Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
21 results
Skill

cybersecurity

OSS-only security for OWASP Top 10, pentest, vuln testing (XSS, SSRF, CSRF, business-logic, Host header), threat modeling (STRIDE, ATT&CK), Sigma rules, SAST, code audit, AI/LLM red-team, or replacing

by secondskyskills.sh
Not rated yet
Free
Skill

owasp-top-10

OWASP Top 10 security vulnerabilities with detection and remediation patterns. Use when conducting security audits, implementing secure coding practices, or reviewing code for common security vulnerab

by nickcrewskills.sh
Not rated yet
Free
Skill

security-practices

OWASP Top 10, authentication, and secure coding practices

by miles990skills.sh
Not rated yet
Free
Skill

exploiting-prototype-pollution-in-javascript

Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection into

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-runtime-application-self-protection

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy confi

by mukul975skills.sh
Not rated yet
Free
Skill

performing-content-security-policy-bypass

Analyze Content-Security-Policy headers and bypass them to achieve cross-site scripting by exploiting unsafe-inline/unsafe-eval, whitelisted JSONP endpoints, base-uri and form-action gaps, and nonce/h

by mukul975skills.sh
Not rated yet
Free
Skill

performing-web-application-firewall-bypass

Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, and payload obfuscation to smuggle SQL injection, XSS, and other exploit payloads pa

by mukul975skills.sh
Not rated yet
Free
Skill

testing-for-xss-vulnerabilities-with-burpsuite

Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.

by mukul975skills.sh
Not rated yet
Free
Skill

testing-for-xss-vulnerabilities

Tests web applications for reflected, stored, and DOM-based Cross-Site Scripting by injecting JavaScript payloads with Burp Suite (XSS extensions, Active Scan++) and browser tools, then bypassing sani

by mukul975skills.sh
Not rated yet
Free
Skill

security-best-practices

Implement security best practices for web applications and infrastructure. Use when securing APIs, preventing common vulnerabilities, or implementing security policies. Handles HTTPS, CORS, XSS, SQL I

by aiskillstoreskills.sh
Not rated yet
Free
Skill

go-security

Use when writing, reviewing, or auditing Go code for security. Covers input validation, SQL injection prevention, path traversal, secrets management, cryptography, HTTP security headers, and dependenc

by saisudhir14skills.sh
Not rated yet
Free
Skill

xss-detection

Detect, exploit, and prevent Cross-Site Scripting (XSS) vulnerabilities in web applications. Use when tasks involve testing for reflected, stored, or DOM-based XSS, building XSS payloads, bypassing WA

by terminalskillsskills.sh
Not rated yet
Free
Skill

web

Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用。

by MuWindsGitHub
Not rated yet
Free
Skill

injection-patterns

Find SQL injection, XSS, SSTI, command injection, SSRF, and path traversal

by kaminocorpGitHub
Not rated yet
Free
Skill

web-exploitation

SQL injection, XSS, CSRF, LFI/RFI, command injection.

by harezadmmGitHub
Not rated yet
Free
Skill

web-exploitation

SQL injection, XSS, CSRF, LFI/RFI, command injection.

by harezadmmGitHub
Not rated yet
Free
Skill

web-exploitation

SQL injection, XSS, CSRF, LFI/RFI, command injection.

by harezadmmGitHub
Not rated yet
Free
Skill

hunt-dom

Hunt client-side DOM vulnerabilities — DOM Clobbering (overwrite JS globals via HTML injection), PostMessage hijacking (missing origin check), Service Worker abuse (intercept requests from same-origin

by uphiagoGitHub
Not rated yet
Free
Skill

content-security-policy-headers

Use when designing or fixing a Content Security Policy on a real site, choosing between nonce-based and hash-based CSP, adding strict-dynamic, debugging "Refused to execute inline script" errors, depl

by curiositechGitHub
Not rated yet
Free
Skill

source-code-security-review

Perform a systematic white-box security review of web application source code to find exploitable vulnerabilities. Use this skill when: you have authorized access to an application's source code and n

by bookforge-aiGitHub
Not rated yet
Free
Skill

owasp-security

Use when reviewing code for security vulnerabilities, threat-modelling a new feature, implementing authentication or authorization, handling user input, hardening dependencies or CI/CD against softwar

by jacob-balslevGitHub
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.