Topic · Security
Best web application vulnerabilities skills, page 6
Web application vulnerabilities skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 241 | 241.Sapui5 This skill should be used when developing SAP UI5 applications, including creating freestyle apps, Fiori Elements apps, custom controls, testing, data binding, OData integration, routing, and… | secondsky/ | 462 | — | ~4.1k | Automated safety check: Pass | GPL-3.0 | 3 days ago |
| 242 | You are a frontend security specialist focusing on Cross-Site Scripting (XSS) vulnerability detection and prevention. | aiskillstore/ | 430 | 7 repos | ~2.4k | Automated safety check: Pass | No licence | today |
| 243 | Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns. | aiskillstore/ | 430 | 7 repos | ~3k | Automated safety check: Pass | No licence | today |
| 244 | Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks | aiskillstore/ | 430 | 7 repos | ~3.7k | Automated safety check: Pass | No licence | today |
| 245 | Application security defense knowledge for builders. An agent skill from telagod/code-abyss. | telagod/ | 243 | — | ~777 | Automated safety check: Pass | MIT | 2 mo ago |
| 246 | Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. | mukul975/ | 34k | — | ~644 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 247 | Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 248 | Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. | mukul975/ | 34k | — | ~564 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 249 | Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 250 | Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 251 | Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. | mukul975/ | 34k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 252 | A skill your agent uses when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based… | thedaviddias/ | 74k | — | ~604 | Automated safety check: Pass | MIT | 2 days ago |
| 253 | Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing. | uphiago/ | 1.3k | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 254 | Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management. | rand/ | 181 | — | ~1.9k | Automated safety check: Pass | MIT | 7 mo ago |
| 255 | PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills. | alirezarezvani/ | 28k | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 256 | 256.Hunt LLM AI Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). | elementalsouls/ | 4.8k | — | ~4k | Automated safety check: Warn | MIT | today |
| 257 | Enhance SEO (meta tags, semantic HTML) and security (vulnerability checks, hardening). | ww-w-ai/ | 601 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 11 days ago |
| 258 | 258.Security Review Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it… | trycompai/ | 2k | — | ~853 | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 259 | 259.Web Ssrf Server-Side Request Forgery detection→internal-access→proof for web apps. | s0ld13rr/ | 828 | — | ~660 | Automated safety check: Warn | MIT | 6 days ago |
| 260 | This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp ... | aiskillstore/ | 430 | 4 repos | ~2.7k | Automated safety check: Pass | No licence | today |
| 261 | 261.Security Auditor Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. | aiskillstore/ | 430 | 6 repos | ~2.6k | Automated safety check: Pass | No licence | today |
| 262 | 262.Php Csrf Audit PHP Web 源码 CSRF 审计工具。识别状态变更接口是否受 CSRF 保护,追踪 token 生成、校验与绕过条件,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~398 | Automated safety check: Pass | No licence | 6 mo ago |
| 263 | 263.Php Xss Audit PHP Web 源码 XSS 审计工具。识别用户输入进入输出上下文(HTML/属性/JS/URL/模板),分析转义与防护策略,输出可利用性分级、PoC 与修复建议(禁止省略)。 | 0xShe/ | 402 | 1 repo | ~370 | Automated safety check: Pass | No licence | 6 mo ago |
| 264 | 264.Xslt Injection XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. | langbyyi/ | 135 | 1 repo | ~3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 265 | 265.Security Audit RLS validation, security audits, OWASP compliance, and vulnerability scanning. | bybren-llc/ | 423 | — | ~1.4k | Automated safety check: Notes | MIT | 2 mo ago |
| 266 | 266.Security Scanner A skill your agent uses when scanning code or configuration for security vulnerabilities. | WrongStack/ | 370 | — | ~2.1k | Automated safety check: Pass | MIT | today |
| 267 | 267.Code Reviewer Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks. | foryourhealth111-pixel/ | 3.6k | — | ~1.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 268 | 268.Zimbra Attack Zimbra SOAP user enum, CVE-2022-37042, SSRF when webmail. An agent skill from uphiago/recon-skills. | uphiago/ | 1.3k | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 269 | 269.Owasp Audit Audit application source code against the OWASP Top 10 (2021) vulnerability categories — broken access control, cryptographic failures, injection, insecure design, security misconfiguration… | briiirussell/ | 413 | — | ~8.6k | Automated safety check: Notes | MIT | 4 mo ago |
| 270 | Review the implementation source code of MCP (Model Context Protocol) servers, clients, and tool handlers against a security baseline — authentication, sessions, rate limiting, input-schema… | github/ | 40k | — | ~5.2k | Automated safety check: Pass | MIT | today |
| 271 | A skill your agent uses when the user says 'OWASP audit', 'OWASP top 10', 'security audit', 'vulnerability assessment', 'full security check', or needs a comprehensive web application security… | cwinvestments/ | 423 | — | ~5k | Automated safety check: Pass | Proprietary | 12 days ago |
| 272 | Security patterns and OWASP guidelines. An agent skill from aiskillstore/marketplace. | aiskillstore/ | 430 | 1 repo | ~1.2k | Automated safety check: Notes | No licence | today |
| 273 | Security auditor for Laravel applications. An agent skill from aiskillstore/marketplace. | aiskillstore/ | 430 | 4 repos | ~1.1k | Automated safety check: Notes | No licence | today |
| 274 | AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and… | modu-ai/ | 1.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | today |
| 275 | OWASP Top 10 security checklist, authentication patterns, input validation, and HTTP security headers reference. | modu-ai/ | 1.2k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 276 | 276.Moai Ref Secops DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning… | modu-ai/ | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | today |
| 277 | 277.Moai Ref SEO Search-visibility and crawlability reference for web output: canonical URL discipline, per-page title and meta description uniqueness, robots.txt and sitemap.xml as host-derived artifacts, JSON-LD… | modu-ai/ | 1.2k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | today |
| 278 | 278.SQL Security SQL injection screening for host code (MoonBit / TS / Rust) plus secretlint setup notes. | mizchi/ | 359 | — | ~1.4k | Automated safety check: Pass | No licence | 7 days ago |
| 279 | 279.Security Auditor Analyzes changed security boundaries against applicable OWASP risks and project contracts. | pavel-molyanov/ | 297 | — | ~566 | Automated safety check: Pass | MIT | 1 mo ago |
| 280 | Check compliance with OWASP Top 10 security risks and best practices. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 281 | Detect and analyze SQL injection vulnerabilities in application code and database queries. | jeremylongshore/ | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | today |
| 282 | Execute this skill enables AI assistant to automatically scan for xss (cross-site scripting) vulnerabilities in code. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 283 | Scan for input validation vulnerabilities and injection risks. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 284 | Validate CSRF protection implementations for security gaps. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 285 | 当目标为微信/支付宝/抖音/百度等小程序(含微信云开发/云函数)、需要小程序包获取与反编译、appid/appsecret/接口提取、微信登录链/支付/越权/WebView/rich-text 渲染/云开发漏洞挖掘时调用。负责小程序全生命周期深度挖掘:包还原 → 代码审计 → 接口与密钥提取 → 登录/支付/越权/渲染/云开发专项 → 验证要点。命中场景:openid 替换越权、code… | zhaji2333/ | 114 | — | ~1.5k | Automated safety check: Pass | MIT | 24 days ago |
| 286 | WordPress plugin development with hooks, security, REST API, custom post types. | secondsky/ | 227 | — | ~4.6k | Automated safety check: Pass | MIT | 10 days ago |
| 287 | Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0. | OWASP/ | 187 | — | ~622 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 288 | Harden code against vulnerabilities. An agent skill from BlackBeltTechnology/pi-agent-dashboard. | BlackBeltTechnology/ | 315 | — | ~4.7k | Automated safety check: Notes | MIT | today |
Explore related skills
More topics in Security
- Security review636
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38