Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

143.8K
listings
1
installs
0
reviews
38.7K
publishers
15 results
Skill

owasp-top-10

OWASP Top 10 security vulnerabilities with detection and remediation patterns. Use when conducting security audits, implementing secure coding practices, or reviewing code for common security vulnerab

by nickcrewskills.sh
(0)
0Free
Skill

security-testing

Scans for security vulnerabilities including XSS, SQL injection, CSRF, and auth flaws using OWASP Top 10 methodology. Use when conducting SAST/DAST scans, auditing authentication flows, testing author

by proffesor-for-testingskills.sh
(0)
0Free
Skill

qe-security-testing

Test for security vulnerabilities using OWASP principles. Use when conducting security audits, testing auth, or implementing security practices.

by proffesor-for-testingskills.sh
(0)
0Free
Skill

exploiting-api-injection-vulnerabilities

Tests API parameters, headers, and request bodies for injection flaws — SQL injection, NoSQL injection, OS command injection, LDAP injection, and SSRF — by crafting payloads tailored to the target bac

by mukul975skills.sh
(0)
0Free
Skill

testing-websocket-api-security

Tests WebSocket API implementations for missing upgrade-handshake authentication, Cross-Site WebSocket Hijacking (CSWSH), message injection, insufficient input validation, message-flooding DoS, and in

by mukul975skills.sh
(0)
0Free
Skill

go-security

Use when writing, reviewing, or auditing Go code for security. Covers input validation, SQL injection prevention, path traversal, secrets management, cryptography, HTTP security headers, and dependenc

by saisudhir14skills.sh
(0)
0Free
Skill

xss-detection

Detect, exploit, and prevent Cross-Site Scripting (XSS) vulnerabilities in web applications. Use when tasks involve testing for reflected, stored, or DOM-based XSS, building XSS payloads, bypassing WA

by terminalskillsskills.sh
(0)
0Free
Skill

exploiting-nosql-injection

Test NoSQL query construction for operator, JSON, expression, and query-DSL injection after fingerprinting the database and input context.

by ThanhHai151GitHub
(0)
0Free
Skill

exploit-xxe

XML External Entity (XXE) injection — local file reading via XML parsers, SOAP/WSDL API exploitation, blind out-of-band exfiltration, SVG/DOCX/XLSX upload XXE. Use for any challenge involving XML proc

by IwakishirokoshuGitHub
(0)
0Free
Skill

injection-patterns

Find SQL injection, XSS, SSTI, command injection, SSRF, and path traversal

by kaminocorpGitHub
(0)
0Free
Skill

testing-websocket-api-security

Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket mess

by andycungkrinx91GitHub
(0)
0Free
Skill

defense-evasion

Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.

by PurpleAILABGitHub
(0)
0Free
Skill

defense-evasion

Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.

by 7ShIkI3GitHub
(0)
0Free
Skill

defense-evasion

Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.

by dnzengouGitHub
(0)
0Free
Skill

owasp-security

Use when reviewing code for security vulnerabilities, threat-modelling a new feature, implementing authentication or authorization, handling user input, hardening dependencies or CI/CD against softwar

by jacob-balslevGitHub
(0)
0Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.