Secure Coding
-
openai Bundle Security Threat ModelPerforms repository-grounded threat modeling by enumerating trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, then writes a concise Markdown threat model.
Audited 23.3k -
openai Bundle Security Best PracticesPerform language and framework-specific security best-practice reviews, write secure-by-default code, and generate prioritized vulnerability reports with suggested fixes.
Audited 23.3k -
android Skill Android Intent SecurityAudit Android component configurations and Intent handling to prevent Intent Redirection and unauthorized access.
Audited 6.1k -
dotnet Skill Configure AuthAdd authentication and authorization to a Blazor Web App, handling render modes, Identity pages, and auth state serialization.
Audited 4k -
dotnet Skill Minimal API File UploadImplement file upload endpoints in ASP.NET Core minimal APIs (.NET 8+) with size limits, content validation, and streaming.
4k -
adobe Bundle Config AuthoringCreate, modify, review, and harden configuration for the Adobe Dispatcher Apache HTTP Server module and Apache HTTPD in AEM 6.5 LTS environments only.
Audited 142 -
getsentry Skill Code ReviewReview pull requests following Sentry engineering practices, covering security, performance, testing, and design.
Audited 845 -
getsentry Bundle Skill ScannerScans agent skills for security issues including prompt injection, malicious scripts, excessive permissions, secret exposure, and supply chain risks.
845 -
getsentry Bundle Django Access ReviewReviews Django codebases for access control vulnerabilities and IDOR by tracing authorization flows, mapping attack surfaces, and reporting confirmed gaps with enforceable fixes.
845 -
getsentry Skill Claude Settings AuditAnalyze a repository to generate recommended Claude Code settings.json permissions for read-only commands, detecting tech stack, build tools, and monorepo structure.
845 -
github Bundle Gdpr CompliantApply GDPR-compliant engineering practices across your codebase, covering API design, data models, authentication, logging, retention, and cloud infrastructure.
Audited 36.2k -
github Bundle Security ReviewScans codebases for security vulnerabilities by reasoning about code context, data flow, and component interactions, covering injection flaws, secrets exposure, authentication issues, and weak cryptography across multiple languages.
36.2k -
github Skill SQL Code ReviewPerforms comprehensive SQL code review across all major databases, analyzing security, performance, maintainability, and anti-patterns.
Audited 36.2k -
github Skill Agent GovernanceAdd governance, safety, and trust controls to AI agent systems with policy enforcement, intent classification, and audit trails.
Audited 36.2k -
github Bundle Threat Model AnalystPerforms STRIDE-A threat model analysis of repositories and systems, producing architecture overviews, DFD diagrams, prioritized findings, and executive assessments. Supports both single analysis and incremental updates with change tracking.
Audited 36.2k -
github Bundle Cloud Design PatternsProvides 42 technology-agnostic cloud design patterns for distributed systems, covering reliability, performance, messaging, security, and deployment to help architects design robust workloads.
Audited 36.2k -
github Skill Postgresql Code ReviewReview PostgreSQL code for best practices, anti-patterns, and quality standards including JSONB, arrays, custom types, schema design, functions, and security features like Row Level Security.
Audited 36.2k -
github Skill Apple Appstore ReviewerAudits iOS app source code and metadata to identify App Store rejection risks and optimization opportunities, producing a structured compliance report.
Audited 36.2k -
github Bundle Github Actions HardeningReviews and hardens GitHub Actions workflows against injection, privilege escalation, supply-chain, and token-scoping risks that pattern matchers miss.
Audited 36.2k -
github Skill AWS Well Architected ReviewReviews AWS infrastructure as code and deployed resources against the Well-Architected Framework, generating findings and GitHub issues for remediation.
36.2k -
github Skill AI Prompt Engineering Safety ReviewAnalyzes prompts for safety, bias, security vulnerabilities, and effectiveness, providing detailed improvement recommendations with frameworks, testing methodologies, and educational content.
Audited 36.2k -
trailofbits Bundle C ReviewPerforms comprehensive C/C++ security review for memory corruption, integer overflows, race conditions, and platform-specific vulnerabilities. Use when auditing native C/C++ applications, reviewing daemons or services for memory safety, or hunting integer overflow / use-after-free / race conditions in userspace code.
7k -
trailofbits Bundle TrailmarkBuilds and queries multi-language source code graphs for security analysis, including blast radius, taint propagation, privilege boundaries, and entry point enumeration.
7k -
trailofbits Bundle CodeqlScans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis, with support for multiple languages, scan modes, and data extension models.
7k -
trailofbits Bundle Vector ForgeUses mutation testing to systematically identify gaps in test vector coverage for cryptographic algorithms, then generates new test vectors that close those gaps. Measures effectiveness by comparing mutation kill rates before and after.
7k -
trailofbits Skill Rust ReviewAudits Rust codebases for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes.
7k -
trailofbits Bundle Sharp EdgesIdentifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes in API designs, configuration schemas, and cryptographic library ergonomics.
Audited 7k -
trailofbits Bundle SemgrepRun Semgrep static analysis scans with automatic language detection, parallel subagent execution, and merged SARIF output. Supports full ruleset coverage or high-confidence security vulnerability filtering.
7k -
trailofbits Bundle Zeroize AuditDetects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data.
7k -
trailofbits Bundle AflppFuzz C/C++ projects with multi-core support using AFL++, a fork of AFL with better performance and advanced features.
7k -
trailofbits Bundle Mermaid To ProverifTranslates Mermaid sequence diagrams of cryptographic protocols into ProVerif formal verification models (.pv files) for proving security properties like secrecy, authentication, and forward secrecy.
Audited 7k -
trailofbits Bundle LibaflBuild custom fuzzers with a modular Rust library, supporting advanced mutation strategies, custom feedback mechanisms, and non-standard target architectures.
7k -
trailofbits Bundle Trailmark StructuralRuns full Trailmark structural analysis by building a graph and computing pre-analysis passes for hotspots, taint, blast radius, privilege boundaries, and attack surface.
7k -
trailofbits Bundle OssfuzzSet up continuous fuzzing infrastructure for open-source projects using Google's OSS-Fuzz platform, including building and running fuzz harnesses locally and enrolling new projects.
7k -
trailofbits Bundle LibfuzzerCoverage-guided fuzzer built into LLVM for C/C++ projects. Use for fuzzing C/C++ code that can be compiled with Clang.
Audited 7k -
trailofbits Bundle Cargo FuzzFuzz Rust projects with libFuzzer using cargo-fuzz, including harness writing, sanitizer integration, and coverage analysis.
7k