Skill4Agent
Skill4Agent
All SkillsSearchTools
|
Explore
Skill4Agent
Skill4Agent

AI Agent Skills Directory with categorization, English/Chinese translation, and script security checks.

Sitemap

  • Home
  • All Skills
  • Search
  • Tools

About

  • About Us
  • Disclaimer
  • Copyright

Help

  • FAQ
  • Privacy
  • Terms
Contact Us:osulivan147@qq.com

© 2026 Skill4Agent. All rights reserved.

All Skills

Total 50,503 skills, Security & Compliance has 1972 skills

Categories

Showing 12 of 1972 skills

Per page
Downloads
Sort
Security & Compliance0xlayerghost/solidity-age...

solidity-audit

Security audit and code review checklist. Covers 30+ vulnerability types with real-world exploit cases (2021-2026) and EVMbench Code4rena patterns. Use when conducting security audits, code reviews, or pre-deployment security assessments.

🇺🇸|EnglishTranslated
9
Security & Compliance0xshe/php-code-audit-skil...

php-crlf-audit

PHP Web source code CRLF/response splitting audit tool. Identifies user input that enters HTTP response headers, analyzes filtering and encoding of newlines/control characters, and outputs severity ratings, PoCs and fix suggestions (omission is prohibited).

🇨🇳|ChineseTranslated
9
Security & Compliancejoellewis/finance_skills

privacy-data-security

Design and operate privacy and data security programs for SEC-registered firms under Reg S-P, Reg S-ID, and SEC cybersecurity expectations. Use when the user asks about privacy notices, the Safeguards Rule, identity theft prevention programs, breach notification obligations, vendor security due diligence, incident response planning, data classification, or state privacy law compliance. Also trigger when users mention 'customer data was exposed', 'do we need to notify clients of a breach', 'cybersecurity exam prep', 'cloud vendor risk assessment', 'encrypting client data', 'BYOD security policy', 'Red Flags Rule', 'NY DFS 500 requirements', or ask how to handle a cybersecurity incident.

🇺🇸|EnglishTranslated
9
Security & Compliancemembranedev/application-s...

falcosecurity

Falcosecurity integration. Manage data, records, and automate workflows. Use when the user wants to interact with Falcosecurity data.

🇺🇸|EnglishTranslated
9
Security & Compliancearadotso/trending-skills

metatron-pentest-assistant

AI-powered penetration testing assistant using local LLM (metatron-qwen via Ollama) on Parrot OS Linux

🇺🇸|EnglishTranslated
9
Security & Compliancejsonwebtoken/jwt-skills

jwt-validate

Verify and validate JSON Web Tokens (JWTs) by checking signatures, expiration, claims, and structure. Use when the user wants to verify, validate, or check a JWT — e.g. "verify this token", "is this JWT valid", "check the signature", "validate this token against my JWKS", "is this token expired". Supports HMAC, RSA, and ECDSA with secrets, PEM keys, or JWKS endpoints.

🇺🇸|EnglishTranslated
9
Security & Compliancemembranedev/application-s...

nowsecure

NowSecure integration. Manage data, records, and automate workflows. Use when the user wants to interact with NowSecure data.

🇺🇸|EnglishTranslated
9
Security & Complianceyaklang/hack-skills

xslt-injection

XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. Use when user-controlled XSLT/stylesheet input or transform endpoints are in scope.

🇺🇸|EnglishTranslated
9
Security & Complianceyaklang/hack-skills

clickjacking

Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.

🇺🇸|EnglishTranslated
9
Security & Complianceyaklang/hack-skills

tunneling-and-pivoting

Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.

🇺🇸|EnglishTranslated
9
Security & Complianceyaklang/hack-skills

subdomain-takeover

Subdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointing to deprovisioned cloud resources, expired third-party services, or unclaimed SaaS tenants that an attacker can register to serve content under the victim's domain.

🇺🇸|EnglishTranslated
9
Security & Complianceyaklang/hack-skills

dangling-markup-injection

Dangling markup injection playbook. Use when HTML injection is possible but JavaScript execution is blocked (CSP, sanitizer strips event handlers, WAF blocks script tags) — exfiltrate CSRF tokens, session data, and page content by injecting unclosed HTML tags that capture subsequent page content.

🇺🇸|EnglishTranslated
9
1...7374757677...165
Page