mcpbeat

Security Skills

1 645 security skills from 285 authors. They hunt for leaked secrets, vulnerabilities and permissions nobody meant to grant. Half of them fit into 2 028 tokens or less — that is what one costs your context window when the agent loads it. 196 ship runnable scripts rather than instructions alone. We also found 192 copies of these same skills sitting in other people's repositories — counted once here, not 192 times.

1 645 unique 285 authors 881 updated this month 119 from vendors

2 028
tokens, median
what a typical one costs in context
196
ship scripts
code that runs, not instructions alone
0
need a server
declared in the skill header
192
copies elsewhere
counted once here, not once per repository

721–768 of 1 645

page 16 of 35
Databricks Core
databricks

Databricks CLI operations and the parent/entry-point skill for Databricks CLI use: authentication, profile selection, and bundles. Load this first for CLI, auth, profile, and bundle tasks, then load the matching product skill. For finding or exploring data, answering questions about the data, or generating SQL, load the databricks-data-discovery skill (it routes to Genie One). Contains up-to-date guidelines for Databricks-related CLI tasks.

15k tokens
Compliance Checker
OneWave-AI

Audits a codebase or business process for regulatory compliance across GDPR, HIPAA, SOC2, CCPA, and PCI-DSS. Scans for PII handling, data retention, encryption, access controls, audit logging, consent management, and data transfer issues. Generates a structured compliance report with findings, gap analysis, remediation steps, and evidence requirements.

13k tokens
Security Pentest Planner
OneWave-AI

Plans security penetration tests for web applications. Analyzes codebase, API routes, auth implementation, and infrastructure config to generate comprehensive pentest plans. For authorized testing only.

15k tokens
Publish Skill
Aperivue

> Convert a personal agent skill into a distributable, open-source-ready skill. Runs PII audit, generalization, license compatibility check, cross-platform adapter review, and packaging workflow.

9k tokens scripts
Superior Trade Auth
Superior-Trade

Request and use a Superior Trade API key for https://api.superior.trade. Use when an agent needs to onboard a user by email, request an API key with POST /auth/sign-in/magic-link, set up x-api-key authentication, or recover from missing/invalid Superior Trade credentials (401/403) before backtesting or deploying a strategy.

95k tokens scripts
007
lingxling

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

79k tokens scripts
Luna
lingxling

Reviews code for objective correctness, security, and reliability.

2k tokens
AI Engineering Toolkit
lingxling

6 production-ready AI engineering workflows: prompt evaluation (8-dimension scoring), context budget planning, RAG pipeline design, agent security audit (65-point checklist), eval harness building, and product sense coaching.

2k tokens
Antigravity Workflows
lingxling

Orchestrate multiple Antigravity skills through guided workflows for SaaS MVP delivery, security audits, AI agent builds, and browser QA.

935 tokens
API Onboarding
lingxling

Reduce time-to-first-API-call (TTFAC) by optimizing every step of the developer onboarding journey. This skill covers authentication simplification, sandbox environments, interactive documentation, and identifying and eliminating common failure points. Trigger phrases: "API...

4k tokens
API Endpoint Builder
lingxling

Builds production-ready REST API endpoints with validation, error handling, authentication, and documentation. Follows best practices for security and scalability.

2k tokens
Audit Context Building
lingxling

Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.

3k tokens
Backend Security Coder
lingxling

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

3k tokens
Broken Authentication
lingxling

Identify and exploit authentication and session management vulnerabilities in web applications. Broken authentication consistently ranks in the OWASP Top 10 and can lead to account takeover, identity theft, and unauthorized access to sensitive systems.

3k tokens
Burpsuite Project Parser
lingxling

Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project.

3k tokens
Cc Skill Security Review
lingxling

This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints.

3k tokens
Cloud Penetration Testing
lingxling

Conduct comprehensive security assessments of cloud infrastructure across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).

6k tokens
Cloudflare Security Audit
lingxling

Audit authorized codebases for exploitable vulnerabilities using scoped reconnaissance, adversarial review, validation, and structured reporting.

24k tokens
Codebase Cleanup Deps Audit
lingxling

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

7k tokens
Container Security Hardening
lingxling

> Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls. Use for Dockerfile security reviews, container CVEs, image scanning, distroless images, or production hardening.

16k tokens
Developer Signup Flow
lingxling

Design frictionless signup experiences for developers including GitHub OAuth, API key generation, and onboarding personalization. Trigger phrases: developer signup, dev registration, OAuth flow, API key onboarding, reduce signup friction, developer authentication, signup conversion,...

4k tokens
Ffuf Web Fuzzing
lingxling

Expert guidance for ffuf web fuzzing during penetration testing, including authenticated fuzzing with raw requests, auto-calibration, and result analysis

5k tokens
Google Docs Automation
lingxling

Lightweight Google Docs integration with standalone OAuth authentication. No MCP server required.

741 tokens
Google Sheets Automation
lingxling

Lightweight Google Sheets integration with standalone OAuth authentication. No MCP server required. Full read/write access.

1k tokens
Google Slides Automation
lingxling

Lightweight Google Slides integration with standalone OAuth authentication. No MCP server required. Full read/write access.

1k tokens
K8s Security Policies
lingxling

Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

4k tokens
Laravel Security Audit
lingxling

Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.

1k tokens
Linux Privilege Escalation
lingxling

Execute systematic privilege escalation assessments on Linux systems to identify and exploit misconfigurations, vulnerable services, and security weaknesses that allow elevation from low-privilege user access to root-level control.

3k tokens
Linux Shell Scripting
lingxling

Provide production-ready shell script templates for common Linux system administration tasks including backups, monitoring, user management, log analysis, and automation. These scripts serve as building blocks for security operations and penetration testing environments.

3k tokens
Malware Analyst
lingxling

Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification.

2k tokens
Microsoft Azure Webjobs Extensions Authentication Events Dotnet
lingxling

Microsoft Entra Authentication Events SDK for .NET. Azure Functions triggers for custom authentication extensions.

4k tokens
Mobile Security Coder
lingxling

Expert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns.

3k tokens
Nestjs Expert
lingxling

You are an expert in Nest.js with deep knowledge of enterprise-grade Node.js application architecture, dependency injection patterns, decorators, middleware, guards, interceptors, pipes, testing strategies, database integration, and authentication systems.

5k tokens
Network 101
lingxling

Configure and test common network services (HTTP, HTTPS, SNMP, SMB) for penetration testing lab environments. Enable hands-on practice with service enumeration, log analysis, and security testing against properly configured target systems.

2k tokens
Odoo Security Rules
lingxling

Expert in Odoo access control: ir.model.access.csv, record rules (ir.rule), groups, and multi-company security patterns.

1k tokens
Pentest Commands
lingxling

Provide a comprehensive command reference for penetration testing tools including network scanning, exploitation, password cracking, and web application testing. Enable quick command lookup during security assessments.

2k tokens
Privacy By Design
lingxling

Use when building apps that collect user data. Ensures privacy protections are built in from the start—data minimization, consent, encryption.

2k tokens
Privacy Mask
lingxling

Mask, redact, anonymize and censor sensitive information (PII) in screenshots and images — phone numbers, emails, IDs, API keys, crypto wallets, credit cards, passwords, and more. Uses OCR (Tesseract + RapidOCR) with 47 regex rules and optional NER (GLiNER) to detect private data and...

1k tokens
Privilege Escalation Methods
lingxling

Provide comprehensive techniques for escalating privileges from a low-privileged user to root/administrator access on compromised Linux and Windows systems. Essential for penetration testing post-exploitation phase and red team operations.

2k tokens
Red Team Tools
lingxling

Implement proven methodologies and tool workflows from top security researchers for effective reconnaissance, vulnerability discovery, and bug bounty hunting. Automate common tasks while maintaining thorough coverage of attack surfaces.

2k tokens
Scanning Tools
lingxling

Master essential security scanning tools for network discovery, vulnerability assessment, web application testing, wireless security, and compliance validation. This skill covers tool selection, configuration, and practical usage across different scanning categories.

3k tokens
Security And Hardening
lingxling

Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.

5k tokens
Security Audit
lingxling

Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.

1k tokens
Security Auditor
lingxling

Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

3k tokens
Security Bluebook Builder
lingxling

Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions, scope, and security gates.

663 tokens
Security Requirement Extraction
lingxling

Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.

6k tokens
Security Scanning Security Dependencies
lingxling

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies.

5k tokens
Security Scanning Security Hardening
lingxling

Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.

3k tokens