Security

Security scanning and vulnerability detection

Showing 889-912 of 2332 skills
florianbuetow

fix

by florianbuetow

This skill should be used when the user asks to "fix security finding", "fix vulnerability", "generate security fix", "appsec fix", "patch vulnerability", "remediate finding", or "apply security patch". Also triggers when the user references a finding ID (e.g., INJ-001) and asks for a fix, or points to a file:line and asks to fix the security issue there.

Code Gen 13 6mo ago
florianbuetow

logging

by florianbuetow

This skill should be used when the user asks to "check for logging issues", "analyze security logging", "find missing audit logs", "check for log injection", "audit monitoring configuration", or mentions "logging", "audit trail", "log injection", "monitoring", or "alerting" in a security context. Maps to OWASP Top 10 2021 A09: Security Logging and Monitoring Failures.

Processing 13 6mo ago
florianbuetow

repudiation

by florianbuetow

This skill should be used when the user asks to "check for repudiation", "analyze audit logging", "find logging gaps", or mentions "repudiation" or "non-repudiation" in a security context. Maps to STRIDE category R.

Code Review 13 6mo ago
florianbuetow

config

by florianbuetow

This skill should be used when the user asks to "configure security", "appsec settings", "security preferences", or invokes /appsec:config. Manages security tool preferences and thresholds.

Code Review 13 6mo ago
florianbuetow

pasta-vulns

by florianbuetow

This skill should be used when the user asks to "analyze vulnerabilities", "find security weaknesses", "map CWEs", "run vulnerability analysis", or is running PASTA stage 5. Also triggers when the user asks about SAST, DAST, dependency scanning, or CWE mapping in a threat modeling context. Part of the PASTA threat modeling methodology (Stage 5 of 7).

Auth 13 6mo ago
florianbuetow

insecure-design

by florianbuetow

This skill should be used when the user asks to "check for design flaws", "analyze security design", "find insecure design patterns", "review threat model", "check business logic security", "find missing security controls", or mentions "insecure design" in a security context. Maps to OWASP Top 10 2021 A04:2021 - Insecure Design.

Security 13 6mo ago
florianbuetow

auth

by florianbuetow

This skill should be used when the user asks to "check for authentication issues", "analyze auth", "find credential vulnerabilities", "review login security", "check session management", or mentions "authentication", "passwords", "MFA", "sessions", or "brute force" in a security context. Maps to OWASP Top 10 2021 A07: Identification and Authentication Failures.

Auth 13 6mo ago
florianbuetow

full-audit

by florianbuetow

This skill should be used when the user asks for a "full security audit", "exhaustive audit", "comprehensive security review", or invokes /appsec:full-audit. Launches every framework, every tool, and every red team agent, producing a dated report file.

Analytics 13 6mo ago
kriscard

code-assistant

by kriscard

"Development: Use when writing, debugging, or refactoring code. Orchestrates specialist agents (TypeScript, React, etc). NOT for architecture decisions."

Security 13 7mo ago
florianbuetow

access-control

by florianbuetow

This skill should be used when the user asks to "check for access control issues", "analyze authorization", "find IDOR vulnerabilities", "audit CORS configuration", "check for privilege escalation", or mentions "access control", "authorization", "IDOR", "CORS", "JWT tampering", or "directory traversal" in a security context. Maps to OWASP Top 10 2021 A01: Broken Access Control.

Auth 13 6mo ago
florianbuetow

misconfig

by florianbuetow

This skill should be used when the user asks to "check for misconfigurations", "analyze security headers", "find misconfigured settings", "check CORS policy", "find debug mode", "audit server configuration", or mentions "misconfiguration" in a security context. Maps to OWASP Top 10 2021 A05: Security Misconfiguration.

Processing 13 6mo ago
florianbuetow

review-plan

by florianbuetow

This skill should be used when the user asks to "review plan for security", "check plan for security issues", "security review of implementation plan", "audit the plan for vulnerabilities", or "check my plan before coding". Also triggers when the user mentions security in the context of an implementation plan, architecture proposal, or design document before code has been written. This is the FLAGSHIP pre-code security skill -- no other tool reviews plans at design time.

Auth 13 6mo ago
parhumm

sec-audit-remediate

by parhumm

Generate security fixes from detect-dev findings with regression tests. Use when remediating security vulnerabilities.

Code Gen 25 6mo ago
parhumm

detect-dev

by parhumm

Engineering audit with SARIF evidence, 4-level confidence, and OpenSSF scoring. Use when evaluating repository health or code quality.

Code Review 25 6mo ago
x-cmd

springboot-security

by x-cmd

Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

Auth 25 7mo ago
liqiongyu

enterprise-sales

by liqiongyu

"Create an Enterprise Deal Execution Pack (buying committee map + champion enablement, “no decision” prevention plan + mutual action plan, procurement/security packet, and POC-as-business-case plan + ROI model). Use for enterprise sales, procurement, security reviews, and enterprise pilots/POCs. Category: Sales & GTM."

Legal 52 7mo ago
liqiongyu

energy-management

by liqiongyu

"Build an Energy Management Operating System Pack (energy drivers/drains map, calendar energy audit, zone-of-genius expansion plan, energy-aligned weekly schedule, recovery routines, and 2-week experiments). Use for sustainable leadership performance and burnout prevention. Category: Leadership."

Automation 52 7mo ago
nesnilnehc

review-security

by nesnilnehc

"Review code for security: injection, sensitive data, authentication and authorization, dependencies and CVEs, configuration and secrets, and crypto. Cognitive-only atomic skill; output is a findings list."

Code Review 7 7mo ago
Ven0m0

skills-eval

by Ven0m0

'Evaluate and improve Claude skill quality through auditing. Use when

Code Review 7 7mo ago
rocky2431

security-rules

by rocky2431

Ultra Builder Pro security rules

Auth 11 7mo ago
kroegha

kali-docker-pentesting

by kroegha

Comprehensive pentesting toolkit using Kali Linux Docker container. Provides direct access to 200+ security tools without MCP overhead. Use when conducting security assessments, penetration testing, vulnerability scanning, or security research. Works via direct docker exec commands for maximum efficiency.

CLI Tools 22 9mo ago
project-codeguard

software-security

by project-codeguard

A software security skill that integrates with Project CodeGuard to help AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.

Auth 421 7mo ago
yoanbernabeu

supabase-audit-rls

by yoanbernabeu

Test Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.

Code Review 67 7mo ago
yoanbernabeu

supabase-help

by yoanbernabeu

Quick reference for all Supabase security audit skills with usage examples and command overview.

Auth 67 7mo ago