Vulnerability Scanning
-
drnabeelkhan Bundle Security Threat IntelligenceRoutes security, compliance, and threat-intelligence tasks to specialized sub-skills for threat modeling, penetration testing, incident response, and vulnerability scanning.
Audited 2 -
drnabeelkhan Skill Ethical HackerConducts authorized security assessments to identify vulnerabilities, map them to OWASP and MITRE frameworks, and provide remediation guidance with responsible disclosure planning.
2 -
nimoqup046-collab Bundle 007Runs a structured security audit across six phases: attack-surface mapping, STRIDE/PASTA threat modeling, technical checklists, red/blue team exercises, and a final verdict, covering code, infrastructure, APIs, bots, payments, AI agents, and compliance.
2 -
sakamoto-family-smile Skill Perl SecuritySecure Perl applications against injection, taint, and web vulnerabilities with validated patterns for input handling, file operations, process execution, and DBI queries.
Audited 0 -
sakamoto-family-smile Skill Django SecurityHardens Django applications against common vulnerabilities with production settings, authentication, authorization, SQL injection and XSS prevention, and secure deployment configurations.
Audited 0 -
sakamoto-family-smile Bundle Security ReviewProvides a security checklist and code patterns for authentication, input validation, secrets management, SQL injection prevention, XSS, CSRF, rate limiting, and sensitive data handling.
Audited 0 -
sakamoto-family-smile Skill Production AuditAudits a codebase for production readiness using local evidence, scoring ship/block risk and listing concrete fixes without sending repo data to external services.
Audited 0 -
luokai0 Bundle DnsrobotRuns DNS, email security, SSL, WHOIS, and network checks by calling the dnsrobot.net API, with no API key required.
10 -
jorcan Bundle 007Runs a structured security audit across six phases: attack-surface mapping, STRIDE/PASTA threat modeling, technical checklists, red/blue team analysis, and a final verdict, with optional Python automation scripts.
0 -
diegosouzapw Bundle OpsPerforms security scanning, compliance checks, deployment planning, and infrastructure setup, with optional dependency auditing and bundle size analysis.
54 -
diegosouzapw Bundle ZenoRuns an evidence-first, read-only workflow over large codebases via an external JSONL REPL server, retrieving only minimal file slices and greps to produce cited architecture and audit reports.
54 -
diegosouzapw Bundle NoneDetect container escape attempts using Falco, seccomp, and auditd, with rules for privileged containers, Docker socket access, and kernel module loading.
54 -
chimeranext Bundle Security Compliance AutomationAutomates security and compliance checks using OPA policies, Trivy vulnerability scanning, AWS CIS benchmark verification, and Kubernetes remediation scripts.
4 -
cloudthinker-ai Skill Managing OpaManage and inspect OPA policies, Gatekeeper constraints, and Rego rules, including discovery, testing, and audit analysis.
7 -
cloudthinker-ai Skill Analyzing AquaAnalyzes container security posture, image assurance, compliance, and runtime alerts on the Aqua Security platform via its API.
7 -
vikingokft Bundle Frontend SecurityAudits frontend codebases for security vulnerabilities and bad practices, covering XSS, CSRF, DOM issues, CSP, input validation, file uploads, and Node.js/NPM dependencies across web, React, Astro, Twig, Node.js, and Bun.
0 -
vikingokft Skill Wp Security DeepAudits WordPress plugin and theme PHP code for advanced security issues beyond basic sanitization, including object injection, SSRF, CSRF, mass assignment, file inclusion, mail header injection, ZipSlip, type juggling, and TOCTOU races.
Audited 0 -
nagarenegishi Bundle Owasp GuardEnforces OWASP Top 10:2025 compliance on code touching security-relevant domains, using cached cheat sheets and verifying fixes against OSV.dev.
0 -
nagarenegishi Skill Owasp UpdateRefreshes the local OWASP Cheat Sheet Series cache for the current project's language, checking GitHub for updates and fetching changed sheets.
0 -
shulkwisec Bundle Bb HugeInitializes bug bounty hunt workspaces, logs vulnerability findings with severity and evidence, and enriches them throughout a session.
21 -
shulkwisec Bundle Cross Site Scripting Xss Complete Deep DiveProvides a complete deep-dive into Cross-Site Scripting (XSS) with exact payloads and bypass techniques for every PortSwigger lab variant, from apprentice to expert level.
Audited 21 -
shulkwisec Skill XxeDetect and exploit XML External Entity (XXE) injection vulnerabilities in XML parsers, including file disclosure, SSRF, and blind out-of-band exfiltration.
21 -
shulkwisec Skill HackRoutes security testing tasks to the correct vulnerability category, guiding recon, validation, privilege escalation, and chain building for web application and API security assessments.
Audited 21 -
shulkwisec Bundle CodebasePerforms a white-box source code security review structured around OWASP ASVS 5.0, mapping attack surfaces, tracing data flows, and chaining into downstream penetration testing and threat modeling skills.
21 -
shulkwisec Skill Bola IdorDetect and exploit Broken Object Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR) vulnerabilities in APIs and web applications.
Audited 21 -
shulkwisec Skill RemediateGenerates specific, implementable fixes for each vulnerability finding, producing code patches, configuration changes, dependency updates, and IaC fixes with before/after code and verification steps.
21 -
shulkwisec Skill Param FuzzSystematically fuzz web applications for hidden content and input validation vulnerabilities across directories, files, parameters, and authentication bypasses.
21 -
addyosmani Skill Security And HardeningHardens code against vulnerabilities by applying threat modeling, OWASP Top 10 prevention patterns, and secure coding practices for web applications.
Audited 69.5k -
antigravity Skill Cred OmegaDiscovers, classifies, protects, and governs API keys, tokens, secrets, and credentials across all providers with enterprise-grade security auditing and governance.
42.4k -
github Skill MCP Security AuditAudit MCP server configurations for security issues including secrets exposure, shell injection, unpinned dependencies, and unapproved servers.
Audited 36.2k -
trailofbits Bundle Fp CheckVerifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each.
Audited 7k -
trailofbits Bundle Graph EvolutionCompares Trailmark code graphs at two source code snapshots to surface security-relevant structural changes that text diffs miss, such as new attack paths, blast radius growth, and privilege boundary modifications.
7k -
trailofbits Bundle Audit AugmentationProjects external audit findings from SARIF static analysis results and weAudit annotation files onto Trailmark code graphs as annotations and subgraphs, enabling cross-referencing with pre-analysis data like blast radius and taint.
Audited 7k -
trailofbits Bundle Insecure DefaultsDetects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.
Audited 7k -
trailofbits Bundle Agentic Actions AuditorAudits GitHub Actions workflows for security vulnerabilities in AI agent integrations, detecting attack vectors where attacker-controlled input reaches AI agents in CI/CD pipelines.
Audited 7k -
trailofbits Bundle Cairo Vulnerability ScannerScans Cairo/StarkNet smart contracts for 6 critical vulnerability patterns including arithmetic overflow, L1-L2 messaging issues, and signature replay. Use when auditing StarkNet projects.
7k