Secure Coding
-
drnabeelkhan Skill Junction GuardEnforces a read-only rule for filesystem junctions and symlinks, blocking writes, deletes, and git commits that resolve outside the current project root.
2 -
drnabeelkhan Skill DevsecopsApplies the DevSecOps framework to structure analysis, guide decision-making, and produce actionable recommendations for engineering and operations contexts.
Audited 2 -
nimoqup046-collab Skill FirebaseGuides Firebase development with best practices for security rules, data modeling, and avoiding common pitfalls.
Audited 2 -
sakamoto-family-smile Skill Perl SecuritySecure Perl applications against injection, taint, and web vulnerabilities with validated patterns for input handling, file operations, process execution, and DBI queries.
Audited 0 -
sakamoto-family-smile Skill Django SecurityHardens Django applications against common vulnerabilities with production settings, authentication, authorization, SQL injection and XSS prevention, and secure deployment configurations.
Audited 0 -
sakamoto-family-smile Bundle Security ReviewProvides a security checklist and code patterns for authentication, input validation, secrets management, SQL injection prevention, XSS, CSRF, rate limiting, and sensitive data handling.
Audited 0 -
sakamoto-family-smile Skill Quarkus SecuritySecure Quarkus applications with authentication, authorization, input validation, and secrets management best practices.
Audited 0 -
sdiamante13 Bundle ReviewPerforms structured code reviews of git branches, tracking findings in a living document and optionally running deep architectural analysis with subagents.
7 -
joshuashepherd Skill Add GuardrailAdds input and output guardrails to an agent, including validation, content filtering, domain scoping, and rate limiting, with TypeScript examples and wiring instructions.
Audited 1 -
luokai0 Bundle ArgusScans Python and JavaScript codebases for bugs, security vulnerabilities, code smells, and anti-patterns, producing a prioritized fix list with line numbers, severity ratings, and suggested corrections.
10 -
luokai0 Bundle CognitoBuilds, configures, and manages AWS Cognito user pools, identity pools, authentication flows, and integrations with other AWS services.
Audited 10 -
jorcan Bundle 007Runs a structured security audit across six phases: attack-surface mapping, STRIDE/PASTA threat modeling, technical checklists, red/blue team analysis, and a final verdict, with optional Python automation scripts.
0 -
jorcan Bundle FirebaseProvides guidance on Firebase best practices, including security rules, data modeling, and avoiding common pitfalls.
Audited 0 -
huuanh20 Bundle Backend MindsetGuides backend development across API design, authentication, security, performance, architecture, and testing, with decision guides and defaults for production-ready systems.
Audited 1 -
neuralblitz Skill App SecurityProvides expert-level guidance on implementing and applying app security concepts, including design, optimization, debugging, and best practices.
Audited 1 -
mhassan0000 Skill Safety GuardPrevents destructive operations on production systems and restricts edits to a specified directory when running agents autonomously.
Audited 1 -
diegosouzapw Bundle AdminGuides building secure admin panels with RBAC, audit logging, and step-up controls for privileged actions.
Audited 54 -
chimeranext Skill SecurityImplements layered security for Flutter apps: code obfuscation, certificate pinning, secure storage, encryption, biometric authentication, and root/jailbreak detection.
4 -
vikingokft Bundle Frontend SecurityAudits frontend codebases for security vulnerabilities and bad practices, covering XSS, CSRF, DOM issues, CSP, input validation, file uploads, and Node.js/NPM dependencies across web, React, Astro, Twig, Node.js, and Bun.
0 -
vikingokft Skill Vikingo SzabvanyEnforces the Vikingo Studio standard for WordPress plugins and repos: naming taxonomy, plugin headers, folder structure, versioning, release flow, private update channel, admin UI rules, security baseline, and pre-release checklist.
Audited 0 -
vikingokft Skill Wp Security DeepAudits WordPress plugin and theme PHP code for advanced security issues beyond basic sanitization, including object injection, SSRF, CSRF, mass assignment, file inclusion, mail header injection, ZipSlip, type juggling, and TOCTOU races.
Audited 0 -
vikingokft Bundle Wp Security AuditAudits WordPress plugin or theme PHP code for common security mistakes including missing nonce checks, capability checks, input sanitization, output escaping, SQL preparation, AJAX exposure, file traversal, and unsafe redirects.
Audited 0 -
vikingokft Bundle Wp Admin List TableBuild WordPress admin tables by extending WP_List_Table, covering required overrides, pagination, bulk actions, and CSRF protection.
Audited 0 -
tools-only Bundle Security Checklist For Connected Apps And EcasUse this checklist before deploying any OAuth application to production.
Audited 7 -
nagarenegishi Bundle Owasp GuardEnforces OWASP Top 10:2025 compliance on code touching security-relevant domains, using cached cheat sheets and verifying fixes against OSV.dev.
0 -
phoroth Skill FirebaseCovers Firebase Authentication, Firestore, Realtime Database, Cloud Functions, Storage, and Hosting, with patterns for security rules, data modeling, and real-time listeners.
Audited 3 -
shulkwisec Skill CsrfDetect and exploit Cross-Site Request Forgery vulnerabilities by testing for missing or predictable CSRF tokens, absent SameSite cookie attributes, and JSON endpoints accepting text/plain Content-Type, with payloads and bypass techniques for security testing.
Audited 21 -
shulkwisec Bundle CodebasePerforms a white-box source code security review structured around OWASP ASVS 5.0, mapping attack surfaces, tracing data flows, and chaining into downstream penetration testing and threat modeling skills.
21 -
shulkwisec Bundle JWT Authentication Complete Deep DiveProvides exact payloads and bypass techniques for every PortSwigger JWT authentication lab variant, from unverified signatures to algorithm confusion attacks.
21 -
shulkwisec Skill RemediateGenerates specific, implementable fixes for each vulnerability finding, producing code patches, configuration changes, dependency updates, and IaC fixes with before/after code and verification steps.
21 -
addyosmani Skill Security And HardeningHardens code against vulnerabilities by applying threat modeling, OWASP Top 10 prevention patterns, and secure coding practices for web applications.
Audited 69.5k -
antigravity Skill FirebaseDesign secure, scalable Firebase backends with Firestore, Auth, Functions, and Storage, following best practices for security rules, data modeling, and real-time listeners.
Audited 42.4k -
antigravity Skill Fix ReviewVerifies that fix commits properly address security audit findings without introducing new bugs or vulnerabilities.
Audited 42.4k -
adobe Bundle DispatcherRoutes user requests to specialist skills for AEM 6.5 LTS Dispatcher configuration, troubleshooting, performance tuning, security hardening, and lifecycle orchestration.
Audited 142 -
getsentry Skill Find BugsReviews local branch changes for bugs, security vulnerabilities, and code quality issues using a structured checklist and attack surface mapping.
Audited 845 -
getsentry Bundle Security ReviewConducts systematic security code reviews to identify exploitable vulnerabilities, reporting only high-confidence findings after researching the codebase.
Audited 845