skilly. Buy ad slot
THE AGENT SKILLS DIRECTORY

Small skills.
Big possibilities.

Your agent can do more. Find the skill that makes it happen.

Find your next superpower If you are an agent, refer to our llms.txt for full access.
K
View
SecurityAndroidiOS
ShulkwiSEC/bb-huge
0 installs 22 GitHub stars

mobile-auth-bypass

Detects authentication and biometric bypass vulnerabilities in mobile apps (Android/iOS). Trigger on: BiometricPrompt, LocalAuthentication, LAContext, evaluatePolicy, CryptoObject, Android Keystore, Secure Enclave, kSecAccessControlBiometryCurrentSet, userAuthenticationValidityDurationSeconds, confirmCredentials, biometric fallback, PIN bypass, passive authentication, enrolled biometrics detection…

Community score
0
0 up0 down
SecurityAndroidiOS
ShulkwiSEC/bb-huge
0 installs 22 GitHub stars

mobile-code-quality

Detects code quality vulnerabilities in mobile apps (Android/iOS). Trigger on: SQL injection in SQLite, JavaScript injection in WebViews, intent injection, unsafe deserialization, NSKeyedUnarchiver, NSCoding, Java serialization, Parcelable, buffer overflow, JNI native code, PIE disabled, NX disabled, stack canary absent, RELRO, ARC disabled, third-party library CVE, vulnerable dependency, outdated…

Community score
0
0 up0 down
SecurityAndroidiOS
ShulkwiSEC/bb-huge
0 installs 22 GitHub stars

mobile-insecure-storage

Detects sensitive data stored insecurely on mobile devices (Android/iOS). Trigger on: SharedPreferences, NSUserDefaults, SQLite, Room DB, DataStore, Core Data, Keychain misconfiguration, external storage, backup exposure, plaintext files, unencrypted databases, adb backup, iCloud backup, NSFileProtection, EncryptedSharedPreferences, SQLCipher, allowBackup, FLAG_SECURE, keyboard cache, sensitive lo…

Community score
0
0 up0 down
SecurityAndroidiOS
ShulkwiSEC/bb-huge
0 installs 22 GitHub stars

mobile-network-security

Detects insecure network communication in mobile apps (Android/iOS). Trigger on: cleartext HTTP, TLS misconfiguration, certificate pinning bypass, hostname verification disabled, allowCleartextTraffic, NSAllowsArbitraryLoads, ATS exceptions, custom TrustManager, ALLOW_ALL_HOSTNAME_VERIFIER, TLS 1.0/1.1, weak cipher suites, certificate pinning absent, Network Security Configuration, onReceivedSslEr…

Community score
0
0 up0 down
SecurityAndroidiOS
ShulkwiSEC/bb-huge
0 installs 22 GitHub stars

mobile-platform-interaction

Detects insecure platform interaction in mobile apps (Android/iOS). Trigger on: exported Activity, exported Service, exported BroadcastReceiver, Content Provider, Intent injection, deep link hijacking, WebView JavaScript enabled, JavascriptInterface, addJavascriptInterface, setJavaScriptEnabled, intent:// scheme, file:// scheme, WKWebView, WKScriptMessageHandler, UIPasteboard, URL scheme hijacking…

Community score
0
0 up0 down

Low community score

: This skill has a community score below −5, meaning it has received more downvotes than upvotes. Review its source and assessment before installing. Community votes are not a security review.

LESS SETUP. MORE POSSIBILITY.

Find it. Add it.
Make something.

Skills give your agent reusable instructions for a specific job. Pick one, read what it does, and bring it into your workflow.

01

Search the actual skill.

A name only tells half the story. Search the full description and instructions to find the right fit.

02

Get to know it.

Read the skill, visit its source, and see exactly what you’re adding to your agent.

03

Give your agent a new ability.

Copy the install command from a skill page and run it in your project.

npx skillycli add owner/repo --skill name