Topic · Security
Best web application vulnerabilities skills, page 9
Web application vulnerabilities skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 385 | 385.Php Security PHP-only security standards for database access, password handling, and input validation. | HoangNguyen0403/ | 571 | — | ~604 | Automated safety check: Pass | MIT | yesterday |
| 386 | 386.Security References Serverless OpenClaw security model. An agent skill from serithemage/serverless-openclaw. | serithemage/ | 196 | — | ~633 | Automated safety check: Pass | No licence | 6 mo ago |
| 387 | Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report. | receptron/ | 236 | — | ~1.5k | Automated safety check: Notes | MIT | today |
| 388 | 388.Django Security Django 安全最佳实践、身份验证(Authentication)、授权(Authorization)、CSRF 防护、SQL 注入防御、XSS 防御以及安全部署配置。 | xu-xiang/ | 2k | — | ~3.5k | Automated safety check: Notes | MIT | 7 mo ago |
| 389 | 389.Django Security Django 安全最佳实践,涵盖身份验证、授权、CSRF 防护、SQL 注入预防、XSS 预防以及安全部署配置. An agent skill from xu-xiang/everything-claude-code-zh. | xu-xiang/ | 2k | — | ~3.5k | Automated safety check: Notes | MIT | 7 mo ago |
| 390 | 390.Security Review 当涉及添加身份验证(Authentication)、处理用户输入、操作机密(Secrets)、创建 API 终端节点或实现支付/敏感功能时,请使用此技能。提供全面的安全检查清单和模式。 | xu-xiang/ | 2k | — | ~2.5k | Automated safety check: Notes | MIT | 7 mo ago |
| 391 | 391.Security Review 在添加身份验证、处理用户输入、操作机密信息(Secrets)、创建 API 端点以及实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。 | xu-xiang/ | 2k | — | ~2.4k | Automated safety check: Notes | MIT | 7 mo ago |
| 392 | 392.Security Review 在添加身份验证、处理用户输入、操作机密信息、创建 API 接口或实现支付/敏感功能时使用此技能。提供全面的安全自查清单和模式。 | xu-xiang/ | 2k | — | ~2.4k | Automated safety check: Notes | MIT | 7 mo ago |
| 393 | Spring Boot 服务的 Spring Security 身份验证/授权、验证、CSRF、密钥、响应头、速率限制和依赖项安全最佳实践。 | xu-xiang/ | 2k | — | ~703 | Automated safety check: Pass | MIT | 7 mo ago |
| 394 | Spring Boot 服务的身份验证/授权、校验、CSRF、机密管理、响应头、速率限制及依赖安全的 Spring Security 最佳实践。 | xu-xiang/ | 2k | — | ~1.7k | Automated safety check: Pass | MIT | 7 mo ago |
| 395 | 395.Code Review This skill should be used when the user requests a code review of changed files. | aiskillstore/ | 430 | — | ~2.3k | Automated safety check: Pass | No licence | yesterday |
| 396 | Comprehensive security vulnerability analysis for codebases and infrastructure. | aiskillstore/ | 430 | — | ~1.2k | Automated safety check: Notes | No licence | yesterday |
| 397 | 397.Security Audit Deep security audit of a codebase - vulnerabilities, dependencies, secrets, auth, injection, and configuration. | RedWoodOG/ | 177 | — | ~1.7k | Automated safety check: Notes | No licence | 4 mo ago |
| 398 | Comprehensive threat modeling for multi-agent systems using CSA MAESTRO 7-layer framework and OWASP Multi-Agentic System Threat Modeling Guide v1.0. | OWASP/ | 187 | — | ~835 | Automated safety check: Notes | Unknown | 13 days ago |
| 399 | Perform evidence-driven security code reviews across application repositories, services, libraries, and pull requests. | SpecterOps/ | 702 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 15 days ago |
| 400 | 400.Operate Sqlmap Use sqlmap to confirm and characterize suspected SQL injection with faithful requests and bounded evidence. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 401 | Assess server-side URL retrieval and network egress during authorized penetration tests or code audits. | cyberful/ | 135 | — | ~867 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 402 | Test and audit authenticated session state across cookies, opaque tokens, bearer tokens, refresh tokens, devices, browsers, APIs, and privilege transitions. | cyberful/ | 135 | — | ~915 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 403 | Focused security audit of code, calibrated to surface real exploitable bugs and suppress theoretical findings. | PostHog/ | 40k | — | ~8k | Automated safety check: Warn | Unknown | today |
| 404 | 404.Agent Bom Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS… | LeoYeAI/ | 2.2k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 405 | AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. | LeoYeAI/ | 2.2k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 406 | 406.Code Review Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to… | LeoYeAI/ | 2.2k | — | ~3.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 407 | 407.Security Auditor A skill your agent uses when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation… | LeoYeAI/ | 2.2k | — | ~2.8k | Automated safety check: Notes | MIT | 2 mo ago |
| 408 | Code vulnerability pattern database. An agent skill from revfactory/harness-100. | revfactory/ | 1.3k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 409 | 409.Security Expert Security specialist perspective for the weekly review. An agent skill from mizchi/skills. | mizchi/ | 356 | — | ~455 | Automated safety check: Pass | No licence | 6 days ago |
| 410 | Validate csrf protection validator operations. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~595 | Automated safety check: Pass | MIT | today |
| 411 | Implement secure Obsidian plugin development practices. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 412 | Detect sql injection detector operations. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~585 | Automated safety check: Pass | MIT | today |
| 413 | 413.Warden Audit Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. | jeremylongshore/ | 2.8k | — | ~910 | Automated safety check: Notes | MIT | today |
| 414 | Scan xss vulnerability scanner operations. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~593 | Automated safety check: Pass | MIT | today |
| 415 | 415.Code Review Pro Performs a deep code review of files, modules, a diff, or a branch - finding security vulnerabilities (mapped to OWASP Top 10:2025), correctness bugs, performance problems, and maintainability… | OneWave-AI/ | 323 | — | ~1.2k | Automated safety check: Pass | MIT | 6 days ago |
| 416 | Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context. | ArabelaTso/ | 253 | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 417 | Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials… | ArabelaTso/ | 253 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 418 | Detects security vulnerabilities by matching code against known vulnerability patterns, insecure coding idioms, and CVE-style patterns. | ArabelaTso/ | 253 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 419 | Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure. | foryourhealth111-pixel/ | 3.6k | — | ~523 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 420 | Security best practices for Micronaut/Kotlin backend including authentication, authorization, input validation, and OWASP prevention. | c0x12c/ | 106 | — | ~672 | Automated safety check: Notes | No licence | 3 mo ago |
| 421 | 421.Security Auditor Security vulnerability scanner and OWASP compliance auditor for codebases. | curiositech/ | 243 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 422 | WordPress security code review for Codex. An agent skill from jorgerosal/wordpress-skills. | jorgerosal/ | 101 | — | ~490 | Automated safety check: Pass | MIT | 4 mo ago |
| 423 | 423.Csrf Protection Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes. | secondsky/ | 227 | — | ~656 | Automated safety check: Pass | MIT | 10 days ago |
| 424 | Configures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks. | secondsky/ | 227 | — | ~638 | Automated safety check: Pass | MIT | 10 days ago |
| 425 | 425.Xss Prevention XSS attack prevention with input sanitization, output encoding, Content Security Policy. | secondsky/ | 227 | — | ~1.5k | Automated safety check: Pass | MIT | 10 days ago |
| 426 | 426.Code Review Security-focused code review of current git changes. An agent skill from SpecterOps/skills. | SpecterOps/ | 702 | — | ~609 | Automated safety check: Pass | Apache-2.0 | 15 days ago |
| 427 | 427.Input Validation Implement comprehensive input validation to prevent XSS, SQL injection, and command injection attacks with sanitization strategies | Hack23/ | 239 | — | ~5.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 428 | Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy | Hack23/ | 239 | — | ~5.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 429 | Systematic vulnerability lifecycle management with SLAs: Critical 7d, High 30d, Medium 90d, Low 180d aligned with OWASP, NIST, CIS Controls | Hack23/ | 239 | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 430 | 430.Dalfox Xss 使用 DalFox 进行 XSS 漏洞扫描。当需要检测反射型/存储型/DOM XSS、分析参数注入点、绕过 WAF 时使用。DalFox 支持自动参数分析、DOM 挖掘、Blind XSS 回调、WAF 绕过、自动生成 PoC。任何涉及 XSS 漏洞检测、参数测试、WAF 绕过的场景都应使用此技能 | wgpsec/ | 1.8k | — | ~551 | Automated safety check: Pass | No licence | 4 days ago |
| 431 | 431.Nikto Scan 使用 Nikto 进行 Web 服务器漏洞扫描。当需要检测 Web 服务器的已知漏洞、过时软件版本、危险文件/CGI、配置错误时使用。Nikto 内置 7000+ 检查项,覆盖 OWASP 常见问题。任何涉及 Web 漏洞扫描、服务器安全检查、配置审计的场景都应使用此技能 | wgpsec/ | 1.8k | — | ~495 | Automated safety check: Pass | No licence | 4 days ago |
| 432 | 432.Xray Scan 使用 xray 进行 Web 漏洞自动化扫描。当需要对 Web 应用进行全面漏洞扫描(XSS/SQLi/命令注入/SSRF/XXE/路径穿越/文件上传/弱口令等)时使用。xray 是长亭科技出品的综合性 Web 安全评估工具,支持主动扫描、被动代理扫描、基础爬虫扫描三种模式,内置丰富的检测插件和社区 POC。任何涉及 xray 漏洞扫描、Web 安全评估、被动代理扫描的场景都应使用此技能 | wgpsec/ | 1.8k | — | ~757 | Automated safety check: Pass | No licence | 4 days ago |
Explore related skills
More topics in Security
- Security review636
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38