- Home
- /
- Categories
- /
- Security
Security
Security scanning and vulnerability detection
ai-writing-audit
by iamkaf
Use when the user asks to "audit AI writing", "remove AI patterns", "make this sound less AI", "un-AI this text", or similar requests to identify/remove AI-generated writing patterns.
action-item-organizer
by slurpyb
Systematic framework for extracting actionable items from documents and
attack-tree-construction
by aiagentskills
Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
rafter
by Raftersecurity
"Entry point for rafter. Invoke when a sub-skill is unclear, or when the task needs rafter run (remote SAST+SCA), rafter secrets (local secrets-only), rafter audit, policy checks, or command-risk evaluation. Scope by security surface, not task label: engage when the diff touches auth, credentials/secrets/tokens, untrusted input, SQL, shell/exec, file paths, deserialization, crypto, network endpoints, data deletion, or dependencies; for research/experimental/local-only code with none of that, a quick surface check is enough. When such surface IS present and no rafter skill or CLI call has been made, invoke this before handing the task off — an un-evaluated \"done\" on genuine security surface is not done."
mcp-gateway-security
by Hack23
MCP gateway security patterns, token management, request validation, and audit logging for MCP communications
yotta-verify
by YottaMeta
元信 —— 装任何技能/包前的确定性安全扫描器:prompt injection(提示注入)+ 危险模式 + SKILL.md 完整性 + 权限需求,输出 verdict(SAFE TO INSTALL / INSTALL WITH CAUTION / REVIEW REQUIRED / DO NOT INSTALL)+ audited 徽章。触发:安装/评估任何技能或 npm 包前、给技能做安全验证、生成 audited 徽章、CI 装前闸门;或用户说 装前扫描/验证/audited/安全验证/verify-skill/可信 等。边界:只做确定性静态扫描与报告,不执行被测代码、不联网、不装包、不修复;结论需人工确认,不代替最终决策。
code-reviewer
by darrenrolf0481-ship-it
Thorough code review with focus on security, performance, and best practices. Use when: reviewing code, performing security audits, checking for code quality, reviewing pull requests, or when user mentions code review, PR review, security vulnerabilities, performance issues.
cairo-auditor
by keep-starknet-strange
Security audit of Cairo/Starknet code. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), deep (+ adversarial reasoning), or specific filenames.
performing-subdomain-enumeration-with-subfinder
by SSZcreate
Enumerate subdomains of target domains using ProjectDiscovery's Subfinder
github-actions-workflows
by Hack23
Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments
AppSec Engineer
by anorbert-cmyk
Application Security Engineer preventing vulnerabilities and enabling secure development.
security
by ruchernchong
Run security audit with GitLeaks pre-commit hook setup and code analysis
qa
by pmco23
Use after /build to run the full post-build QA pipeline. Supports --parallel (all audits simultaneously) or --sequential (denoise → qf → qb → qd → security-review in order). Requires .pipeline/build.complete.
information-security-strategy
by Hack23
AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model
opencode-config-audit
by markfred5377
Comprehensive configuration audit skill for OpenCode desktop application. Detects configuration errors, security issues, duplicate files, and optimization opportunities. Supports self-check of installed skills.
python-backend-development
by lct1407
Generate Python FastAPI code following project design patterns. Use when creating models, schemas, repositories, services, controllers, database migrations, authentication, or tests. Enforces layered architecture, async patterns, OWASP security, and Alembic migration naming conventions (yyyymmdd_HHmm_feature).
secure-development-policy
by Hack23
Hack23 secure development policy enforcement, SAST/DAST integration, dependency scanning, and code signing practices
nodejs
by kprsnt2
Node.js server development patterns including async patterns, error handling, and security best practices.
sdlc-autopilot
by mrqureshi95
Full software development lifecycle orchestrator for ANY coding task. Triggers on ALL code changes — bug fixes, features, refactors, improvements, performance, security fixes, API changes, UI changes, database changes, config changes, new files, deletions, or any request to modify, create, fix, build, or ship code. This skill should activate FIRST on every coding prompt to orchestrate the full pipeline — understand, plan, implement, test, audit, guard against recurrence, and ship. It automatically discovers and delegates to other installed skills for domain expertise.
maintaining-npm-packages
by lenneTech
Analyzes and optimizes npm package dependencies. Handles outdated packages, npm audit findings, security vulnerabilities, dependency updates, unused dependency removal, and devDependencies recategorization. Recommends the lt-dev:npm-package-maintainer agent via /maintain commands. Activates for "update packages", "npm audit", "check dependencies", "security fix", or package.json optimization. NOT for @lenne.tech/nest-server version updates (use nest-server-updating).
maui-authentication
by Rimblehelm
A brief description of what this skill does
recipe-security-audit
by cuioss
On-demand security-audit recipe that runs the shared five-stage audit engine over the current footprint and emits findings into the triage pipeline
fp-check
by aleister1102
"Systematically verifies suspected security bugs to eliminate false positives. Produces TRUE POSITIVE or FALSE POSITIVE verdicts with documented evidence for each bug."
mac-cleanup
by jwa91
"Interactive macOS system cleanup for any dev machine. Frees disk space by pruning caches, package managers, unused apps, stale dev artifacts, and more. Discovers what's installed rather than assuming a specific setup. Always consults the user before deleting anything. Use when the user asks to: clean up their Mac, free disk space, remove unused apps, prune caches, clean developer artifacts, or any disk space maintenance task."