Security

Security scanning and vulnerability detection

Showing 1-24 of 2221 skills
dadbodgeoff

file-uploads

by dadbodgeoff

Production-grade secure file upload pipeline with multi-stage validation, malware scanning (ClamAV), hash-based duplicate detection, and race condition protection using distributed locks.

Security 782 3mo ago
TencentBlueKing

蓝鲸代码安全三大红线

by TencentBlueKing

基于 IEG 安全规范,覆盖输入校验、鉴权、数据加密三大高危领域

Security 833 4mo ago
TencentBlueKing

Node.js 安全审查

by TencentBlueKing

检查 RCE、SSRF、SQL 注入、路径穿越等安全问题,支持 Express/Koa/NestJS

Security 833 4mo ago
TencentBlueKing

Web 安全漏洞学习指南

by TencentBlueKing

OWASP 十大漏洞原理、影响与修复方案,覆盖 Python/Java 场景

Security 833 4mo ago
TencentBlueKing

JavaScript 安全审查

by TencentBlueKing

检查 XSS、CSRF、原型污染等安全问题,支持 React/Vue/Angular

Security 833 4mo ago
dadbodgeoff

audit-logging

by dadbodgeoff

Comprehensive audit logging for compliance and security. Track user actions, data changes, and system events with tamper-proof storage.

Security 782 3mo ago
dadbodgeoff

error-sanitization

by dadbodgeoff

Production-safe error handling that logs full details server-side while exposing only generic, safe messages to users. Prevents information leakage of database strings, file paths, stack traces, and API keys.

Security 782 3mo ago
rohitg00

k8s-policy

by rohitg00

Kubernetes policy management with Kyverno and Gatekeeper. Use when enforcing security policies, validating resources, or auditing policy compliance.

Security 904 4mo ago
Leavesfly

security-checklist

by Leavesfly

OWASP 安全检查清单

Security 222 6mo ago
UseAI-pro

config-hardener

by UseAI-pro

"Audit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission policies for security weaknesses."

Security 58 3mo ago
UseAI-pro

setup-auditor

by UseAI-pro

"Audit your OpenClaw environment for credential leaks, unsafe defaults, and missing sandbox configuration. Wizard-style: answers questions about your setup and produces a fix checklist."

Security 58 3mo ago
UseAI-pro

credential-scanner

by UseAI-pro

"Scan your project for exposed credentials, API keys, and secrets before running OpenClaw skills. Prevents accidental exfiltration."

Security 58 3mo ago
UseAI-pro

skill-guard

by UseAI-pro

"Runtime security monitor for active OpenClaw skills. Watches file access, network calls, and shell commands. Flags anomalous behavior and enforces permission boundaries."

Security 58 3mo ago
UseAI-pro

prompt-guard

by UseAI-pro

"Detect and neutralize prompt injection attacks in OpenClaw skill content, user inputs, and external data sources. Prevents instruction hijacking and context manipulation."

Security 58 3mo ago
UseAI-pro

permission-auditor

by UseAI-pro

"Analyze OpenClaw skill permissions and explain exactly what each permission allows. Identifies over-privileged skills and suggests minimal permission sets."

Security 58 3mo ago
UseAI-pro

incident-responder

by UseAI-pro

"Step-by-step incident response for OpenClaw security breaches. Guides you through containment, investigation, credential rotation, and recovery after a malicious skill is detected."

Security 58 3mo ago
UseAI-pro

network-watcher

by UseAI-pro

"Audit and monitor network requests made by OpenClaw skills. Detects data exfiltration, unauthorized API calls, and suspicious outbound connections."

Security 58 3mo ago
rohitg00

k8s-certs

by rohitg00

Kubernetes certificate management with cert-manager. Use when managing TLS certificates, configuring issuers, or troubleshooting certificate issues.

Security 902 4mo ago
rohitg00

k8s-security

by rohitg00

Audit Kubernetes RBAC, enforce policies, and manage secrets. Use for security reviews, permission audits, policy enforcement with Kyverno/Gatekeeper, and secret management.

Security 902 4mo ago
UseAI-pro

skill-auditor

by UseAI-pro

"Comprehensive security auditor for OpenClaw skills. Checks for typosquatting, dangerous permissions, prompt injection, supply chain risks, and data exfiltration patterns — before you install anything."

Security 57 3mo ago
williamzujkowski

api-security

by williamzujkowski

Broken Object Level Authorization (BOLA) - API fails to validate user

Security 17 5mo ago
truongnat

security-specialist

by truongnat

Elite security engineering based on threat modeling, defensive coding, vulnerability management, and compliance standards. Focused on the "Security-by-Design" philosophy.

Security 6 3mo ago
markus41

code-review

by markus41

Comprehensive code review knowledge including security, performance, accessibility, and quality standards across multiple languages and frameworks

Accessibility 12 5mo ago
HacktronAI

ctf-solver

by HacktronAI

Solve CTF (Capture The Flag) challenges by analyzing challenge descriptions, source code, and interacting with challenge environments to capture flags.

Security 103 5mo ago