技能目录

为 AI Agent 发现可复用技能。

按任务搜索真实的 GitHub 技能,并在使用前查看 Stars、信任、审计、分类和安装路径。

每个推荐都保留与其仓库、审计和安装路径的明确关联。

搜索结果: owasp

英文目录

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

13K
Stars
87/100
信任
分类: development审计

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

5.3K
Stars
85/100
信任
分类: security审计

AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.

4.6K
Stars
85/100
信任
分类: agent-frameworks审计

Adversarial code review that breaks the self-review monoculture. Use when you want a genuinely critical review of recent changes, before merging a PR, or when you suspect Claude is being too agreeable about code quality. Forces perspective shifts through hostile reviewer personas that catch blind spots the author's mental model shares with the reviewer.

25K
Stars
77/100
信任
分类: engineering / code quality审计

Claude Code skill for OWASP security best practices (2025-2026). Includes Top 10:2025, ASVS 5.0, Agentic AI security, and 20+ language-specific security quirks.

328
Stars
72/100
信任
分类: development审计

The Firmware Security Testing Methodology (FSTM) is composed of nine stages tailored to enable security researchers, software developers, consultants, and Information Security professionals with conducting firmware security assessments.

472
Stars
70/100
信任
分类: robotics-iot审计

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

434
Stars
69/100
信任
分类: security审计

🇰🇷 400+ Korean AI Coding Agent Skills — Claude Code, Gemini CLI, Codex, Cursor 스킬을 기능별로 모은 큐레이션

26
Stars
64/100
信任
分类: utility审计

Black-box, open-source red-team testing for AI agents. Point Argus at any HTTP, gRPC, or browser-using agent endpoint, run 500+ adversarial probes (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, TAP/PAIR/GCG), get LLM-judged findings as SARIF, gate CI via GitHub Code Scanning. Ships with CLI + GH Action.

154
Stars
65/100
信任
分类: github-automation审计

Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).

140
Stars
70/100
信任
分类: devops审计

Đây là bộ SKILL, RULES, COMMANDS do Anh Tester xây dựng dành riêng cho cộng đồng Tester để thiết lập AI Agent trên Claude Code hỗ trợ kiểm thử phần mềm.

42
Stars
69/100
信任
分类: utility审计

Hands-on DevSecOps project deploying a Tetris game on AWS EKS. Features Jenkins CI/CD, ArgoCD GitOps, Terraform-based IaC, Kubernetes, Docker, Trivy vulnerability scanning, OWASP Dependency-Check, and SonarQube for code quality.

108
Stars
68/100
信任
分类: devops审计