Security

Security scanning and vulnerability detection

Showing 1969-1992 of 2236 skills
whackur

solidity-security-best-practices

by whackur

Smart contract security best practices for Solidity development. Use when writing, reviewing, or auditing Solidity code. Covers reentrancy prevention, access control patterns, safe external calls, input validation, upgrade safety, and OWASP Smart Contract Top 10 vulnerabilities. Triggers on tasks involving security, vulnerability detection, access control, CEI pattern, ReentrancyGuard, SafeERC20, or smart contract auditing.

Code Review 0 5mo ago
shaul1991

code-reviewer

by shaul1991

Code Reviewer Agent. Frontend/Backend 코드 리뷰를 담당합니다. 코드 품질, 테스트 커버리지, 보안, 성능을 검토합니다.

Code Review 0 6mo ago
doric9

naver-blog-audit

by doric9

기존 네이버 블로그 포스트의 SEO 상태를 분석하고 개선점을 제안합니다.

Code Review 0 5mo ago
simplerick0

sast

by simplerick0

Security reviewer specializing in Static Application Security Testing - analyzing source code without execution. Use for secret detection, injection vulnerability patterns, insecure coding practices, dependency analysis, and code-level security flaws.

Code Review 0 5mo ago
pc-style

aidr

by pc-style

Offload context-heavy but low-complexity codebase work to Aider through a thin CLI wrapper. Use when another AI agent should avoid loading large repository context for tasks like discovery, repetitive refactors, cross-file version bumps, and broad search/explain passes. Supports safe read-only scanning, scoped edit runs, model-mode routing, and setup/model diagnostics.

Automation 0 4mo ago
djankies

securing-data-access-layer

by djankies

Teach Data Access Layer pattern to prevent CVE-2025-29927 middleware authentication bypass. Use when implementing authentication, authorization, protecting routes, or working with server actions that need auth.

Auth 0 7mo ago
pachoroa

security-audit

by pachoroa

Audit installed skills for malicious code, hidden instructions, and security vulnerabilities. Use when users want to scan their skills for potential security issues, verify skill safety before use, or investigate suspicious skill behavior.

CLI Tools 0 5mo ago
jcastillotx

php-best-practices

by jcastillotx

PHP coding standards and best practices. This skill should be used when writing, reviewing, or refactoring PHP code. Triggers on tasks involving PHP applications, WordPress plugins, Laravel projects, or any PHP-based backend.

Debugging 0 6mo ago
tomwangowa

research-synthesis

by tomwangowa

Use after running 2+ research skills (critical-research, tech-feasibility, narrative-auditor, codebase-audit) to synthesize findings into a unified decision document. Resolves conflicts between sources, weighs evidence, and produces an actionable recommendation.

Academic 0 5mo ago
arielperez82

skill-intake

by arielperez82

This skill should be used when evaluating, sandboxing, or incorporating new skills into a project's skill pipeline. Trigger when the user mentions "intake skill", "add new skill", "evaluate skill", "incorporate skill", "skill pipeline gap", or discusses discovering and integrating external or from-scratch skills.

CI/CD 0 4mo ago
Tomlord1122

code-review-master

by Tomlord1122

Code review expert for security, quality, and performance analysis. Use when reviewing code, PRs, conducting security audits, or identifying performance issues.

Code Review 0 5mo ago
profbernardoj

everclaw

by profbernardoj

Open-source first AI inference — GLM-5 as default, Claude as fallback only. Own your inference forever via the Morpheus decentralized network. Stake MOR tokens, access GLM-5, GLM-4.7 Flash, Kimi K2.5, and 30+ models with persistent inference by recycling staked MOR. Open-source first model router routes all tiers to Morpheus by default — Claude only kicks in as an escape hatch when needed. Includes Morpheus API Gateway bootstrap for zero-config startup, OpenAI-compatible proxy with auto-session management, automatic retry with fresh sessions, OpenAI-compatible error classification to prevent cooldown cascades, multi-key auth rotation v2 with proactive DIEM balance monitoring and reactive 402 watchdog, Gateway Guardian v5 with direct curl inference probes (eliminates Signal spam), proactive Venice DIEM credit monitoring, circuit breaker for stuck sub-agents, nuclear self-healing restart, always-on proxy-router with launchd auto-restart, smart session archiver, three-shift cyclic execution engine (v2 with 15-minute execution loops), 24/7 always-on power configuration for macOS, bundled security skills, zero-dependency wallet management via macOS Keychain, x402 payment client for agent-to-agent USDC payments, ERC-8004 agent registry reader for discovering trustless agents on Base, and hardware-aware local Ollama fallback with auto model selection (Qwen3.5 family, 1.5B–72B based on available RAM/GPU).

Automation 0 4mo ago
seekaxis

security-auditor

by seekaxis

"Proactively audit agent skills (SKILL.md and bundled scripts) for security risks including malicious installers, obfuscated payloads, credential exfiltration, and supply-chain attacks. Use when installing, reviewing, or triaging any agent skill, or when the user asks to check a skill for safety."

CLI Tools 0 5mo ago
nimeshgurung

fda-consultant-specialist

by nimeshgurung

Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management. Provides FDA pathway expertise, QSR compliance, cybersecurity guidance, and regulatory submission support. Use for FDA submission planning, QSR compliance assessments, HIPAA evaluations, and FDA regulatory strategy development.

Code Review 0 8mo ago
ShotaIuchi

migration-resolver

by ShotaIuchi

Dependency resolution for migrations. Apply when resolving version conflicts, transitive dependency issues, peer dependency requirements, and incompatible dependency trees.

Code Review 0 5mo ago
ShotaIuchi

feature-security

by ShotaIuchi

Security analysis for new features. Apply when reviewing authentication, authorization, input validation, data protection, and security best practices in new feature implementations.

Auth 0 5mo ago
Jackiexiao

audit-website

by Jackiexiao

(中文)Audit websites for SEO, performance, security, technical, content, and 15 other issue cateories with 230+ rules using the squirrelscan CLI. Returns LLM-optimized reports with health scores, broken links, meta tag analysis, and actionable recommendations. Use to discover and asses website or webapp issues and health.

Code Review 0 5mo ago
Olino3

dotnet-code-review

by Olino3

Forge is a marketplace for a Claude Code Plugins

Code Review 0 5mo ago
Bethamil

drupal-update

by Bethamil

Automate Drupal module updates in DDEV environments with safety snapshots, composer update, drush updb, config export, and changelog generation. Handles security updates, patch versions, minor versions, and major version upgrades with compatibility checking. Use when updating Drupal modules, checking for module updates, running composer update, upgrading dependencies, checking outdated packages, or when user mentions DDEV, drush, composer outdated, or module security updates.

CLI Tools 0 6mo ago
aravhawk

prod-ready

by aravhawk

Production-readiness audit covering linting, security, edge cases, and deployment checks. Only trigger when the user explicitly says "run prod-ready workflow" — do not run proactively.

Code Review 0 5mo ago
Narenreddy2302

swiff-ios

by Narenreddy2302

Expert assistant for the Swiff iOS subscription and expense management application. Use when working on Swiff iOS features, architecture, SwiftUI/SwiftData development, widgets, notifications, subscriptions, expenses, group billing, security, accessibility, or performance optimization. Provides comprehensive knowledge of MVVM architecture, service layer patterns, and iOS best practices.

Accessibility 0 5mo ago
rozwer

scan

by rozwer

SKILL.md ファイルのセキュリティスキャンを行います。2段階: 静的パターンマッチング + AI コンテキストレビュー。

CI/CD 0 4mo ago
kprsnt2

security

by kprsnt2

Application security best practices including OWASP Top 10, authentication, and data protection.

Auth 0 6mo ago
AgustinAlbonico

sonarqube-quality-gate-playbook

by AgustinAlbonico

Playbook iterativo para llevar proyectos Node y TypeScript (NestJS + React en monorepo) a cumplir Quality Gates de SonarQube sin romper build ni pipelines. Usar cuando se necesite subir cobertura priorizando New Code, eliminar issues nuevos (Bugs, Vulnerabilities, Code Smells), revisar Security Hotspots y controlar duplicacion y deuda tecnica.

Code Gen 0 5mo ago