Security

Security scanning and vulnerability detection

Showing 721-744 of 2332 skills
saadshahd

intent

by saadshahd

Turn rough ideas into iron-clad work orders. Use when request is vague like "add a button", "make it better", "fix the thing". Triggers on ambiguous or underspecified requests.

Debugging 34 6mo ago
booch

security

by booch

Security guidelines for secure coding and code review. This skill should be used when architecting/designing systems, writing code, or reviewing code. Use proactively when discussing vulnerabilities, OWASP, injection attacks, XSS, CSRF, SQL injection, authentication, authorization, access control, encryption, secrets management, input validation, or secure coding practices. (user)

Auth 18 8mo ago
fortunto2

solo-audit

by fortunto2

Health check knowledge base for broken links, missing frontmatter, tag inconsistencies, and coverage gaps. Use when user says "audit KB", "check frontmatter", "find broken links", "tag cleanup", or "knowledge base quality". Do NOT use for SEO audits (use /seo-audit) or code reviews.

Code Review 18 6mo ago
dirnbauer

security-incident-reporting

by dirnbauer

Security Incident Report templates drawing from NIST/SANS. DDoS post-mortem, CVE correlation, timeline documentation, and blameless root cause analysis. Use when working with incident report, post-mortem, sir, ddos analysis, security reporting, root cause analysis, cve correlation, nist 800-61.

Security 33 7mo ago
dirnbauer

typo3-security

by dirnbauer

Security hardening checklist and best practices for TYPO3 v13/v14 installations, covering configuration, file permissions, and common vulnerabilities. Use when working with security, hardening, permissions, authentication, vulnerabilities.

Monitoring 33 7mo ago
bobmatnyc

threat-modeling

by bobmatnyc

"Threat modeling workflow for software systems: scope, data flow diagrams, STRIDE analysis, risk scoring, and turning mitigations into backlog and tests"

Code Gen 73 8mo ago
bobmatnyc

kubernetes

by bobmatnyc

"Kubernetes operations playbook for deploying services: core objects, probes, resource sizing, safe rollouts, and fast kubectl debugging"

Code Review 73 8mo ago
mastepanoski

owasp-llm-top10

by mastepanoski

Security audit for LLM and GenAI applications using OWASP Top 10 for LLM Apps 2025. Assess prompt injection, data leakage, supply chain, and 7 more critical vulnerabilities.

Processing 48 7mo ago
bobmatnyc

env-manager

by bobmatnyc

"Environment variable validation, security scanning, and management for Next.js, Vite, React, and Node.js applications"

CLI Tools 73 8mo ago
zephyrwang6

mem-weekly

by zephyrwang6

AI个人记忆系统的周复盘功能。分析本周L1情境层记录,识别重复模式,提炼到L2行为层。使用场景:(1) 用户说"周复盘"时;(2) 每周定期回顾时;(3) 需要从日常记录中提炼行为模式时。该skill会自动统计重复出现的行为(3次+),生成候选列表,等待用户确认后更新L2行为层。

Docs Gen 336 7mo ago
zephyrwang6

mem-file-scan

by zephyrwang6

AI个人记忆系统的文件扫描回顾功能。扫描Obsidian仓库中本周修改的文件(排除AI_MEMORY目录),识别潜在的重要事件和决策。使用场景:(1) 用户说"文件扫描"、"查看本周文件"、"扫描文件变化"时;(2) 周复盘时补充L1记录前;(3) 用户想回顾本周在Obsidian中的活动时。该skill会列出修改的文件,询问用户哪些需要记录到L1,并辅助记录。

File Ops 336 7mo ago
bobmatnyc

security-scanning

by bobmatnyc

"CI security scanning: secrets, deps, SAST, triage, expiring exceptions"

CI/CD 73 7mo ago
kochetkov-ma

brewcode:secrets-scan

by kochetkov-ma

Scans all git-tracked files for leaked secrets and credentials. Use when - scanning for secrets, security audit, finding leaked credentials. Trigger keywords - secrets scan, find credentials, security scan, leaked keys, security audit.

Processing 31 6mo ago
mastepanoski

don-norman-principles-audit

by mastepanoski

Evaluate UX/UI using Don Norman's 7 fundamental design principles from The Design of Everyday Things. Audit discoverability, affordances, signifiers, feedback, mapping, constraints and conceptual models.

Code Review 48 7mo ago
acedergren

health-check

by acedergren

"Run all quality gates across the entire codebase and report results. Headless — no analysis, just execute and print. Use for pre-PR validation, phase completion, or routine health monitoring."

CLI Tools 26 6mo ago
Geeksfino

code-review

by Geeksfino

Reviews code for quality, best practices, and potential issues. Use when asked to review, audit, or check code for problems.

Code Review 70 7mo ago
acedergren

api-audit

by acedergren

"Audit API routes against shared types — scan routes, plugins, and types for mismatches. Read-only, no changes. Use before PRs, after adding routes, or for periodic API contract validation."

API Dev 26 6mo ago
acedergren

prod-readiness

by acedergren

Autonomous production readiness review pipeline — spawns 5 parallel specialist agents (security, testing, performance, observability, code quality) and synthesizes findings into a prioritized remediation plan. Use before major releases or milestone completions.

Code Review 26 6mo ago
acedergren

doc-sync

by acedergren

"Audit project documentation against the codebase and fix drift. Run before PRs or after major changes. Compares documented architecture, test counts, and file paths against actual state."

Code Review 26 6mo ago
acedergren

review-all

by acedergren

"Pre-PR review pipeline — runs security, API audit, and scope check agents in parallel. Read-only, no changes. Use before creating PRs or after completing a phase of work."

Code Review 26 6mo ago
Geeksfino

event-driven-detector

by Geeksfino

Identify and analyze corporate events that create mispricing opportunities, including M&A, spinoffs, buybacks, restructurings, and index changes. Use when the user asks about merger arbitrage, spinoff opportunities, share buyback analysis, corporate restructuring plays, index rebalancing trades, special situations investing, or event-driven strategies.

Code Gen 278 7mo ago
plurigrid

address-sanitizer

by plurigrid

Use AddressSanitizer to detect memory safety bugs in C/C++ programs. Identifies use-after-free, buffer overflow, memory leaks, and other memory errors.

Legal 61 7mo ago
armanzeroeight

security-group-analyzer

by armanzeroeight

Audit AWS security groups for overly permissive rules and security vulnerabilities. Use when reviewing AWS security, auditing security groups, or improving network security posture.

Cloud 29 9mo ago
armanzeroeight

ssl-helper

by armanzeroeight

Configures SSL/TLS certificates, implements secure protocols and ciphers, and sets up security headers. Use when setting up HTTPS, SSL certificates, TLS configuration, or web security hardening.

API Dev 29 9mo ago