Security

Security scanning and vulnerability detection

Showing 1057-1080 of 2332 skills
yoanbernabeu

supabase-audit-rpc

by yoanbernabeu

List and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.

Code Review 67 7mo ago
yoanbernabeu

supabase-evidence

by yoanbernabeu

Initialize and manage the evidence collection directory for professional security audits with documented proof of findings.

Code Review 67 7mo ago
nahisaho

code-reviewer

by nahisaho

Copilot agent that assists with comprehensive code review focusing on code quality, SOLID principles, security, performance, and best practices Trigger terms: code review, review code, code quality, best practices, SOLID principles, code smells, refactoring suggestions, code analysis, static analysis Use when: User requests involve code reviewer tasks.

Auth 72 9mo ago
nahisaho

security-auditor

by nahisaho

security-auditor skill Trigger terms: security audit, vulnerability scan, OWASP, security analysis, penetration testing, security review, threat modeling, security best practices, CVE Use when: User requests involve security auditor tasks.

Database 72 9mo ago
nahisaho

design-reviewer

by nahisaho

Copilot agent that assists with systematic design review using ATAM (Architecture Tradeoff Analysis Method), SOLID principles, design patterns, coupling/cohesion analysis, error handling, and security requirements Trigger terms: design review, architecture review, ATAM, SOLID principles, design patterns, coupling, cohesion, ADR review, C4 review, architecture analysis, design quality Use when: User requests involve design document review, architecture evaluation, or design quality assessment tasks.

Code Review 72 8mo ago
sergiodxa

owasp-security-check

by sergiodxa

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

Auth 91 7mo ago
shaniidev

bug-reaper

by shaniidev

"Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF, IDOR, auth bypass, RCE, SSTI, LFI, XXE, CORS, CSRF, prototype pollution, subdomain takeover, HTTP smuggling, open redirect, API/GraphQL bugs; auditing locally downloaded GitHub repos or source code (white-box/source code review); writing platform-specific reports. Trigger on: 'pentest', 'find bugs', 'security audit', 'bug bounty', 'find vulnerabilities', 'source code review', 'audit this repo', 'review repo', 'white-box', 'local repo', vulnerability class names, or program/target names. Reports only real, confirmed medium+ severity bugs that pass real triage."

API Dev 67 6mo ago
LaravelDaily

technical-debt-manager-php-laravel

by LaravelDaily

Expert technical debt analyst for PHP/Laravel code health, maintainability, and strategic refactoring planning. Use PROACTIVELY when a Laravel codebase shows complexity growth, when planning sprints, or when prioritizing engineering work.

Code Review 48 6mo ago
third774

adversarial-code-review

by third774

Review code through hostile perspectives to find bugs, security issues, and unintended consequences the author missed. Use when reviewing PRs, auditing codebases, or before critical deployments.

Code Review 5 7mo ago
skyosev

security-hunter-ts

by skyosev

Audit TypeScript code for security vulnerabilities — hardcoded secrets, injection risks, missing input validation at trust boundaries, insecure defaults, auth gaps, sensitive data exposure, and unsafe patterns like eval or innerHTML. Use when: reviewing TypeScript code before deployment, auditing trust boundaries, preparing for a security review, onboarding third-party integrations, or hardening an application.

Auth 5 6mo ago
skyosev

simplicity-hunter-go

by skyosev

Audit Go code for unnecessary structural complexity — duplication, avoidable abstractions, dead logic paths, over-parameterized APIs, deep nesting, interface pollution, channel misuse, and mixed concerns. Recommends the simplest shape that preserves intended behavior. Use when: reviewing Go code for over-engineering, reducing complexity after prototyping, enforcing reuse over addition, or simplifying before a refactor.

File Ops 5 6mo ago
aihxp

godpowers

by aihxp

AI-powered development system that takes a project from raw idea to hardened production. Fuses artifact discipline, execution engine, quality enforcement, and team intelligence into one unified workflow. Triggers on: "god mode", "god init", "god prd", "god arch", "god roadmap", "god stack", "god repo", "god build", "god deploy", "god observe", "god launch", "god harden", "god status", "god audit", "god debug", "god review", "god smite", "godpowers", "start a project", "build this", "ship this", "take this from idea to production", "one-shot the whole thing", "autonomous build", "full arc", "idea to deploy"

Security 5 3mo ago
skyosev

security-hunter-go

by skyosev

Audit Go code for security vulnerabilities — hardcoded secrets, injection risks (SQL, command, template, path), missing input validation at trust boundaries, insecure defaults, auth gaps, sensitive data exposure, unsafe package usage, and weak crypto. Use when: reviewing Go code before deployment, auditing trust boundaries, preparing for a security review, onboarding third-party integrations, or hardening an application.

Auth 5 6mo ago
skyosev

simplicity-hunter-ts

by skyosev

Audit TypeScript code for unnecessary structural complexity — duplication, avoidable abstractions, dead logic paths, flag-heavy APIs, deep nesting, and mixed concerns. Recommends the simplest shape that preserves intended behavior. Use when: reviewing TypeScript code for over-engineering, reducing complexity after prototyping, enforcing reuse over addition, or simplifying before a refactor.

File Ops 5 6mo ago
acedergren

best-practices

by acedergren

Use when architecting OCI solutions, migrating from AWS/Azure, designing multi-AD deployments, or avoiding common OCI anti-patterns. Covers VCN sizing mistakes, Cloud Guard gotchas, free tier specifics, OCI terminology confusion, and multi-AD patterns.

Cloud 19 7mo ago
AIDotNet

security-scanner

by AIDotNet

全面的安全分析,识别OWASP Top 10漏洞、检测硬编码密钥和审查安全配置。

Database 83 7mo ago
AIDotNet

port-scanner

by AIDotNet

扫描网络端口以检查可用性和检测运行的服务。

CLI Tools 83 7mo ago
jgtolentino

audit-skill

by jgtolentino

Comprehensive audit capabilities for security, code quality, module structure, compliance, and performance analysis. Use this skill when performing security audits, code reviews, vulnerability assessments, module structure validation, or generating audit reports.

Code Review 22 10mo ago
Salesably

multithread-outreach

by Salesably

Creates role-specific messages for multiple stakeholders in a deal. Use this skill when engaging additional contacts, following up with people who weren't on calls, or executing account-based selling strategies.

Email 48 8mo ago
yoanbernabeu

supabase-extract-anon-key

by yoanbernabeu

Extract the Supabase anon/public API key from client-side code. This key is expected in client apps but important for RLS testing.

Processing 67 7mo ago
Flux-Point-Studios

aiken-dex-security-audit

by Flux-Point-Studios

Adversarial security audit playbook for Plutus V3 Aiken DEX contracts (threat model, invariants, findings, tests, tx repro shapes).

Analytics 8 7mo ago
Flux-Point-Studios

aiken-dex-security-audit-operator

by Flux-Point-Studios

"Operator skill: run local Aiken build/test commands and capture evidence for the audit. Manual invoke only."

Code Review 8 7mo ago
maxnorm

magento-security-analyst

by maxnorm

Conducts comprehensive Magento 2 security assessments and implements security measures. Use when auditing security, identifying vulnerabilities, implementing security controls, or ensuring compliance. Masters security auditing, vulnerability management, and compliance frameworks.

Processing 28 7mo ago
duongductrong

backend-development

by duongductrong

Build robust backend systems with modern technologies (Node.js, Python, Go, Rust), frameworks (NestJS, FastAPI, Django), databases (PostgreSQL, MongoDB, Redis), APIs (REST, GraphQL, gRPC), authentication (OAuth 2.1, JWT), testing strategies, security best practices (OWASP Top 10), performance optimization, scalability patterns (microservices, caching, sharding), DevOps practices (Docker, Kubernetes, CI/CD), and monitoring. Use when designing APIs, implementing authentication, optimizing database queries, setting up CI/CD pipelines, handling security vulnerabilities, building microservices, or developing production-ready backend systems.

API Dev 21 9mo ago