trailofbits/skills-curated.
31 skills★ 459View on GitHub ↗
- 50/100
ffuf-web-fuzzing
>-
- 100/100
ghidra-headless
>-
- 100/100
grilling
>-
- 100/100
handoff
>-
- 100/100
humanizer
|
- 80/100
last30days
"Researches a topic from the last 30 days on Reddit, X, and the web. Surfaces real community discussions with engagement metrics and synthesizes findings into actionable insights. Use when the user wants to know what people are saying about a topic right now."
- 100/100
openai-cloudflare-deploy
Deploy applications and infrastructure to Cloudflare using Workers, Pages, and related platform
- 100/100
openai-develop-web-game
'Use when the agent is building or iterating on a web game (HTML/JS) and needs a reliable
- 100/100
openai-doc
Use when the task involves reading, creating, or editing `.docx` documents, especially when
- 100/100
openai-gh-address-comments
Help address review/issue comments on the open GitHub PR for the current branch using gh
- 100/100
openai-gh-fix-ci
Use when a user asks to debug or fix failing GitHub PR checks that run in GitHub Actions;
- 100/100
openai-jupyter-notebook
Use when the user asks to create, scaffold, or edit Jupyter notebooks (`.ipynb`) for experiments,
- 100/100
openai-netlify-deploy
Deploy web projects to Netlify using the Netlify CLI (`npx netlify`). Use when the user asks
- 100/100
openai-pdf
Use when tasks involve reading, creating, or reviewing PDF files where rendering and layout
- 100/100
openai-playwright
Use when the task requires automating a real browser from the terminal (navigation, form
- 100/100
openai-screenshot
Use when the user explicitly asks for a desktop or system screenshot (full screen, specific
- 100/100
openai-security-best-practices
Perform language and framework specific security best-practice reviews and suggest improvements.
- 100/100
openai-security-ownership-map
'Analyze git repositories to build a security ownership topology (people-to-file), compute
- 100/100
openai-security-threat-model
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities,
- 100/100
openai-sentry
Use when the user asks to inspect Sentry issues or events, summarize recent production errors,
- 100/100
openai-spreadsheet
Use when tasks involve creating, editing, analyzing, or formatting spreadsheets (`.xlsx`,
- 100/100
openai-yeet
Use only when the user explicitly asks to stage, commit, push, and open a GitHub pull request
- 100/100
planning-with-files
>-
- 100/100
react-pdf
- Generating PDF documents (reports, invoices, resumes, forms, certificates) - Creating PDFs that need complex layouts (multi-column, grids, cards) - Building PDFs with inline SVG graphics, charts, or icons - Producing documents with custom Google Fonts or emoji - Any PDF task where flexbox layout is easier than absolute coordinate math
- 100/100
scv-scan
"Audits Solidity codebases for smart contract vulnerabilities using a four-phase workflow (cheatsheet loading, codebase sweep, deep validation, reporting) covering 36 vulnerability classes. Use when auditing Solidity contracts for security issues, performing smart contract vulnerability scans, or reviewing Solidity code for common exploit patterns."
- 80/100
security-awareness
>
- 100/100
skill-extractor
>-
- 100/100
teach
>-
- 100/100
wooyun-legacy
>-
- 100/100
writing-great-skills
>-
- 100/100
x-research
>