All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,868
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 97–120 of 26,868 skills
- Hardware Ot IcsAssess OT/ICS environments — PLC, SCADA, DCS, HMI — safely and passive-first: Purdue-model zoning, industrial protocol discovery (Modbus, S7, DNP3, EtherNet/IP), mirrored-traffic analysis, and read-only verification. Load for an authorized engagement touching industrial control networks, engineering workstations, historians, or IT/OT boundaries. Signals: ports 502, 102, 44818, 20000; Modbus/S7comm banners; PLC/RTU inventory requests.Votes: 0GitHub stars: 20
- Identity MapMap a contributor's GitHub handle to their Slack, Discord, Matrix, mailing-list, and social-media identities. Infers each mapping from the sources the session can reach, grades the evidence, and records only what the maintainer confirms, in a project-wide identity file shared by the contributor-growth skills.Votes: 0GitHub stars: 108
- Candidate ScreenSurface details about likely committer and <governance-body> candidates — deliberately more people than would be picked — as an alphabetical list with a short summary, in a verified-private repository. Never a ranking or a readiness verdict.Votes: 0GitHub stars: 108
- CalibrateDerive committer and <governance-body> reference levels from the project's own past nomination decisions on <private-list>, deliberately relaxed below what was elected, and propose them as a numbers-only config diff.Votes: 0GitHub stars: 108
- PaperclipPaperclip is a self-hosted Node.js server and web dashboard that runs a team of AI coding agents (Claude Code, Codex, Gemini CLI, OpenCode, OpenClaw) as a company, with an org chart, goals, tasks, monthly budgets and approval gates. Use when someone wants to install or run Paperclip, hire agents, assign tasks to them, cap agent spend, or script it through the paperclipai CLI or its REST API. Phrases: "set up Paperclip", "run my agents like a company", "too many Claude Code tabs", "give each a...Votes: 0GitHub stars: 155
- Red TeamerAttacks a weft program before it faces the world, hunting every credible hole: an outsider lying through an input, a hallucination the graph trusts, a rogue step with agency, an unguarded path to something that matters. Dispatched by Tangle when the program is high-stakes; reads the weft source, the prompts, and the node code, walks each attack from input to consequence, and reports verified findings with the layer that closes each. Never fixes, never runs the program, never edits.Votes: 0GitHub stars: 1,992
- Red TeamerAttacks a weft program before it faces the world, hunting every credible hole: an outsider lying through an input, a hallucination the graph trusts, a rogue step with agency, an unguarded path to something that matters. Dispatched by Tangle when the program is high-stakes; reads the weft source, the prompts, and the node code, walks each attack from input to consequence, and reports verified findings with the layer that closes each. Never fixes, never runs the program, never edits.Votes: 0GitHub stars: 1,992
- Red TeamerAttacks a weft program before it faces the world, hunting every credible hole: an outsider lying through an input, a hallucination the graph trusts, a rogue step with agency, an unguarded path to something that matters. Dispatched by Tangle when the program is high-stakes; reads the weft source, the prompts, and the node code, walks each attack from input to consequence, and reports verified findings with the layer that closes each. Never fixes, never runs the program, never edits.Votes: 0GitHub stars: 1,992
- Weft SafetyRead when a program talks to a model, messages people, spends money or writes into other systems: the swiss cheese model, the free layers built by default, the layers that cost something and the one-sentence test for when a program is high stakes, the wiring shapes, and the red-teamer pass.Votes: 0GitHub stars: 1,992
- Weft DatabaseRead when a cloud install needs its database: the user has no Postgres for it, or asks which to use. Gets one that scales to zero (Neon), with the user only signing up and pasting one key, and puts its addresses in the fork's secrets. Part of weft-cloud-install.Votes: 0GitHub stars: 1,992
- Nano Add Api Client ConfigurationWire an existing Nano Api Client into this application - adds the App:Apis configuration entry and injects the client into a controller/worker so it can call another Nano service. Use when the user asks to call another Nano service/API from this app, add an API client to a Public API, or compose internal services together in a Nano API, Web, or Console application.Votes: 0GitHub stars: 5
- Nano Add Api Client ConfigurationWire an existing Nano Api Client into this application - adds the App:Apis configuration entry, injects the client into a controller/worker, and nests the target service into this app's local docker-compose (with its own incremental publish step) so it's actually runnable end-to-end. Use when the user asks to call another Nano service/API from this app, add an API client to a Public API, or compose internal services together in a Nano API, Web, or Console application.Votes: 0GitHub stars: 5
- Audit SecurityA project-agnostic, WHOLE-PROJECT security audit - the "subscribe to a security firm" skill. It runs the real scanners (osv-scanner for dependency CVEs, gitleaks for secrets in the working tree AND full git history, semgrep for SAST, trivy for IaC), then performs its OWN LLM-driven whole-repository security review (a full local sweep, NOT a git-diff/PR lens - it replaces Anthropic's diff-scoped /security-review), builds a threat model so findings are ranked by what is actually worth attacking...Votes: 0GitHub stars: 2
- Restaking EigenlayerDetect restaking / AVS bugs — EigenLayer / Symbiotic / Karak operator slashing edge cases, withdrawal-queue gaming, cascading-slashing across AVSs, LST depeg solvency, AVS opt-in granularity. Activate on EigenLayer / Symbiotic / Karak imports, StrategyManager, DelegationManager, EigenPod, AVS registration, slasher contracts.Votes: 0GitHub stars: 36
- ReentrancyDetect reentrancy vulnerabilities — classic, cross-function, and cross-contract (especially read-only reentrancy). Activate whenever Solidity/Vyper code performs external calls, low-level call/transfer/send, ERC-721 safeTransfer with a receiver hook, or any pattern where control flow leaves the contract before state finalization.Votes: 0GitHub stars: 36
- Erc4337 Account AbstractionDetect ERC-4337 account-abstraction bugs — validateUserOp storage-rule violations, paymaster postOp DoS, session-key scope bypasses, signature aggregation issues, EIP-7702 delegation risks. Activate on `validateUserOp`, `validatePaymasterUserOp`, `postOp`, `UserOperation`, `EntryPoint`, `IAccount`, `IPaymaster`, session-key modules, ERC-7579 modules, EIP-7702 authorization payloads.Votes: 0GitHub stars: 36
- Cross Chain MessagingDetect cross-chain messaging bugs — replay protection gaps, untrusted-remote acceptance, default-config inheritance, validator-set misconfig, force-include vulnerabilities, chainId / domain-separator omissions. Activate on `_lzReceive`, `ccipReceive`, `handle` (Hyperlane), `receiveMessage`, `verifyVAA`, IRouterClient, IMailbox, EndpointV2, OApp/OFT, LayerZero / CCIP / Hyperlane / Wormhole / Axelar / Polyhedra integration code.Votes: 0GitHub stars: 36
- CosmwasmDetect bug classes specific to CosmWasm (Rust) contracts — missing info.sender authorization in execute handlers, unbounded map iteration → gas/DoS, reply/submessage reply_id confusion, migrate admin backdoors, addr_validate vs raw string addresses, unchecked info.funds, Uint128 overflow, query reentrancy, and migration/version state. Activate on any `.rs` file with `use cosmwasm_std`, `#[entry_point]`, `ExecuteMsg`, `InstantiateMsg`, `QueryMsg`, `cw_storage_plus`, or `DepsMut`.Votes: 0GitHub stars: 36
- Access ControlDetect missing or incorrect access control — missing modifiers, wrong role checks, privileged function exposure, public initializers, and role-escalation paths. Activate on any function that mutates state, transfers funds, mints tokens, sets admin parameters, upgrades implementations, or pauses/unpauses.Votes: 0GitHub stars: 36
- Security And HardeningUse when handling sensitive data, authentication, network communication, or before shipping to the Play Store. Three-tier framework (Always Do, Ask First, Never Do) with Android-specific security patterns, plus data privacy and compliance (GDPR/CCPA, Play Data safety, account deletion).Votes: 0GitHub stars: 2
- Addyosmani Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.Votes: 0GitHub stars: 2
- Addyosmani Code Review And QualityConducts multi-axis code review. Use before merging any change. Use when reviewing code written by yourself, another agent, or a human. Use when you need to assess code quality across multiple dimensions before it enters the main branch.Votes: 0GitHub stars: 2
- Arxiv 2609 28900 Codetta Multi Agent CollusionResearch paper: Codetta: High-Capacity, Keyless, and Undetectable Multi-Agent Collusion.Votes: 0GitHub stars: 3
- Arxiv 2609 28693 Progressive Skill Discovery Access ControlResearch paper: Progressive Skill Discovery as Access Control for Tool-Using LLM Agents: Structural Governance through Role-Scoped Capability Delivery.Votes: 0GitHub stars: 3