Security

Security scanning and vulnerability detection

Showing 1873-1896 of 2326 skills
lukhanteanini21-glitch

code-audit

by lukhanteanini21-glitch

Professional code security audit skill covering 55+ vulnerability types. Enhanced with WooYun 88,636 real-world vulnerability cases (2010-2016). This skill should be used when performing security audits, vulnerability scanning, penetration testing preparation, or code review for security issues. Supports 9 languages: Java, Python, Go, PHP, JavaScript/Node.js, C/C++, .NET/C#, Ruby, Rust. Includes 143 mandatory detection items across all languages with language-specific checklists. Covers SQL injection, XSS, RCE, deserialization, SSRF, JNDI injection, JDBC protocol injection, authentication bypass, business logic flaws, race conditions, and modern security domains (LLM, Serverless, Android). WooYun integration adds: statistical-driven parameter priority, bypass techniques library, logic vulnerability patterns, and real-case references. v1.0: Initial public release with Docker deployment verification framework.

Security 2 6mo ago
Coowoolf

Energy Audit and Zone of Genius

by Coowoolf

Review your calendar, color-code activities by energy impact (Green/Red), and systematically delegate draining tasks to maximize time in your Zone of Genius.

Code Review 2 7mo ago
plutowang

code-critic

by plutowang

Use when explicitly asked to critique code, find bugs, audit code quality, analyze performance, or review a specific code snippet for security issues. Do not use for full branch or PR reviews.

Code Review 2 6mo ago
jforksy

cto

by jforksy

CTO Co-Pilot - strategic technical leadership, architecture decisions, infrastructure optimization, and engineering team coordination

Code Review 2 7mo ago
fefogarcia

dependency-audit

by fefogarcia

Comprehensive dependency health auditing for JavaScript/TypeScript projects. Run npm audit, detect outdated packages, check for security advisories, and verify license compliance. Prioritises vulnerabilities by severity and provides actionable fix recommendations. Use when: auditing project dependencies, checking for vulnerabilities, updating packages, preparing for release, or investigating "npm audit" warnings. Keywords: audit, vulnerabilities, outdated, security, npm audit, pnpm audit, CVE, GHSA, license.

Code Review 2 6mo ago
jforksy

ciso-vendor-risk

by jforksy

Third-party risk management - vendor security assessments, SaaS tool reviews, vendor risk scoring, and onboarding checklists

Processing 2 6mo ago
plutowang

critical-thinking

by plutowang

Always-on skill that enforces critical thinking during coding. Auto-apply on every coding task to prevent yes-man behavior, challenge assumptions, and ensure technical decisions are well-reasoned.

Debugging 2 6mo ago
jforksy

ciso-compliance

by jforksy

Compliance management - SOC 2 policies, Vanta integration, evidence collection, audit readiness, and gap analysis

Processing 2 6mo ago
cartoonitunes

ai-readiness-audit

by cartoonitunes

Audit any website for AI agent readiness. Check llms.txt, MCP servers, structured data, semantic HTML, meta quality, and more. Use when optimizing a site for AI agents, checking AI discoverability, or preparing for AI search engines.

Code Review 1 6mo ago
baotoq

kubernetes-architect

by baotoq

Expert Kubernetes architect specializing in cloud-native

Docker 1 6mo ago
oakencore

skillvet

by oakencore

"Security scanner for ClawHub/community skills — detects malware, credential theft, exfiltration, prompt injection, obfuscation, homograph attacks, ANSI injection, campaign-specific attack patterns, and more before you install. Use when installing skills from ClawHub or any public marketplace, reviewing third-party agent skills for safety, or vetting untrusted code before giving it to your AI agent. Triggers: install skill, audit skill, check skill, vet skill, skill security, safe install, is this skill safe."

CLI Tools 1 6mo ago
baotoq

k8s-manifest-generator

by baotoq

Create production-ready Kubernetes manifests for Deployments, Services, ConfigMaps, and Secrets following best practices and security standards. Use when generating Kubernetes YAML manifests, creating K8s resources, or implementing production-grade Kubernetes configurations.

Code Gen 1 6mo ago
chen-ye

app-audit

by chen-ye

Analyzes installed Termux packages and Android apps to identify redundancies, categorize usage, and suggest cleanups. Use when the user asks to audit apps, check for bloatware, or analyze installed software.

Automation 1 7mo ago
yellinzero

aico-pm-clarification

by yellinzero

Resolve requirement ambiguities through STRUCTURED questioning: one question at a time, with recommended options and reasoning. UNIQUE VALUE: Prevents overwhelming users with multiple questions. Provides expert recommendations for each decision. Use this skill when: - Running /pm.clarify command - User says "unclear", "not sure what this means", "confused about" - User asks "what does X mean?", "how should X work?", "can you clarify?" - Requirements have conflicting or inconsistent details - Stories are missing acceptance criteria or have gaps - Need to fill information gaps BEFORE development can proceed Process: Ask ONE question at a time (max 5 per session), provide recommended option with reasoning. DO NOT ask multiple questions at once - this overwhelms users.

Auth 1 7mo ago
ANGUARDA

clawvitals

by ANGUARDA

Security health checks and secure configuration auditing for OpenClaw. Reviews your core security vitals across authentication, version currency, and platform config. Tracks whether your security posture improves or regresses over time, and alerts on new critical findings. Run "run clawvitals" to get your first score in under 30 seconds.

Security 1 5mo ago
keep-starknet-strange

starknet-skills

by keep-starknet-strange

Routes Cairo/Starknet coding and audit tasks to the smallest relevant module for focused, high-quality execution.

Code Review 1 6mo ago
danielcubas

security-audit-saas-generic

by danielcubas

Perform a full security audit for any SaaS web application regardless of specific framework or ORM. Use before production or after MVP completion.

Auth 1 6mo ago
theepan

java-code-review

by theepan

Review Java source code for bugs, security vulnerabilities, performance problems, concurrency issues, AI-generated code quality issues, dependency licensing risks, and best practice violations. Use when a user asks to review Java code, audit Java files, find bugs in Java, check Java code quality, detect AI slop, check library licenses, or perform a code review on .java files. Accepts code provided directly, as local file paths, as directory paths, or as unified diff output.

Code Review 1 6mo ago
cachemoney

dependency-updater

by cachemoney

Smart dependency management for any language. Auto-detects project type, applies safe updates automatically, prompts for major versions, diagnoses and fixes dependency issues.

CLI Tools 1 6mo ago
WyrdWerk

repo-security-audit

by WyrdWerk

Quick security checklist for evaluating GitHub repos and npm packages before/after installation. For non-coders and users. Heavy details live in references/.

Git & VCS 1 3mo ago
yariv1025

owasp-api-security-top-10

by yariv1025

"OWASP API Security Top 10 - prevention, detection, and remediation for REST/GraphQL/API security. Use when designing or reviewing APIs - object- and function-level authorization, authentication, rate limiting and resource consumption, sensitive business flows, SSRF, API inventory and versioning, or consumption of third-party APIs."

API Dev 1 7mo ago
Git-Fg

managing-npm

by Git-Fg

"Manages npm, pnpm, and bun dependencies following strict protocols. Use when installing, updating, or auditing packages. Do not use for TypeScript configuration or build tooling."

CLI Tools 1 7mo ago
makgunay

macos-distribution

by makgunay

macOS app distribution covering code signing (Developer ID, App Store certificates), notarization (notarytool), DMG/pkg creation, App Store submission workflow, sandboxing entitlements, StoreKit for in-app purchases and subscriptions (SubscriptionOfferView, appTransactionID, Transaction.currentEntitlements, subscriptionStatusTask), StoreKit testing with local configuration files, PrivacyInfo.xcprivacy manifest, and dual distribution strategies (App Store + direct). Use when preparing an app for distribution, implementing purchases/subscriptions, configuring signing, or troubleshooting App Store rejection.

Code Gen 1 7mo ago
getskillsdev

claude-md-bp-context

by getskillsdev

Audit CLAUDE.md for best practices. 18-point checklist.

Code Review 1 7mo ago