Topic · Security

Best web application vulnerabilities skills, page 9

Skills #385–432 of 467, ranked by score.

Web application vulnerabilities skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Web application vulnerabilities skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
385

PHP-only security standards for database access, password handling, and input validation.

HoangNguyen0403/agent-skills-standard571—~604Automated safety check: PassMITyesterday
386

References Serverless OpenClaw security model. An agent skill from serithemage/serverless-openclaw.

serithemage/serverless-openclaw196—~633Automated safety check: PassNo licence6 mo ago
387

Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report.

receptron/mulmoterminal236—~1.5kAutomated safety check: NotesMITtoday
388

Django 安全最佳实践、身份验证(Authentication)、授权(Authorization)、CSRF 防护、SQL 注入防御、XSS 防御以及安全部署配置。

xu-xiang/everything-claude-code-zh2k—~3.5kAutomated safety check: NotesMIT7 mo ago
389

Django 安全最佳实践,涵盖身份验证、授权、CSRF 防护、SQL 注入预防、XSS 预防以及安全部署配置. An agent skill from xu-xiang/everything-claude-code-zh.

xu-xiang/everything-claude-code-zh2k—~3.5kAutomated safety check: NotesMIT7 mo ago
390

当涉及添加身份验证(Authentication)、处理用户输入、操作机密(Secrets)、创建 API 终端节点或实现支付/敏感功能时,请使用此技能。提供全面的安全检查清单和模式。

xu-xiang/everything-claude-code-zh2k—~2.5kAutomated safety check: NotesMIT7 mo ago
391

在添加身份验证、处理用户输入、操作机密信息(Secrets)、创建 API 端点以及实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。

xu-xiang/everything-claude-code-zh2k—~2.4kAutomated safety check: NotesMIT7 mo ago
392

在添加身份验证、处理用户输入、操作机密信息、创建 API 接口或实现支付/敏感功能时使用此技能。提供全面的安全自查清单和模式。

xu-xiang/everything-claude-code-zh2k—~2.4kAutomated safety check: NotesMIT7 mo ago
393

Spring Boot 服务的 Spring Security 身份验证/授权、验证、CSRF、密钥、响应头、速率限制和依赖项安全最佳实践。

xu-xiang/everything-claude-code-zh2k—~703Automated safety check: PassMIT7 mo ago
394

Spring Boot 服务的身份验证/授权、校验、CSRF、机密管理、响应头、速率限制及依赖安全的 Spring Security 最佳实践。

xu-xiang/everything-claude-code-zh2k—~1.7kAutomated safety check: PassMIT7 mo ago
395

This skill should be used when the user requests a code review of changed files.

aiskillstore/marketplace430—~2.3kAutomated safety check: PassNo licenceyesterday
396

Comprehensive security vulnerability analysis for codebases and infrastructure.

aiskillstore/marketplace430—~1.2kAutomated safety check: NotesNo licenceyesterday
397

Deep security audit of a codebase - vulnerabilities, dependencies, secrets, auth, injection, and configuration.

RedWoodOG/Hermes-Desktop177—~1.7kAutomated safety check: NotesNo licence4 mo ago
398

Comprehensive threat modeling for multi-agent systems using CSA MAESTRO 7-layer framework and OWASP Multi-Agentic System Threat Modeling Guide v1.0.

OWASP/secure-agent-playbook187—~835Automated safety check: NotesUnknown13 days ago
399

Perform evidence-driven security code reviews across application repositories, services, libraries, and pull requests.

SpecterOps/skills702—~2.3kAutomated safety check: PassApache-2.015 days ago
400

Use sqlmap to confirm and characterize suspected SQL injection with faithful requests and bounded evidence.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago
401

Assess server-side URL retrieval and network egress during authorized penetration tests or code audits.

cyberful/cyberful135—~867Automated safety check: PassAGPL-3.01 mo ago
402

Test and audit authenticated session state across cookies, opaque tokens, bearer tokens, refresh tokens, devices, browsers, APIs, and privilege transitions.

cyberful/cyberful135—~915Automated safety check: PassAGPL-3.01 mo ago
403
403.Security AuditOfficial

Focused security audit of code, calibrated to surface real exploitable bugs and suppress theoretical findings.

PostHog/posthog40k—~8kAutomated safety check: WarnUnknowntoday
404

Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…

LeoYeAI/openclaw-master-skills2.2k—~4.4kAutomated safety check: PassApache-2.02 mo ago
405

AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.

LeoYeAI/openclaw-master-skills2.2k—~1.9kAutomated safety check: PassApache-2.02 mo ago
406

Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to…

LeoYeAI/openclaw-master-skills2.2k—~3.1kAutomated safety check: PassMIT2 mo ago
407

A skill your agent uses when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation…

LeoYeAI/openclaw-master-skills2.2k—~2.8kAutomated safety check: NotesMIT2 mo ago
408

Code vulnerability pattern database. An agent skill from revfactory/harness-100.

revfactory/harness-1001.3k—~1.5kAutomated safety check: PassApache-2.06 mo ago
409

Security specialist perspective for the weekly review. An agent skill from mizchi/skills.

mizchi/skills356—~455Automated safety check: PassNo licence6 days ago
410

Validate csrf protection validator operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~595Automated safety check: PassMITtoday
411

Implement secure Obsidian plugin development practices. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~3.3kAutomated safety check: PassMITtoday
412

Detect sql injection detector operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~585Automated safety check: PassMITtoday
413

Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage.

jeremylongshore/tons-of-skills-marketplace2.8k—~910Automated safety check: NotesMITtoday
414

Scan xss vulnerability scanner operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~593Automated safety check: PassMITtoday
415

Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability…

OneWave-AI/claude-skills323—~1.2kAutomated safety check: PassMIT6 days ago
416

Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context.

ArabelaTso/Skills-4-SE253—~3.5kAutomated safety check: PassApache-2.01 mo ago
417

Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials…

ArabelaTso/Skills-4-SE253—~2kAutomated safety check: PassApache-2.01 mo ago
418

Detects security vulnerabilities by matching code against known vulnerability patterns, insecure coding idioms, and CVE-style patterns.

ArabelaTso/Skills-4-SE253—~2.8kAutomated safety check: PassApache-2.01 mo ago
419

Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure.

foryourhealth111-pixel/Vibe-Skills3.6k—~523Automated safety check: PassApache-2.01 mo ago
420

Security best practices for Micronaut/Kotlin backend including authentication, authorization, input validation, and OWASP prevention.

c0x12c/ai-toolkit106—~672Automated safety check: NotesNo licence3 mo ago
421

Security vulnerability scanner and OWASP compliance auditor for codebases.

curiositech/some_claude_skills243—~2.2kAutomated safety check: PassMIT1 mo ago
422

WordPress security code review for Codex. An agent skill from jorgerosal/wordpress-skills.

jorgerosal/wordpress-skills101—~490Automated safety check: PassMIT4 mo ago
423

Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes.

secondsky/claude-skills227—~656Automated safety check: PassMIT10 days ago
424

Configures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks.

secondsky/claude-skills227—~638Automated safety check: PassMIT10 days ago
425

XSS attack prevention with input sanitization, output encoding, Content Security Policy.

secondsky/claude-skills227—~1.5kAutomated safety check: PassMIT10 days ago
426

Security-focused code review of current git changes. An agent skill from SpecterOps/skills.

SpecterOps/skills702—~609Automated safety check: PassApache-2.015 days ago
427

Implement comprehensive input validation to prevent XSS, SQL injection, and command injection attacks with sanitization strategies

Hack23/cia239—~5.9kAutomated safety check: PassApache-2.0yesterday
428

Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy

Hack23/cia239—~5.8kAutomated safety check: PassApache-2.0yesterday
429

Systematic vulnerability lifecycle management with SLAs: Critical 7d, High 30d, Medium 90d, Low 180d aligned with OWASP, NIST, CIS Controls

Hack23/cia239—~6.2kAutomated safety check: PassApache-2.0yesterday
430

使用 DalFox 进行 XSS 漏洞扫描。当需要检测反射型/存储型/DOM XSS、分析参数注入点、绕过 WAF 时使用。DalFox 支持自动参数分析、DOM 挖掘、Blind XSS 回调、WAF 绕过、自动生成 PoC。任何涉及 XSS 漏洞检测、参数测试、WAF 绕过的场景都应使用此技能

wgpsec/AboutSecurity1.8k—~551Automated safety check: PassNo licence4 days ago
431

使用 Nikto 进行 Web 服务器漏洞扫描。当需要检测 Web 服务器的已知漏洞、过时软件版本、危险文件/CGI、配置错误时使用。Nikto 内置 7000+ 检查项,覆盖 OWASP 常见问题。任何涉及 Web 漏洞扫描、服务器安全检查、配置审计的场景都应使用此技能

wgpsec/AboutSecurity1.8k—~495Automated safety check: PassNo licence4 days ago
432

使用 xray 进行 Web 漏洞自动化扫描。当需要对 Web 应用进行全面漏洞扫描(XSS/SQLi/命令注入/SSRF/XXE/路径穿越/文件上传/弱口令等)时使用。xray 是长亭科技出品的综合性 Web 安全评估工具,支持主动扫描、被动代理扫描、基础爬虫扫描三种模式,内置丰富的检测插件和社区 POC。任何涉及 xray 漏洞扫描、Web 安全评估、被动代理扫描的场景都应使用此技能

wgpsec/AboutSecurity1.8k—~757Automated safety check: PassNo licence4 days ago