安全

安全扫描与漏洞检测

显示 889-912 / 共 2332 个技能
florianbuetow

fix

florianbuetow

This skill should be used when the user asks to "fix security finding", "fix vulnerability", "generate security fix", "appsec fix", "patch vulnerability", "remediate finding", or "apply security patch". Also triggers when the user references a finding ID (e.g., INJ-001) and asks for a fix, or points to a file:line and asks to fix the security issue there.

代码生成 13 6个月前
florianbuetow

logging

florianbuetow

This skill should be used when the user asks to "check for logging issues", "analyze security logging", "find missing audit logs", "check for log injection", "audit monitoring configuration", or mentions "logging", "audit trail", "log injection", "monitoring", or "alerting" in a security context. Maps to OWASP Top 10 2021 A09: Security Logging and Monitoring Failures.

数据处理 13 6个月前
florianbuetow

repudiation

florianbuetow

This skill should be used when the user asks to "check for repudiation", "analyze audit logging", "find logging gaps", or mentions "repudiation" or "non-repudiation" in a security context. Maps to STRIDE category R.

代码评审 13 6个月前
florianbuetow

config

florianbuetow

This skill should be used when the user asks to "configure security", "appsec settings", "security preferences", or invokes /appsec:config. Manages security tool preferences and thresholds.

代码评审 13 6个月前
florianbuetow

pasta-vulns

florianbuetow

This skill should be used when the user asks to "analyze vulnerabilities", "find security weaknesses", "map CWEs", "run vulnerability analysis", or is running PASTA stage 5. Also triggers when the user asks about SAST, DAST, dependency scanning, or CWE mapping in a threat modeling context. Part of the PASTA threat modeling methodology (Stage 5 of 7).

认证鉴权 13 6个月前
florianbuetow

insecure-design

florianbuetow

This skill should be used when the user asks to "check for design flaws", "analyze security design", "find insecure design patterns", "review threat model", "check business logic security", "find missing security controls", or mentions "insecure design" in a security context. Maps to OWASP Top 10 2021 A04:2021 - Insecure Design.

安全 13 6个月前
florianbuetow

auth

florianbuetow

This skill should be used when the user asks to "check for authentication issues", "analyze auth", "find credential vulnerabilities", "review login security", "check session management", or mentions "authentication", "passwords", "MFA", "sessions", or "brute force" in a security context. Maps to OWASP Top 10 2021 A07: Identification and Authentication Failures.

认证鉴权 13 6个月前
florianbuetow

full-audit

florianbuetow

This skill should be used when the user asks for a "full security audit", "exhaustive audit", "comprehensive security review", or invokes /appsec:full-audit. Launches every framework, every tool, and every red team agent, producing a dated report file.

分析 13 6个月前
kriscard

code-assistant

kriscard

"Development: Use when writing, debugging, or refactoring code. Orchestrates specialist agents (TypeScript, React, etc). NOT for architecture decisions."

安全 13 7个月前
florianbuetow

access-control

florianbuetow

This skill should be used when the user asks to "check for access control issues", "analyze authorization", "find IDOR vulnerabilities", "audit CORS configuration", "check for privilege escalation", or mentions "access control", "authorization", "IDOR", "CORS", "JWT tampering", or "directory traversal" in a security context. Maps to OWASP Top 10 2021 A01: Broken Access Control.

认证鉴权 13 6个月前
florianbuetow

misconfig

florianbuetow

This skill should be used when the user asks to "check for misconfigurations", "analyze security headers", "find misconfigured settings", "check CORS policy", "find debug mode", "audit server configuration", or mentions "misconfiguration" in a security context. Maps to OWASP Top 10 2021 A05: Security Misconfiguration.

数据处理 13 6个月前
florianbuetow

review-plan

florianbuetow

This skill should be used when the user asks to "review plan for security", "check plan for security issues", "security review of implementation plan", "audit the plan for vulnerabilities", or "check my plan before coding". Also triggers when the user mentions security in the context of an implementation plan, architecture proposal, or design document before code has been written. This is the FLAGSHIP pre-code security skill -- no other tool reviews plans at design time.

认证鉴权 13 6个月前
parhumm

sec-audit-remediate

parhumm

Generate security fixes from detect-dev findings with regression tests. Use when remediating security vulnerabilities.

代码生成 25 6个月前
parhumm

detect-dev

parhumm

Engineering audit with SARIF evidence, 4-level confidence, and OpenSSF scoring. Use when evaluating repository health or code quality.

代码评审 25 6个月前
x-cmd

springboot-security

x-cmd

Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

认证鉴权 25 7个月前
liqiongyu

enterprise-sales

liqiongyu

"Create an Enterprise Deal Execution Pack (buying committee map + champion enablement, “no decision” prevention plan + mutual action plan, procurement/security packet, and POC-as-business-case plan + ROI model). Use for enterprise sales, procurement, security reviews, and enterprise pilots/POCs. Category: Sales & GTM."

法律 52 7个月前
liqiongyu

energy-management

liqiongyu

"Build an Energy Management Operating System Pack (energy drivers/drains map, calendar energy audit, zone-of-genius expansion plan, energy-aligned weekly schedule, recovery routines, and 2-week experiments). Use for sustainable leadership performance and burnout prevention. Category: Leadership."

自动化 52 7个月前
nesnilnehc

review-security

nesnilnehc

"Review code for security: injection, sensitive data, authentication and authorization, dependencies and CVEs, configuration and secrets, and crypto. Cognitive-only atomic skill; output is a findings list."

代码评审 7 7个月前
Ven0m0

skills-eval

Ven0m0

'Evaluate and improve Claude skill quality through auditing. Use when

代码评审 7 7个月前
rocky2431

security-rules

rocky2431

Ultra Builder Pro security rules

认证鉴权 11 7个月前
kroegha

kali-docker-pentesting

kroegha

Comprehensive pentesting toolkit using Kali Linux Docker container. Provides direct access to 200+ security tools without MCP overhead. Use when conducting security assessments, penetration testing, vulnerability scanning, or security research. Works via direct docker exec commands for maximum efficiency.

CLI 工具 22 9个月前
project-codeguard

software-security

project-codeguard

A software security skill that integrates with Project CodeGuard to help AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.

认证鉴权 421 7个月前
yoanbernabeu

supabase-audit-rls

yoanbernabeu

Test Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.

代码评审 67 7个月前
yoanbernabeu

supabase-help

yoanbernabeu

Quick reference for all Supabase security audit skills with usage examples and command overview.

认证鉴权 67 7个月前