mcpbeat

Security Skills

1 645 security skills from 285 authors. They hunt for leaked secrets, vulnerabilities and permissions nobody meant to grant. Half of them fit into 2 028 tokens or less — that is what one costs your context window when the agent loads it. 196 ship runnable scripts rather than instructions alone. We also found 192 copies of these same skills sitting in other people's repositories — counted once here, not 192 times.

1 645 unique 285 authors 884 updated this month 119 from vendors

2 028
tokens, median
what a typical one costs in context
196
ship scripts
code that runs, not instructions alone
0
need a server
declared in the skill header
192
copies elsewhere
counted once here, not once per repository

1 009–1 056 of 1 645

page 22 of 35
Skill Security Auditor
aAAaqwq

Scan and audit AI agent skills for security risks before installation. Produces a Security audit and vulnerability scanner for AI agent skills before installation. directory or git repo URL for malicious code, (3) pre-install security gate for Claude Code plugins, OpenClaw skills, or Codex skills, (4) scanning Python scripts for dangerous patterns like os.system, eval, subprocess, network exfiltration, (5) detecting prompt injection in SKILL.md files, (6) checking dependency supply chain risks, (7) verifying file system access stays within skill boundaries. "check skill before install", "skill security check", "skill vulnerability scan".

14k tokens scripts
Thinking Warren Buffett
aAAaqwq

蒸馏Warren Buffett思维模式的实用框架——价值投资、能力圈、护城河、安全边际、反向思考

4k tokens zh
Auth0 Webhooks
hookdeck

> Receive and verify Auth0 webhooks delivered via Custom Log Streams (HTTP). Use when setting up an Auth0 log stream HTTP endpoint, validating the configured Authorization token, or handling batched authentication log events like s (success login), f (failed login), ss (signup), and sepft (token exchange / MFA).

11k tokens scripts
Fusionauth Webhooks
hookdeck

> Receive and verify FusionAuth webhooks. Use when setting up FusionAuth webhook handlers, debugging JWT signature verification, or handling authentication events like user.create, user.login.success, user.registration.create, or user.delete.

16k tokens scripts
Greendot Webhooks
hookdeck

> Receive and authenticate Green Dot Embedded Finance (BaaS) webhooks. Use when setting up a Green Dot partner webhook endpoint, validating the OAuth undocumented x-gd-signature header, echoing the x-GD-RequestId header, returning the responseDetails acknowledgement, or handling eventType events like transaction, accountUpdated, achTransfer, cardUpdate, billPayTransfer, directDepositSwitch, and provisioning.

14k tokens scripts
Praxis Webhooks
hookdeck

> Receive and verify Praxis (Praxis Tech / Cashier payment orchestration) webhooks. Use when setting up a Praxis webhook endpoint, verifying the gt-authentication SHA-384 signature, signing the acknowledgement with the external-request-signature header, or handling Payment Notification (transaction_status pending, approved, rejected, error) and Subscription Notification events.

15k tokens scripts
Prd Writer
TestAny-io

Write PRD, 写产品需求文档。Use when: 需要写新功能 PRD(有UI/无UI)、第三方集成、功能重构、性能/安全优化需求。

46k tokens zh
Configure Dast Scan
harness

>- Add Dynamic Application Security Testing (DAST) steps to existing Harness pipelines using Harness STO scanners. Supports API DAST / Traceable (default), Burp Suite Enterprise, ZAP (OWASP), Nikto, and Nmap. Scans running application instances for vulnerabilities including API security issues, injection flaws, misconfigurations, and exposed services. Can insert the scan step into an existing CI or SecurityTests stage or create a dedicated SecurityTests stage. Use when asked to add DAST scanning, configure dynamic application testing, set up API security scanning, scan a running application, or add runtime security testing to a pipeline. scan running app, add Burp Suite scan, add ZAP scan, add Nikto scan, runtime security scan, API security scan.

6k tokens
Audit Report
harness

>- Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools. Track user actions, resource changes, authentication events, and access patterns across accounts, organizations, and projects. Use when asked to audit activity, generate compliance reports, investigate security incidents, review user actions, check change logs, or produce SOC2/GDPR/HIPAA change log, access audit, security investigation, who changed what, audit events.

2k tokens
Configure Secret Scan
harness

>- Add secret detection scanning steps to existing Harness pipelines using STO security scanners. Detects exposed credentials, API keys, tokens, and sensitive data in code repositories. Supports Harness Code (default, native, unified SAST/SCA/secret detection), Gitleaks (standalone secret scanner, open-source), Semgrep, Snyk, SonarQube, Checkmarx, Fossa, Aqua Trivy, and Wiz. Only works with existing pipelines that have a codebase connector configured. Use when asked to add secret scanning, detect exposed secrets, find leaked API keys, configure secret detection, or scan code for credentials. scan for exposed API keys, add Gitleaks, secret scanning pipeline.

3k tokens
Configure Repo Scan
harness

>- Configure code scanning in Harness pipelines using STO security scanners. Helps identify where to inject SAST/SCA scanning steps into existing pipelines, recommends appropriate scanners, and configures them with proper connector references. Use when asked to add code scanning, configure security scans, set up SAST/SCA, configure repo scan, set up SAST, add security scan, configure vulnerability scanning, integrate scanner.

5k tokens
Exempt Vuln
harness

>- Create Harness STO security exemptions (waivers) for vulnerabilities found by SAST, SCA, DAST, Vulnerabilities tab of a specific pipeline execution (Target, Pipeline, or Project scope) and the All Issues page (Project scope only). Supports single creates with per-row error tolerance and bulk creates of up to 100 issues in one all-or-none transaction. The requester is derived automatically from the authenticated user. Use when a user wants to exempt a vulnerability, waive a CVE, suppress a security finding, mark a finding as a false positive, accept the risk, or exempt several vulnerabilities at once. exemption, suppress security issue, false positive, accept risk, ignore CVE, bulk exempt.

7k tokens
Manage Artifacts
harness

>- Manage Harness Artifact Registry (AR) via MCP. Configure private registries for Docker, Helm, Maven, npm, and PyPI artifacts, set up upstream proxies for caching public images, configure RBAC and cross-region replication, and define security scanning policies with CVE thresholds and license compliance checks. Use when asked to set up an artifact registry, configure Docker or Helm repositories, manage artifact security scanning, or set up replication. Do NOT use artifact registry, docker registry, helm repository, artifact security, image scanning, private registry, artifact replication, CVE threshold, license compliance, SBOM.

1k tokens
Manage Supply Chain
harness

>- Manage Harness Software Supply Chain Assurance (SSCA) via MCP. Configure automated SBOM generation with CycloneDX or SPDX formats, set up artifact signing and attestation with Cosign, define supply chain security policies using OPA, and track SLSA provenance levels. Use when asked to generate SBOMs, sign artifacts, enforce supply chain policies, track software provenance, or manage SLSA compliance. Do NOT use for OPA pipeline governance policies (use create-policy instead) or vulnerability scanning (use security-report instead). signing, cosign, provenance, attestation, CycloneDX, SPDX, supply chain policy.

1k tokens
Security Report
harness

Generate security compliance reports using Harness SCS and STO via MCP. Analyze vulnerabilities, SBOMs, and manage exemptions. Use when user says "security report", "vulnerabilities", "SBOM", "security scan", "compliance check", or asks about application security.

1k tokens
Ctf Kit
KerberosClaw

Use when the user is solving an authorized CTF / lab reverse-engineering challenge focused on Windows application authentication or license-check bypass. Guides triage → static analysis → dynamic experiment planning → bypass verification, with strong evidence discipline and VM safety boundaries. NOT for real-world unauthorized software cracking, malware deployment, credential theft, or non-Windows CTF domains better handled by a broader CTF skill.

24k tokens scripts zh
Repo Scan
KerberosClaw

Use when the user wants to evaluate a GitHub repository before installing, running, forking, or depending on it. Takes a GitHub repo URL, cleans tracking params, shallow-clones to /tmp, inspects dependency/supply-chain risk, static vulnerability patterns, issue-reported security problems, maintainer health, and produces a risk summary. NOT for reviewing the user's own PR diff or for running untrusted code.

4k tokens zh
Reverse Engineering
haikow

Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, game clients, malware-like loaders, and anti-debug or anti-analysis logic. Do not use it when the vulnerability is already understood and the remaining task is exploitation; use pwn instead. Do not use it for pure web workflows, log or disk forensics, or standalone crypto problems unless reversing the implementation is the real blocker.

88k tokens
Cvss Score Extraction
cxcscmu

Extract and handle CVSS scores from multiple vulnerability data sources (NVD, GHSA, RedHat) with proper fallback priority.

837 tokens
Security Audit Csv Reporting
cxcscmu

Generate structured CSV security audit reports from vulnerability data with proper filtering, formatting, and field mapping.

967 tokens
Trivy Vulnerability Scanning
cxcscmu

Use Trivy vulnerability scanner in offline mode to detect CVEs in npm dependencies and generate structured JSON reports.

750 tokens
Druid Javascript Security
cxcscmu

Securing Apache Druid's JavaScript execution engine against code injection and security bypass attacks.

711 tokens
Cvss Score Extraction
cxcscmu

Extract CVSS scores from vulnerability data sources with proper fallback handling across NVD, GHSA, and RedHat sources.

306 tokens
Trivy Offline Vulnerability Scanning
cxcscmu

Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files.

426 tokens
Vulnerability Csv Reporting
cxcscmu

Generate structured CSV security audit reports from vulnerability data with proper filtering and formatting.

474 tokens
Druid Javascript Rce
cxcscmu

Apache Druid JavaScript RCE vulnerability (CVE-2021-25646) fix via @JacksonInject hardening and constructor validation.

489 tokens
Cvss Score Extraction
cxcscmu

Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling. This skill covers understanding CVSS v3, handling multiple score sources (NVD, GHSA, RedHat), implementing source priority logic, and dealing with missing scores in security reporting.

2k tokens
Trivy Offline Vulnerability Scanning
cxcscmu

Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files without internet access.

528 tokens
Vulnerability Csv Reporting
cxcscmu

Generate structured CSV security audit reports from Trivy JSON vulnerability data with severity filtering and proper field mapping.

543 tokens
Apache Druid Security
cxcscmu

Security patching for Apache Druid - covers JavaScript execution vulnerabilities, sampler endpoint protection, and filter validation patterns.

968 tokens
Jackson Injection Security
cxcscmu

Security considerations for Jackson @JacksonInject - preventing JSON input from overriding injected values, covering CVE patterns and defense strategies.

690 tokens
Trivy Offline Vulnerability Scanning
cxcscmu

Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. This skill covers setting up offline scanning, executing Trivy against package lock files, and generating JSON vulnerability reports without requiring internet access.

2k tokens
Vulnerability Csv Reporting
cxcscmu

Generate structured CSV security audit reports from vulnerability data with proper filtering and formatting. This skill covers CSV schema design for security reports, using Python csv.DictWriter, severity-based filtering, and field mapping from JSON to tabular format.

3k tokens
Jackson Security
cxcscmu

Security considerations for Jackson JSON deserialization, specifically regarding `@JacksonInject` and unintended property overrides.

518 tokens
Trivy Audit
cxcscmu

Performing offline security audits on package-lock.json files using Trivy.

128 tokens
Apache Druid Security
cxcscmu

Security practices and vulnerability patching for Apache Druid, focusing on JavaScript sandbox configuration.

223 tokens
Trivy Offline Scanning
cxcscmu

Use Trivy for offline vulnerability scanning of dependency files like package-lock.json.

294 tokens
Jackson Druid Cve
cxcscmu

Security and Jackson deserialization issues in Apache Druid, focusing on property bypasses.

199 tokens
Run2 Npm Vulnerability Scanning Enhanced
cxcscmu

Enhanced npm vulnerability scanning with Trivy supporting multiple severity levels and complete metadata extraction

1k tokens
Run2 Jackson Security Patching
cxcscmu

Creating and applying security patches for Jackson deserialization vulnerabilities in Java

1k tokens
Run2 Maven Security Build
cxcscmu

Building Apache Druid with Maven while maintaining security patch integrity and skipping unnecessary checks

2k tokens
Run2 Csv Reporting
cxcscmu

Generate structured CSV security audit reports from Trivy JSON vulnerability data with deduplication, proper quoting, and field mapping.

575 tokens
Run2 Cvss Score
cxcscmu

Extract CVSS v3 scores from Trivy vulnerability data with source priority fallback (NVD > GHSA > RedHat) and handle missing data gracefully.

331 tokens
Run2 Trivy Offline
cxcscmu

Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files, covering setup, execution, and JSON output parsing.

559 tokens
Run2 Druid Cve 2021 25646
cxcscmu

Complete fix for Apache Druid CVE-2021-25646 JavaScript RCE via @JacksonInject override in all 7 affected components.

651 tokens
Run2 Cvss Score Extraction
cxcscmu

Extract CVSS v3 scores from Trivy vulnerability JSON with source priority (NVD > GHSA > RedHat) and fallback to N/A.

379 tokens
Run2 Trivy Offline Scanning
cxcscmu

Use Trivy vulnerability scanner in offline mode to scan dependency lock files and produce JSON vulnerability reports without internet access.

768 tokens
Run2 Vulnerability Csv Reporting
cxcscmu

Generate structured CSV security audit reports from Trivy JSON output with severity filtering, deduplication, and proper field mapping.

880 tokens