Secure Coding
-
neuralblitz Skill CryptographyExplains cryptographic primitives and provides Python implementations for encryption, hashing, key exchange, and digital signatures.
Audited 1 -
chimeranext Bundle Container SecurityImplements container security with image scanning, runtime protection, image signing, and security policies using tools like Falco, Trivy, and Notary.
4 -
vikingokft Skill Wp REST APIScaffolds and reviews custom WordPress REST API endpoints, covering registration, authorization, input validation, response shaping, and security best practices.
Audited 0 -
tools-only Bundle HTTP Monitoring And ManagementIf you are developing a web application, Spring Boot Actuator auto-configures all enabled endpoints to be exposed over HTTP.
Audited 7 -
nagarenegishi Skill Owasp ScanScans a single file against the OWASP Top 10:2025, tracks cross-file connections, and maintains a persistent findings record.
0 -
rosendolu Skill Code ReviewReviews pull request diffs for correctness, security, maintainability, and test coverage, providing severity-ranked findings and a close-out recommendation.
Audited 0 -
shulkwisec Bundle Cors Misconfiguration Complete Deep DiveProvides a structured deep-dive into CORS misconfiguration vulnerabilities with exact payloads for every PortSwigger lab variant, including zero-day escalation techniques and blue-team detection guidance.
21 -
shulkwisec Skill SstiDetect and exploit Server-Side Template Injection vulnerabilities across multiple template engines including Jinja2, Twig, Freemarker, and Velocity, with payloads for sandbox escape and remote code execution. Includes detection methodology, bypass techniques, and fix patterns.
21 -
shulkwisec Skill Dom XssDetect and exploit DOM-based XSS vulnerabilities by auditing JavaScript for tainted data flow from controllable sources to dangerous sinks, with payloads and bypass techniques for client-side testing.
Audited 21 -
shulkwisec Bundle Dom Based Vulnerabilities Complete Deep DiveProvides exact payloads and bypass techniques for every PortSwigger DOM-based vulnerability lab variant, including zero-day extensions and blue team detection strategies.
Audited 21 -
nivkazdan Skill Oauth2 Flow HelperProvides step-by-step guidance and generates configurations for OAuth2 flows, following industry best practices and security patterns.
Audited 4