- Home
- /
- Categories
- /
- Security
Security
Security scanning and vulnerability detection
qr-code-scanner-tracking
by tippyentertainment
Design, build, and refine a QR code–based tracking system. This skill helps generate QR codes, define what happens when they are scanned, and track scan events (who, where, when, how) for marketing, operations, product flows, or internal tools.
supabase-best-practices
by jcastillotx
Supabase development standards. Triggers when working with Supabase projects, Row Level Security, real-time subscriptions, or Edge Functions.
elm-review
by bromanko
This skill should be used when the user asks to "review Elm", "full Elm review", "review all Elm", "comprehensive Elm review", or wants a complete review covering code quality, security, performance, and testing for Elm code.
fsharp-security-review
by bromanko
This skill should be used when the user asks for "security review", "vulnerability scan", "audit F# security", "security audit", "find vulnerabilities", "check for security issues", or wants a deep security analysis of F# code including input validation, .NET interop safety, and dependency concerns.
base-rules
by ryoshimm
AI エージェンティック開発の基本ルール。プロジェクト調査・コード品質・安全性の共通規約を自動適用する。
solidity-code-review
by whackur
Smart contract code review and security audit methodology for Solidity. Use when reviewing, auditing, or assessing the security of Solidity code. Provides structured review process, severity classification, key inspection areas, and OWASP SCWE integration. Triggers on tasks involving code review, security audit, vulnerability assessment, smart contract review, or best practices check.
openclaw-skill-auditor
by CalWade
Audit installed OpenClaw skills for security risks, token bloat, and hidden cost patterns. Use this skill whenever the user asks to scan, audit, check, or review their installed skills — including questions like "are my skills safe?", "which skills are wasting tokens?", "do I have any suspicious skills?", "clean up my skills", or "check my OpenClaw skills". Always invoke this skill for any skill health, quality, or cost investigation.
code-review
by Nomik94
Code Reviewer 에이전트 스폰. Use when: /code-review, 코드 리뷰해줘, PR 리뷰, 리뷰해줘, 코드 품질 점검, 리팩토링 방향, 기술 부채 식별, 코드 스멜. NOT for: 단순 포맷팅, 오타 수정.
security-bounty-hunter
by affaan-m
Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports instead of noisy local-only findings. Use when hunting reportable, remotely reachable vulnerabilities in a repository.
smart-code-review
by lordprotein
"Expert code review with a senior engineer lens. Reviews git changes or targeted code (files, folders, features). Detects SOLID violations, security risks, and proposes actionable improvements."
nist-csf-mapping
by Hack23
Map CIA platform security controls to NIST Cybersecurity Framework functions: Identify, Protect, Detect, Respond, Recover
firebase-security-rules-auditor
by anoopithunt
Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists. Don't use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.
_security-compliance-mastery
by TriNgo0108
Master application security, threat mitigation, compliance frameworks, and secure authentication. Use this as a central index to access specialized sub-skills.
ai-agent-security
by DonArtkins
"Security guardrails for the Griot AI layer: service-token boundary, prompt-injection treatment, propose-before-write, token budgets, audit trail."
fullstack-engineering
by iam-prabha
End-to-end best practices for full-stack development — from architecture and design through deployment and production observability. Use this skill when building, scaling, or shipping any web application across the entire stack (frontend, backend, database, DevOps, security, testing, and monitoring). Produces production-grade, maintainable, and secure software.
iso-27001-controls
by Hack23
Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations
github-actions
by yldgio
GitHub Actions workflow security, performance optimization, and best practices
inspecting-changes-skill
by viktar-silakou
```
audit-content
by TakaGoto
"Audit academy materials for outdated references, deprecated patterns, and stale content"
moses-product
by christopheraaronhogg
Provides expert product management analysis, requirements review, and scope assessment. Use this skill when the user needs requirements evaluation, feature prioritization guidance, or scope assessment. Triggers include requests for product review, requirements audit, or when asked to evaluate feature completeness and prioritization. Produces detailed consultant-style reports with findings and prioritized recommendations — does NOT write implementation code.
bezaleel-architect
by christopheraaronhogg
Provides expert architectural analysis and strategic recommendations for software projects. Use for architecture reviews, system design evaluation, tech stack assessment, scalability/modernization strategy, or when asked to analyze a codebase architecturally. Produces consultant-style reports with prioritized recommendations — does NOT write implementation code.
code-health-remediation
by jamelna-apps
When user mentions "dead code", "duplicates", "cleanup", "tech debt", "health scan", "remediation", "unused", or wants to act on health scan results. Guides safe code cleanup.
terraform
by yldgio
Terraform IaC patterns, state management, security, and modular design
code-quality-setup
by metyatech
Use when setting up or configuring code quality tools (formatters, linters, type checkers, dependency scanners) for a repository. Also use when adding visual accessibility automation or security baseline scanning. Do not use for general coding or when tools are already configured.