安全
安全扫描与漏洞检测
code-review
Nomik94
Code Reviewer 에이전트 스폰. Use when: /code-review, 코드 리뷰해줘, PR 리뷰, 리뷰해줘, 코드 품질 점검, 리팩토링 방향, 기술 부채 식별, 코드 스멜. NOT for: 단순 포맷팅, 오타 수정.
security-bounty-hunter
affaan-m
Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports instead of noisy local-only findings. Use when hunting reportable, remotely reachable vulnerabilities in a repository.
smart-code-review
lordprotein
"Expert code review with a senior engineer lens. Reviews git changes or targeted code (files, folders, features). Detects SOLID violations, security risks, and proposes actionable improvements."
nist-csf-mapping
Hack23
Map CIA platform security controls to NIST Cybersecurity Framework functions: Identify, Protect, Detect, Respond, Recover
firebase-security-rules-auditor
anoopithunt
Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists. Don't use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.
_security-compliance-mastery
TriNgo0108
Master application security, threat mitigation, compliance frameworks, and secure authentication. Use this as a central index to access specialized sub-skills.
ai-agent-security
DonArtkins
"Security guardrails for the Griot AI layer: service-token boundary, prompt-injection treatment, propose-before-write, token budgets, audit trail."
fullstack-engineering
iam-prabha
End-to-end best practices for full-stack development — from architecture and design through deployment and production observability. Use this skill when building, scaling, or shipping any web application across the entire stack (frontend, backend, database, DevOps, security, testing, and monitoring). Produces production-grade, maintainable, and secure software.
iso-27001-controls
Hack23
Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations
github-actions
yldgio
GitHub Actions workflow security, performance optimization, and best practices
inspecting-changes-skill
viktar-silakou
```
audit-content
TakaGoto
"Audit academy materials for outdated references, deprecated patterns, and stale content"
moses-product
christopheraaronhogg
Provides expert product management analysis, requirements review, and scope assessment. Use this skill when the user needs requirements evaluation, feature prioritization guidance, or scope assessment. Triggers include requests for product review, requirements audit, or when asked to evaluate feature completeness and prioritization. Produces detailed consultant-style reports with findings and prioritized recommendations — does NOT write implementation code.
bezaleel-architect
christopheraaronhogg
Provides expert architectural analysis and strategic recommendations for software projects. Use for architecture reviews, system design evaluation, tech stack assessment, scalability/modernization strategy, or when asked to analyze a codebase architecturally. Produces consultant-style reports with prioritized recommendations — does NOT write implementation code.
code-health-remediation
jamelna-apps
When user mentions "dead code", "duplicates", "cleanup", "tech debt", "health scan", "remediation", "unused", or wants to act on health scan results. Guides safe code cleanup.
terraform
yldgio
Terraform IaC patterns, state management, security, and modular design
code-quality-setup
metyatech
Use when setting up or configuring code quality tools (formatters, linters, type checkers, dependency scanners) for a repository. Also use when adding visual accessibility automation or security baseline scanning. Do not use for general coding or when tools are already configured.
Private Network Security Scan
BizShuk
Run a private network security scan, diagnose all discovered hosts against 11 risk categories, and generate a security report within 60 minutes
cryptoeconomic-protocol-security
curiositech
Analyze bonded agent systems, escrow workflows, slashing rules, oracle trust, Sybil cost, and front-running risk in protocols where agents post bonds or stake reputation. Use for collateral sizing, griefing analysis, dispute design, and bonded-agent security reviews. NOT for smart contract auditing, DeFi tokenomics, blockchain consensus design, or trading strategy.
attack-surface-analyzer
flight505
Analyze attack surface analyzer operations. Auto-activating skill for Security Advanced. Triggers on: attack surface analyzer, attack surface analyzer Part of the Security Advanced skill category. Use when analyzing or auditing attack surface analyzer. Trigger with phrases like "attack surface analyzer", "attack analyzer", "analyze attack surface r".
aivault
moldable-ai
Complete guide for using aivault as a zero-trust local vault and proxy for API secrets. Use this skill when initializing/configuring aivault, managing secrets and credentials, invoking capability-backed API calls, setting workspace/group isolation, adding custom providers, or troubleshooting daemon and policy issues.
cloud-architect
Tomlord1122
Cloud architecture expert for Kubernetes, Helm, Terraform, and AWS EKS. Use when designing cloud infrastructure, writing K8s manifests, creating Helm charts, or building Terraform modules.
Pentest Checklist
jcastillotx
This skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration testing", "define pentest scope", "follow security testing best practices", or needs a structured methodology for penetration testing engagements.
aikido-security-remediator
orbiqhq
Access Aikido Security through its API, pull open issue groups, triage findings, and execute first-pass fixes in your repository. Use when asked to review Aikido alerts, remediate dependency or SAST findings, or close security issues.