Security

Security scanning and vulnerability detection

Showing 385-408 of 2236 skills
kdcokenny

code-review

by kdcokenny

Comprehensive code review methodology with severity classification and confidence thresholds

Code Review 543 5mo ago
markdown-viewer

security

by markdown-viewer

Create security architecture diagrams using PlantUML syntax with identity, encryption, firewall, and compliance stencil icons. Best for IAM flows, zero-trust architectures, encryption pipelines, compliance auditing, and threat detection. NOT for general cloud infra (use cloud skill) or simple flowcharts (use mermaid).

Auth 3.1K 3mo ago
semgrep

llm-security

by semgrep

Security guidelines for LLM applications based on OWASP Top 10 for LLM 2025. Use when building LLM apps, reviewing AI security, implementing RAG systems, or asking about LLM vulnerabilities like "prompt injection" or "check LLM security".

Embeddings 248 6mo ago
romiluz13

code-review-patterns

by romiluz13

"Internal skill. Use cc10x-router for all development tasks."

Code Review 155 4mo ago
phodal

code-review

by phodal

Perform comprehensive code review with best practices

Code Review 4.5K 6mo ago
seo-skills

seo-audit

by seo-skills

Audit websites for SEO, technical, content, security, JS rendering, and AI readiness using SEOmator CLI. Returns LLM-optimized reports with health scores across 251 rules and 20 categories. Use when analyzing websites, debugging SEO issues, or checking site health.

Code Review 330 5mo ago
wdm0006

reviewing-python-libraries

by wdm0006

Comprehensively reviews Python libraries for quality across project structure, packaging, code quality, testing, security, documentation, API design, and CI/CD. Provides actionable feedback and improvement recommendations. Use when evaluating library health, preparing for major releases, or auditing dependencies.

CI/CD 66 5mo ago
BrownFineSecurity

nmap

by BrownFineSecurity

Professional network reconnaissance and port scanning using nmap. Supports various scan types (quick, full, UDP, stealth), service detection, vulnerability scanning, and NSE scripts. Use when you need to enumerate network services, detect versions, or perform network reconnaissance.

Automation 803 7mo ago
pskoett

agent-teams-simplify-and-harden

by pskoett

"Implementation + audit loop using parallel agent teams with structured simplify, harden, and document passes. Spawns implementation agents to do the work, then audit agents to find complexity, security gaps, and spec deviations, then loops until code compiles cleanly, all tests pass, and auditors find zero issues or the loop cap is reached. Use when: implementing features from a spec or plan, hardening existing code, fixing a batch of issues, or any multi-file task that benefits from a build-verify-fix cycle."

Code Review 266 4mo ago
kevinslin

dev.can-make-public

by kevinslin

Scan a repository and its git history for secrets, credentials, private keys, internal URLs, PII, and other sensitive artifacts before making it public. Use when a user asks if a repo is safe to open-source, requests a pre-publication audit, or wants to sanitize a repo for public release.

Code Review 21 5mo ago
secondsky

access-control-rbac

by secondsky

Role-based access control (RBAC) with permissions and policies. Use for admin dashboards, enterprise access, multi-tenant apps, fine-grained authorization, or encountering permission hierarchies, role inheritance, policy conflicts.

Code Gen 193 7mo ago
yonatangross

assess

by yonatangross

"Assesses and rates quality 0-10 with pros/cons analysis. Use when evaluating code, designs, or approaches."

Agents 207 5mo ago
yonatangross

mcp-patterns

by yonatangross

MCP server building, advanced patterns, and security hardening. Use when building MCP servers, implementing tool handlers, adding authentication, creating interactive UIs, hardening MCP security, or debugging MCP integrations.

Auth 207 5mo ago
parhumm

detect-dev

by parhumm

Engineering audit with SARIF evidence, 4-level confidence, and OpenSSF scoring. Use when evaluating repository health or code quality.

Code Review 25 5mo ago
llama-farm

python-skills

by llama-farm

Shared Python best practices for LlamaFarm. Covers patterns, async, typing, testing, error handling, and security.

Security 834 5mo ago
semgrep

semgrep

by semgrep

Run Semgrep static analysis scans and create custom detection rules. Use when asked to scan code with Semgrep, find security vulnerabilities, write custom YAML rules, or detect specific bug patterns.

CLI Tools 248 6mo ago
vasilyu1983

marketing-seo-complete

by vasilyu1983

Complete SEO skill for technical audits (Core Web Vitals, site speed, crawlability/indexation, robots/sitemaps/canonicals, structured data, mobile, security, internal linking), SEO marketing strategy (keyword research, content planning, competitive analysis, E-E-A-T), operational workflows (cross-team collaboration, OKRs), link building, local SEO, international SEO (hreflang), and multi-platform SEO (Google, YouTube, Reddit, social). Updated for January 2026.

Code Review 66 5mo ago
henkisdabro

fifteen-factor-app

by henkisdabro

The Fifteen-Factor App methodology for modern cloud-native SaaS applications. This skill should be automatically invoked when planning SaaS tools, product software architecture, microservices design, PRPs/PRDs, or cloud-native application development. Extends the original Twelve-Factor App principles with three additional factors (API First, Telemetry, Security). Trigger keywords include "fifteen factor", "12 factor", "SaaS architecture", "cloud-native design", "application architecture", "microservices best practices", or when in a planning/architecture session.

API Dev 75 5mo ago
scaffold-eth

solidity-security

by scaffold-eth

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

Legal 2K 5mo ago
fluxcd

gitops-repo-audit

by fluxcd

Audit Flux CD GitOps repositories for structure, security, API compliance, and best practices. Use this skill whenever the user asks to audit, analyze, review, validate, or check a GitOps repository. Also use it when users mention Flux repo structure, GitOps best practices, manifest validation, deprecated APIs, security review, or repository organization — even if they don't explicitly say "audit".

Code Review 200 4mo ago
tanweai

vuln-analysis-expert

by tanweai

WooYun漏洞分析专家系统。基于88,636个真实漏洞案例提炼的元思考方法论、测试流程、利用技巧、绕过方法。覆盖SQL注入、XSS、命令执行、逻辑漏洞、文件上传、未授权访问等主要漏洞类型。当用户进行漏洞挖掘、渗透测试、安全审计、代码审计时触发。

CLI Tools 1.7K 6mo ago
mblode

agents-md

by mblode

Audits and writes AGENTS.md files using execution-first standards. Checks commands, gotchas, and signal-to-noise ratio. Use when asked to audit, review, score, refactor, or improve agent instruction files, fix stale commands, or reduce bloat.

Code Review 64 5mo ago
mblode

audit-typography

by mblode

Audits web typography for punctuation, font selection, sizing, spacing, OpenType features, hierarchy, layout, typeface pairing, brand identity, and display type. Use when writing CSS/HTML for text, selecting or pairing typefaces, reviewing typography in web designs, configuring font-feature-settings, building a type system, or auditing typographic quality. Triggers on tasks involving font-family, font-size, line-height, letter-spacing, @font-face, font pairing, or typographic correctness.

Code Review 64 5mo ago
better-auth

email-and-password-best-practices

by better-auth

This skill provides guidance and enforcement rules for implementing secure email and password authentication using Better Auth.

Auth 204 5mo ago