All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,878
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 577–600 of 26,878 skills
- FlaskExpert skill for Flask web framework development. Covers application factory, blueprints, routing, request/response handling, Jinja2 templates, application and request context (g, current_app), configuration, extensions ecosystem (SQLAlchemy, Login, WTF, CORS, Migrate), error handling, testing, and deployment. WHEN: \"Flask\", \"flask\", \"Werkzeug\", \"Jinja2\", \"Blueprint\", \"Flask blueprint\", \"flask factory\", \"create_app\", \"Flask-SQLAlchemy\", \"Flask-Login\", \"Flask-WTF\", \"Flas...Votes: 0GitHub stars: 4
- CodexOpenAI Codex harness operations end-to-end: CLI install and sign-in, layered `config.toml` (user/project/profile/system) and its key catalog, approval policies vs sandbox modes, `AGENTS.md` discovery and merge order, Codex Skills (`.agents/skills`, `$skill`), MCP server wiring, `codex exec` headless/CI and the Codex GitHub Action, Codex cloud tasks and environments, git worktrees, `/review` and `@codex` PR reviews, the IDE extension, model IDs and reasoning effort, and enterprise `requirement...Votes: 0GitHub stars: 4
- Ai SecuritySecurity engineering for LLM applications and AI agents: OWASP Top 10 for LLM Applications (2025), OWASP MCP Top 10 (Beta v0.1), prompt-injection and jailbreak defense, agent threat patterns (lethal trifecta, tool poisoning, confused deputy, exfiltration via tool results), the Claude Code trust/permission model, vendor guardrail and moderation options, and governance frameworks (Google SAIF, NIST AI RMF). WHEN: \"prompt injection\", \"indirect prompt injection\", \"jailbreak\", \"OWASP LLM To...Votes: 0GitHub stars: 4
- Backend Service AuditorAudit backend services for security, reliability, performance, and operability issues. Use when reviewing APIs, microservices, workers, or backend code changes. Triggers on "audit backend", "security review", "service audit", "API audit", "check vulnerabilities", "review microservice", "backend security", "audit API", "review service".Votes: 0GitHub stars: 3
- Web ReportWeb penetration testing report generation skill. Activate when the user wants to write, generate, or finalize a report for a web pentest or bug bounty engagement. Consolidates outputs from web-recon, web-exploitation, and web-postexploitation skills into a structured technical and executive report. Produces findings in standardized format (name, criticality, CVSS, description, impact, recommendation, evidence). Default mode: combined technical + executive report. Publishes to Notion via MCP w...Votes: 0GitHub stars: 34
- Web HackingOWASP Top 10 focused web vulnerability analysis, payload crafting, and bypass techniques for penetration testers.Votes: 0GitHub stars: 34
- Seagull PentestEvidence-driven penetration and attack-surface engineering for web applications, APIs, networks, identity systems, Active Directory, cloud, containers, Kubernetes, authentication flows, and source-assisted assessments. Use when Codex receives a URL, host, request/response, API schema, JavaScript bundle, network inventory, cloud configuration, identity graph, or needs recon, endpoint extraction, hypothesis ranking, precise validation, finding reproduction, attack-path analysis, remediation, or...Votes: 0GitHub stars: 34
- Performing Firmware Extraction With BinwalkPerforms firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system secur...Votes: 0GitHub stars: 34
- Performing Cryptographic Audit Of ApplicationA cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardcoVotes: 0GitHub stars: 34
- Pentest ReconStructured penetration test reconnaissance covering OSINT, network enumeration, attack surface mapping, and CVE prioritization.Votes: 0GitHub stars: 34
- Openai Security ReviewPerform Shannon-inspired, OpenAI/Codex-native defensive security reviews of local repositories and authorized web apps. Use when the user asks to audit code, review a repo for vulnerabilities, assess OWASP risks, map attack surface, create a stateful security review workspace, log into an authorized test account, run authenticated passive Playwright crawling, perform safe read-only validation, generate vulnerability hypotheses, prepare a pentest-style report without Shannon/Anthropic, or revi...Votes: 0GitHub stars: 34
- Mcp Protocol ExploitationTest Model Context Protocol (MCP) servers and tool-calling systems for security vulnerabilities including tool injection, parameter manipulation, privilege escalation, and data exfiltration through AI agent tool interfaces. Use this skill when assessing MCP server implementations, AI agent tool integrations, or any system that exposes tools to language models. Covers tool confusion attacks, cross-tool exploitation, and MCP server hardening assessment.Votes: 0GitHub stars: 34
- 09 Web SecurityOWASP Top 10 testing, injection vulnerability detection, API security assessment, authentication testing, and web vulnerability reporting for authorized assessmentsVotes: 0GitHub stars: 34
- Generate Cve JsonGenerate a CVE 5.x JSON document from an <tracker> tracking issue, ready to paste into the Vulnogram `#source` tab of the ASF CVE tool at https://cveprocess.apache.org/cve5/<CVE-ID>#source. The conversion is deterministic: same issue in, same JSON bytes out. Handles multiple credits (one per line) and multiple references (URLs extracted from the issue's "Public advisory URL" and "PR with the fix" fields; the "Security mailing list thread" field is treated as internal-only and never exported).Votes: 0GitHub stars: 108
- Write SkillWrite a new skill for the Apache Magpie framework, or bring an existing one up to current conventions. Scaffolds the directory, walks the house style and the prompt-injection defences, and validates before it ships.Votes: 0GitHub stars: 108
- Skill ReconcilerCompare two near-duplicate skills — typically an ASF variant and a non-ASF or multi-project variant — and classify every difference as ALLOWED, DRIFT, or SAFETY-BASELINE. Produces a structured diff and a reconciliation proposal. Read-only: it never rewrites either skill; convergence is a separate confirmed authoring step. A safety-baseline divergence is always a must-fix, never silently merged into allowed-divergence noise.Votes: 0GitHub stars: 108
- Report Framework IssueHelp an adopter or framework developer file a clean, redacted GitHub issue against the Apache Magpie framework repo when a skill, tool, or doc misbehaves. It gathers the problem from the user — never from the raw session transcript — then runs a mandatory public-disclosure scrub before rendering the report into the framework's `bug_report` / `change_proposal` issue template, checking for duplicates, and filing via `gh issue create --web` only on explicit confirmation. The scrub is the point: ...Votes: 0GitHub stars: 108
- Optimize SkillMake an existing framework skill leaner without changing its behavior. Diagnose context-cost smells, propose the applicable optimization passes, and validate before and after every approved change.Votes: 0GitHub stars: 108
- List SkillsPrint a human-readable index of every skill installed for this repository, grouped by the family each one declares, with the name to invoke it by and the first sentence of its `description`. Discovery is installation-aware: it covers a pinned snapshot install, the framework checkout, and marketplace plugin installs, so the index matches what the agent can actually run. Generated on every run from live `SKILL.md` frontmatter, so it never goes stale when skills are added, removed, or rewritten.Votes: 0GitHub stars: 108
- Upstream FixTurn a framework defect the agent hit while running a Magpie skill into a fix PR against `apache/magpie`, one PR per defect. Confirms it is a framework bug rather than local misconfiguration or a stale snapshot, then searches for an existing issue or PR and points at that instead of opening a duplicate.Votes: 0GitHub stars: 108
- StatusShow how Magpie is adopted in this repo — install method and pin, drift, wired agent targets, installed skill families, symlink health — and change that wiring from the same view. The change itself runs through the setup skill.Votes: 0GitHub stars: 108
- Shared Config SyncCommit and push the user's shared Claude config to the `~/.claude-config` sync repo, rebasing first so a push never buries work from another machine. Bootstraps the repo when it is missing. Never force-pushes, never rewrites pushed history, never creates a public remote, and touches nothing outside `~/.claude-config/`.Votes: 0GitHub stars: 108
- SetupInstall Magpie, configure it for yourself, or adopt it for a repo. Installing touches only this machine; configuring writes gitignored local files; adopting commits a floor and the project's configuration for every contributor. Marketplace by default, pinned snapshot as fallback.Votes: 0GitHub stars: 108
- Privacy LlmDecide which LLMs this project's skills may send private foundation content to, then prove it. Detects the stack in use, writes <project-config>/privacy-llm.md, and runs the approved-model gate and the PII redactor end to end so the result is demonstrated rather than declared.Votes: 0GitHub stars: 108