Topic · Security
Best web application vulnerabilities skills, page 7
Web application vulnerabilities skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 289 | A skill your agent uses when debugging or preventing errors in Frappe Client Scripts. | Impertio-Studio/ | 187 | — | ~2.4k | Automated safety check: Pass | MIT | 21 days ago |
| 290 | A skill your agent uses when handling database errors in Frappe/ERPNext. | Impertio-Studio/ | 187 | — | ~3.9k | Automated safety check: Pass | MIT | 21 days ago |
| 291 | A skill your agent uses when debugging or preventing errors in Frappe Server Scripts. | Impertio-Studio/ | 187 | — | ~3k | Automated safety check: Pass | MIT | 21 days ago |
| 292 | A skill your agent uses when building database queries with frappe.qb in Frappe v14-v16. | Impertio-Studio/ | 187 | — | ~1.7k | Automated safety check: Pass | MIT | 21 days ago |
| 293 | Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md | ruvnet/ | 74k | — | ~805 | Automated safety check: Notes | MIT | today |
| 294 | Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | — | ~5.7k | Automated safety check: Pass | MIT | yesterday |
| 295 | A skill your agent uses when code touches user input, tokens, redirects, raw SQL, or logging — injection, XSS, atom exhaustion, timing attacks, audit tooling. | j-morgan6/ | 166 | — | ~2k | Automated safety check: Pass | MIT | 3 mo ago |
| 296 | 296.Security Testing Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests… | petrkindlmann/ | 165 | — | ~4.9k | Automated safety check: Pass | MIT | 4 mo ago |
| 297 | 297.API Hardening API hardening for Express, FastAPI, and serverless. An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~12k | Automated safety check: Pass | MIT | 4 days ago |
| 298 | 298.Secure Auth Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~14k | Automated safety check: Pass | MIT | 4 days ago |
| 299 | Pre-deployment security audit organized by OWASP Top 10. An agent skill from jamditis/claude-skills-journalism. | jamditis/ | 416 | — | ~8k | Automated safety check: Notes | MIT | 4 days ago |
| 300 | Authorized testing of access-control and business-logic flaws that pattern scanners cannot find — IDOR/BOLA, broken function-level authorization, mass assignment, business-logic abuse, and race… | ptn1411/ | 219 | — | ~1.9k | Automated safety check: Notes | No licence | 16 days ago |
| 301 | 301.Sast Sqli Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 302 | 302.LLM Security Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP… | sickn33/ | 47k | 1 repo | ~1.2k | Automated safety check: Warn | MIT | yesterday |
| 303 | 303.Security Arsenal Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. | sickn33/ | 47k | 1 repo | ~3.2k | Automated safety check: Warn | MIT | yesterday |
| 304 | Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 305 | 305.Waf Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic. | TheDecipherist/ | 338 | — | ~1.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 306 | Security rule for timing-safe secret comparison. An agent skill from paralleldrive/aidd. | paralleldrive/ | 384 | — | ~575 | Automated safety check: Pass | MIT | 3 mo ago |
| 307 | Read findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable- grade markdown vulnerability report with per-finding sections (title… | jeremylongshore/ | 2.8k | — | ~1.9k | Automated safety check: Notes | MIT | today |
| 308 | Scan a source tree for SQL-injection vulnerable patterns: string concatenation into queries, f-string interpolation in SQL, string-format substitution into raw queries, deprecated cursor methods… | jeremylongshore/ | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 309 | Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report. | jeremylongshore/ | 2.8k | — | ~2.2k | Automated safety check: Notes | MIT | today |
| 310 | Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present. | jeremylongshore/ | 2.8k | — | ~2.1k | Automated safety check: Notes | MIT | today |
| 311 | A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing… | jabrena/ | 446 | — | ~885 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 312 | A skill your agent uses when you need to design, review, or improve security in Spring Boot applications — including SecurityFilterChain, OAuth2/JWT resource server patterns, form login basics… | jabrena/ | 446 | — | ~719 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 313 | A skill your agent uses when you need to write or review programmatic JDBC with Spring — including JdbcClient (Spring Framework 7+) as the default API, JdbcTemplate only where batch/streaming APIs… | jabrena/ | 446 | — | ~975 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 314 | A skill your agent uses when you need to design, review, or improve security in Micronaut applications — including micronaut-security authentication, @Secured and intercept-url-map rules… | jabrena/ | 446 | — | ~680 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 315 | 315.Security Secure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth. | BuilderIO/ | 7.1k | — | ~5.2k | Automated safety check: Notes | No licence | today |
| 316 | 316.Security Review Security review via Codex exec. An agent skill from sd0xdev/sd0x-harness. | sd0xdev/ | 192 | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 317 | 317.Security Guide Comprehensive security development guide for Mobazha decentralized marketplace covering XSS prevention, Web3 transaction safety, key management, and input validation. | mobazha/ | 165 | — | ~1.7k | Automated safety check: Pass | MPL-2.0 | 5 days ago |
| 318 | CORS misconfiguration testing playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.4k | Automated safety check: Pass | MIT | 25 days ago |
| 319 | Advanced Content Security Policy bypass techniques. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~3.1k | Automated safety check: Pass | MIT | 25 days ago |
| 320 | Dangling markup injection playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~3.3k | Automated safety check: Pass | MIT | 25 days ago |
| 321 | 321.Hunt Cors Hunt CORS Misconfiguration | sickn33/ | 47k | 1 repo | ~4.2k | Automated safety check: Pass | MIT | yesterday |
| 322 | Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. | SnailSploit/ | 7.3k | — | ~5k | Automated safety check: Pass | MIT | 18 days ago |
| 323 | Penetration test and red team report writing methodology. An agent skill from SnailSploit/Claude-Red. | SnailSploit/ | 7.3k | — | ~3.7k | Automated safety check: Pass | MIT | 18 days ago |
| 324 | 324.Secure Coding Apply security-conscious thinking when generating or modifying code. | techygarg/ | 198 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 325 | Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF… | LUC4N3X/ | 531 | — | ~2.3k | Automated safety check: Pass | GPL-3.0 | today |
| 326 | 326.Clerk Auth Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP… | LeoYeAI/ | 2.2k | — | ~6.1k | Automated safety check: Notes | MIT | 2 mo ago |
| 327 | Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable… | Goldziher/ | 158 | — | ~250 | Automated safety check: Pass | MIT | today |
| 328 | 328.Security Audit Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers. | Houseofmvps/ | 123 | — | ~3.9k | Automated safety check: Notes | MIT | 3 mo ago |
| 329 | 329.Hunt API API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 330 | 330.Hunt Federation OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 331 | 331.Hunt Injection GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE. | Encod3d-Sec/ | 329 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 332 | 332.Hunt LLM LLM / AI application attack hunting - prompt injection (direct + indirect), excessive agency, insecure output handling, system-prompt + data leakage. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 333 | 333.Hunt Ssrf SSRF hunting - OOB-mandatory methodology. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 334 | 334.Hunt Upload File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS. | Encod3d-Sec/ | 329 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 335 | 335.Hunt Xss XSS hunting - reflected, stored, DOM-based. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 336 | 336.Sca Audit Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook. | OWASP/ | 187 | — | ~494 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
Explore related skills
More topics in Security
- Security review636
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38