Security

Security scanning and vulnerability detection

Showing 1969-1992 of 2326 skills
physics91

code-reviewer

by physics91

WHEN: Code review, quality check, code smell detection, refactoring suggestions WHAT: Complexity analysis + code smell list + severity-based issues + improvement suggestions WHEN NOT: Next.js specific → nextjs-reviewer, Security → security-scanner, Performance → perf-analyzer

Code Review 1 9mo ago
terraphim

quality-gate

by terraphim

Right-side-of-V verification/validation orchestration for a change or PR. Produces a single Quality Gate Report with evidence covering: code review, security audit, performance regression risk, requirements traceability, acceptance/UAT scenarios, and (when UI changes) visual regression testing. Use when preparing a PR for merge/release, doing a “ready?” check, or enforcing an engineering quality gate.

Code Review 1 7mo ago
ViniciusMarsili

kube-audit-kit

by ViniciusMarsili

Performs read-only Kubernetes security audits by exporting resources, sanitizing metadata, grouping applications by topology, and generating PSS/NSA-compliant audit reports. Use when the user requests auditing Kubernetes clusters, Namespaces, security reviews, or configuration analysis.

CLI Tools 1 8mo ago
physics91

fastapi-reviewer

by physics91

WHEN: FastAPI project review, Pydantic models, async endpoints, dependency injection WHAT: Pydantic validation + Dependency injection + Async patterns + OpenAPI docs + Security WHEN NOT: Django → django-reviewer, Flask → flask-reviewer, General Python → python-reviewer

API Dev 1 9mo ago
yariv1025

owasp-cloud-native-top-10

by yariv1025

"OWASP Cloud-Native Application Security Top 10 - prevention, detection, and remediation for containers, orchestration, and cloud-native apps. Use when securing insecure config, injection, auth, CI/CD and supply chain, secrets, network policies. Note - official list has 6 risks; project archived."

Auth 1 7mo ago
youlianvr

dependency-auditor

by youlianvr

"Audit and manage dependencies across multi-language projects. Identifies vulnerabilities, license conflicts, transitive dependency risks, and safe-upgrade paths. Use when auditing third-party packages before release, investigating a CVE, planning a major version bump, or running a license-compliance review. Examples: 'audit our npm dependencies', 'do we have GPL contamination', 'plan the upgrade to React 19'."

Legal 1 2d ago
anavvanzin

SQLite Database Expert

by anavvanzin

Expert in SQLite embedded database development for Tauri/desktop applications with focus on SQL injection prevention, migrations, FTS search, and secure data handling

Database 1 2mo ago
Hack23

input-validation

by Hack23

Implement comprehensive input validation to prevent XSS, SQL injection, and command injection attacks with sanitization strategies

Comments 236 6mo ago
ecelayes

htmx-universal-patterns

by ecelayes

The definitive guide for building Hypermedia-Driven Applications (HDA) using HTMX, prioritizing security and UX patterns.

Debugging 0 7mo ago
ameistad

native-app-publish-ready

by ameistad

Comprehensive app store submission readiness checker for mobile apps. Audits iOS App Store and Google Play Store requirements including build config, privacy compliance, store assets, metadata, technical requirements, and common rejection causes. Use when the user asks to "check if my app is ready to submit", "review for app store", "app store checklist", "pre-submission check", "ready for Play Store", "ready for App Store", "submission readiness", or wants to audit a mobile app before publishing. Supports native iOS (Swift/ObjC), native Android (Kotlin/Java), Flutter, and React Native (including Expo) projects.

Code Review 0 6mo ago
kbrdn1

role-definitions

by kbrdn1

Skill migrated from _fragments/base/role-definitions

Security 3 1d ago
jcastillotx

SSH Penetration Testing

by jcastillotx

This skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH vulnerabilities", "perform SSH tunneling", or "audit SSH security". It provides comprehensive SSH penetration testing methodologies and techniques.

CLI Tools 0 7mo ago
jcastillotx

javascript-best-practices

by jcastillotx

JavaScript coding standards and best practices. This skill should be used when writing, reviewing, or refactoring JavaScript code. Triggers on tasks involving vanilla JavaScript, DOM manipulation, async operations, or performance optimization.

Debugging 0 7mo ago
shivamsinghchahar

rails-security-audits

by shivamsinghchahar

Audit Rails applications for security vulnerabilities using Brakeman, Bundler Audit, and security best practices. Use when scanning for CVEs, setting up security checks, or implementing security headers.

Code Review 0 6mo ago
waseemkhan00777

wcag-audit

by waseemkhan00777

Automated WCAG 2.1 AA accessibility audit using Puppeteer and axe-core across all application routes.

Accessibility 0 6mo ago
nexscope-ai

Domain Monitoring

by nexscope-ai

E-commerce skills for AI agents — product research, marketing automation, supply chain optimization, and business analytics for online sellers across Amazon, Shopify, Etsy, TikTok Shop, and all platforms.

Processing 835 5mo ago
kbrdn1

security

by kbrdn1

Skill migrated from _fragments/backend/security

Auth 3 1d ago
jonathanprozzi

pre-pr-scan

by jonathanprozzi

Pre-PR compliance and security scan. Checks diff against CLAUDE.md guidelines and security best practices before creating a pull request.

Code Review 0 7mo ago
whatyourname12345

poc-validator

by whatyourname12345

Automated Vulnerability Verification and Payload Replay Probe. Dynamically executes HTTP requests and analyzes HTTP status codes, error traces, time delays, and response lengths (e.g., Error-based, Time-based, and Boolean Blind SQLi). Use when: Testing specific payloads, verifying vulnerabilities, checking for blind injection conditions, or replaying raw HTTP requests. NOT for: Automated mass scanning, DDoS attacks, or unauthorized exploitation.

Processing 0 5mo ago
dtsvetkov1

security-audit

by dtsvetkov1

Scans code for security vulnerabilities, hardcoded secrets, and unsafe patterns in React Native and Expo applications. Use before merging sensitive changes or as part of a regular audit.

Code Review 0 8mo ago
Nomik94

python-best-practices

by Nomik94

Python 코드 리뷰 및 베스트 프랙티스 검증. Use when: /python-best-practices, 코드 품질 분석, .py 파일 리뷰, 타입 힌트 검증, 린팅, 테스트 커버리지 분석, 의존성 점검. NOT for: 아키텍처 리뷰 (/code-review), 보안 전문 분석 (/security-audit).

Code Review 0 6mo ago
bromanko

gleam-review

by bromanko

This skill should be used when the user asks to "review Gleam", "full Gleam review", "review all Gleam", "comprehensive Gleam review", or wants a complete review covering code quality, security, performance, and testing for Gleam code.

Code Review 0 6mo ago
gajakannan

writing-blogs

by gajakannan

"Writes technical blog posts, devlogs, tutorials, and retrospectives based on completed project work. Activates when writing blog posts, creating devlogs, writing about features, summarizing builds, writing retrospectives, or documenting learnings. Does not handle official API or operations documentation (technical-writer), writing production code (backend-developer or frontend-developer), or security reviews (security)."

Security 0 6mo ago
open-agreements

iso-27001-evidence-collection

by open-agreements

Collect, organize, and validate evidence for ISO 27001 and SOC 2 audits. API-first approach with CLI commands for major cloud platforms. Produces timestamped, auditor-ready evidence packages. Use when user says "collect audit evidence," "prepare evidence package," "evidence for the auditor," "refresh evidence," or "evidence gap analysis."

Processing 53 2mo ago