Topic · Security
Best web application vulnerabilities skills, page 8
Web application vulnerabilities skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 337 | 337.Security Fuzzing Essential fuzzing payloads: SQL injection, command injection, special characters. | Ch1nfo/ | 113 | 1 repo | ~329 | Automated safety check: Pass | MIT | 17 days ago |
| 338 | 338.Ghost Scan Code Ghost Security - SAST code scanner. An agent skill from aAAaqwq/AGI-Super-Team. | aAAaqwq/ | 105 | 1 repo | ~1.4k | Automated safety check: Notes | Apache-2.0 | 11 days ago |
| 339 | Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report. | receptron/ | 236 | — | ~1.5k | Automated safety check: Notes | MIT | today |
| 340 | 340.Sast Ssrf Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to destinations in parallel… | utkusen/ | 1.3k | — | ~6.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 341 | 341.Sast Xss Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 342 | 342.Mobile Security Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC… | transilienceai/ | 562 | — | ~2.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 343 | 343.Server Side Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection. | transilienceai/ | 562 | — | ~484 | Automated safety check: Pass | MIT | 2 mo ago |
| 344 | A skill your agent uses when you add or change an endpoint, an auth check, a query by id, an outbound call to a user-supplied URL, file handling, or anything touching credentials — the OWASP API Top… | makifbaysal/ | 109 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 345 | 345.Security Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries… | telagod/ | 243 | — | ~907 | Automated safety check: Pass | MIT | 2 mo ago |
| 346 | Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for… | forcedotcom/ | 1.1k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 347 | Activate an Enhanced MessagingChannel (WhatsApp/Apple/Facebook/SMS/RCS) by PATCHing MessagingChannelUsage.DeploymentStatus from Disabled to Provisioning via the REST sobject endpoint. | forcedotcom/ | 1.1k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 348 | Application security covering input validation, auth, headers, secrets management, and dependency auditing | rohitg00/ | 2.7k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | 4 mo ago |
| 349 | 对前端代码进行安全审计,检测 XSS、CSRF 等漏洞。当用户请求代码审查或询问代码安全性时使用. An agent skill from TencentBlueKing/bk-bcs. | TencentBlueKing/ | 840 | — | ~216 | Automated safety check: Pass | Unknown | today |
| 350 | A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data… | NoobyGains/ | 107 | — | ~2.4k | Automated safety check: Notes | MIT | 7 mo ago |
| 351 | 351.Hunt Csrf Hunting skill for csrf vulnerabilities. | sickn33/ | 47k | 1 repo | ~7.1k | Automated safety check: Pass | MIT | yesterday |
| 352 | A skill your agent uses when closing a patch cycle with rigorous stress LAST on the Railway hub, bensbench x86 fieldbus → MQTTS, CSV/synth59/Creekside/gate 19, B100 Railway-only, light OWASP ZAP… | bbartling/ | 172 | — | ~1.2k | Automated safety check: Pass | Unknown | today |
| 353 | WordPress security code review and vulnerability detection. An agent skill from jorgerosal/wordpress-skills. | jorgerosal/ | 101 | — | ~6.4k | Automated safety check: Pass | MIT | 4 mo ago |
| 354 | Cloudflare Workers security with authentication, CORS, rate limiting, input validation. | secondsky/ | 227 | — | ~1.9k | Automated safety check: Pass | MIT | 10 days ago |
| 355 | 355.Webapp Review Web application security testing workflow and checklist generation. | SpecterOps/ | 702 | — | ~1k | Automated safety check: Pass | Apache-2.0 | 15 days ago |
| 356 | Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 357 | Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 358 | Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 359 | Comprehensive code security audit with AI-powered vulnerability detection. | LeoYeAI/ | 2.2k | — | ~3.7k | Automated safety check: Notes | MIT | 2 mo ago |
| 360 | 360.Security Build and harden Phoenix auth and security — OAuth login, password hashing, sessions, RBAC, rate limiting, CSRF, XSS, SQL injection, secrets. | oliver-kriska/ | 565 | — | ~1k | Automated safety check: Pass | MIT | 3 days ago |
| 361 | Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash… | trilwu/ | 156 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 362 | 362.Hardening Siti Applica regole di sicurezza (hardening) ogni volta che si costruisce, modifica o revisiona un sito web o un'app. | ccplugins/ | 968 | — | ~875 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 363 | 363.Security Security audit workflow - vulnerability scan → verification. An agent skill from parcadei/Continuous-Claude-v3. | parcadei/ | 3.9k | — | ~1.5k | Automated safety check: Pass | MIT | 8 mo ago |
| 364 | 364.Senior Secops SecOps for application security, vulnerability management, compliance, and secure development. | borghei/ | 881 | — | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 365 | 扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。 | rongxinzy/ | 154 | — | ~868 | Automated safety check: Pass | MIT | today |
| 366 | Entry P1 category router for injection testing. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~570 | Automated safety check: Pass | MIT | 25 days ago |
| 367 | 367.Dt Sec Insights Query and analyze Dynatrace security data in security.events with DQL: vulnerabilities, threat detections, compliance posture, and scan coverage. | Dynatrace/ | 161 | — | ~7.2k | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 368 | 368.Cso Chief Security Officer mode. An agent skill from mr-daedalium/ostack-saas. | mr-daedalium/ | 114 | — | ~7.4k | Automated safety check: Notes | MIT | 6 mo ago |
| 369 | 369.Prompt Injection AI/LLM 间接 Prompt 注入攻击。当目标 AI 系统会处理外部数据源(网页、文档、邮件、数据库、API 返回)时使用。覆盖间接注入、工具链劫持、RAG 投毒、数据外泄等技术。OWASP LLM Top 10 1 漏洞类别 | wgpsec/ | 1.8k | — | ~704 | Automated safety check: Notes | No licence | 5 days ago |
| 370 | 370.Security Scan A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 167 | — | ~2.8k | Automated safety check: Notes | MIT | today |
| 371 | 371.Sqli Testing Detect and exploit SQL injection vulnerabilities in web application parameters | NeoTheCapt/ | 142 | — | ~1.2k | Automated safety check: Pass | No licence | 2 mo ago |
| 372 | 372.Ssrf Testing Detect and exploit server-side request forgery to access internal resources and cloud metadata | NeoTheCapt/ | 142 | — | ~768 | Automated safety check: Pass | No licence | 2 mo ago |
| 373 | 373.Xss Testing Detect and exploit cross-site scripting vulnerabilities in web applications | NeoTheCapt/ | 142 | — | ~1.4k | Automated safety check: Pass | No licence | 2 mo ago |
| 374 | 374.Xxe Testing XML external entity injection for file read, SSRF, and DoS. An agent skill from NeoTheCapt/RedteamAgent. | NeoTheCapt/ | 142 | — | ~1k | Automated safety check: Pass | No licence | 2 mo ago |
| 375 | Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. | giuseppe-trisciuoglio/ | 355 | — | ~2.4k | Automated safety check: Notes | MIT | 28 days ago |
| 376 | 376.Auth Sec Entry P1 category router for authentication and authorization. | majiayu000/ | 666 | 1 repo | ~4.6k | Automated safety check: Pass | MIT | today |
| 377 | 当未授权/零身份测试但路径不在主站 JS、禁止依赖登录 Network 截图、独立 H5/旧域名 NXDOMAIN/品牌迁域、兄弟域或同 IP Host 漏路径、网关 405 或 data 空数组、getRsaKey/JSEncrypt/前端加密被当成鉴权时调用。负责零身份公开面还原路径与密钥、响应指纹分流、加密证伪、迁域复查。JS 拆包见 recon-js-analysis;角色/IDOR… | zhaji2333/ | 113 | — | ~1.4k | Automated safety check: Pass | MIT | 23 days ago |
| 378 | 当payload被拦截、请求被WAF/过滤/403拒绝、连续多次payload失败、需要绕过黑名单/白名单/正则/语义分析防御时调用。负责编码/变形/逻辑/协议层绕过、换入口、组合利用与时间维度攻击的完整升级路径。 | zhaji2333/ | 113 | — | ~620 | Automated safety check: Pass | MIT | 23 days ago |
| 379 | 当目标存在评论/昵称/富文本/私信/工单/搜索反射/Markdown解析/AI输出渲染/前端DOM操作/postMessage/跨域配置等功能时调用。负责反射型/存储型/DOM XSS、AI/Markdown 渲染型存储 XSS、CSRF、CORS错误配置、Clickjacking 的深度挖掘与绕过。命中跳转页/开放重定向/target 参数驱动 location 跳转时优先测试跳转型… | zhaji2333/ | 113 | — | ~2.1k | Automated safety check: Pass | MIT | 23 days ago |
| 380 | 380.Client Side Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution. | transilienceai/ | 562 | — | ~374 | Automated safety check: Pass | MIT | 2 mo ago |
| 381 | 381.Aurakit Sonnet Amplified fullstack engine. An agent skill from davepoon/buildwithclaude. | davepoon/ | 3.6k | — | ~469 | Automated safety check: Pass | MIT | 2 days ago |
| 382 | 382.Security Audit Deep security audit covering OWASP Top 10, authentication, authorization, data protection, dependency vulnerabilities, and secrets scanning. | davepoon/ | 3.6k | — | ~442 | Automated safety check: Pass | MIT | 2 days ago |
| 383 | 383.Laravel Security Harden Laravel apps with Policies for model authorization, Gate-based RBAC, validated mass assignment, and CSRF protection. | HoangNguyen0403/ | 571 | — | ~887 | Automated safety check: Pass | MIT | yesterday |
| 384 | 384.Nestjs Security Implement JWT authentication, RBAC guards, Helmet hardening, and Argon2 hashing in NestJS. | HoangNguyen0403/ | 571 | — | ~778 | Automated safety check: Notes | MIT | yesterday |
Explore related skills
More topics in Security
- Security review636
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38