Security

Security scanning and vulnerability detection

Showing 913-936 of 2236 skills
LaravelDaily

technical-debt-manager-php-laravel

by LaravelDaily

Expert technical debt analyst for PHP/Laravel code health, maintainability, and strategic refactoring planning. Use PROACTIVELY when a Laravel codebase shows complexity growth, when planning sprints, or when prioritizing engineering work.

Code Review 45 5mo ago
ancoleman

configuring-firewalls

by ancoleman

Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts. Use when exposing services, hardening servers, or implementing network segmentation with defense-in-depth strategies.

Cloud 388 7mo ago
ancoleman

architecting-security

by ancoleman

Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001). Use when designing security for new systems, auditing existing architectures, or establishing security governance programs.

Cloud 388 7mo ago
ancoleman

configuring-nginx

by ancoleman

Configure nginx for static sites, reverse proxying, load balancing, SSL/TLS termination, caching, and performance tuning. When setting up web servers, application proxies, or load balancers, this skill provides production-ready patterns with modern security best practices for TLS 1.3, rate limiting, and security headers.

API Dev 388 7mo ago
ancoleman

implementing-service-mesh

by ancoleman

Implement production-ready service mesh deployments with Istio, Linkerd, or Cilium. Configure mTLS, authorization policies, traffic routing, and progressive delivery patterns for secure, observable microservices. Use when setting up service-to-service communication, implementing zero-trust security, or enabling canary deployments.

Kubernetes 388 7mo ago
mitkox

security-audit-rlm

by mitkox

Run and troubleshoot privacy-preserving, local DSPy RLM security audits for large legacy .NET codebases. Use when asked to scan repositories for vulnerabilities, tune RLM/tool limits, fix truncation/stall issues, or produce actionable markdown/json audit outputs without loading entire codebases into model context.

File Ops 76 5mo ago
omer-metin

Auth Specialist

by omer-metin

API Dev 115 6mo ago
ancoleman

operating-kubernetes

by ancoleman

Operating production Kubernetes clusters effectively with resource management, advanced scheduling, networking, storage, security hardening, and autoscaling. Use when deploying workloads to Kubernetes, configuring cluster resources, implementing security policies, or troubleshooting operational issues.

Kubernetes 388 7mo ago
docxology

Codomyrmex

by docxology

Full-spectrum coding workspace skill providing 171 MCP tools across 33 modules. USE WHEN user says 'verify codomyrmex', 'codomyrmexVerify', 'audit codomyrmex', 'trust codomyrmex', 'codomyrmexTrust', 'trust tools', 'enable destructive tools', 'check pai status', 'codomyrmex tools', 'codomyrmex analyze', 'codomyrmex search', 'codomyrmex memory', 'codomyrmex docs', 'codomyrmex status', 'codomyrmex git', 'codomyrmex security', 'codomyrmex ai', 'codomyrmex code', 'codomyrmex data', 'codomyrmex deploy', 'codomyrmex test', or uses any 'codomyrmex' automation tools.

Code Review 7 4mo ago
ahmed-lakosha

odoo-security

by ahmed-lakosha

"Comprehensive Odoo security auditor for model access rules, HTTP route authentication, sudo() usage, SQL injection risks, and record rule completeness across Odoo 14-19."

Processing 71 5mo ago
kcns008

security

by kcns008

Security Agent (Shield) — handles Pod Security Standards, RBAC audits, NetworkPolicy enforcement, secrets management (Vault), image scanning (Trivy), policy enforcement (Kyverno/OPA), CIS benchmarks, and compliance for Kubernetes and OpenShift clusters.

Docker 25 4mo ago
alffei

springboot-init

by alffei

Define development specifications for Spring Boot monolithic projects, supporting multiple technology stack configurations.

Code Gen 69 5mo ago
groupzer0

code-review-checklist

by groupzer0

Structured code review criteria for pre-implementation plan review (Critic) and post-implementation security/quality review. Covers security, performance, maintainability, and correctness with severity ratings.

Agents 280 7mo ago
shaniidev

bug-reaper

by shaniidev

"Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF, IDOR, auth bypass, RCE, SSTI, LFI, XXE, CORS, CSRF, prototype pollution, subdomain takeover, HTTP smuggling, open redirect, API/GraphQL bugs; auditing locally downloaded GitHub repos or source code (white-box/source code review); writing platform-specific reports. Trigger on: 'pentest', 'find bugs', 'security audit', 'bug bounty', 'find vulnerabilities', 'source code review', 'audit this repo', 'review repo', 'white-box', 'local repo', vulnerability class names, or program/target names. Reports only real, confirmed medium+ severity bugs that pass real triage."

API Dev 62 5mo ago
yoanbernabeu

supabase-audit-rls

by yoanbernabeu

Test Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.

Code Review 57 5mo ago
yoanbernabeu

supabase-detect

by yoanbernabeu

Detect if a web application uses Supabase by analyzing client-side code, network patterns, and API endpoints.

API Dev 57 5mo ago
yoanbernabeu

supabase-report-compare

by yoanbernabeu

Compare two security audit reports to track remediation progress and identify new vulnerabilities.

Code Gen 57 5mo ago
yoanbernabeu

supabase-audit-buckets-list

by yoanbernabeu

List all storage buckets and their configuration to identify the storage attack surface.

Code Review 57 5mo ago
yoanbernabeu

supabase-pentest

by yoanbernabeu

Orchestrate a complete Supabase security audit with guided step-by-step execution and ownership confirmation.

Code Review 57 5mo ago
yoanbernabeu

supabase-audit-tables-read

by yoanbernabeu

Attempt to read data from exposed tables to verify actual data exposure and RLS effectiveness.

Code Review 57 5mo ago
yoanbernabeu

supabase-audit-rpc

by yoanbernabeu

List and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.

Code Review 57 5mo ago
yoanbernabeu

supabase-audit-functions

by yoanbernabeu

Discover and test Supabase Edge Functions for security vulnerabilities and misconfigurations.

Auth 57 5mo ago
yoanbernabeu

supabase-evidence

by yoanbernabeu

Initialize and manage the evidence collection directory for professional security audits with documented proof of findings.

Code Review 57 5mo ago
yoanbernabeu

supabase-audit-realtime

by yoanbernabeu

Test Supabase Realtime WebSocket channels for unauthorized subscriptions and data exposure.

Code Review 57 5mo ago