Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
Excellent quality, 12K stars, and a 26 use-case fit score.
$ npx skills add future-architect/vulsReduce risk
Explore skills for vulnerability checks, secret scanning, dependency review, policy validation, and security-aware automation.
Builders choosing skills for scan dependencies and find exposed secrets. Ranked from the OpenAgentSkill index using quality, trust, freshness, adoption, and install readiness.
Workflow
Scan dependencies
Workflow
Find exposed secrets
Workflow
Review security findings
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
Excellent quality, 12K stars, and a 26 use-case fit score.
$ npx skills add future-architect/vulsA static analysis security vulnerability scanner for Ruby on Rails applications
Excellent quality, 7.2K stars, and a 25 use-case fit score.
$ npx skills add presidentbeef/brakemanNuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Excellent quality, 29K stars, and a 24 use-case fit score.
$ npx skills add projectdiscovery/nucleiLynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Excellent quality, 16K stars, and a 23 use-case fit score.
$ npx skills add CISOfy/lynisA vulnerability scanner for container images and filesystems
Excellent quality, 12K stars, and a 23 use-case fit score.
$ npx skills add anchore/grypeOpen Policy Agent (OPA) is an open source, general-purpose policy engine.
Excellent quality, 12K stars, and a 23 use-case fit score.
$ npx skills add open-policy-agent/opaUnified Policy as Code
Excellent quality, 7.8K stars, and a 22 use-case fit score.
$ npx skills add kyverno/kyvernoTrail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
Excellent quality, 5.7K stars, and a 22 use-case fit score.
$ npx skills add trailofbits/skillsDeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
Excellent quality, 6.4K stars, and a 22 use-case fit score.
$ npx skills add lintsinghua/DeepAuditCode security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Excellent quality, 2.7K stars, and a 21 use-case fit score.
$ npx skills add Bearer/bearerTest your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
Excellent quality, 22K stars, and a 20 use-case fit score.
$ npx skills add promptfoo/promptfoo337 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 330+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commercial & finance, and your daily productivity skills.
Excellent quality, 18K stars, and a 20 use-case fit score.
$ npx skills add alirezarezvani/claude-skills🏛️ 三省六部制 · OpenClaw Multi-Agent Orchestration System — 9 specialized AI agents with real-time dashboard, model config, and full audit trails
Excellent quality, 16K stars, and a 20 use-case fit score.
$ npx skills add cft0808/edictWazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Excellent quality, 16K stars, and a 20 use-case fit score.
$ npx skills add wazuh/wazuhLightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Excellent quality, 15K stars, and a 20 use-case fit score.
$ npx skills add semgrep/semgrepThe ZAP by Checkmarx Core project
Excellent quality, 15K stars, and a 20 use-case fit score.
$ npx skills add zaproxy/zaproxyVulnerability Static Analysis for Containers
Excellent quality, 11K stars, and a 20 use-case fit score.
$ npx skills add quay/clairThe recursive internet scanner for hackers. 🧡
Excellent quality, 9.9K stars, and a 19 use-case fit score.
$ npx skills add blacklanternsecurity/bbotWPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com
Excellent quality, 9.6K stars, and a 19 use-case fit score.
$ npx skills add wpscanteam/wpscanA Kubernetes controller and tool for one-way encrypted Secrets
Excellent quality, 9.1K stars, and a 19 use-case fit score.
$ npx skills add bitnami-labs/sealed-secretsA powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
Excellent quality, 8.9K stars, and a 19 use-case fit score.
$ npx skills add We5ter/Scanners-BoxCloudNativePG is a comprehensive platform designed to seamlessly manage PostgreSQL databases within Kubernetes environments, covering the entire operational lifecycle from initial deployment to ongoing maintenance
Excellent quality, 8.8K stars, and a 19 use-case fit score.
$ npx skills add cloudnative-pg/cloudnative-pgPrevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Excellent quality, 8.8K stars, and a 19 use-case fit score.
$ npx skills add bridgecrewio/checkovOneForAll是一款功能强大的子域收集工具
Excellent quality, 9.8K stars, and a 19 use-case fit score.
$ npx skills add shmilylty/OneForAllBandit is a tool designed to find common security issues in Python code.
Excellent quality, 8.1K stars, and a 19 use-case fit score.
$ npx skills add PyCQA/banditAgent skill that generates rich HTML pages or slide decks for diagrams, diff reviews, plan audits, data tables, and project recaps
Excellent quality, 8.7K stars, and a 19 use-case fit score.
$ npx skills add nicobailon/visual-explainerValidate and visualize dependencies. Your rules. JavaScript, TypeScript, CoffeeScript. ES6, CommonJS, AMD.
Excellent quality, 6.8K stars, and a 19 use-case fit score.
$ npx skills add sverweij/dependency-cruiserData pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from AWS, Azure, GCP, and 70+ cloud and SaaS sources.
Excellent quality, 6.4K stars, and a 19 use-case fit score.
$ npx skills add cloudquery/cloudqueryTfsec is now part of Trivy
Excellent quality, 7.0K stars, and a 19 use-case fit score.
$ npx skills add aquasecurity/tfsecRules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources
Excellent quality, 6.0K stars, and a 19 use-case fit score.
$ npx skills add cloud-custodian/cloud-custodianSelection method
OpenAgentSkill scores each candidate against the workflow keywords, then balances fit with GitHub stars, quality signals, trust profile, maintenance freshness, and whether there is a clear install path.
The ranking combines workflow fit, quality score, trust profile, GitHub adoption, maintenance freshness, and whether a clear install path exists.
No. Treat the list as a shortlist, open the skill detail page, inspect the repository and license, then test the install command in a sandbox workflow.
Yes. Use /api/skills/search with the related task or /api/agent/rankings?slug=best-security-compliance-skills to fetch ranked skill data.