Skill4Agent
Skill4Agent
All SkillsSearchTools
|
Explore
Skill4Agent
Skill4Agent

AI Agent Skills Directory with categorization, English/Chinese translation, and script security checks.

Sitemap

  • Home
  • All Skills
  • Search
  • Tools

About

  • About Us
  • Disclaimer
  • Copyright

Help

  • FAQ
  • Privacy
  • Terms
Contact Us:osulivan147@qq.com

© 2026 Skill4Agent. All rights reserved.

All Skills

Total 54,344 skills, Security & Compliance has 2130 skills

Categories

Showing 12 of 2130 skills

Per page
Downloads
Sort
Security & Complianceyaklang/hack-skills

browser-exploitation-v8

Browser and V8 exploitation playbook. Use when exploiting JavaScript engine vulnerabilities including JIT type confusion, incorrect bounds elimination, and V8 sandbox bypass to achieve renderer RCE and sandbox escape in Chrome/Chromium.

🇺🇸|EnglishTranslated
17
Security & Complianceyaklang/hack-skills

format-string-exploitation

Format string exploitation playbook. Use when printf-family functions receive user-controlled format strings, enabling arbitrary stack reads (%p/%s), arbitrary memory writes (%n/%hn/%hhn), GOT/hook overwrites, and canary/libc/PIE leaks.

🇺🇸|EnglishTranslated
17
Security & Complianceyaklang/hack-skills

macos-security-bypass

macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbox, code signing, or entitlement-based protections during authorized red team or pentest engagements.

🇺🇸|EnglishTranslated
17
Security & Complianceyaklang/hack-skills

http-host-header-attacks

HTTP Host header injection and routing abuse playbook. Use when the application trusts the Host header for generating URLs, routing requests, or access control — enabling password reset poisoning, web cache poisoning, SSRF via routing, and virtual host bypass.

🇺🇸|EnglishTranslated
17
Security & Compliancegithub/awesome-copilot

agent-supply-chain

Verify supply chain integrity for AI agent plugins, tools, and dependencies. Use this skill when: - Generating SHA-256 integrity manifests for agent plugins or tool packages - Verifying that installed plugins match their published manifests - Detecting tampered, modified, or untracked files in agent tool directories - Auditing dependency pinning and version policies for agent components - Building provenance chains for agent plugin promotion (dev → staging → production) - Any request like "verify plugin integrity", "generate manifest", "check supply chain", or "sign this plugin"

🇺🇸|EnglishTranslated
17
Security & Complianceascend/agent-skills

skill-auditor

Comprehensive security auditor for AI agent skills, prompts, and instructions. Checks for typosquatting, dangerous permissions, prompt injection, supply chain risks, and data exfiltration patterns — before you use any agent or skill.

🇺🇸|EnglishTranslated
17
Security & Compliancedavincidreams/agent-team-...

threat-modeling

Threat modeling methodologies (STRIDE, PASTA, LINDDUN), attack tree analysis, common attack patterns (OWASP Top 10, CWE), risk assessment frameworks, and security architecture patterns

🇺🇸|EnglishTranslated
17
Security & Compliancefactory-ai/factory-plugin...

security-review

Scan code changes for security vulnerabilities using STRIDE threat modeling, validate findings for exploitability, and output structured results for downstream patch generation. Supports PR review, scheduled scans, and full repository audits.

🇺🇸|EnglishTranslated
17
Security & Complianceruvnet/ruflo

pii-detect

Detect and flag personally identifiable information (PII) in text, code, and configurations

🇺🇸|EnglishTranslated
17
Security & Compliancealirezarezvani/claude-ski...

env-secrets-manager

Env & Secrets Manager

🇺🇸|EnglishTranslated
17
1 scripts/Attention
Security & Compliancesnyk/studio-recipes

sbom-analyzer

Software Bill of Materials (SBOM) security analysis for vulnerability assessment and third-party risk management. Validates SBOMs from vendors or generates SBOMs for internal projects. Use this skill when: - User asks to analyze an SBOM file - User mentions "third-party risk" or "vendor security" - User needs to validate a supplier's SBOM - User wants to check SBOM for vulnerabilities - User asks about CycloneDX or SPDX formats

🇺🇸|EnglishTranslated
17
Security & Compliancejoellewis/finance_skills

gips-compliance

Ensure investment firms satisfy CFA Institute GIPS requirements for composite construction, performance calculation, presentation, and verification. Use when the user asks about building composites, time-weighted return calculation, GIPS-compliant presentations, error correction policies, pooled fund reporting, wrap fee or SMA program performance, or GIPS advertising guidelines. Also trigger when users mention 'claiming GIPS compliance', 'composite membership rules', 'terminated portfolio returns', 'gross vs net of fees under GIPS', 'GIPS verification findings', 'can we show this track record to prospects', or ask whether a firm's performance reporting meets GIPS standards.

🇺🇸|EnglishTranslated
17
1...6869707172...178
Page