Secure Coding
-
github Bundle Audit IntegrityEnforces output quality, intellectual honesty, and continuous improvement across security analysis agents with anti-rationalization guards, self-critique loops, retry protocols, and quality gates.
Audited 36.2k -
github Skill Agent Supply ChainVerify supply chain integrity for AI agent plugins, tools, and dependencies by generating SHA-256 manifests, detecting tampered files, auditing dependency pinning, and enforcing promotion gates.
Audited 36.2k -
github Skill Agent Owasp ComplianceCheck any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks, scanning for controls and generating a compliance report.
36.2k -
github Skill Salesforce Component StandardsEnforce quality, security, and accessibility standards for Salesforce Lightning Web Components, Aura components, and Visualforce pages.
Audited 36.2k -
trailofbits Bundle RuzzyCoverage-guided fuzzing for Ruby code and C extensions using libFuzzer and sanitizers.
7k -
trailofbits Bundle Crypto Protocol DiagramExtracts protocol message flow from source code, RFCs, academic papers, pseudocode, or formal models (ProVerif/Tamarin) and generates Mermaid sequence diagrams with cryptographic annotations.
7k -
trailofbits Bundle Insecure DefaultsDetects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.
Audited 7k -
trailofbits Bundle Address SanitizerDetect memory errors like buffer overflows and use-after-free bugs in C/C++ code during fuzzing and testing using AddressSanitizer.
Audited 7k -
trailofbits Bundle Audit Context BuildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
Audited 7k -
trailofbits Bundle Agentic Actions AuditorAudits GitHub Actions workflows for security vulnerabilities in AI agent integrations, detecting attack vectors where attacker-controlled input reaches AI agents in CI/CD pipelines.
Audited 7k -
trailofbits Bundle Cairo Vulnerability ScannerScans Cairo/StarkNet smart contracts for 6 critical vulnerability patterns including arithmetic overflow, L1-L2 messaging issues, and signature replay. Use when auditing StarkNet projects.
7k -
trailofbits Bundle Semgrep Rule Variant CreatorPorts existing Semgrep rules to new target languages with applicability analysis and test-driven validation.
Audited 7k -
jeffallan Bundle Fullstack GuardianBuilds security-focused full-stack web applications by implementing integrated frontend and backend components with layered security at every level, covering the complete stack from database to UI.
Audited 10.4k -
zhaoxuya520 Bundle Code AuditPerforms authorized source-code security reviews using SAST tools like Semgrep and CodeQL, with manual verification of findings and fix recommendations.
12.8k -
zhaoxuya520 Bundle Edr Bypass ReReverse-engineers EDR, Defender, and AV hook tables, ETW providers, and AMSI implementations to build targeted bypasses including unhooking, indirect syscalls, ETW patching, and call stack spoofing for authorized red team operations.
12.8k -
zhaoxuya520 Bundle Dotnet ReverseProvides a structured workflow for reverse engineering .NET and C# binaries, including deobfuscation with de4dot, static analysis via dnSpyEx IL view, dynamic debugging, and reliable IL patching for red-team tools and malware.
12.8k -
zhaoxuya520 Bundle Identity FederationAuthorized assessment of federated identity systems covering SAML, OIDC, and OAuth2 flows, SSO misconfigurations, and token confusion issues.
12.8k -
zhaoxuya520 Skill Dsl Vm ReverseReverse-engineers custom JavaScript-based WASM virtual machines and risk-control engines by identifying DSL VM patterns, extracting opcodes, analyzing constant tables, and tracing exported functions through static analysis and runtime injection.
12.8k -
iamcorey Bundle Wifi OptimizerDiagnose intermittent Wi-Fi issues like buffering, lag, packet loss, and weak coverage through read-only analysis, then safely optimize authorized router settings when evidence supports a change.
53 -
tinh2 Skill OwaspSystematically audits a web application against the OWASP 2021 Top 10, producing severity-rated, file-level findings with fixes for each category.
13 -
sakamoto-family-smile Skill Security ScanAudits Claude Code configuration files for security vulnerabilities, misconfigurations, and injection risks using AgentShield, covering CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.
0 -
sakamoto-family-smile Skill Laravel SecurityHardens Laravel applications against common vulnerabilities with guidance on authentication, authorization, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
Audited 0 -
sakamoto-family-smile Skill Defi Amm SecurityProvides a security checklist and hardened Solidity patterns for auditing AMM contracts, liquidity pools, and swap flows, covering reentrancy, CEI ordering, donation attacks, oracle manipulation, slippage, admin controls, and integer math.
Audited 0 -
luokai0 Bundle API SecurityImplements secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common vulnerabilities.
Audited 10 -
auto-skiller Skill Code ReviewReviews staged and unstaged code changes for security vulnerabilities, code quality issues, and adherence to project conventions, reporting findings by severity.
1 -
vikingokft Skill Wp I18N AuditAudits WordPress plugin or theme PHP code for internationalization (i18n) correctness, including text-domain consistency, escaped translation helpers, placeholder usage, plurals, context, and text-domain loading. Produces a severity-ranked report of issues to fix before release.
Audited 0 -
vikingokft Skill Wp Security SecretsAudits WordPress plugin and theme code for secret-handling issues: hardcoded credentials, weak randomness, insecure password storage, cookie flags, and secret leakage in logs.
Audited 0 -
johnalbertini14-glitch Bundle HsBlocks dangerous shell commands and warns on risky ones, applying a safety protocol before executing any command.
1 -
paramchordiya Skill Code Review StandardsEnforces a principal-engineer self-review checklist on every code block before output, covering correctness, performance, security, naming, and testability.
Audited 0 -
lucaspmarie-a11y Skill FirebaseGuides Firebase development with best practices for security rules, data modeling, and avoiding common pitfalls.
Audited 5 -
anantha-236 Skill Safety GuardPrevents destructive operations when working on production systems or running agents autonomously by intercepting risky commands and restricting file edits to a specified directory.
Audited 1 -
adobe Bundle Unbounded QueryDetects and triages explicitly-unbounded AEM queries (p.limit=-1 or setLimit(-1)) that cause OOMs, safely capping only where provably safe and escalating others for human pagination.
142 -
zhaoxuya520 Bundle Reverse Skill RouterRoutes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
12.8k -
zhaoxuya520 Bundle Thick ClientAuthorized security testing framework for desktop thick clients covering local storage, IPC, update channels, traffic interception, and client-side trust boundaries.
12.8k -
tinh2 Skill SecurePerforms a full-stack security posture assessment with 0-100 risk scoring, scanning dependencies, code patterns, configuration, and data handling, then produces a prioritized report and routes to specialized skills.
13 -
pranavnagrecha Bundle Lwc SecurityGuides secure design and review of Lightning Web Components, covering DOM safety, Apex data exposure, and Lightning Web Security.
Audited 15