Security

Security scanning and vulnerability detection

Showing 1753-1776 of 2236 skills
mrsknetwork

audit

by mrsknetwork

Performs structured code, security, and architecture audits. Produces severity-categorized findings with file/line evidence and actionable remediation steps. Use when reviewing a PR, conducting a security review, evaluating technical debt, or assessing code quality before a release. Never merge critical audit findings without a documented resolution.

Code Review 2 4mo ago
amorriscode

code-review

by amorriscode

Perform thorough code reviews on pull requests, diffs, or code changes. Use when asked to review code, check a PR, or provide feedback on changes.

Code Review 2 6mo ago
vchirrav

sca-osv-scanner

by vchirrav

Run Google's OSV-Scanner for Software Composition Analysis. Scans lockfiles and SBOMs across all major ecosystems (npm, PyPI, Maven, Go, Cargo, NuGet, RubyGems) for known vulnerabilities.

Processing 2 5mo ago
kaelen-hou

code-review-assistant

by kaelen-hou

Comprehensive code review assistant that analyzes code for security vulnerabilities, performance issues, and code quality. Use when reviewing pull requests, conducting code audits, or analyzing code changes. Supports Python, JavaScript/TypeScript, and general code patterns. Includes automated analysis scripts and structured checklists.

Code Review 2 6mo ago
vchirrav

iac-scan-tfsec

by vchirrav

Run tfsec (now part of Trivy) to scan Terraform code for security misconfigurations. Deep HCL analysis with support for Terraform modules, variables, and expressions.

Cloud 2 5mo ago
costa-marcello

ci-cd

by costa-marcello

"Creates production-ready GitHub Actions workflows for CI/CD, Docker builds, security scanning, and monorepo orchestration. Triggers on requests for CI/CD setup, workflow creation, pipeline automation, GitHub Actions help, deployment workflows, matrix builds, reusable workflows, or security scanning configuration."

CI/CD 2 5mo ago
costa-marcello

production-audit

by costa-marcello

"Audits a codebase for production readiness across six dimensions: API completeness, frontend-backend sync, security, scalability, infrastructure, and dead code/architecture. Use when asked for a launch assessment, production readiness check, pre-deployment audit, or multi-agent patchwork cleanup."

Agents 2 5mo ago
masanao-ohba

security-patterns

by masanao-ohba

PHP security best practices and patterns for preventing common vulnerabilities

Code Gen 2 9mo ago
starwreckntx

GOVERNANCE TRIAD

by starwreckntx

P-001-R1: The Journey IS The Artifact

Code Review 2 6mo ago
clearsmog

qa

by clearsmog

Adversarial quality audit loop. Critic finds issues, fixer applies fixes, loops until APPROVED (max 5 rounds). Works with any document format.

Code Review 2 4mo ago
pluginagentmarketplace

docker-security

by pluginagentmarketplace

Secure Docker containers and images with hardening, scanning, and secrets management

Docker 2 6mo ago
silvainfm

monaco-payslip-calculator

by silvainfm

Calculate Monaco payslips (bulletin de salaire) with social security contributions, taxes, and net salary. Use when user requests Monaco payslip calculations, salary breakdowns for Monaco employees, or needs to compute Monegasque employer/employee contributions.

Processing 2 8mo ago
masanao-ohba

nextjs-deliverable-criteria

by masanao-ohba

Quality gates and acceptance criteria for Next.js 15 App Router projects

Code Review 2 6mo ago
liuchiawei

code-reviewer

by liuchiawei

Elite code review expert specializing in modern AI-powered code

Code Review 2 5mo ago
jforksy

ciso

by jforksy

CISO Co-Pilot - pragmatic startup security, compliance readiness, risk management, and security program building

Processing 2 5mo ago
vchirrav

tls-scan-testssl

by vchirrav

Run testssl.sh to analyze TLS/SSL configurations. Checks cipher suites, protocols, certificate validity, known vulnerabilities (Heartbleed, POODLE, ROBOT), and compliance.

Processing 2 5mo ago
jorgealves

prompt-injection-scanner

by jorgealves

Audits agent skill instructions and system prompts for vulnerabilities to prompt hijacking and indirect injection. Use when designing new agent skills or before deploying agents to public environments where users provide untrusted input.

Agents 2 5mo ago
jorgealves

hipaa-compliance-guard

by jorgealves

Audits HealthTech applications for HIPAA technical safeguards like encryption and audit logging. Use when reviewing healthcare infrastructure or ensuring PHI is handled according to legal security standards.

Code Review 2 5mo ago
peterbamuhigire

skill-safety-audit

by peterbamuhigire

Scan new or updated skills for unsafe or malicious instructions (unknown tools, external installers, credential harvesting) before accepting them into the repository.

Code Gen 2 5mo ago
costa-marcello

review-code

by costa-marcello

"Reviews current git changes with a senior engineer lens. Detects SOLID violations, YAGNI/DRY/KISS breaches, security risks, performance issues, and proposes actionable improvements. Use when reviewing pull requests, checking code quality before merging, or auditing changes for security vulnerabilities."

Code Review 2 5mo ago
vchirrav

sast-flawfinder

by vchirrav

Run Flawfinder SAST scans on C/C++ code. Detects buffer overflows, format string vulnerabilities, race conditions, and other memory safety issues.

Processing 2 5mo ago
carmandale

lint

by carmandale

Use this agent when you need to run linting and code quality checks on Ruby and ERB files. Run before pushing to origin.

Code Review 2 5mo ago
Kooooooma

code-security-scanner

by Kooooooma

Scan code repositories for security threats including data exfiltration, backdoors, malicious code injection, dependency chain risks, and sensitive file access. Use this skill when users want to audit a codebase (especially TypeScript/JavaScript/Node.js projects) for security vulnerabilities, detect hidden malware, review npm dependencies for supply-chain attacks, check for credential leaks, or perform a pre-deployment security review. Triggers on requests like "scan for malicious code", "security audit", "check for backdoors", "review dependencies for vulnerabilities", "detect data exfiltration".

Code Review 2 5mo ago
vchirrav

dast-zap

by vchirrav

Run OWASP ZAP for Dynamic Application Security Testing. Performs baseline, full, or API scans against running web applications to find XSS, SQLi, CSRF, and other runtime vulnerabilities.

API Dev 2 5mo ago