Security

Security scanning and vulnerability detection

Showing 937-960 of 2236 skills
yoanbernabeu

supabase-extract-anon-key

by yoanbernabeu

Extract the Supabase anon/public API key from client-side code. This key is expected in client apps but important for RLS testing.

Processing 57 5mo ago
groupzer0

security-patterns

by groupzer0

Security vulnerability detection patterns including OWASP Top 10, language-specific vulnerabilities, and remediation guidance. Load when reviewing code for security issues, conducting audits, or implementing authentication/authorization.

Auth 280 7mo ago
udapy

Agent Router

by udapy

Analyzing user intent and delegating tasks.

Code Gen 48 6mo ago
martinholovsky

Auto-Update Systems Expert

by martinholovsky

Expert in Tauri auto-update implementation with focus on signature verification, rollback mechanisms, staged rollouts, and secure update distribution

Processing 45 8mo ago
martinholovsky

prompt-engineering

by martinholovsky

"Expert skill for prompt engineering and task routing/orchestration. Covers secure prompt construction, injection prevention, multi-step task orchestration, and LLM output validation for JARVIS AI assistant."

Prompts 45 8mo ago
martinholovsky

cicd-expert

by martinholovsky

"Elite CI/CD pipeline engineer specializing in GitHub Actions, GitLab CI, Jenkins automation, secure deployment strategies, and supply chain security. Expert in building efficient, secure pipelines with proper testing gates, artifact management, and ArgoCD/GitOps patterns. Use when designing pipelines, implementing security gates, or troubleshooting CI/CD issues."

CI/CD 45 8mo ago
martinholovsky

CI/CD Pipeline Security Expert

by martinholovsky

Expert in CI/CD pipeline design with focus on secret management, code signing, artifact security, and supply chain protection for desktop application builds

CI/CD 45 8mo ago
martinholovsky

applescript

by martinholovsky

"Expert in AppleScript and JavaScript for Automation (JXA) for macOS system scripting. Specializes in secure script execution, application automation, and system integration. HIGH-RISK skill due to shell command execution and system-wide control capabilities."

Automation 45 8mo ago
workleap

workleap-chromatic-best-practices

by workleap

Workleap's Chromatic best practices for snapshot cost control and CI optimization. Use this skill when: (1) Auditing or implementing Chromatic cost optimizations in a repository (2) Fixing Chromatic TurboSnap-disabling patterns (barrel imports, large preview dependencies, local scripts) (3) Setting up or updating chromatic.config.json and GitHub Actions CI workflows for Chromatic (4) Reviewing PRs for Chromatic snapshot cost impact (5) Configuring Chromatic in Turborepo/monorepo projects

CI/CD 6 4mo ago
pubnub

pubnub-security

by pubnub

Secure PubNub applications with Access Manager, encryption, and TLS

Auth 6 5mo ago
TheSethRose

clawdbot-self-security-audit

by TheSethRose

Perform a comprehensive read-only security audit of Clawdbot's own configuration. This is a knowledge-based skill that teaches Clawdbot to identify hardening opportunities and generate reports. Use when user asks to "run security check", "audit clawdbot", "check security hardening", or "what vulnerabilities do I have". This skill only READS configuration and generates reports—it never modifies settings or executes fixes automatically. Designed to be extensible—new checks can be added by updating this skill's knowledge.

Code Review 63 5mo ago
OEN-Tech

Incident Report Generator — 資安事件通報報告產生器

by OEN-Tech

Taiwan PDPA (個人資料保護法) — Personal Data Protection Act

Processing 63 4mo ago
Z-M-Huang

vcp-config

by Z-M-Huang

View and modify VCP configuration. Add or remove ignore entries, toggle scopes, manage compliance frameworks, change severity threshold, and manage exclude patterns. Supports both project config (.vcp/config.json) and global config (~/.vcp/config.json).

Processing 14 4mo ago
Z-M-Huang

vcp-audit

by Z-M-Huang

Run a comprehensive audit against all applicable VCP standards. Supports full audit, compliance-specific audit, and quick release readiness check.

Code Review 14 4mo ago
adamos486

production-ready

by adamos486

Use when preparing any project for production deployment, performing security audits, or release preparation. Triggers on "make production ready", "security audit", "prepare for release", "hardening", "pre-deployment checklist".

Code Review 9 6mo ago
Aznatkoiny

openclaw-setup

by Aznatkoiny

Set up, install, configure, and deploy OpenClaw (formerly ClawdBot/MoltBot) — a personal AI assistant that runs on your own devices and connects to messaging channels. Use when users ask to "set up OpenClaw," "install ClawdBot," "install MoltBot," "deploy a personal AI assistant," "configure OpenClaw on Mac," "deploy OpenClaw to VPS," "set up OpenClaw on Hostinger," "connect OpenClaw to Telegram," "configure iMessage with OpenClaw," or any variation involving OpenClaw installation, gateway configuration, channel setup, Anthropic auth, or security hardening. Also triggers on "openclaw onboard," "openclaw doctor," "openclaw security audit," troubleshooting OpenClaw deployments, OpenClaw security, OpenClaw cost control, or ClawHub skills safety.

Auth 9 5mo ago
Tyler-R-Kendrick

security

by Tyler-R-Kendrick

Use when addressing cross-cutting security concerns that apply to all languages, frameworks, and platforms. Covers OWASP standards, threat modeling, authentication, cryptography, supply chain security, and AI security. USE FOR: application security strategy, security architecture, choosing security controls, OWASP compliance, security tool selection, secure development lifecycle DO NOT USE FOR: specific language security implementations (use language-specific skills), infrastructure hardening (use iac skills), network security appliance configuration

API Dev 9 5mo ago
olehsvyrydov

secops-engineer

by olehsvyrydov

Senior Security Engineer with 12+ years application security experience. Use when implementing authentication/authorization, configuring JWT/OAuth2, conducting security reviews, implementing rate limiting, ensuring GDPR compliance, or performing security scanning.

Auth 11 6mo ago
olehsvyrydov

backend-reviewer

by olehsvyrydov

Senior Backend Code Reviewer with 12+ years Java experience. Use when reviewing Java/Spring code, checking code quality and style, identifying code smells and anti-patterns, verifying security practices, ensuring test coverage, or configuring static analysis tools (Checkstyle, SpotBugs, SonarQube).

Code Review 11 6mo ago
olehsvyrydov

reviewer

by olehsvyrydov

Rev - Senior Full-Stack Code Reviewer with 12+ years experience in Java/Kotlin and TypeScript/React. Use when reviewing code quality, checking security vulnerabilities, validating style compliance, running static analysis tools, or ensuring test coverage. Also responds to 'Rev' or /rev command.

Code Review 11 6mo ago
app-incubator-xyz

skill-vetter

by app-incubator-xyz

"Multi-scanner security gate. TRIGGER when: user mentions installing, adding, or reviewing a skill to Claude Code, OpenClaw, or any other AI agent. Detects malicious code, vulnerabilities, and suspicious patterns."

Prompts 51 4mo ago
1Mangesh1

healthcare-audit-logger

by 1Mangesh1

This skill should be used when the user asks to "generate audit logs", "create HIPAA audit trail", "log healthcare events", "configure audit logging", "track PHI access", "maintain compliance logs", "audit log format", "healthcare event logging", "access control logging", "authentication logging", "HIPAA logging requirements", or mentions HIPAA audit trails, healthcare event logging, compliance logging, PHI access tracking, authentication auditing, or §164.312(b) logging requirements.

Code Review 6 5mo ago
1Mangesh1

hipaa-guardian

by 1Mangesh1

This skill should be used when the user asks to "scan for PHI", "detect PII", "HIPAA compliance check", "audit for protected health information", "find sensitive healthcare data", "generate HIPAA audit report", "check code for PHI leakage", "scan logs for PHI", "check authentication on PHI endpoints", "scan FHIR resources", "check HL7 messages", or mentions PHI detection, HIPAA compliance, healthcare data privacy, medical record security, logging PHI violations, authentication checks for health data, or healthcare data formats (FHIR, HL7, CDA).

Code Review 6 5mo ago
lv416e

differential-review

by lv416e

Performs security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.

Analytics 6 5mo ago