Security

Security scanning and vulnerability detection

Showing 817-840 of 2236 skills
oyi77

code-reviewer

by oyi77

Professional code review skill. Review local changes or PRs for correctness, maintainability, and best practices. Based on playbooks.com community skill.

Code Review 5 4mo ago
mastepanoski

owasp-llm-top10

by mastepanoski

Security audit for LLM and GenAI applications using OWASP Top 10 for LLM Apps 2025. Assess prompt injection, data leakage, supply chain, and 7 more critical vulnerabilities.

Processing 44 5mo ago
mgiovani

team-review

by mgiovani

"Multi-agent PR review team orchestration with 7 specialized reviewers for security-sensitive or architectural PRs. Spawns architecture, security, performance, testing, style, docs/UX, and adversary reviewers as a coordinated team. Premium review for critical code changes."

Agents 6 5mo ago
mgiovani

review-security

by mgiovani

Perform comprehensive security review targeting OWASP Top 10 2025 vulnerabilities

Agents 6 5mo ago
mgiovani

review-deps

by mgiovani

Audit project dependencies for vulnerabilities, license compliance risks,

Code Review 6 5mo ago
majesticlabs-dev

devops-plan

by majesticlabs-dev

Gather DevOps context for infrastructure planning. Detects IaC tools, providers, and recommends skills. Use when /majestic:plan detects infrastructure work.

Cloud 43 5mo ago
majesticlabs-dev

infra-security-review

by majesticlabs-dev

Security patterns and checklists for reviewing Infrastructure-as-Code. Covers Terraform/OpenTofu state, secrets, network, compute, database, and storage security.

Code Review 43 6mo ago
niracler

code-sync

by niracler

Use when syncing all git repos under ~/code across machines, typically at end-of-day (push) or start-of-day (pull). Triggers on「同步代码」「code-sync」「下班同步」「上班更新」.

Analytics 11 5mo ago
runkids

insecure-defaults

by runkids

"Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling."

Auth 11 4mo ago
runkids

firebase-apk-scanner

by runkids

Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzing APK files for Firebase vulnerabilities, performing mobile app security audits, or testing Firebase endpoint security. For authorized security research only.

Auth 11 4mo ago
runkids

differential-review

by runkids

Performs security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.

Analytics 11 4mo ago
runkids

audit-context-building

by runkids

Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.

ML Ops 11 4mo ago
runkids

feature-radar-scan

by runkids

Discover new feature opportunities from creative brainstorming, user feedback, ecosystem trends, and cross-project research. Writes results to .feature-radar/opportunities/. MUST use this skill when the user wants to GENERATE new ideas — not evaluate existing ones. Trigger on any request to brainstorm, explore, discover, or find new feature ideas, even casual ones like "I wonder what else we could do" or "give me ideas". Use when the user: - Asks "what else could we build?", "give me feature ideas", "what are we missing?" - Wants to brainstorm, explore new directions, or refresh the opportunity backlog - Says "scan ecosystem", "scan opportunities", "find new features" - Asks to review GitHub issues, community feedback, or adjacent tools for inspiration - Mentions "explore", "discover", or "new directions" in a feature context Do NOT use for evaluating/prioritizing existing features — that's feature-radar's job.

Code Gen 11 4mo ago
odyssey4me

code-review

by odyssey4me

Review PRs, MRs, and Gerrit changes with focus on security, maintainability, and architectural fit. Leverages github, gitlab, or gerrit skills based on repository context.

Code Review 11 5mo ago
runkids

docker-expert

by runkids

Docker containerization expert with deep knowledge of multi-stage builds, image optimization, container security, Docker Compose orchestration, and production deployment patterns. Use PROACTIVELY for Dockerfile optimization, container issues, image size problems, security hardening, networking, and orchestration challenges.

Docker 11 5mo ago
runkids

algorand-vulnerability-scanner

by runkids

Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).

Code Review 11 4mo ago
runkids

audit-prep-assistant

by runkids

Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments).

Accessibility 11 4mo ago
runkids

fp-check

by runkids

"Systematically verifies suspected security bugs to eliminate false positives. Produces TRUE POSITIVE or FALSE POSITIVE verdicts with documented evidence for each bug."

Code Review 11 4mo ago
runkids

secure-workflow-guide

by runkids

Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for fuzzing/verification, and reviews manual security areas.

Agents 11 4mo ago
runkids

cairo-vulnerability-scanner

by runkids

Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay. Use when auditing StarkNet projects.

Legal 11 4mo ago
runkids

cosmos-vulnerability-scanner

by runkids

Scans Cosmos SDK blockchains for 9 consensus-critical vulnerabilities including non-determinism, incorrect signers, ABCI panics, and rounding errors. Use when auditing Cosmos chains or CosmWasm contracts.

Agents 11 4mo ago
multiversx

clarification_expert

by multiversx

Expert at identifying underspecified requirements and asking high-value clarifying questions.

Code Review 12 5mo ago
multiversx

multiversx-clarification-expert

by multiversx

Identify ambiguous requirements and ask targeted clarifying questions for MultiversX development. Use when user requests are vague, missing technical constraints, or have conflicting requirements.

Code Review 12 5mo ago
multiversx

multiversx-project-culture

by multiversx

Assess codebase quality and maturity based on documentation, testing practices, and code hygiene indicators. Use when evaluating project reliability, estimating audit effort, or onboarding to new codebases.

Code Review 12 5mo ago