Security

Security scanning and vulnerability detection

Showing 1873-1896 of 2236 skills
Jackiexiao

supabase-postgres-best-practices

by Jackiexiao

"Postgres performance optimization and best practices from Supabase for schema, indexing, query tuning, security, and operations."

Database 1 5mo ago
terraphim

disciplined-verification

by terraphim

Phase 4 of disciplined development. Verifies implementation against design through unit and integration testing. Builds traceability matrices, tracks coverage, and loops defects back to originating left-side phases.

Security 1 5mo ago
josavicentevw

devsecops

by josavicentevw

DevSecOps skill for security automation, vulnerability management, secure CI/CD pipelines, container security, secrets management, compliance, and security testing. Use when implementing security in development workflows, scanning for vulnerabilities, securing infrastructure, or when user mentions security automation, SAST, DAST, container scanning, or compliance.

CI/CD 1 6mo ago
arc-claw-bot

clawdefender

by arc-claw-bot

Security scanner and input sanitizer for AI agents. Detects prompt injection, command injection, SSRF, credential exfiltration, and path traversal attacks. Use when (1) installing new skills from ClawHub, (2) processing external input like emails, calendar events, Trello cards, or API responses, (3) validating URLs before fetching, (4) running security audits on your workspace. Protects agents from malicious content in untrusted data sources.

CLI Tools 1 5mo ago
chrysos

security-audit

by chrysos

Run comprehensive security audit on any project. Detects package manager (npm, pnpm, yarn, bun, pip, composer, cargo, go), runs native audit commands, and searches the web for CVEs and security advisories for ALL dependencies — even those that pass the audit. Generates a detailed security report.

Code Review 1 5mo ago
KaribuLab

python-fastapi

by KaribuLab

FastAPI Secure Engineering

Auth 1 5mo ago
fethallaheth

audit-reports

by fethallaheth

Generate formatted security audit findings for Web3 platforms (Sherlock, Code4rena, Cantina). Use when user needs to report vulnerabilities, format findings, or create audit reports for smart contract security contests.

Code Gen 1 5mo ago
IdoKendo

opencode-audit

by IdoKendo

Audit OpenCode configuration quality, safety, and operability with a 100-point rubric and concrete remediations.

Code Review 1 5mo ago
Ontos-AI

driver-license-eligibility

by Ontos-AI

Provides driver license eligibility requirements based on user's country/state and age. It can specify minimum age, required documents, and any specific conditions.

Code Review 1 5mo ago
starbuck100

agentaudit-skill

by starbuck100

Automatic security gate that checks packages against a vulnerability database before installation. Use before any npm install, pip install, yarn add, or package manager operation.

API Dev 1 5mo ago
yariv1025

owasp-iot-top-10

by yariv1025

"OWASP IoT Top 10 - prevention, detection, and remediation for IoT device and ecosystem security. Use when designing or reviewing IoT devices - passwords, network services, ecosystem interfaces, secure updates, components, data transfer/storage, device management, default settings, physical hardening, privacy."

Code Gen 1 5mo ago
yariv1025

owasp-privacy-top-10

by yariv1025

"OWASP Top 10 Privacy Risks - prevention, detection, and remediation for privacy in web applications. Use when addressing app vulnerabilities, data leakage, breach response, consent, transparency, data deletion, data quality, session expiration, user access rights, excessive data collection."

API Dev 1 5mo ago
Jackiexiao

react-doctor

by Jackiexiao

Run after making React changes to catch issues early. Use when reviewing code, finishing a feature, or fixing bugs in a React project.

Debugging 1 5mo ago
johnsonshi

acr

by johnsonshi

'Comprehensive Azure Container Registry (ACR) knowledge skill. Use when users ask about: container registries, ACR authentication, private endpoints, geo-replication, ACR Tasks, image signing (Notation), artifact cache, connected registry, vulnerability scanning, customer-managed keys, RBAC, network security, artifact streaming, Helm charts in ACR, ORAS, or any Azure container registry feature. Triggers: "ACR", "container registry", "azurecr.io", "az acr", "docker push/pull to Azure", "registry authentication", "private registry", "geo-replicated registry", "image signing", "Notation", "Ratify".'

Auth 1 5mo ago
yariv1025

owasp-cicd-top-10

by yariv1025

"OWASP Top 10 CI/CD Security Risks - prevention, detection, and remediation for pipeline security. Use when securing or reviewing CI/CD - flow control, IAM, dependency chain, poisoned pipeline execution, PBAC, credential hygiene, system config, third-party services, artifact integrity, logging and visibility."

CI/CD 1 5mo ago
KaribuLab

titvo

by KaribuLab

Analyze generated code, identify vulnerabilities, and report them to the user.

Analytics 1 5mo ago
chen-ye

app-audit

by chen-ye

Analyzes installed Termux packages and Android apps to identify redundancies, categorize usage, and suggest cleanups. Use when the user asks to audit apps, check for bloatware, or analyze installed software.

Automation 1 5mo ago
yariv1025

owasp-mobile-top-10

by yariv1025

"OWASP Mobile Top 10 - prevention, detection, and remediation for iOS/Android app security. Use when building or reviewing mobile apps - credentials, supply chain, auth, input/output validation, communication, privacy, binary protection, config, data storage, cryptography."

Processing 1 5mo ago
yellinzero

aico-pm-clarification

by yellinzero

Resolve requirement ambiguities through STRUCTURED questioning: one question at a time, with recommended options and reasoning. UNIQUE VALUE: Prevents overwhelming users with multiple questions. Provides expert recommendations for each decision. Use this skill when: - Running /pm.clarify command - User says "unclear", "not sure what this means", "confused about" - User asks "what does X mean?", "how should X work?", "can you clarify?" - Requirements have conflicting or inconsistent details - Stories are missing acceptance criteria or have gaps - Need to fill information gaps BEFORE development can proceed Process: Ask ONE question at a time (max 5 per session), provide recommended option with reasoning. DO NOT ask multiple questions at once - this overwhelms users.

Auth 1 6mo ago
Arjun-Ingole

vue-doctor

by Arjun-Ingole

Diagnose and fix Vue/Nuxt codebase health issues. Use when reviewing Vue code, fixing performance problems, auditing security, or improving code quality.

Debugging 1 5mo ago
gigs-slc

dev-client

by gigs-slc

Build and distribute Expo development clients locally or via TestFlight

CLI Tools 1 5mo ago
agentnode-dev

skills-security-audit

by agentnode-dev

Audit AI agent skills for security risks before installation or periodically. Works on Claude Code, OpenClaw, and all platforms. Detect prompt injection, data exfiltration, malicious commands, obfuscated code, privilege abuse, supply chain risks, memory poisoning, trust exploitation, and behavioral manipulation. Use before installing third-party skills from any marketplace.

Analytics 1 5mo ago
terraphim

disciplined-validation

by terraphim

Phase 5 of disciplined development. Validates system against original requirements through system testing and user acceptance testing (UAT). Uses structured stakeholder interviews to gather sign-off and traces defects back to research or design phases.

Academic 1 6mo ago
Jackiexiao

audit-website

by Jackiexiao

"Audit websites for SEO, performance, security, technical and content issues with actionable recommendations."

Code Review 1 5mo ago