Security

Security scanning and vulnerability detection

Showing 1321-1344 of 2236 skills
CsHeng

security-logging

by CsHeng

Security controls and structured logging implementation. Use when security logging guidance is required.

File Ops 10 6mo ago
CuriousLearner

security-headers

by CuriousLearner

Validate and implement HTTP security headers to protect web applications.

API Dev 27 9mo ago
gked2121

code-review-pro

by gked2121

Comprehensive code review covering security vulnerabilities, performance bottlenecks, best practices, and refactoring opportunities. Use when user requests code review, security audit, or performance analysis.

Code Review 27 9mo ago
CuriousLearner

dependency-updater

by CuriousLearner

Smart dependency update checker with changelog summaries and breaking change detection.

Code Gen 27 9mo ago
CuriousLearner

code-reviewer

by CuriousLearner

Automated code review with best practices, security checks, and quality standards.

Database 27 9mo ago
CuriousLearner

compliance-checker

by CuriousLearner

Check code against security compliance standards and best practices.

Processing 27 9mo ago
CuriousLearner

secret-scanner

by CuriousLearner

Detect accidentally committed secrets, credentials, and sensitive information in code.

Cloud 27 9mo ago
gked2121

brand-consistency-checker

by gked2121

Scan documents and slides for off-brand colors, fonts, and logos. Validate against brand guidelines and suggest corrections.

Code Gen 27 9mo ago
CuriousLearner

dependency-auditor

by CuriousLearner

Automated security auditing of project dependencies to identify known vulnerabilities.

CLI Tools 27 9mo ago
CuriousLearner

meeting-notes

by CuriousLearner

Convert meeting discussions into clear, actionable notes with tasks, decisions, and follow-ups fo...

Code Review 27 9mo ago
WhatIfWeDigDeeper

uv-deps

by WhatIfWeDigDeeper

Maintain Python packages through security audits or dependency updates on a dedicated branch using uv. Use for: security audits, CVE fixes, vulnerability checks, dependency updates, package upgrades, outdated packages, bump versions, fix Python vulnerabilities, check for Python CVEs, audit Python packages, update pyproject.toml dependencies, modernize Python deps, or when user types "/uv-deps" with or without specific package names or glob patterns. Use "help" or "--help" to show options.

Code Review 2 4mo ago
br3eze-code

Available Skills in AgentOS (br3ezeclaw)

by br3eze-code

Code Gen 2 3mo ago
zalaca

SKILL: Traducción SC en-EN → es-ES

by zalaca

Vulture, Vulcan, X1

File Ops 2 3mo ago
br3eze-code

Available Skills in AgentOS (br3ezeclaw)

by br3eze-code

Code Gen 2 3mo ago
display-design-studio

ruby-on-rails

by display-design-studio

Comprehensive Ruby on Rails 8.1 best-practices skill covering MVC, Active Record, routing, views, background jobs, storage, security, testing, and performance. Use when the user mentions Rails, Ruby on Rails, ActiveRecord, ActiveJob, ActionMailer, ActionCable, Active Storage, rails generate, rails routes, Hotwire, Turbo, Stimulus, or asks to build, review, debug, or migrate a Rails application or API.

Code Gen 2 4mo ago
isdvsv

bug-hunter

by isdvsv

"Adversarial bug hunting with a sequential-first pipeline (Recon, Hunter, Skeptic, Referee) that can optionally use safe read-only parallel triage. Finds, verifies, and auto-fixes real bugs by default (with --scan-only opt-out) using checkpointed verification and resume state for large codebases. Use this skill whenever the user wants bug finding, security audits, regression checks, or code review focused on runtime behavior."

CLI Tools 2 4mo ago
dvmrry

zscaler

by dvmrry

Answer questions about the Zscaler portfolio — full operational depth (Tier 1, with SDK / TF / OneAPI exposure) on ZIA, ZPA (including AppProtection inline WAF/IPS and Browser Access), ZCC (Client Connector), ZDX (Digital Experience), ZBI (Zero Trust Browser / Cloud Browser Isolation), ZIdentity (unified identity + OneAPI authentication + step-up auth), Cloud & Branch Connector (ZTW/ZTC — VM-based traffic forwarding for cloud workloads and branch offices), and ZWA (Workflow Automation — DLP incident lifecycle); plus extended awareness with reasoning docs (Tier 2a, portal-only / no SDK) on Deception (decoys/honeypots for post-perimeter detection), Risk360 (cyber risk quantification / Monte Carlo / CISO board reporting), the AI Security family (AI Guard runtime guardrails for LLM prompt-injection / jailbreak / sensitive-data / toxicity / refusal detection plus AI Red Teaming / AI Guardrails / four-pillar governance), and ZMS (workload microsegmentation east-west, host-agent + WFP/nftables enforcement); plus paragraph-level awareness (Tier 2b) of ZINS (shadow-IT NSS Collector), EASM, Federal Cloud variants, ITDR, DSPM, Posture Control, and others. Covers URL category coverage, URL filtering rule precedence, wildcard matching semantics, SSL inspection ordering, cloud app control interaction with URL filtering, DLP three-layer model, sandbox / malware / ATP, firewall filtering, ZPA app-segment matching and policy evaluation order, AppProtection profiles / paranoia levels, Browser Access wildcard certificate rules, ZCC forwarding-profile / trusted-network decisions (which decide whether traffic reaches ZIA or ZPA in the first place), ZDX score / probe / diagnostic-session questions about user experience, browser isolation (Isolate action, Smart Browser Isolation, isolation profiles), Cloud Connector provisioning and activation, and Zscaler portfolio breadth ("what is X?", "does Zscaler do Y?"). Use whenever the user mentions Zscaler, ZIA, ZPA, ZCC, ZDX, ZBI, ZWA, ZTW, ZTC, CBC, Zero Trust Browser, Cloud Browser Isolation, Client Connector, AppProtection, Browser Access, Deception, Risk360, AI Guard, AI Guardrails, AI Red Teaming, AI Security, ZMS, microsegmentation, east-west traffic, ZINS, EASM, URL categories, URL filtering, cloud app control, SSL inspection, DLP, sandbox, app segments, forwarding profiles, trusted networks, ZDX score, probes, diagnostic sessions / deeptraces, isolation profiles, prompt injection, jailbreak detection, LLM guardrails, or asks "is $URL covered / blocked / allowed". Also use for "why does this rule win", "what happens when these policies overlap", "why is this user's app slow", "what happens when traffic gets isolated", "what is $product", or "does Zscaler have something for $use-case" questions, even if the user does not explicitly name Zscaler.

API Dev 2 2mo ago
aihxp

godpowers

by aihxp

AI-powered development system that takes a project from raw idea to hardened production. Fuses artifact discipline, execution engine, quality enforcement, and team intelligence into one unified workflow. Triggers on: "god mode", "god init", "god prd", "god arch", "god roadmap", "god stack", "god repo", "god build", "god deploy", "god observe", "god launch", "god harden", "god status", "god audit", "god debug", "god review", "god smite", "godpowers", "start a project", "build this", "ship this", "take this from idea to production", "one-shot the whole thing", "autonomous build", "full arc", "idea to deploy"

Security 2 1mo ago
nicholasgriffintn

security-review

by nicholasgriffintn

A specialist skill for security reviews, threat modeling, and remediation guidance. Use for auth/permissions changes, secrets or PII handling, public endpoints, or dependency upgrades.

Auth 2 6mo ago
adriannutiu

nightshift

by adriannutiu

Scriptless overnight repository and code-quality audit for Codex that runs deterministic checks first (code correctness gates, dead code or orphan hints, test gaps, refactor and DRY opportunities, doc drift, dependency or security posture, tech debt, optional infra drift) and then synthesizes prioritized actions with structured artifacts in .nightshift/runs/timestamp. Use after large implementation sessions, before releases, before handoff, or when asking "what did we miss?"

Code Review 9 5mo ago
AndreaGriffiths11

open-source-best-practices

by AndreaGriffiths11

Complete framework for preparing GitHub projects for sustainable open source release. Covers security scanning with Git History Cleaner, legal foundations, governance, contributor onboarding, maintainer expectations, and GitHub Sponsors setup. Use when launching a project publicly, preparing a private repo for open source, or hardening an existing public repo for long-term maintenance.

Code Gen 9 5mo ago
amber-moe

oceanbase-sql-optimization

by amber-moe

SQL optimization best practices for OceanBase database (MySQL & Oracle modes). Covers query optimization, index usage, execution plan analysis, slow query tuning, and performance optimization techniques. Activates for SQL optimization, query performance, index design, execution plan, slow query, database performance.

Code Gen 9 5mo ago
kuangre123

iosdev-cn

by kuangre123

通用 iOS App 开发、构建、签名、测试与 App Store 上架流程(中国区)指南。用于当用户询问 iOS 开发/上架/审核/签名/TestFlight/App Store Connect/隐私合规/订阅配置,或输入触发词 iosdev 时。

Code Review 24 6mo ago
johnlindquist

deps

by johnlindquist

Manage dependencies with npm/yarn/pnpm. Use for auditing vulnerabilities, checking outdated packages, understanding dependency trees, and upgrading packages safely.

CLI Tools 24 7mo ago