Security

Security scanning and vulnerability detection

Showing 1561-1584 of 2236 skills
vchirrav

sast-gosec

by vchirrav

Run gosec SAST scans on Go code. Detects SQL injection, hardcoded credentials, insecure TLS, command injection, and other Go security issues.

Processing 2 5mo ago
vchirrav

api-security-spectral

by vchirrav

Run Spectral to lint OpenAPI and AsyncAPI specs for security issues. Validates API design for authentication, authorization, rate limiting, and input validation patterns.

API Dev 2 5mo ago
vchirrav

sast-bandit

by vchirrav

Run Bandit SAST scans on Python code. Detects common security issues like SQL injection, hardcoded passwords, exec usage, and insecure crypto.

Processing 2 5mo ago
pramseier-tenb

security-intel-brief

by pramseier-tenb

Build a leadership-ready security intelligence brief (PDF) for selected vendors and software products, down to specific versions. Collects CVEs, CISA KEV (known exploited vulnerabilities) status, latest/fixed versions, end-of-life dates, vendor advisories, and recent security news, then assigns per-product risk ratings. Use this skill whenever the user wants security research on a vendor or product, asks about CVEs/KEVs/vulnerabilities affecting software they run, wants a patch/version exposure check, or asks for a security report or briefing for leadership — even if they don't say "PDF" or "brief". Trigger on phrases like "what vulnerabilities affect X", "security posture of [vendor/product]", "CVE report", "vulnerability briefing", "is [software version] safe/exposed".

Processing 2 1mo ago
vchirrav

secret-scan-gitleaks

by vchirrav

Run Gitleaks to detect hardcoded secrets in git repositories. Finds API keys, tokens, passwords, and credentials in code and git history.

Processing 2 5mo ago
vchirrav

sast-semgrep

by vchirrav

Run Semgrep SAST scans on code. Supports 30+ languages with OWASP, security, and custom rulesets. Parses results and provides remediation guidance.

CI/CD 2 5mo ago
ymd38

vulnerability-scan

by ymd38

Run an offensive security audit (OWASP-based) using Semgrep and produce a read-only vulnerability report. Use before committing code to detect Broken Access Control, Injection (SQL/NoSQL/OS/Template), Frontend Security issues (XSS/CSP/HSTS), SSRF, and hardcoded secrets or PII exposure. Triggers on requests like "security scan", "vulnerability check", "audit security", "find vulnerabilities", "/vulnerability-scan", or when asked for an offensive security review of the codebase. Does NOT modify any code — read-only inspection only.

Auth 2 5mo ago
vchirrav

secure-coding-generate

by vchirrav

Generate secure code following OWASP Secure Coding rules. Automatically detects the security domain and produces code with inline Rule ID citations (e.g., [INPUT-04], [AUTH-07]) plus a rules-applied summary.

Auth 2 5mo ago
Mikacr1138

bug-bounty

by Mikacr1138

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth), bypass tables (SSRF IP bypass, open redirect bypass, file upload bypass), language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, 4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, always-rejected list, conditional chain table, submission checklist). Use for ANY bug bounty task — starting a new target, doing recon, hunting specific vulns, auditing source code, testing AI features, validating findings, or writing reports.

Auth 1 4mo ago
melodic-software

audit-agents

by melodic-software

Audit Claude Code subagents for quality, compliance, and maintainability. Use after creating or modifying agents, before releases, or for periodic quality checks.

Code Review 1 5mo ago
melodic-software

audit-log

by melodic-software

View audit log entries for all component types (skills, commands, agents, hooks, etc.) to monitor audit health and track coverage

Code Review 1 5mo ago
manastalukdar

container-optimize

by manastalukdar

Docker/container optimization for size, layers, caching, and security

Docker 1 5mo ago
famaoai-creator

license-auditor

by famaoai-creator

Output path for license report

Code Gen 1 4mo ago
PrakharMNNIT

backend-principle-eng-javascript-pro-max

by PrakharMNNIT

"Principal backend engineering intelligence for JavaScript services. Actions: plan, design, build, implement, review, fix, optimize, refactor, debug, secure, scale backend code and architectures. Focus: correctness, reliability, performance, security, observability, scalability, operability, cost."

Monitoring 1 5mo ago
famaoai-creator

investor-readiness-audit

by famaoai-creator

Output file path

Code Review 1 4mo ago
b-mendoza

validate-implementation-plan

by b-mendoza

Audit and annotate an AI-generated implementation plan for requirements traceability, YAGNI compliance, and assumption risks. Use when reviewing, validating, or auditing an implementation plan or design proposal produced by an AI agent.

Code Review 1 5mo ago
melodic-software

audit-hooks

by melodic-software

Audit Claude Code hooks for quality, compliance, and maintainability. Use after creating hooks, before releases, or for periodic quality checks.

Code Review 1 5mo ago
famaoai-creator

financial-modeling-maestro

by famaoai-creator

Output file path

Code Review 1 4mo ago
melodic-software

ecosystem-health

by melodic-software

Analyzes Claude Code ecosystem health by tracking all 27 extensibility components across 6 tiers - including plugin components, core configuration, environment/CLI, authentication, session features, and integrations. Use when checking if Claude Code components are up-to-date, orchestrating audits efficiently, tracking documentation coverage, applying updates from new Claude Code versions, or getting an overview of ecosystem component staleness.

Code Review 1 5mo ago
factorial-io

security-audit

by factorial-io

Use when conducting security reviews, investigating vulnerabilities, or creating security documentation - provides systematic methodology for code audits with severity assessment, dual documentation patterns (client + internal), and acceptance-focused ticket creation

Code Gen 1 5mo ago
samChang72

docker-expert

by samChang72

Docker containerization expert with deep knowledge of multi-stage builds, image optimization, container security, Docker Compose orchestration, and production deployment patterns. Use PROACTIVELY for Dockerfile optimization, container issues, image size problems, security hardening, networking, and orchestration challenges.

Docker 1 5mo ago
famaoai-creator

ai-ethics-auditor

by famaoai-creator

Audits AI systems for bias, fairness, and privacy. Analyzes prompts and datasets to ensure ethical and safe AI implementation.

Code Review 1 5mo ago
famaoai-creator

red-team-adversary

by famaoai-creator

Output path for report

Code Review 1 4mo ago
famaoai-creator

mcp-aws-knowledge-connector

by famaoai-creator

status: implemented

Cloud 1 4mo ago