Security

Security scanning and vulnerability detection

Showing 865-888 of 2236 skills
koolamusic

nestjs-best-practices

by koolamusic

NestJS best practices and architecture patterns for building production-ready applications. This skill should be used when writing, reviewing, or refactoring NestJS code to ensure proper patterns for modules, dependency injection, security, and performance.

API Dev 9 5mo ago
rocky2431

security-rules

by rocky2431

Ultra Builder Pro security rules

Auth 9 5mo ago
1Password

security-awareness

by 1Password

Teaches AI agents to recognize and avoid security threats during normal activity. Covers phishing detection, credential protection, domain verification, and social engineering defense. Use when building agents that access email, credential vaults, web browsers, or sensitive data.

Email 134 5mo ago
omer-metin

Anti Marketing

by omer-metin

Code Review 115 6mo ago
dykyi-roman

access-control-knowledge

by dykyi-roman

Access Control knowledge base. Provides ACL, RBAC, ABAC, ReBAC models, multi-tenancy patterns, and PHP implementations (Symfony Voters, Laravel Gates) for security audits and generation.

Auth 92 5mo ago
rand

discover-security

by rand

Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management. Activates for application security, OWASP, and security hardening tasks.

Auth 117 5mo ago
rand

discover-containers

by rand

Automatically discover container skills when working with Docker, Dockerfile optimization, docker-compose, container networking, container security, container registries, or Kubernetes. Activates for containerization and orchestration tasks.

Agents 117 5mo ago
srstomp

security-audit

by srstomp

Use when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying OWASP vulnerabilities (injection, XSS, CSRF), or addressing security concerns about implementations.

Auth 9 5mo ago
srstomp

feature-audit

by srstomp

Use when verifying feature completeness against PRD requirements, identifying gaps between backend implementation and user-facing accessibility, generating remediation tasks, or auditing across frameworks (Next.js, React Router, TanStack, React Native, Expo).

Accessibility 9 5mo ago
srstomp

api-design

by srstomp

Use when designing new REST APIs, reviewing API designs, establishing API standards, designing request/response formats, pagination, versioning, authentication flows, or creating OpenAPI specifications.

API Dev 9 5mo ago
dougkeefe

gc-review-security

by dougkeefe

"Use when reviewing code changes for Protected B security compliance. Triggers: security review, ITSG-33 compliance, GoC security, Protected B data handling, access control review, PII protection check, or requests to audit security-sensitive code."

Code Review 13 5mo ago
mfwarren

founder-productivity

by mfwarren

Production-ready entrepreneurship skills for Claude Code — marketing, sales, operations, finance, and leadership. 24 skills built by a founder, for founders.

Automation 43 5mo ago
yoanbernabeu

supabase-help

by yoanbernabeu

Quick reference for all Supabase security audit skills with usage examples and command overview.

Auth 57 5mo ago
Aedelon

security-audit

by Aedelon

Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults. MUST BE USED when user mentions: "security", "vulnerability", "audit", "OWASP", "CVE", "security review", "pentest", "injection", "XSS", "CSRF", "authentication", "authorization", "secrets", "hardcoded password", "secure", "npm audit", "pip-audit", "check security", "is this secure", "security risk", "data leak", "SQL injection", "command injection", "path traversal", "SSRF", "RCE", "privilege escalation", "supply chain", "dependency scan", "snyk", "trivy", "semgrep", "bandit". Scans code for vulnerabilities, checks dependencies, verifies auth patterns. NOT for explaining security concepts (use pedagogical-explain), or general code review (use code-review).

Security 108 4mo ago
alchemiststudiosDOTai

codebase-research

by alchemiststudiosDOTai

This skill should be used when mapping or researching a codebase to understand its structure, patterns, and architecture. Use when the user asks to "map the codebase", "research how X works", "find all Y patterns", or needs to understand code organization. Produces factual structural maps in memory-bank/research/—no suggestions, no recommendations, just what exists. Uses ast-grep for structural pattern matching.

Academic 104 4mo ago
kadenzipfel

scv-scan

by kadenzipfel

Systematically audit Solidity smart contract codebases for security vulnerabilities using a 4-phase approach - load a vulnerability cheatsheet, sweep code with grep and semantic analysis, deep-validate candidates against reference files, and output a severity-ranked findings

Security 104 4mo ago
greatpie

smart-contract-audit

by greatpie

Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology. Use when asked to audit a smart contract repo from a URL or local path, auto-prepare the environment, find high-severity loss-of-funds vulnerabilities, validate exploitability, propose safe fixes, and deliver a structured report with exact code references.

CLI Tools 101 5mo ago
yoanbernabeu

supabase-audit-authenticated

by yoanbernabeu

Create a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation.

Auth 57 5mo ago
matteocervelli

frontend-design-fix

by matteocervelli

Fix generic frontend designs by applying aesthetic upgrades across the 5 design dimensions

Code Review 25 8mo ago
rfxlamia

red-teaming

by rfxlamia

Comprehensive red teaming methodology for both cybersecurity and AI/LLM systems. Use when conducting adversary emulation, vulnerability assessment, attack simulation, or security validation. Trigger on requests for penetration testing, threat modeling, security audits, MITRE ATT&CK operations, LLM safety testing, prompt injection attacks, or compliance validation (OWASP, NIST, TIBER, DORA, EU AI Act). Apply when users ask to "test like an attacker", "red team our system", "validate security posture", "assess LLM vulnerabilities", or "simulate cyber attacks". Includes planning frameworks, execution strategies, reporting templates, and progressive references to specialized attack techniques and tools.

Legal 98 5mo ago
multiversx

mvx_dapp_audit

by multiversx

Auditing dApps and standard Frontend flows.

Code Review 12 5mo ago
multiversx

multiversx-security-audit

by multiversx

Complete security audit methodology for MultiversX smart contracts. Covers context building, entry point analysis, static analysis patterns, and automated Semgrep scanning. Use when performing security audits, code reviews, or setting up automated vulnerability detection.

API Dev 12 5mo ago
multiversx

multiversx-dapp-audit

by multiversx

Audit frontend dApp components for security vulnerabilities in wallet integration and transaction handling. Use when reviewing React/TypeScript dApps using sdk-dapp, or assessing client-side security.

Processing 12 5mo ago
lisbeth718

pseo-orchestrate

by lisbeth718

Orchestrate the full programmatic SEO implementation by coordinating all pseo-* skills in the correct order. Use when implementing pSEO from scratch, running the full pSEO pipeline, or when the user asks to "set up programmatic SEO" or "build pSEO pages" without specifying a single skill.

Code Review 51 5mo ago