Topic: security-tools
92 skills in this topic.
-
frontend-design
Create distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, artifacts, posters, or applications (examples include websites, landing pages, dashboards, React components, HTML/CSS layouts, or when styling/beautifying any web UI). Generates creative, polished code and UI design that avoids generic AI aesthetics.
onecli/onecli 1,737
-
web-design-guidelines
Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices".
onecli/onecli 1,737
-
find-skills
Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.
onecli/onecli 1,737
-
vercel-react-best-practices
React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.
onecli/onecli 1,737
-
bun-file-io
Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.
CyberStrikeus/CyberStrike 166
-
wstg-injection
WSTG input validation and injection testing - SQLi, XSS, SSTI, SSRF, command injection, XXE
CyberStrikeus/CyberStrike 166
-
wstg-auth-session
WSTG identity, authentication, authorization, and session management testing
CyberStrikeus/CyberStrike 166
-
recon-methodology
Bug bounty and pentest reconnaissance methodology
CyberStrikeus/CyberStrike 166
-
wstg-logic-client-api
WSTG business logic, client-side, and API security testing
CyberStrikeus/CyberStrike 166
-
ad-security
Active Directory security testing and attack techniques
CyberStrikeus/CyberStrike 166
-
kerberos-attacks
Kerberos protocol attack techniques and exploitation
CyberStrikeus/CyberStrike 166
-
wstg-recon-config
WSTG reconnaissance, configuration, error handling, and cryptography testing techniques
CyberStrikeus/CyberStrike 166
-
narsil
Use narsil-mcp code intelligence tools effectively. Use when searching code, finding symbols, analyzing call graphs, scanning for security vulnerabilities, exploring dependencies, or performing static analysis on indexed repositories.
postrv/narsil-mcp 134
-
authentication
Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.
transilienceai/communitytools 129
-
hackthebox
HackTheBox platform automation - login via Playwright, browse challenges/machines/labs, manage VPN connections, solve challenges using pentest skills, log all proceedings, and feed learnings back into skill improvement.
transilienceai/communitytools 129
-
source-code-scanning
Security-focused source code review and SAST. Scans for vulnerabilities (OWASP Top 10, CWE Top 25), CVEs in third-party dependencies/packages, hardcoded secrets, malicious code, and insecure patterns. Use when given source code, a repo path, or asked to "audit", "scan", "review" code security, or "check dependencies for CVEs".
transilienceai/communitytools 129
-
http-fingerprinting
Analyzes HTTP responses for technology signatures in headers, cookies, and error pages
transilienceai/communitytools 129
-
code-repository-intel
Scans GitHub/GitLab for public repos, dependencies, and CI configurations
transilienceai/communitytools 129
-
html-content-analysis
Parses HTML for meta tags, generator comments, and script URL patterns
transilienceai/communitytools 129
-
confidence_scorer
transilienceai/communitytools 129
-
client-side
Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.
transilienceai/communitytools 129
-
signal_correlator
transilienceai/communitytools 129
-
infrastructure
Network infrastructure testing - port scanning, DNS attacks, MITM, VLAN hopping, IPv6, SMB/NetBIOS, sniffing, and DoS assessment.
transilienceai/communitytools 129
-
subdomain-enumeration
Enumerates subdomains using CT logs, passive DNS, and search engine dorks
transilienceai/communitytools 129