Security

Security scanning and vulnerability detection

Showing 505-528 of 2236 skills
lawvable

tech-contract-negotiation-patrick-munro

by lawvable

"Guide to negotiating technology services agreements, professional services contracts, and commercial B2B transactions. Provides three-position frameworks (provider-favorable, balanced, client-favorable), deal-size tactics, objection handling templates, and concession roadmaps. Use when: (1) Developing negotiation strategies for SaaS, cloud, or managed services agreements, (2) Preparing position papers and fallback positions, (3) Responding to counterparty objections and demands, (4) Creating concession roadmaps that protect critical interests, (5) Assessing tactics based on deal value and leverage, or (6) Structuring balanced outcomes for liability, IP, payment, SLA, or warranty provisions."

Legal 588 5mo ago
squirrelscan

audit-website

by squirrelscan

Audit websites for SEO, performance, security, technical, content, and 15 other issue cateories with 230+ rules using the squirrelscan CLI. Returns LLM-optimized reports with health scores, broken links, meta tag analysis, and actionable recommendations. Use to discover and asses website or webapp issues and health.

Code Review 85 5mo ago
mapbox

mapbox-token-security

by mapbox

Security best practices for Mapbox access tokens, including scope management, URL restrictions, rotation strategies, and protecting sensitive data. Use when creating, managing, or advising on Mapbox token security.

API Dev 59 6mo ago
Mindrally

docker

by Mindrally

Docker containerization best practices for building, securing, and deploying containers.

CI/CD 195 6mo ago
scalus3

smart-contract-security-review

by scalus3

Security review for Scalus/Cardano smart contracts. Analyzes @Compile annotated validators for vulnerabilities like redirect attacks, inexact value validation, missing token verification, integer overflow, and self-dealing. Use when reviewing on-chain code, before deploying validators, or when /security-review is invoked. Requires explicit path argument.

Code Review 105 5mo ago
Uniswap

v4-security-foundations

by Uniswap

Security-first Uniswap v4 hook development. Use when user mentions "v4 hooks", "hook security", "PoolManager", "beforeSwap", "afterSwap", or asks about V4 hook best practices, vulnerabilities, or audit requirements.

Code Review 219 5mo ago
sugarforever

Python Security Scan

by sugarforever

"Comprehensive security vulnerability scanner for Python projects including Flask, Django, and FastAPI applications. Detects OWASP Top 10 vulnerabilities, injection flaws, insecure deserialization, authentication issues, hardcoded secrets, and framework-specific security problems. Audits dependencies for known CVEs and generates actionable security reports."

Auth 125 6mo ago
joaquimscosta

spring-boot-scanner

by joaquimscosta

Smart code scanner that detects Spring Boot patterns and routes to appropriate skills. Use when editing Java or Kotlin files in Spring Boot projects, working with pom.xml/build.gradle containing spring-boot-starter, or when context suggests Spring Boot development. Detects annotations (@RestController, @Entity, @EnableWebSecurity, @SpringBootTest) to determine relevant skills and provides contextual guidance. Uses progressive automation - auto-invokes for low-risk patterns (web-api, data, DDD), confirms before loading high-risk skills (security, testing, verify).

Automation 21 5mo ago
joaquimscosta

spring-boot-security

by joaquimscosta

Spring Security 7 implementation for Spring Boot 4. Use when configuring authentication, authorization, OAuth2/JWT resource servers, method security, or CORS/CSRF. Covers the mandatory Lambda DSL migration, SecurityFilterChain patterns, @PreAuthorize, and password encoding. For testing secured endpoints, see spring-boot-testing skill.

API Dev 21 6mo ago
LangConfig

security-review

by LangConfig

"Comprehensive security code review covering OWASP Top 10, authentication, authorization, and secure coding practices. Use when reviewing code for vulnerabilities or implementing security features."

Auth 52 7mo ago
cosmix

security-audit

by cosmix

Performs comprehensive security audits identifying vulnerabilities, misconfigurations, and security best practice violations across applications, APIs, infrastructure, and data pipelines. Covers OWASP Top 10, compliance requirements (SOC2, PCI-DSS, HIPAA, GDPR), penetration testing, vulnerability assessment, risk assessment, security reviews, and hardening. Trigger keywords: security audit, vulnerability assessment, penetration test, pentest, OWASP, CVE, security review, risk assessment, compliance, SOC2, PCI-DSS, HIPAA, GDPR, security checklist, threat modeling, attack surface, security posture, vulnerability scan, security hardening, security baseline, security controls, security gap analysis, infrastructure security, API security, cloud security, container security, Kubernetes security, network security, application security, data security, ML model security.

Processing 51 5mo ago
project-codeguard

software-security

by project-codeguard

A software security skill that integrates with Project CodeGuard to help AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.

Auth 413 5mo ago
Mindrally

chrome-extension-development

by Mindrally

Expert guidelines for Chrome extension development with Manifest V3, covering security, performance, and best practices

Performance 195 6mo ago
lawvable

vendor-due-diligence-patrick-munro

by lawvable

"Framework for assessing IT service providers, technology vendors, and third-party partners. Creates structured risk assessments across financial, operational, compliance, security, and reputational dimensions with regulatory checklists (GDPR, DORA, NIS2, SOX). Use when: (1) Evaluating new vendors or technology providers, (2) Conducting third-party risk assessments for procurement, (3) Performing critical vendor due diligence for regulatory compliance, (4) Creating vendor onboarding documentation, (5) Establishing ongoing vendor monitoring processes, (6) Assessing vendor concentration risk, or (7) Generating executive-level vendor risk reports."

Code Review 588 5mo ago
Mindrally

bash-scripting

by Mindrally

Bash scripting guidelines covering security, portability, error handling, and automation best practices for DevOps.

CLI Tools 195 6mo ago
simota

Canon

by simota

世界標準・業界標準で物事を解決する調査・分析エージェント。OWASP/WCAG/OpenAPI/ISO 25010ç­‰ã®æ¨™æº–ã¸ã®æº–æ‹ åº¦è©•ä¾¡ã€æ¨™æº–é•åæ¤œå‡ºã€æ”¹å–„ææ¡ˆã‚’æ‹…å½“ã€‚æ¨™æº–æº–æ‹ è©•ä¾¡ã€è¦æ ¼é©ç”¨ãŒå¿…è¦ãªæ™‚ã«ä½¿ç”¨ã€‚

Accessibility 66 5mo ago
simota

Grove

by simota

ãƒªãƒã‚¸ãƒˆãƒªæ§‹é€ ã®è¨­è¨ˆãƒ»æœ€é©åŒ–ãƒ»ç›£æŸ»ã€‚ãƒ‡ã‚£ãƒ¬ã‚¯ãƒˆãƒªè¨­è¨ˆã€docs/æ§‹æˆï¼ˆè¦ä»¶å®šç¾©æ›¸ãƒ»è¨­è¨ˆæ›¸ãƒ»ãƒã‚§ãƒƒã‚¯ãƒªã‚¹ãƒˆå¯¾å¿œï¼‰ã€ãƒ†ã‚¹ãƒˆæ§‹æˆã€ã‚¹ã‚¯ãƒªãƒ—ãƒˆç®¡ç†ã€ã‚¢ãƒ³ãƒãƒ‘ã‚¿ãƒ¼ãƒ³æ¤œå‡ºã€æ—¢å­˜ãƒªãƒã‚¸ãƒˆãƒªã®æ§‹æˆç§»è¡Œã‚’æ‹…å½“ã€‚ãƒªãƒã‚¸ãƒˆãƒªæ§‹é€ ã®è¨­è¨ˆãƒ»æ”¹å–„ãŒå¿…è¦ãªæ™‚ã«ä½¿ç”¨ã€‚

Code Review 66 5mo ago
simota

Probe

by simota

OWASP ZAP/Burp Suite連携、ペネトレーションテスト計画、DAST実行、脆弱性スキャン。動的セキュリティテスト、侵入テスト、実行時脆弱性検証が必要な時に使用。Sentinelの静的分析を補完。

Auth 66 5mo ago
terrylica

health

by terrylica

"Cal.com Commander health check across all subsystems. TRIGGERS - calcom health, calendar bot status, cal.com diagnostics, booking bot check."

CLI Tools 59 5mo ago
tenequm

solana-security

by tenequm

Audit Solana programs (Anchor or native Rust) for security vulnerabilities. Use when reviewing smart contract security, finding exploits, analyzing attack vectors, performing security assessments, or when explicitly asked to audit, review security, check for bugs, or find vulnerabilities in Solana programs.

Code Review 31 8mo ago
LangConfig

code-review

by LangConfig

"Systematic code review guidance covering best practices, security, performance, and maintainability. Use when reviewing code, checking PRs, or analyzing code quality."

Code Review 52 7mo ago
bobmatnyc

security-scanning

by bobmatnyc

"CI security scanning: secrets, deps, SAST, triage, expiring exceptions"

CI/CD 60 6mo ago
proflead

vendor-evaluation

by proflead

Evaluate third-party vendors for engineering fit. Use when a senior developer needs a structured vendor assessment.

Legal 125 6mo ago
plurigrid

address-sanitizer

by plurigrid

Use AddressSanitizer to detect memory safety bugs in C/C++ programs. Identifies use-after-free, buffer overflow, memory leaks, and other memory errors.

Legal 31 5mo ago