Security

Security scanning and vulnerability detection

Showing 505-528 of 2326 skills
trailofbits

scv-scan

by trailofbits

"Audits Solidity codebases for smart contract vulnerabilities using a four-phase workflow (cheatsheet loading, codebase sweep, deep validation, reporting) covering 36 vulnerability classes. Use when auditing Solidity contracts for security issues, performing smart contract vulnerability scans, or reviewing Solidity code for common exploit patterns."

File Ops 493 6mo ago
trailofbits

openai-security-best-practices

by trailofbits

Perform language and framework specific security best-practice reviews and suggest improvements.

Analytics 493 6mo ago
trailofbits

security-awareness

by trailofbits

Teaches agents to recognize and avoid security threats during normal activity. Covers phishing detection, credential protection, domain verification, and social engineering defense. Use when building or operating agents that access email, credential vaults, web browsers, or sensitive data.

Email 493 6mo ago
trailofbits

wooyun-legacy

by trailofbits

Provides web vulnerability testing methodology distilled from 88,636 real-world cases from the WooYun vulnerability database (2010-2016). Use when performing penetration testing, security audits, code reviews for security flaws, or vulnerability research. Covers SQL injection, XSS, command execution, file upload, path traversal, unauthorized access, information disclosure, and business logic flaws.

Database 493 6mo ago
trailofbits

openai-security-ownership-map

by trailofbits

'Analyze git repositories to build a security ownership topology (people-to-file), compute

Processing 493 6mo ago
flpbalada

what-not-to-do-as-product-manager

by flpbalada

Anti-patterns and mistakes to avoid as a product manager. Use when evaluating

Code Gen 281 7mo ago
flpbalada

trust-psychology

by flpbalada

Build trust signals that reduce perceived risk and enable user action. Use

Code Gen 281 7mo ago
DmitrL-dev

Agent Security Audit

by DmitrL-dev

Проверка безопасности AI-агентов по OWASP Agentic Top 10 2026

Code Review 109 6mo ago
hoodini

owasp-security

by hoodini

Implement secure coding practices following OWASP Top 10. Use when preventing security vulnerabilities, implementing authentication, securing APIs, or conducting security reviews. Triggers on OWASP, security, XSS, SQL injection, CSRF, authentication security, secure coding, vulnerability.

Processing 274 8mo ago
scalus3

smart-contract-security-review

by scalus3

Security review for Scalus/Cardano smart contracts. Analyzes @Compile annotated validators for vulnerabilities like redirect attacks, inexact value validation, missing token verification, integer overflow, and self-dealing. Use when reviewing on-chain code, before deploying validators, or when /security-review is invoked. Requires explicit path argument.

Code Review 105 6mo ago
henkisdabro

fifteen-factor-app

by henkisdabro

The Fifteen-Factor App methodology for modern cloud-native SaaS applications. This skill should be automatically invoked when planning SaaS tools, product software architecture, microservices design, PRPs/PRDs, or cloud-native application development. Extends the original Twelve-Factor App principles with three additional factors (API First, Telemetry, Security). Trigger keywords include "fifteen factor", "12 factor", "SaaS architecture", "cloud-native design", "application architecture", "microservices best practices", or when in a planning/architecture session.

API Dev 83 6mo ago
simota

Probe

by simota

OWASP ZAP/Burp Suite連携、ペネトレーションテスト計画、DAST実行、脆弱性スキャン。動的セキュリティテスト、侵入テスト、実行時脆弱性検証が必要な時に使用。Sentinelの静的分析を補完。

Auth 74 6mo ago
alirezarezvani

secret-scanner

by alirezarezvani

Detect exposed secrets, API keys, credentials, and tokens in code. Use before commits, on file saves, or when security is mentioned. Prevents accidental secret exposure. Triggers on file changes, git commits, security checks, .env file modifications.

Docs Gen 766 10mo ago
alirezarezvani

security-auditor

by alirezarezvani

Continuous security vulnerability scanning for OWASP Top 10, common vulnerabilities, and insecure patterns. Use when reviewing code, before deployments, or on file changes. Scans for SQL injection, XSS, secrets exposure, auth issues. Triggers on file changes, security mentions, deployment prep.

Auth 766 10mo ago
alirezarezvani

dependency-auditor

by alirezarezvani

Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. Use when package.json or requirements.txt changes, or before deployments. Alerts on vulnerable dependencies. Triggers on dependency file changes, deployment prep, security mentions.

Code Review 766 10mo ago
alirezarezvani

code-reviewer

by alirezarezvani

Automatic code quality and best practices analysis. Use proactively when files are modified, saved, or committed. Analyzes code style, patterns, potential bugs, and security basics. Triggers on file changes, git diff, code edits, quality mentions.

Agents 766 10mo ago
vasilyu1983

dev-dependency-management

by vasilyu1983

Package and dependency management patterns across ecosystems (npm, pip, cargo, maven). Covers lockfiles, semantic versioning, dependency security scanning, update strategies, monorepo workspaces, transitive dependencies, and avoiding dependency hell.

Code Gen 81 6mo ago
vasilyu1983

marketing-seo-complete

by vasilyu1983

Complete SEO skill for technical audits (Core Web Vitals, site speed, crawlability/indexation, robots/sitemaps/canonicals, structured data, mobile, security, internal linking), SEO marketing strategy (keyword research, content planning, competitive analysis, E-E-A-T), operational workflows (cross-team collaboration, OKRs), link building, local SEO, international SEO (hreflang), and multi-platform SEO (Google, YouTube, Reddit, social). Updated for January 2026.

Code Review 81 7mo ago
stellarlinkco

skill-install

by stellarlinkco

Install Claude skills from GitHub repositories with automated security scanning. Triggers when users want to install skills from a GitHub URL, need to browse available skills in a repository, or want to safely add new skills to their Claude environment.

Git & VCS 2.8K 8mo ago
aaron-he-zhu

technical-seo-checker

by aaron-he-zhu

'Use when the user asks to "technical SEO audit", "check page speed", "crawl issues", "Core Web Vitals", "site indexing problems", "my site is slow", "Google cannot crawl my site", "mobile issues", or "indexing problems". Performs technical SEO audits covering site speed, crawlability, indexability, mobile-friendliness, security, and structured data. Identifies technical issues preventing optimal search performance. For content and heading element issues, see on-page-seo-auditor. For link architecture, see internal-linking-optimizer.'

Code Review 167 6mo ago
rohitg00

security-hardening

by rohitg00

Application security covering input validation, auth, headers, secrets management, and dependency auditing

Auth 2.6K 7mo ago
vintasoftware

django-expert

by vintasoftware

Expert Django backend development guidance. Use when creating Django models, views, serializers, or APIs; debugging ORM queries or migrations; optimizing database performance; implementing authentication; writing tests; or working with Django REST Framework. Follows Django best practices and modern patterns.

API Dev 129 7mo ago
docxology

Codomyrmex

by docxology

Full-spectrum coding workspace skill providing 171 MCP tools across 33 modules. USE WHEN user says 'verify codomyrmex', 'codomyrmexVerify', 'audit codomyrmex', 'trust codomyrmex', 'codomyrmexTrust', 'trust tools', 'enable destructive tools', 'check pai status', 'codomyrmex tools', 'codomyrmex analyze', 'codomyrmex search', 'codomyrmex memory', 'codomyrmex docs', 'codomyrmex status', 'codomyrmex git', 'codomyrmex security', 'codomyrmex ai', 'codomyrmex code', 'codomyrmex data', 'codomyrmex deploy', 'codomyrmex test', or uses any 'codomyrmex' automation tools.

Code Review 11 6mo ago
TerminalSkills

agent-sandbox

by TerminalSkills

Run AI agent code safely in isolated sandboxes with resource limits, audit trails, and kill switches. Use when someone asks to "sandbox my agent", "run agent code safely", "add guardrails to AI agent", "isolate agent execution", "audit agent actions", "prevent agent from deleting files", "restrict agent permissions", or "add safety controls to AI coding agent". Covers Docker isolation, filesystem restrictions, network policies, resource locking, and comprehensive audit logging.

Agents 140 6mo ago