@skills · Owner
Agent skills by superagent-ai
16 skills indexed from github.com/superagent-ai. Reference any of them in AdaL, Claude Code, Cursor or any coding agent — nothing to install.
- authz-security · Skill · 76 stars
Review application source code for broken authorization — IDOR / Broken Object Level Authorization (OWASP API1), Broken Function Level Authorization (API5)
- ci-cd-security · Skill · 76 stars
Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, n
- crypto-secrets · Skill · 76 stars
Audit application source code and configuration for cryptography and secrets hygiene issues: hardcoded API keys, committed .env files, private keys, weak h
- hacker · Skill · 76 stars
Cursor-native offensive security engagement and exploitability autoresearch orchestrator inspired by offensive-claude. Use for an authorized offensive enga
- infra-security · Skill · 76 stars
Audit Infrastructure-as-Code for security misconfigurations before it ships — Terraform (.tf/.tfvars/.hcl), CloudFormation/SAM (YAML/JSON), Kubernetes & He
- pr-github-ops · Skill · 76 stars
Post Superagent PR security scan findings as inline GitHub pull request review comments using the authenticated gh CLI. Use whenever you need to comment on
- recon-security · Skill · 76 stars
Guide authorized external penetration testing from recon through validation and scoped exploitation using free and open-source tools. Use for domain/IP att
- redteam-autoresearch · Skill · 76 stars
Run a bounded red-teaming autoresearch loop to generate LLM guardrail training data. You (the agent running the skill) are the attacker and the judge: you
- repo-security-posture · Skill · 76 stars
Audit a GitHub repository's security posture and hardening gaps across branch protection, CODEOWNERS, GitHub Actions, publish/release integrity, collaborat
- security-disclosure-triage · Skill · 76 stars
Verify whether an incoming security advisory is a real, disclosable vulnerability in a target repository checkout, and assign an honest severity. Use when
- skill-security · Skill · 76 stars
Audit an AI agent skill for security risks before installing or trusting it. Runs a deterministic scanner (regex patterns, Python AST analysis, source-to-s
- skills · Collection · 76 stars
- skills · Collection · 76 stars
- supply-chain-security · Skill · 76 stars
Review new or changed dependencies for supply-chain compromise before they enter a project — malicious install scripts (preinstall/postinstall), binding.gy
- vulnerability-triage · Skill · 76 stars
Triage inbound vulnerability reports - GitHub Advisories (GHSA/CVE), bug bounty submissions, HackerOne/Bugcrowd/Intigriti exports, or a researcher's issue
- superagent · Skill
Set up Superagent Context Guardrails at coding-agent tool boundaries, configure and safely use the remote MCP server, and manage signed webhooks for findin