Topic · Security

Best web application vulnerabilities skills, page 7

Skills #289–336 of 467, ranked by score.

Web application vulnerabilities skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Web application vulnerabilities skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
289

A skill your agent uses when debugging or preventing errors in Frappe Client Scripts.

Impertio-Studio/Frappe_Claude_Skill_Package187—~2.4kAutomated safety check: PassMIT21 days ago
290

A skill your agent uses when handling database errors in Frappe/ERPNext.

Impertio-Studio/Frappe_Claude_Skill_Package187—~3.9kAutomated safety check: PassMIT21 days ago
291

A skill your agent uses when debugging or preventing errors in Frappe Server Scripts.

Impertio-Studio/Frappe_Claude_Skill_Package187—~3kAutomated safety check: PassMIT21 days ago
292

A skill your agent uses when building database queries with frappe.qb in Frappe v14-v16.

Impertio-Studio/Frappe_Claude_Skill_Package187—~1.7kAutomated safety check: PassMIT21 days ago
293

Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md

ruvnet/ruflo74k—~805Automated safety check: NotesMITtoday
294

Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

elementalsouls/Claude-BugHunter4.8k—~5.7kAutomated safety check: PassMITyesterday
295

A skill your agent uses when code touches user input, tokens, redirects, raw SQL, or logging — injection, XSS, atom exhaustion, timing attacks, audit tooling.

j-morgan6/elixir-phoenix-guide166—~2kAutomated safety check: PassMIT3 mo ago
296

Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…

petrkindlmann/qa-skills165—~4.9kAutomated safety check: PassMIT4 mo ago
297

API hardening for Express, FastAPI, and serverless. An agent skill from jamditis/claude-skills-journalism.

jamditis/claude-skills-journalism416—~12kAutomated safety check: PassMIT4 days ago
298

Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism.

jamditis/claude-skills-journalism416—~14kAutomated safety check: PassMIT4 days ago
299

Pre-deployment security audit organized by OWASP Top 10. An agent skill from jamditis/claude-skills-journalism.

jamditis/claude-skills-journalism416—~8kAutomated safety check: NotesMIT4 days ago
300

Authorized testing of access-control and business-logic flaws that pattern scanners cannot find — IDOR/BOLA, broken function-level authorization, mass assignment, business-logic abuse, and race…

ptn1411/skill219—~1.9kAutomated safety check: NotesNo licence16 days ago
301

Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3…

utkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT6 mo ago
302

Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP…

sickn33/agentic-awesome-skills47k1 repo~1.2kAutomated safety check: WarnMITyesterday
303

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table.

sickn33/agentic-awesome-skills47k1 repo~3.2kAutomated safety check: WarnMITyesterday
304

Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: WarnApache-2.01 mo ago
305
305.Waf

Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic.

TheDecipherist/claude-code-mastery-project-starter-kit338—~1.4kAutomated safety check: PassMIT3 mo ago
306

Security rule for timing-safe secret comparison. An agent skill from paralleldrive/aidd.

paralleldrive/aidd384—~575Automated safety check: PassMIT3 mo ago
307

Read findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable- grade markdown vulnerability report with per-finding sections (title…

jeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: NotesMITtoday
308

Scan a source tree for SQL-injection vulnerable patterns: string concatenation into queries, f-string interpolation in SQL, string-format substitution into raw queries, deprecated cursor methods…

jeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: PassMITtoday
309

Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report.

jeremylongshore/tons-of-skills-marketplace2.8k—~2.2kAutomated safety check: NotesMITtoday
310

Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present.

jeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMITtoday
311

A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…

jabrena/plinth446—~885Automated safety check: PassApache-2.0yesterday
312

A skill your agent uses when you need to design, review, or improve security in Spring Boot applications — including SecurityFilterChain, OAuth2/JWT resource server patterns, form login basics…

jabrena/plinth446—~719Automated safety check: PassApache-2.0yesterday
313

A skill your agent uses when you need to write or review programmatic JDBC with Spring — including JdbcClient (Spring Framework 7+) as the default API, JdbcTemplate only where batch/streaming APIs…

jabrena/plinth446—~975Automated safety check: PassApache-2.0yesterday
314

A skill your agent uses when you need to design, review, or improve security in Micronaut applications — including micronaut-security authentication, @Secured and intercept-url-map rules…

jabrena/plinth446—~680Automated safety check: PassApache-2.0yesterday
315

Secure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth.

BuilderIO/agent-native7.1k—~5.2kAutomated safety check: NotesNo licencetoday
316

Security review via Codex exec. An agent skill from sd0xdev/sd0x-harness.

sd0xdev/sd0x-harness192—~1.1kAutomated safety check: PassMITtoday
317

Comprehensive security development guide for Mobazha decentralized marketplace covering XSS prevention, Web3 transaction safety, key management, and input validation.

mobazha/mobazha-unified165—~1.7kAutomated safety check: PassMPL-2.05 days ago
318

CORS misconfiguration testing playbook. An agent skill from yaklang/hack-skills.

yaklang/hack-skills2.4k—~2.4kAutomated safety check: PassMIT25 days ago
319

Advanced Content Security Policy bypass techniques. An agent skill from yaklang/hack-skills.

yaklang/hack-skills2.4k—~3.1kAutomated safety check: PassMIT25 days ago
320

Dangling markup injection playbook. An agent skill from yaklang/hack-skills.

yaklang/hack-skills2.4k—~3.3kAutomated safety check: PassMIT25 days ago
321

Hunt CORS Misconfiguration

sickn33/agentic-awesome-skills47k1 repo~4.2kAutomated safety check: PassMITyesterday
322

Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces.

SnailSploit/Claude-Red7.3k—~5kAutomated safety check: PassMIT18 days ago
323

Penetration test and red team report writing methodology. An agent skill from SnailSploit/Claude-Red.

SnailSploit/Claude-Red7.3k—~3.7kAutomated safety check: PassMIT18 days ago
324

Apply security-conscious thinking when generating or modifying code.

techygarg/lattice198—~1.5kAutomated safety check: PassMIT2 days ago
325

Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF…

LUC4N3X/Levyra-deepsound531—~2.3kAutomated safety check: PassGPL-3.0today
326

Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP…

LeoYeAI/openclaw-master-skills2.2k—~6.1kAutomated safety check: NotesMIT2 mo ago
327

Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…

Goldziher/ai-rulez158—~250Automated safety check: PassMITtoday
328

Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers.

Houseofmvps/ultraship123—~3.9kAutomated safety check: NotesMIT3 mo ago
329

API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT1 mo ago
330

OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection.

Encod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT1 mo ago
331

GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE.

Encod3d-Sec/TORCH329—~2kAutomated safety check: PassMIT1 mo ago
332

LLM / AI application attack hunting - prompt injection (direct + indirect), excessive agency, insecure output handling, system-prompt + data leakage.

Encod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT1 mo ago
333

SSRF hunting - OOB-mandatory methodology. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~2.3kAutomated safety check: PassMIT1 mo ago
334

File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS.

Encod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT1 mo ago
335

XSS hunting - reflected, stored, DOM-based. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT1 mo ago
336

Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

OWASP/secure-agent-playbook187—~494Automated safety check: PassCC-BY-4.013 days ago