Scan the world (for secrets)
$ npx skills add betterleaks/betterleaksAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
Scan the world (for secrets)
$ npx skills add betterleaks/betterleaksMobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
$ npx skills add MobSF/Mobile-Security-Framework-MobSFA powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
$ npx skills add We5ter/Scanners-BoxThe OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
$ npx skills add OWASP/mastgTfsec is now part of Trivy
$ npx skills add aquasecurity/tfsecPrevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
$ npx skills add bridgecrewio/checkovProtect against malicious open source packages 🤖
$ npx skills add safedep/vetAll-in-One malware analysis tool.
$ npx skills add CYB3RMX/Qu1cksc0peA reactive Python kernel for Jupyter notebooks.
$ npx skills add ipyflow/ipyflowShellCheck, a static analysis tool for shell scripts
$ npx skills add koalaman/shellcheckAn analysis tool for Python that blurs the line between testing and type systems.
$ npx skills add pschanely/CrossHairDeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
$ npx skills add lintsinghua/DeepAuditOfficial ESLint plugin for Vue.js
$ npx skills add vuejs/eslint-plugin-vueAnalyze ELF binaries like a boss 😼🕵️♂️
$ npx skills add orhun/binsiderCodebase intelligence for TypeScript and JavaScript. Free static layer: unused code, duplication, circular deps, complexity hotspots, architecture boundaries. Optional paid runtime layer: hot-path review and cold-path deletion evidence from real production traffic. Rust-native, sub-second, zero-config framework support.
$ npx skills add fallow-rs/fallowStatic Analyzer for Solidity and Vyper
$ npx skills add crytic/slitherHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Packj if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.