Skill4Agent
Skill4Agent
All SkillsSearchTools
|
Explore
Skill4Agent
Skill4Agent

AI Agent Skills Directory with categorization, English/Chinese translation, and script security checks.

Sitemap

  • Home
  • All Skills
  • Search
  • Tools

About

  • About Us
  • Disclaimer
  • Copyright

Help

  • FAQ
  • Privacy
  • Terms
Contact Us:osulivan147@qq.com

© 2026 Skill4Agent. All rights reserved.

All Skills

Total 55,220 skills, Security & Compliance has 2170 skills

Categories

Showing 12 of 2170 skills

Per page
Downloads
Sort
Security & Compliancetartinerlabs/skills

deps

Use when hardening npm supply chain, pinning dependency versions, adding .npmrc security flags, or setting up Renovate and audit workflows. Locks down install-time scripts, registries, version ranges, and CI checks.

🇺🇸|EnglishTranslated
12
Security & Complianceyaklang/hack-skills

prototype-pollution

Prototype pollution testing for JavaScript stacks. Use when user input is merged into objects (query parsers, JSON bodies, deep assign), when configuring libraries via untrusted keys, or when hunting RCE gadgets via polluted Object.prototype in Node or the browser.

🇨🇳|ChineseTranslated
12
Security & Complianceyaklang/hack-skills

api-authorization-and-bola

API authorization and BOLA testing playbook. Use when APIs expose object identifiers, nested resources, hidden writable fields, or weak function-level authorization.

🇺🇸|EnglishTranslated
12
Security & Complianceyaklang/hack-skills

subdomain-takeover

Subdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointing to deprovisioned cloud resources, expired third-party services, or unclaimed SaaS tenants that an attacker can register to serve content under the victim's domain.

🇺🇸|EnglishTranslated
12
Security & Complianceyaklang/hack-skills

csp-bypass-advanced

Advanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy weaknesses, trusted endpoint abuse, nonce leakage, or exfiltration channels that CSP cannot block.

🇺🇸|EnglishTranslated
12
Security & Complianceyaklang/hack-skills

code-obfuscation-deobfuscation

Code obfuscation analysis and deobfuscation playbook. Use when reversing binaries protected by junk code, opaque predicates, self-modifying code, control flow flattening, VM protection, or string encryption.

🇺🇸|EnglishTranslated
12
Security & Complianceyaklang/hack-skills

email-header-injection

Email header injection and spoofing playbook. Use when testing contact forms, email APIs, password reset flows, or any feature that constructs SMTP messages with user-controlled fields. Covers CRLF injection in headers, SPF/DKIM/DMARC bypass, and phishing amplification.

🇺🇸|EnglishTranslated
12
Security & Complianceyaklang/hack-skills

windows-privilege-escalation

Windows local privilege escalation playbook. Use when you have low-privilege shell access on Windows and need to escalate via token abuse, Potato exploits, service misconfigurations, DLL hijacking, UAC bypass, or registry autoruns.

🇺🇸|EnglishTranslated
12
Security & Complianceyaklang/hack-skills

network-protocol-attacks

Network protocol attack playbook. Use when exploiting layer 2/3 protocols including ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, STP manipulation, DNS spoofing, IPv6 attacks, and IDS/IPS evasion.

🇺🇸|EnglishTranslated
12
Security & Complianceyaklang/hack-skills

heap-exploitation

Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging tcache/fastbin/unsortedbin attacks for arbitrary write or code execution.

🇺🇸|EnglishTranslated
12
Security & Complianceyaklang/hack-skills

macos-security-bypass

macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbox, code signing, or entitlement-based protections during authorized red team or pentest engagements.

🇺🇸|EnglishTranslated
12
Security & Complianceborghei/claude-skills

red-team

This skill should be used when the user asks to "plan a red team engagement", "scope a penetration test", "design a security assessment methodology", "create rules of engagement", or "plan an adversary simulation".

🇺🇸|EnglishTranslated
12
1 scripts/Checked
1...122123124125126...181
Page