Leaderboard
Scored on public signals; components with none are listed as Unranked · Formula
Component
Domain
Vertical
| Rank | Score | Component | Description | Evidence | Last commit | Install |
|---|---|---|---|---|---|---|
| 1 | 99.099 | trail-of-bits-security-skillsskill · ai-agents | A very professional collection of over a dozen security-focused skills for code auditing and vulnerability detection. Includes skills for static… | 6,939 stars · 597 forks | No one-command install · Source | |
| 2 | Unranked | active-directory-attacksskill · other | This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound… | No signals yet | No commit datelisted | armory install active-directory-attacks --cli claude |
| 3 | Unranked | api-fuzzing-for-bug-bountyskill · back-end | This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API… | No signals yet | No commit datelisted | armory install api-fuzzing-for-bug-bounty --cli claude |
| 4 | Unranked | api-integration-specialistskill · back-end | Expert in integrating third-party APIs with proper authentication, error handling, rate limiting, and retry logic. Use when integrating REST APIs… | No signals yet | No commit datelisted | armory install api-integration-specialist --cli claude |
| 5 | Unranked | api-security-best-practicesskill · front-end | Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API… | No signals yet | No commit datelisted | armory install api-security-best-practices --cli claude |
| 6 | Unranked | api-security-testingskill · back-end | API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best… | No signals yet | No commit datelisted | armory install api-security-testing --cli claude |
| 7 | Unranked | aws-penetration-testingskill · devops | This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege… | No signals yet | No commit datelisted | armory install aws-penetration-testing --cli claude |
| 8 | Unranked | best-practicesskill · other | Apply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit"… | No signals yet | No commit datelisted | armory install best-practices --cli claude |
| 9 | Unranked | broken-authentication-testingskill · auth | This skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform… | No signals yet | No commit datelisted | armory install broken-authentication-testing --cli claude |
| 10 | Unranked | burp-suite-web-application-testingskill · other | This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web… | No signals yet | No commit datelisted | armory install burp-suite-web-application-testing --cli claude |
| 11 | Unranked | clerk-authskill · auth | Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync Use when: adding authentication, clerk auth, user… | No signals yet | No commit datelisted | armory install clerk-auth --cli claude |
| 12 | Unranked | cloud-penetration-testingskill · devops | This skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud… | No signals yet | No commit datelisted | armory install cloud-penetration-testing --cli claude |
| 13 | Unranked | code-review-2skill · front-end | Perform code reviews following Sentry engineering practices. Use when reviewing pull requests, examining code changes, or providing feedback on code… | No signals yet | No commit datelisted | armory install code-review-2 --cli claude |
| 14 | Unranked | code-review-checklistskill · other | Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability | No signals yet | No commit datelisted | armory install code-review-checklist --cli claude |
| 15 | Unranked | code-reviewer-2skill · github-vcs | Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go. Includes automated code analysis, best practice checking… | No signals yet | No commit datelisted | armory install code-reviewer-2 --cli claude |
| 16 | Unranked | computer-use-agentsskill · ai-agents | Build AI agents that interact with computers like humans do - viewing screens, moving cursors, clicking buttons, and typing text. Covers Anthropic's… | No signals yet | No commit datelisted | armory install computer-use-agents --cli claude |
| 17 | Unranked | cosmic-databaseskill · database | Access COSMIC cancer mutation database. Query somatic mutations, Cancer Gene Census, mutational signatures, gene fusions, for cancer research and… | No signals yet | No commit datelisted | armory install cosmic-database --cli claude |
| 18 | Unranked | cross-site-scripting-and-html-injection-testingskill · database | This skill should be used when the user asks to "test for XSS vulnerabilities", "perform cross-site scripting attacks", "identify HTML injection… | No signals yet | No commit datelisted | armory install cross-site-scripting-and-html-injection-testing --cli claude |
| 19 | Unranked | devops-iac-engineerskill · devops | Implements infrastructure as code using Terraform, Kubernetes, and cloud platforms. Designs scalable architectures, CI/CD pipelines, and observability… | No signals yet | No commit datelisted | armory install devops-iac-engineer --cli claude |
| 20 | Unranked | django-securityskill · back-end | Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment… | No signals yet | No commit datelisted | armory install django-security --cli claude |
| 21 | Unranked | django-verificationskill · back-end | "Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or… | No signals yet | No commit datelisted | armory install django-verification --cli claude |
| 22 | Unranked | docker-expertskill · devops | Docker containerization expert with deep knowledge of multi-stage builds, image optimization, container security, Docker Compose orchestration, and… | No signals yet | No commit datelisted | armory install docker-expert --cli claude |
| 23 | Unranked | docker-patternsskill · devops | Docker and Docker Compose patterns for local development, container security, networking, volume strategies, and multi-service orchestration. | No signals yet | No commit datelisted | armory install docker-patterns --cli claude |
| 24 | Unranked | enterprise-agent-opsskill · observability | Operate long-lived agent workloads with observability, security boundaries, and lifecycle management. | No signals yet | No commit datelisted | armory install enterprise-agent-ops --cli claude |
| 25 | Unranked | ethical-hacking-methodologyskill · other | This skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance"… | No signals yet | No commit datelisted | armory install ethical-hacking-methodology --cli claude |
| 26 | Unranked | fastapi-endpointskill · back-end | Plan and build production-ready FastAPI endpoints with async SQLAlchemy, Pydantic v2 models, dependency injection for auth, and pytest tests. Uses… | No signals yet | No commit datelisted | armory install fastapi-endpoint --cli claude |
| 27 | Unranked | fastapi-patternsskill · back-end | FastAPI patterns for async APIs, dependency injection, Pydantic request and response models, OpenAPI docs, tests, security, and production readiness. | No signals yet | No commit datelisted | armory install fastapi-patterns --cli claude |
| 28 | Unranked | fastmcp-serverskill · back-end | Complete guide for building MCP servers with FastMCP 3.0 - tools, resources, authentication, providers, middleware, and deployment. Use when creating… | No signals yet | No commit datelisted | armory install fastmcp-server --cli claude |
| 29 | Unranked | find-bugsskill · other | Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or… | No signals yet | No commit datelisted | armory install find-bugs --cli claude |
| 30 | Unranked | firebaseskill · back-end | Firebase gives you a complete backend in minutes - auth, database, storage, functions, hosting. But the ease of setup hides real complexity. Security… | No signals yet | No commit datelisted | armory install firebase --cli claude |
| 31 | Unranked | flutter-dart-code-reviewskill · other | Library-agnostic Flutter/Dart code review checklist covering widget best practices, state management patterns (BLoC, Riverpod, Provider, GetX, MobX… | No signals yet | No commit datelisted | armory install flutter-dart-code-review --cli claude |
| 32 | Unranked | github-actions-creatorskill · devops | Use when the user wants to create, generate, or set up a GitHub Actions workflow. Handles CI/CD pipelines, testing, deployment, linting, security… | No signals yet | No commit datelisted | armory install github-actions-creator --cli claude |
| 33 | Unranked | github-opsskill · github-vcs | GitHub repository operations, automation, and management. Issue triage, PR management, CI/CD operations, release management, and security monitoring… | No signals yet | No commit datelisted | armory install github-ops --cli claude |
| 34 | Unranked | gke-basicsskill · devops | Plans, creates, and configures production-ready Google Kubernetes Engine (GKE) clusters using the golden path Autopilot configuration. Covers… | No signals yet | No commit datelisted | armory install gke-basics --cli claude |
| 35 | Unranked | google-cloud-networking-observabilityskill · observability | Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics. Use when investigating VPC Flow Logs, NAT, firewall, or… | No signals yet | No commit datelisted | armory install google-cloud-networking-observability --cli claude |
| 36 | Unranked | google-cloud-waf-securityskill · other | Generates security-focused guidance for Google Cloud workloads based on the Google Cloud Well-Architected Framework (WAF). Use to evaluate a workload… | No signals yet | No commit datelisted | armory install google-cloud-waf-security --cli claude |
| 37 | Unranked | graphql-architect-2skill · front-end | Master modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and… | No signals yet | No commit datelisted | armory install graphql-architect-2 --cli claude |
| 38 | Unranked | homelab-network-readinessskill · other | Readiness checklist for homelab VLAN segmentation, local DNS filtering, and WireGuard-style remote access before changing router, firewall, DHCP, or… | No signals yet | No commit datelisted | armory install homelab-network-readiness --cli claude |
| 39 | Unranked | homelab-vlan-segmentationskill · back-end | Segmenting home networks into VLANs for IoT, guest, trusted, and server traffic using UniFi, pfSense/OPNsense, and MikroTik — including switch trunk… | No signals yet | No commit datelisted | armory install homelab-vlan-segmentation --cli claude |
| 40 | Unranked | idor-vulnerability-testingskill · auth | This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access… | No signals yet | No commit datelisted | armory install idor-vulnerability-testing --cli claude |
| 41 | Unranked | information-security-manager-iso27001skill · front-end | Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies. Provides ISMS… | No signals yet | No commit datelisted | armory install information-security-manager-iso27001 --cli claude |
| 42 | Unranked | kotlin-ktor-patternsskill · back-end | Ktor server patterns including routing DSL, plugins, authentication, Koin DI, kotlinx.serialization, WebSockets, and testApplication testing. | No signals yet | No commit datelisted | armory install kotlin-ktor-patterns --cli claude |
| 43 | Unranked | laravel-expertskill · other | Senior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security… | No signals yet | No commit datelisted | armory install laravel-expert --cli claude |
| 44 | Unranked | laravel-securityskill · auth | Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment. | No signals yet | No commit datelisted | armory install laravel-security --cli claude |
| 45 | Unranked | laravel-verificationskill · devops | "Verification loop for Laravel projects: env checks, linting, static analysis, tests with coverage, security scans, and deployment readiness." | No signals yet | No commit datelisted | armory install laravel-verification --cli claude |
| 46 | Unranked | metasploit-frameworkskill · other | This skill should be used when the user asks to "use Metasploit for penetration testing", "exploit vulnerabilities with msfconsole", "create payloads… | No signals yet | No commit datelisted | armory install metasploit-framework --cli claude |
| 47 | Unranked | nestjs-expertskill · auth | Nest.js framework expert specializing in module architecture, dependency injection, middleware, guards, interceptors, testing with Jest/Supertest… | No signals yet | No commit datelisted | armory install nestjs-expert --cli claude |
| 48 | Unranked | network-101skill · back-end | This skill should be used when the user asks to "set up a web server", "configure HTTP or HTTPS", "perform SNMP enumeration", "configure SMB shares"… | No signals yet | No commit datelisted | armory install network-101 --cli claude |
| 49 | Unranked | network-config-validationskill · devops | Pre-deployment checks for router and switch configuration, including dangerous commands, duplicate addresses, subnet overlaps, stale references… | No signals yet | No commit datelisted | armory install network-config-validation --cli claude |
| 50 | Unranked | nextjs-supabase-authskill · front-end | Expert integration of Supabase Auth with Next.js App Router Use when: supabase auth next, authentication next.js, login supabase, auth middleware… | No signals yet | No commit datelisted | armory install nextjs-supabase-auth --cli claude |
| 51 | Unranked | nodejs-best-practicesskill · back-end | Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying. | No signals yet | No commit datelisted | armory install nodejs-best-practices --cli claude |
| 52 | Unranked | pentest-checklistskill · other | This skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration… | No signals yet | No commit datelisted | armory install pentest-checklist --cli claude |
| 53 | Unranked | pentest-commandsskill · other | This skill should be used when the user asks to "run pentest commands", "scan with nmap", "use metasploit exploits", "crack passwords with hydra or… | No signals yet | No commit datelisted | armory install pentest-commands --cli claude |
| 54 | Unranked | perl-securityskill · database | Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF)… | No signals yet | No commit datelisted | armory install perl-security --cli claude |
| 55 | Unranked | playwright-e2e-builderskill · auth | Plan and build comprehensive Playwright E2E test suites with Page Object Model, authentication state persistence, custom fixtures, visual regression… | No signals yet | No commit datelisted | armory install playwright-e2e-builder --cli claude |
| 56 | Unranked | postgres-patternsskill · database | PostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices. | No signals yet | No commit datelisted | armory install postgres-patterns --cli claude |
| 57 | Unranked | quarkus-securityskill · auth | Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency… | No signals yet | No commit datelisted | armory install quarkus-security --cli claude |
| 58 | Unranked | quarkus-verificationskill · other | "Verification loop for Quarkus projects: build, static analysis, tests with coverage, security scans, native compilation, and diff review before… | No signals yet | No commit datelisted | armory install quarkus-verification --cli claude |
| 59 | Unranked | red-team-tools-and-methodologyskill · other | This skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS… | No signals yet | No commit datelisted | armory install red-team-tools-and-methodology --cli claude |
| 60 | Unranked | returns-reverse-logisticsskill · auth | Codified expertise for returns authorization, receipt and inspection, disposition decisions, refund processing, fraud detection, and warranty claims… | No signals yet | No commit datelisted | armory install returns-reverse-logistics --cli claude |
| 61 | Unranked | saas-multi-tenantskill · database | Design and implement multi-tenant SaaS architectures with row-level security, tenant-scoped queries, shared-schema isolation, and safe cross-tenant… | No signals yet | No commit datelisted | armory install saas-multi-tenant --cli claude |
| 62 | Unranked | sast-configurationskill · other | Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple… | No signals yet | No commit datelisted | armory install sast-configuration --cli claude |
| 63 | Unranked | secrets-managementskill · devops | Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools. | No signals yet | No commit datelisted | armory install secrets-management --cli claude |
| 64 | Unranked | security-audit-2skill · back-end | Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security… | No signals yet | No commit datelisted | armory install security-audit-2 --cli claude |
| 65 | Unranked | security-best-practicesskill · other | Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests… | No signals yet | No commit datelisted | armory install security-best-practices --cli claude |
| 66 | Unranked | security-bounty-hunterskill · github-vcs | Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports… | No signals yet | No commit datelisted | armory install security-bounty-hunter --cli claude |
| 67 | Unranked | security-ownership-mapskill · github-vcs | Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON… | No signals yet | No commit datelisted | armory install security-ownership-map --cli claude |
| 68 | Unranked | security-reviewskill · back-end | Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive… | No signals yet | No commit datelisted | armory install security-review --cli claude |
| 69 | Unranked | security-scanning-toolsskill · other | This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security"… | No signals yet | No commit datelisted | armory install security-scanning-tools --cli claude |
| 70 | Unranked | security-threat-modelskill · front-end | Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a… | No signals yet | No commit datelisted | armory install security-threat-model --cli claude |
| 71 | Unranked | senior-backendskill · back-end | Comprehensive backend development skill for building scalable backend systems using NodeJS, Express, Go, Python, Postgres, GraphQL, REST APIs… | No signals yet | No commit datelisted | armory install senior-backend --cli claude |
| 72 | Unranked | senior-secopsskill · other | Comprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security… | No signals yet | No commit datelisted | armory install senior-secops --cli claude |
| 73 | Unranked | senior-securityskill · front-end | Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes… | No signals yet | No commit datelisted | armory install senior-security --cli claude |
| 74 | Unranked | shodan-reconnaissance-and-pentestingskill · back-end | This skill should be used when the user asks to "search for exposed devices on the internet," "perform Shodan reconnaissance," "find vulnerable… | No signals yet | No commit datelisted | armory install shodan-reconnaissance-and-pentesting --cli claude |
| 75 | Unranked | smtp-penetration-testingskill · back-end | This skill should be used when the user asks to "perform SMTP penetration testing", "enumerate email users", "test for open mail relays", "grab SMTP… | No signals yet | No commit datelisted | armory install smtp-penetration-testing --cli claude |
| 76 | Unranked | springboot-securityskill · auth | Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot… | No signals yet | No commit datelisted | armory install springboot-security --cli claude |
| 77 | Unranked | springboot-verificationskill · other | "Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR." | No signals yet | No commit datelisted | armory install springboot-verification --cli claude |
| 78 | Unranked | sql-injection-testingskill · database | This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL… | No signals yet | No commit datelisted | armory install sql-injection-testing --cli claude |
| 79 | Unranked | sqlmap-database-penetration-testingskill · database | This skill should be used when the user asks to "automate SQL injection testing," "enumerate database structure," "extract database credentials using… | No signals yet | No commit datelisted | armory install sqlmap-database-penetration-testing --cli claude |
| 80 | Unranked | ssh-penetration-testingskill · auth | This skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH… | No signals yet | No commit datelisted | armory install ssh-penetration-testing --cli claude |
| 81 | Unranked | threat-modeling-expertskill · front-end | Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security… | No signals yet | No commit datelisted | armory install threat-modeling-expert --cli claude |
| 82 | Unranked | top-100-web-vulnerabilities-referenceskill · back-end | This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability… | No signals yet | No commit datelisted | armory install top-100-web-vulnerabilities-reference --cli claude |
| 83 | Unranked | using-neonskill · back-end | Guides and best practices for working with Neon Serverless Postgres. Covers getting started, local development with Neon, choosing a connection… | No signals yet | No commit datelisted | armory install using-neon --cli claude |
| 84 | Unranked | vulnerability-scannerskill · other | Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization. | No signals yet | No commit datelisted | armory install vulnerability-scanner --cli claude |
| 85 | Unranked | web-security-testingskill · auth | Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues. | No signals yet | No commit datelisted | armory install web-security-testing --cli claude |
| 86 | Unranked | wordpress-penetration-testingskill · other | This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes… | No signals yet | No commit datelisted | armory install wordpress-penetration-testing --cli claude |
Score colour shows how many signals stand behind it, never how good it is: amber, three or more; dimmer amber, two; grey, one. The Evidence column names them.
Stars, forks and last commit are as GitHub reported them when Armory last read each repository: for most, or later. A repository may have changed since.