- Home
- /
- Categories
- /
- Security
Security
Security scanning and vulnerability detection
drill-recovery
by quangrau
Disaster recovery drill exercises and security checklists for web application projects (SPA, SSR, full-stack web apps). Focused on solo/indie developers using free-tier infrastructure (Vercel, Supabase, Cloudflare, Netlify, Railway, etc.). Bridges big-tech best practices (NIST, Google SRE DiRT, ISO 22301) to indie scale. Use when the user mentions drills, disaster recovery, security audit, incident simulation, project health check, resilience testing, backup strategies, secret rotation, or incident response for web projects. Not for mobile apps, desktop software, CLI tools, or games.
auth-patterns
by yanko-belov
Use when implementing authentication. Use when storing passwords. Use when asked to store credentials insecurely.
security-guardian
by Bikach
Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité. OWASP Top 10, authentification, autorisation, cryptographie, gestion de secrets. Utiliser pour audits sécurité, reviews de code sensible, conception de features sécurisées, ou résolution de failles.
nestjs-best-practices
by xirothedev
NestJS best practices and patterns for building scalable, maintainable backend applications. This skill should be used when writing, reviewing, or refactoring NestJS code to ensure proper architecture, security, performance, and code quality. Triggers on tasks involving NestJS modules, controllers, services, guards, pipes, middleware, Prisma database operations, authentication, or any NestJS-specific patterns.
thor-skills
by NextronSystems
Entry point and router for THOR-related work: running scans, analyzing THOR logs, troubleshooting THOR behavior, maintaining THOR installs, THOR Lens workflows, writing THOR plugins (v11+), and creating custom signatures/IOCs.
Comunicador Backend
by scaleto
Enlace A2A del Grupo Backend. Gestiona la comunicación con otros grupos del Conglomerado.
Comunicador Seguridad
by scaleto
Enlace A2A del Grupo Seguridad.
Comunicador Testing
by scaleto
Enlace A2A del Grupo Testing.
Orquestador Seguridad
by scaleto
Líder del Grupo Seguridad. Planifica y delega tareas de ciberseguridad, auditorías, compliance y pentesting a los especialistas del grupo.
Comunicador DevOps
by scaleto
Enlace A2A del Grupo DevOps.
mail-security
by aashari
Find security-related emails — login alerts, 2FA changes, password resets, new device notifications, suspicious activity, and account security events across all accounts. Use when user asks about security alerts in their email, account access notifications, or wants to review security events. Arguments: optional time range or account/service filter.
goodvibesonly
by JDDoesDev
Security scanner for vibe-coded projects. AUTO-INVOKE this skill before any git commit, git push, or when user says "commit", "push", "ship it", "deploy", "is this safe?", "check for security issues", or "goodvibesonly". Also invoke after generating code that handles user input, authentication, database queries, or file operations.
wfc-deepen
by sam-fakhreddine
Augments an existing /wfc-plan directory by researching codebase patterns, project documentation, and dependency constraints to add supporting evidence to tasks. Reads TASKS.md and PROPERTIES.md, simulates parallel analysis across 4 dimensions, and appends sourced findings as annotations. Does NOT modify task structure, add/remove tasks, or write implementation steps. Triggers: /wfc-deepen, /wfc-deepen <path>, "add research evidence to the plan", "validate plan against codebase patterns", "annotate plan with known pitfalls", "cross-reference plan with existing solutions". Not for: writing or expanding task implementation steps; decomposing tasks into subtasks; prioritizing or reordering tasks; adding or removing tasks; pre-planning research before a plan directory exists; targeted research on specific questions unrelated to plan validation; re-deepening plans with existing Research Findings sections (use --force to override); general research with no plan context.
copilot-cli-agent
by richfrem
Copilot CLI sub-agent system for persona-based analysis. Use when piping large contexts to GitHub Copilot models for security audits, architecture reviews, QA analysis, or any specialized analysis requiring a fresh model context.
security-antipatterns-python
by subhashdasyam
Use when generating Python code for web applications, APIs, or handling user input - prevents OWASP Top 10 vulnerabilities in Django, Flask, FastAPI
mail-digest
by aashari
Email digest for any time period — today, yesterday, last N hours/days, this week, a specific date, or while-I-was-away ranges. Categorizes by urgency, surfaces unread, flags financial/security emails, filters noise. Auto-invoke when user asks about email for any time period: "what came in today", "catch me up", "any emails this week", "what did I miss", "emails from yesterday", "last 3 hours", "since Monday".
tech-blog-seo-draft-creator
by masayan1126
テックブログ記事の下書きをSEO最適化込みで一括作成するスキル。雑なメモから体裁を整え、タイトル・メタディスクリプション・ハッシュタグまで生成。「SEO込みで記事にして」「SEO最適化された下書きを作成して」「公開できる形にして」などのリクエストで利用。
audit-plugin
by richfrem
Audits a local plugin directory to ensure it perfectly matches the Agent Skills and Claude Plugin Open Standards.
auditing-permission-ux
by clix-so
Audits notification permission request flows. Use when reviewing or improving permission prompts, settings paths, or denial handling.
seven-advisors
by krishagel
Seven Advisors decision council - structured multi-perspective deliberation for important decisions. Use when facing complex choices, strategic decisions, or when you need to think through a problem from multiple angles.
wfc-security
by sam-fakhreddine
Architectural threat modeling (STRIDE) and design-level security analysis for software systems. Analyzes system descriptions, architecture diagrams, or explicitly pasted configuration files. Does NOT perform live CVE scanning, code logic review, or implementation patching. Use when: User requests threat modeling, attack surface mapping, or static dependency risk assessment. Do NOT use when: User requests live vulnerability scanning, code review, specific bug remediation (SQLi, XSS), or compliance auditing.
project-showcase
by ayushxx7
"Automate the creation of high-quality project showcases, including UI captures using Playwright, professional README galleries, and feature summaries for portfolios or social media."
audit-plugin-l5
by richfrem
Triggers the L5 Red Team Sub-Agent to rigorously audit a plugin against the 39-point L4 pattern matrix.
red-team-review
by richfrem
"(Industry standard: Review and Critique Pattern) Primary Use Case: Iterative generation paired with adversarial review, continuing until an 'Approved' verdict is reached. Orchestrated adversarial review loop. Use when: research, designs, architectures, or decisions need to be reviewed by red team agents (human, browser, or CLI). Iterates in rounds of research → bundle → review → feedback until approved."