Security

Security scanning and vulnerability detection

Showing 1441-1464 of 2236 skills
hackIDLE

iac-security-scanner

by hackIDLE

Scan Terraform, Kubernetes, CloudFormation, ARM templates, and Dockerfiles for security misconfigurations using 790 Terrascan-derived policies with NIST 800-53 control mappings. Use when users need to review IaC for security issues, audit cloud configurations, check compliance posture, harden infrastructure code, or identify misconfigurations across AWS, Azure, GCP, and Kubernetes before deployment.

Cloud 2 5mo ago
crtvrffnrt

Cross-Site Scripting (XSS) Assessment

by crtvrffnrt

Automation 2 4mo ago
gemstone-source

0-day

by gemstone-source

Systematic vulnerability research for CVE discovery, bug bounty methodology, patch-diff auditing, and offensive security work. Combines strategic architecture analysis with tactical exploitation testing. Covers source-to-sink tracing, trust boundary violations, authorization flaws, and variant hunting.

Auth 2 14d ago
crtvrffnrt

pentest-exploit-execution-payload-control

by crtvrffnrt

"Security assessment skill for deterministic exploit execution from validated primitives. Use when prompts include exploit implementation, payload hardening, chaining confirmed weaknesses, post-exploitation proof, or controlled impact demonstration. Do not use for early-stage reconnaissance, speculative hypothesis generation, or report-only requests."

Analytics 2 5mo ago
Agentient

firestore-security-rules-generation

by Agentient

Firestore Security Rules patterns for user-scoped access, RBAC, and field validation. PROACTIVELY activate for: (1) implementing user-scoped data access rules, (2) setting up role-based access with custom claims, (3) validating fields and enforcing immutability. Triggers: "security rules", "rbac", "firestore rules"

Auth 2 5mo ago
crtvrffnrt

pentest-outbound-interaction-oob-detection

by crtvrffnrt

"Security assessment skill for outbound interaction and out-of-band (OOB) validation. Use when prompts include SSRF callback confirmation, blind XSS beacons, webhook abuse, XXE/OOB behavior, DNS/HTTP callback correlation, or asynchronous server-side interaction proof. Do not use when vulnerabilities are fully in-band and require no external callback correlation."

Security 2 5mo ago
crtvrffnrt

pentest-input-protocol-manipulation

by crtvrffnrt

"Security assessment skill for input validation abuse and protocol-level manipulation. Use when prompts include injection, parser differential testing, request smuggling, method tampering, header confusion, serialization abuse, or payload mutation for exploitability testing. Do not use when the task is mainly authz boundary review, business workflow abuse, or report synthesis."

Automation 2 5mo ago
AntJanus

track-roadmap

by AntJanus

Plan, update, and audit a high-level project roadmap. Use when asked to "create a roadmap", "plan features", "what should we build next", "update the roadmap", "audit the roadmap", "review project direction", "prioritize features", or when starting a new project and needing to map out future work.

Code Gen 2 5mo ago
spjoshis

threat-modeling

by spjoshis

Master threat modeling with STRIDE, attack trees, risk assessment, and identifying security threats in systems and applications.

Auth 6 6mo ago
Dexploarer

dependency-vulnerability-scanner

by Dexploarer

Scans dependencies for known vulnerabilities (npm audit, pip-audit, etc.), generates reports, and suggests fixes. Use when user asks to "check vulnerabilities", "security scan", "audit dependencies", "check CVEs", or "vulnerable packages".

Code Review 6 8mo ago
Lap-Platform

akamai-application-security-api

by Lap-Platform

"Akamai: Application Security API skill. Use when working with Akamai: Application Security for activations, api-discovery, configs. Covers 213 endpoints."

Legal 6 4mo ago
spjoshis

security-documentation

by spjoshis

Master security documentation with security policies, incident response plans, security procedures, and compliance documentation.

Code Review 6 6mo ago
RandyPen

sui-keypair-cryptography

by RandyPen

"Helps Claude Code understand Sui blockchain keypair and cryptography operations, providing guidelines and examples for key generation, signing, verification, address derivation, and multi-signature scheme support. Use when working with cryptography in Sui development or when the user mentions keypairs, cryptography, signing, or verification."

Security 6 6mo ago
spjoshis

security-assessment

by spjoshis

Master security assessments with vulnerability scanning, penetration testing, security testing, and security audits.

Auth 6 6mo ago
Eli-yu-first

Security Audit Reporter

by Eli-yu-first

"Generates comprehensive security audit reports with findings, risk ratings, and remediation timelines"

Agents 6 4mo ago
mduongvandinh

spring-boot-full-stack

by mduongvandinh

Complete Java Spring Boot skill set for building enterprise applications. Includes modular architecture with optional components: - PostgreSQL database with JPA/Hibernate + Flyway migration - Redis caching (optional) - Kafka/RabbitMQ messaging (optional, choose one) - JWT + OAuth2 authentication (optional OAuth2) - RBAC authorization (optional) - TDD with Mockito - Spec-First Development with OpenSpec

Caching 6 6mo ago
Dexploarer

security-header-generator

by Dexploarer

Generates security HTTP headers (CSP, HSTS, CORS, etc.) for web applications to prevent common attacks. Use when user asks to "add security headers", "setup CSP", "configure CORS", "secure headers", or "HSTS setup".

Legal 6 8mo ago
poindexter12

terraform

by poindexter12

Terraform infrastructure-as-code reference for HCL syntax, state management, module design, and provider configuration. Use when working with Terraform configurations (.tf files), running terraform commands, troubleshooting state issues, or designing modules. Includes Telmate Proxmox provider patterns. Triggers: terraform, tfstate, .tf files, HCL, modules, providers, proxmox_vm_qemu.

Cloud 7 6mo ago
yanko-belov

auth-patterns

by yanko-belov

Use when implementing authentication. Use when storing passwords. Use when asked to store credentials insecurely.

Auth 13 6mo ago
bdmorin

create-design-document

by bdmorin

You are an expert in software, cloud and cybersecurity architecture.

Code Gen 5 4mo ago
meriley

safe-commit

by meriley

⚠️ MANDATORY - YOU MUST invoke this skill when committing. Complete commit workflow with all safety checks. Invokes security-scan, quality-check, and run-tests skills. Shows diff, gets user approval, creates commit with conventional format. NO AI attribution. User approval REQUIRED except during PR creation. NEVER commit manually.

Code Review 5 5mo ago
SherifEldeeb

detection

by SherifEldeeb

Security detection use cases for identifying threats across network, endpoint, identity, cloud, application, and email vectors. Use for building detection rules, analyzing security events, and threat hunting operations.

API Dev 5 6mo ago
scaleto

Comunicador Backend

by scaleto

Enlace A2A del Grupo Backend. Gestiona la comunicación con otros grupos del Conglomerado.

Kubernetes 5 5mo ago
amogha-dalvi

creating-sales-enablement

by amogha-dalvi

Use when sales reps lack deal-stage-specific content, when the founder's sales knowledge lives in their head instead of a system, when win rates are declining or sales cycles are lengthening, when no buying group content map exists, or when reps spend significant time creating content that should already exist. Use when sales and marketing lack shared definitions and feedback loops.

Code Review 5 5mo ago