Security

Security scanning and vulnerability detection

Showing 1057-1080 of 2236 skills
outfitter-dev

simplify

by outfitter-dev

This skill should be used when evaluating complexity, planning features, or when "over-engineering", "simpler", "is this overkill", or "keep it simple" are mentioned.

Processing 27 5mo ago
outfitter-dev

code-review

by outfitter-dev

This skill should be used when reviewing code before commit, conducting quality gates, or when "review", "fresh eyes", "pre-commit review", or "quality gate" are mentioned.

Code Review 27 5mo ago
outfitter-dev

claude-agents

by outfitter-dev

This skill should be used when creating agents, writing agent frontmatter, configuring subagents, or when "create agent", "agent.md", "subagent", or "Task tool" are mentioned.

Agents 27 5mo ago
0xlayerghost

solidity-audit

by 0xlayerghost

"Security audit and code review checklist. Covers 30+ vulnerability types with real-world exploit cases (2021-2026) and EVMbench Code4rena patterns. Use when conducting security audits, code reviews, or pre-deployment security assessments."

Code Review 4 5mo ago
0xlayerghost

solidity-security

by 0xlayerghost

"[AUTO-INVOKE] MUST be invoked BEFORE writing or modifying any Solidity contract (.sol files). Covers private key handling, access control, reentrancy prevention, gas safety, and pre-audit checklists. Trigger: any task involving creating, editing, or reviewing .sol source files."

Code Review 4 5mo ago
zircote

backend-development

by zircote

Build robust backend systems with modern technologies (Node.js, Python, Go, Rust), frameworks (NestJS, FastAPI, Django), databases (PostgreSQL, MongoDB, Redis), APIs (REST, GraphQL, gRPC), authentication (OAuth 2.1, JWT), testing strategies, security best practices (OWASP Top 10), performance optimization, scalability patterns (microservices, caching, sharding), DevOps practices (Docker, Kubernetes, CI/CD), and monitoring. Use when designing APIs, implementing authentication, optimizing database queries, setting up CI/CD pipelines, handling security vulnerabilities, building microservices, or developing production-ready backend systems.

API Dev 26 7mo ago
zircote

python-deprecation-fixer

by zircote

Automatically detect and fix Python deprecation warnings in codebases, including datetime.utcnow(), and other common deprecated patterns. Supports extensible pattern matching for future deprecations.

CLI Tools 26 7mo ago
vchirrav

network-scan-nmap

by vchirrav

Run Nmap for network discovery and security auditing. Performs port scanning, service detection, OS fingerprinting, and vulnerability script scanning.

CLI Tools 16 5mo ago
vchirrav

sast-bandit

by vchirrav

Run Bandit SAST scans on Python code. Detects common security issues like SQL injection, hardcoded passwords, exec usage, and insecure crypto.

Processing 16 5mo ago
vchirrav

cloud-security-prowler

by vchirrav

Run Prowler for comprehensive cloud security posture assessment. Audits AWS, Azure, and GCP against CIS Benchmarks, PCI-DSS, HIPAA, GDPR, and other compliance frameworks.

Cloud 16 5mo ago
vchirrav

api-security-spectral

by vchirrav

Run Spectral to lint OpenAPI and AsyncAPI specs for security issues. Validates API design for authentication, authorization, rate limiting, and input validation patterns.

API Dev 16 5mo ago
vchirrav

sast-eslint-security

by vchirrav

Run ESLint with security plugins on JavaScript/TypeScript code. Detects eval usage, non-literal RegExp, prototype pollution, and other JS/TS security anti-patterns.

Processing 16 5mo ago
vchirrav

cloud-security-scoutsuite

by vchirrav

Run ScoutSuite for multi-cloud security auditing. Collects configuration data from AWS, Azure, GCP, Oracle, and Alibaba Cloud and generates an interactive security report.

Cloud 16 5mo ago
vchirrav

sast-psalm

by vchirrav

Run Psalm with taint analysis on PHP code. Detects SQL injection, XSS, command injection, path traversal, and other taint-flow vulnerabilities in PHP applications.

Processing 16 5mo ago
vchirrav

iac-scan-tfsec

by vchirrav

Run tfsec (now part of Trivy) to scan Terraform code for security misconfigurations. Deep HCL analysis with support for Terraform modules, variables, and expressions.

Cloud 16 5mo ago
vchirrav

dast-zap

by vchirrav

Run OWASP ZAP for Dynamic Application Security Testing. Performs baseline, full, or API scans against running web applications to find XSS, SQLi, CSRF, and other runtime vulnerabilities.

API Dev 16 5mo ago
vchirrav

secret-scan-gitleaks

by vchirrav

Run Gitleaks to detect hardcoded secrets in git repositories. Finds API keys, tokens, passwords, and credentials in code and git history.

Processing 16 5mo ago
vchirrav

sca-npm-audit

by vchirrav

Run npm audit for Node.js dependency vulnerability scanning. Built-in SCA for npm projects with automatic fix suggestions.

Code Review 16 5mo ago
vchirrav

container-scan-dockle

by vchirrav

Run Dockle to audit container images against CIS Docker Benchmark and best practices. Checks for running as root, sensitive files, HEALTHCHECK, and more.

Processing 16 5mo ago
andrew

managing-dependencies

by andrew

Evaluates packages, manages dependencies, and addresses supply chain security. Use when adding npm/pip/cargo/bundler/go dependencies, auditing packages, reviewing lockfile changes, checking for vulnerabilities, comparing package alternatives, or assessing package trustworthiness.

Code Review 16 6mo ago
vchirrav

sast-semgrep

by vchirrav

Run Semgrep SAST scans on code. Supports 30+ languages with OWASP, security, and custom rulesets. Parses results and provides remediation guidance.

CI/CD 16 5mo ago
vchirrav

dast-nuclei

by vchirrav

Run Nuclei template-based vulnerability scanner. Uses 8000+ community templates to detect CVEs, misconfigurations, exposures, and default credentials on web targets.

Code Gen 16 5mo ago
vchirrav

license-scan-scancode

by vchirrav

Run ScanCode Toolkit for comprehensive license and copyright detection. Identifies license types, copyright holders, and compliance obligations across codebases.

Processing 16 5mo ago
vchirrav

sast-detekt

by vchirrav

Run detekt static analysis on Kotlin code with security-focused rules. Detects hardcoded secrets, insecure crypto, and code quality issues affecting security.

CLI Tools 16 5mo ago