MIT | today |
| 214 | Integrates Power Pages generative-AI summarization APIs (PREVIEW) into a Single Page Application (SPA) site — the Search Summary API and the Data Summarization API — on any record-detail or list page. | microsoft/ | 972 | — | ~13k | Automated safety check: Notes | MIT | today |
| 215 | A skill your agent uses when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis. | sangrokjung/ | 850 | — | ~1k | Automated safety check: Notes | MIT | 1 mo ago |
| 216 | This skill provides guidance for implementing security features that span across Better Auth, including rate limiting, CSRF protection, session security, trusted origins, secret management, OAuth… | viclafouch/ | 110 | — | ~4.2k | Automated safety check: Pass | No licence | 6 mo ago |
| 217 | 217.Vc Security STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit. | withkynam/ | 1.1k | — | ~1.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 218 | 218.Security Audit Audits Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit authorization policies. | ThibautBaissac/ | 665 | — | ~846 | Automated safety check: Notes | MIT | 4 mo ago |
| 219 | Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP… | trilwu/ | 156 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 220 | Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills. | rampstackco/ | 940 | — | ~3k | Automated safety check: Pass | MIT | yesterday |
| 221 | Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 222 | 222.Hunt RAG Vector Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) | sickn33/ | 47k | 1 repo | ~3k | Automated safety check: Pass | MIT | yesterday |
| 223 | 223.Hunt Shadow API Hunt shadow / zombie / undocumented API surface (OWASP API9 Improper Inventory Management) | sickn33/ | 47k | 1 repo | ~2.5k | Automated safety check: Pass | MIT | yesterday |
| 224 | Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 225 | Laravel 框架特效安全审计工具。针对 Laravel 常见鉴权/CSRF/Session/模型填充/Blade 渲染等框架特性进行白盒静态审计,并将风险映射到你现有通用漏洞类型体系(AUTH/CSRF/LOGIC/XSS/CFG 等)。 | 0xShe/ | 402 | 1 repo | ~821 | Automated safety check: Pass | No licence | 6 mo ago |
| 226 | 226.Php Ssrf Audit PHP Web 源码 SSRF 审计工具。识别用户可控 URL/地址进入网络请求 Sink,追踪内网/协议/端口限制与回显,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~481 | Automated safety check: Pass | No licence | 6 mo ago |
| 227 | Symfony 框架特效安全审计工具。针对 Symfony 常见 security.yaml、CSRF、Twig/Twig raw、表达式与访问控制等框架机制做白盒静态审计,并将风险映射到通用漏洞类型体系(AUTH/CSRF/CFG/XSS/TPL/LOGIC 等)。 | 0xShe/ | 402 | 1 repo | ~599 | Automated safety check: Pass | No licence | 6 mo ago |
| 228 | ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。 | 0xShe/ | 402 | 1 repo | ~779 | Automated safety check: Pass | No licence | 6 mo ago |
| 229 | WordPress 框架特效安全审计工具。针对 WordPress 常见 nonce/capability/checkadminreferer、AJAX action、escape/sanitize、重定向、安全上传与远程请求等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/SQL/CFG/SSRF 等)。 | 0xShe/ | 402 | 1 repo | ~666 | Automated safety check: Pass | No licence | 6 mo ago |
| 230 | 230.Php Yii Audit Yii 框架特效安全审计工具。针对 Yii(通常指 Yii2)访问控制(AccessControl/RBAC)、CSRF、输入过滤规则、输出编码策略、URL/重定向安全等进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/CFG/LOGIC 等)。 | 0xShe/ | 402 | 1 repo | ~528 | Automated safety check: Pass | No licence | 6 mo ago |
| 231 | 231.Security Review Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles. | affaan-m/ | 275k | — | ~3.4k | Automated safety check: Notes | MIT | 3 days ago |
| 232 | 232.Laravel Security Buenas prácticas de seguridad en Laravel para autenticación/autorización, validación, CSRF, asignación masiva, subida de archivos, secretos, limitación de velocidad y despliegue seguro. | affaan-m/ | 275k | — | ~2.1k | Automated safety check: Pass | MIT | 3 days ago |
| 233 | 233.Laravel Security Laravel セキュリティベストプラクティス:認証・認可、バリデーション、CSRF、一括割当、ファイルアップロード、シークレット管理、レート制限、安全なデプロイメント | affaan-m/ | 275k | — | ~1.5k | Automated safety check: Pass | MIT | 3 days ago |
| 234 | 234.Quarkus Security Buenas prácticas de seguridad en Quarkus para autenticación, autorización, JWT/OIDC, RBAC, validación de entrada, CSRF, gestión de secretos y seguridad de dependencias. | affaan-m/ | 275k | — | ~2.6k | Automated safety check: Pass | MIT | 3 days ago |
| 235 | 235.Quarkus Security Quarkus認証、認可、JWT/OIDC、RBAC、入力検証、CSRF、シークレット管理、依存関係セキュリティのセキュリティベストプラクティス。 | affaan-m/ | 275k | — | ~2.8k | Automated safety check: Pass | MIT | 3 days ago |
| 236 | 236.Quarkus Security Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security. | affaan-m/ | 275k | — | ~3.1k | Automated safety check: Pass | MIT | 3 days ago |
| 237 | Buenas prácticas de Spring Security para autenticación/autorización, validación, CSRF, secretos, cabeceras, limitación de velocidad y seguridad de dependencias en servicios Java Spring Boot. | affaan-m/ | 275k | — | ~2.1k | Automated safety check: Pass | MIT | 3 days ago |
| 238 | 238.Security Audit A skill your agent uses when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying… | nicepkg/ | 192 | 1 repo | ~676 | Automated safety check: Pass | No licence | 7 mo ago |
| 239 | Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. | transilienceai/ | 562 | — | ~1.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 240 | 240.Bug Bounty Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling… | awarexone/ | 5.3k | — | ~20k | Automated safety check: Warn | MIT | 3 days ago |
Explore related skills
Category
More topics in Security
- Security review636
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38