- Home
- /
- Categories
- /
- Security
Security
Security scanning and vulnerability detection
security-auditor
by jgarrison929
Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review.
forge-audit-skill
by fwehrling
FORGE Skill Auditor — Security audit of third-party Claude Code skills. Usage: /forge-audit-skill <path-to-skill>
quality-gate
by terraphim
Right-side-of-V verification/validation orchestration for a change or PR. Produces a single Quality Gate Report with evidence covering: code review, security audit, performance regression risk, requirements traceability, acceptance/UAT scenarios, and (when UI changes) visual regression testing. Use when preparing a PR for merge/release, doing a “ready?” check, or enforcing an engineering quality gate.
owasp-cloud-native-top-10
by yariv1025
"OWASP Cloud-Native Application Security Top 10 - prevention, detection, and remediation for containers, orchestration, and cloud-native apps. Use when securing insecure config, injection, auth, CI/CD and supply chain, secrets, network policies. Note - official list has 6 risks; project archived."
managing-npm
by Git-Fg
"Manages npm, pnpm, and bun dependencies following strict protocols. Use when installing, updating, or auditing packages. Do not use for TypeScript configuration or build tooling."
auditing-security
by Git-Fg
"Scans for secrets and performs comprehensive security audits. MUST Use when verifying security of code changes or auditing file safety."
security-architecture
by pluginagentmarketplace
Design security architectures with threat modeling and zero trust
django-reviewer
by physics91
WHEN: Django project review, ORM queries, views/templates, admin customization WHAT: ORM optimization + View patterns + Template security + Admin config + Migration safety WHEN NOT: FastAPI → fastapi-reviewer, Flask → flask-reviewer, DRF API only → consider api-expert
ai-code-reviewer
by physics91
WHEN: Deep AI-powered code analysis, multi-model code review, security scanning with Codex and Gemini WHAT: Comprehensive code review using external AI models with severity-based findings, deduplication, and secret detection WHEN NOT: Simple lint checks -> code-reviewer, Quick security only -> security-scanner, Style formatting -> code-quality-checker
sql-optimizer
by physics91
WHEN: SQL query review, query optimization, index usage, N+1 detection, performance analysis WHAT: Query plan analysis + Index recommendations + N+1 detection + Join optimization + Performance tuning WHEN NOT: Schema design → schema-reviewer, ORM code → orm-reviewer
cloud-resources
by SerendipityOneInc
Cloud resource management and monitoring for GCP (云资源管理与监控 - GCP)
security-scanner
by physics91
WHEN: Security scan, vulnerability detection, XSS/CSRF analysis, secret exposure, OWASP Top 10 WHAT: XSS/injection detection + hardcoded secrets + auth/authz issues + severity-based vulnerability list WHEN NOT: Performance → perf-analyzer, Cloud security → cloud-security-expert
auditing-plugins
by Git-Fg
"Comprehensive plugin auditing for compliance with marketplace best practices. MUST Use when validating, refactoring, or improving plugin quality. Do not use for creating new plugins, scaffolding components, or development tasks."
wcag-audit-perceivable-color
by Jkense
Route color usage and visual distinction accessibility requirements
Compensation Benchmarks
by yamz8
This skill should be used when the user asks about "salary ranges", "equity grants", "compensation benchmarks", "how much to pay", "competitive offer", "market rate", "startup compensation", "equity percentages", "option grants", or mentions specific compensation questions like "what should I pay a senior engineer" or "how much equity for a VP".
smart-contract-security
by pluginagentmarketplace
Master smart contract security with auditing, vulnerability detection, and incident response
wcag-audit-perceivable-media
by Jkense
Route audio, video, and multimedia accessibility requirements
architecture
by dy9759
Comprehensive system architecture design and implementation workflow that orchestrates expert analysis, technical decision-making, and architectural pattern selection using the integrated toolset. Handles everything from initial system analysis to implementation-ready technical specifications.
wcag-audit-perceivable-layout
by Jkense
Route page structure and spatial organization accessibility requirements
fullstack-security
by pluginagentmarketplace
Security and performance - hardening, optimization, auditing
backend-dev
by dy9759
Comprehensive backend development workflow that orchestrates expert analysis, architecture design, implementation, and deployment using the integrated toolset. Handles everything from API design and database architecture to security implementation and DevOps automation.
spring-boot-reviewer
by physics91
WHEN: Spring Boot code review, DI patterns, @Transactional, REST API design, security configuration WHAT: Dependency injection + Transaction management + API design + Security config + JPA patterns WHEN NOT: Kotlin Spring → kotlin-spring-reviewer, Pure Java → java-reviewer, Django/FastAPI → respective reviewers
security
by pluginagentmarketplace
JavaScript security best practices and vulnerability prevention.
code-test-review-expert
by dy9759
Advanced code testing and review expert system that provides comprehensive code quality analysis, security vulnerability assessment, test strategy design, and quality assurance through multi-expert collaboration and intelligent tool integration.