Security

Security scanning and vulnerability detection

Showing 553-576 of 2326 skills
TerminalSkills

auth-system-setup

by TerminalSkills

When the user wants to set up authentication and authorization for a web application. Use when the user mentions "auth," "login," "OAuth," "SSO," "single sign-on," "role-based access," "RBAC," "permissions," "user roles," "access control," "authentication," or "authorization." Covers OAuth 2.0 provider integration, session management, and role/permission architecture. For JWT-specific tasks, see jwt-handler. For security review, see security-audit.

Auth 140 6mo ago
mycelium-hq

sunday-review

by mycelium-hq

'Use when the user asks for the weekly meta-review or Sunday wrap-up of their week and vault: says /sunday, /sunday-review, ''let''s do the weekly review,'' ''Sunday review,'' ''review my week,'' ''weekly retro,'' ''week in review,'' ''end-of-week review,'' or wants journals, patterns, vault health, and stale decisions reviewed together at week''s end. Not for a journal-pattern read alone (use /weekly) or mid-week single checks.'

Automation 35 1mo ago
mycelium-hq

secret-warn

by mycelium-hq

Use when adding or tuning edit-time secret and code-injection guardrails or security hooks in Claude Code, or on mentions of secret detection, API key safety, hardcoded or leaked keys (AWS, Stripe, GCP, OpenAI, Anthropic, GitHub, Slack, JWT, PEM, .env), gitleaks-style or pre-commit secret scanning, false positives or allowlists, unsafe pipe-to-shell or MCP server installs, or prompt injection in audited third-party content (README, AGENTS.md). Not for full security audits, pen testing, or DLP.

CLI Tools 35 2mo ago
mycelium-hq

security-snapshot

by mycelium-hq

'Use when the user says /security-snapshot, /snapshot <domain>, "run a security check on X", "generate a security report for [company]", or wants a security hygiene snapshot or free lead-magnet report on a prospect''s public domain: SSL/TLS grade, HTTP security headers, SPF/DMARC email authentication, server fingerprint leaks. Passive, unauthenticated scans only. NOT for penetration testing, internal infrastructure audits, or application-layer vulnerability assessment.'

File Ops 35 1mo ago
bobmatnyc

mcp-security-review

by bobmatnyc

Security review gate for MCP server installations. Checks provenance, classifies risk, enforces version pinning, and documents credentials exposure before any MCP is added to your environment.

Code Review 149 6mo ago
proflead

vendor-evaluation

by proflead

Evaluate third-party vendors for engineering fit. Use when a senior developer needs a structured vendor assessment.

Legal 139 7mo ago
melodic-software

audit-mcp

by melodic-software

Audit MCP server configurations for quality, compliance, and security. Use to validate .mcp.json files and server setups.

Code Review 12 6mo ago
proflead

iac-reviewer

by proflead

Review infrastructure-as-code changes for safety and correctness. Use when a mid-level developer needs a second look on IaC.

Agents 139 7mo ago
proflead

data-governance-check

by proflead

Review data handling for privacy and retention. Use when a senior developer needs governance validation.

Code Review 139 7mo ago
melodic-software

audit-plugins

by melodic-software

Audit Claude Code plugins for quality, compliance, and distribution readiness. Use before releases or for periodic quality checks.

Code Review 12 6mo ago
Dokhacgiakhoa

🧠 Strategic Research & Wisdom Engine

by Dokhacgiakhoa

Created by Antigravity Orchestrator - Powered by Strategic Wisdom Patterns.

Academic 505 6mo ago
dgalarza

parallel-code-review

by dgalarza

This skill should be used when performing comprehensive code reviews using multiple specialized review agents in parallel. It provides patterns for concurrent execution, decision tracking to prevent redundancy, and consolidated reporting. Use when needing thorough review coverage from multiple perspectives (security, architecture, performance) or when reviewing large changesets.

Agents 59 7mo ago
mapbox

mapbox-token-security

by mapbox

Security best practices for Mapbox access tokens, including scope management, URL restrictions, rotation strategies, and protecting sensitive data. Use when creating, managing, or advising on Mapbox token security.

API Dev 59 8mo ago
shipshitdev

aws-infrastructure

by shipshitdev

Expert in AWS infrastructure setup including EC2, VPC, security groups, Application Load Balancers, Route53 DNS, and SSL/TLS certificates. Use this skill for AWS infrastructure configuration and deployment.

API Dev 35 7mo ago
akaszubski

security-patterns

by akaszubski

"Security best practices covering API key management, input validation, injection prevention, and OWASP patterns. Use when handling secrets, user input, or security-sensitive code. TRIGGER when: security, API key, secret, input validation, injection, OWASP. DO NOT TRIGGER when: non-security code, styling, documentation, test scaffolding."

Security 33 5mo ago
akin-ozer

terraform-validator

by akin-ozer

Comprehensive toolkit for validating, linting, testing, and automating Terraform configurations and HCL files. Use this skill when working with Terraform files (.tf, .tfvars), validating infrastructure-as-code, debugging Terraform configurations, performing dry-run testing with terraform plan, or working with custom providers and modules.

CLI Tools 298 7mo ago
akin-ozer

dockerfile-validator

by akin-ozer

Comprehensive toolkit for validating, linting, and securing Dockerfiles. Use this skill when validating Dockerfile syntax, checking security best practices, optimizing image builds. Applies to all Dockerfile variants (Dockerfile, Dockerfile.prod, Dockerfile.dev, etc.).

CLI Tools 298 7mo ago
akin-ozer

azure-pipelines-validator

by akin-ozer

Comprehensive toolkit for validating, linting, and securing Azure DevOps Pipeline configurations.

Cloud 298 7mo ago
0xDarkMatter

techdebt

by 0xDarkMatter

"Technical debt detection and remediation. Run at session end to find duplicated code, dead imports, security issues, and complexity hotspots. Triggers: 'find tech debt', 'scan for issues', 'check code quality', 'wrap up session', 'ready to commit', 'before merge', 'code review prep'. Always uses parallel subagents for fast analysis."

Debugging 32 7mo ago
0xDarkMatter

security-patterns

by 0xDarkMatter

"Security patterns and OWASP guidelines. Triggers on: security review, OWASP, XSS, SQL injection, CSRF, authentication, authorization, secrets management, input validation, secure coding."

Auth 32 8mo ago
0xDarkMatter

atomise

by 0xDarkMatter

"Atom of Thoughts (AoT) reasoning - decompose complex problems into atomic units with confidence tracking and backtracking. For genuinely complex reasoning, not everyday questions. Triggers on: atomise, complex reasoning, decompose problem, structured thinking, verify hypothesis."

Security 32 7mo ago
LangConfig

code-review

by LangConfig

"Systematic code review guidance covering best practices, security, performance, and maintainability. Use when reviewing code, checking PRs, or analyzing code quality."

Code Review 60 8mo ago
LangConfig

security-review

by LangConfig

"Comprehensive security code review covering OWASP Top 10, authentication, authorization, and secure coding practices. Use when reviewing code for vulnerabilities or implementing security features."

Auth 60 8mo ago
bobmatnyc

env-manager

by bobmatnyc

Environment variable validation, synchronization, and management across local development, CI/CD, and deployment platforms

Cloud 149 9mo ago