leo4135
- 9 skills
- 0 followers
- 8 hours ago last updated
- ▌ Owasp Javascript · leo4135Maps JavaScript/TypeScript vulnerabilities to OWASP Top 10 (2021) with detection patterns, code examples, and remediation. Use during security audits, when the user mentions OWASP, or when categorizing security findings.
- ▌ Release Management · leo4135Manages versioning and releases for cursor-javascript-security-skills and projects using these security skills. Use when creating a GitHub release, updating CHANGELOG, tagging versions, or when the user asks about release process for security skills.
- ▌ Supply Chain Security · leo4135Reviews JavaScript project supply chain security including npm provenance, install scripts, CI/CD integrity, typosquatting, and dependency pinning. Use for supply chain audits, SBOM requests, or when the user asks about npm security, package integrity, or software supply chain risks.
- ▌ Security Bug Reporting · leo4135Formats security vulnerability findings and guides responsible disclosure workflows. Use when writing security bug reports, CVE submissions, creating SECURITY.md, or when the user asks how to report a security vulnerability.
- ▌ Framework Security Checks · leo4135 bundleFramework-specific security checks for React, Next.js, Express, Fastify, Vue, Nuxt, Svelte, and Hono. Use when auditing a project built with a specific JavaScript framework or when the user asks for framework security review.
- ▌ Javascript Security Audit · leo4135Orchestrates end-to-end security audits of JavaScript/TypeScript web applications. Use when the user asks for a security audit, vulnerability assessment, security review, penetration test preparation, or wants to find security bugs in a JS/TS project.
- ▌ Threat Modeling · leo4135Creates STRIDE-based threat models for JavaScript/TypeScript web applications. Use when the user asks for threat modeling, attack surface analysis, trust boundary mapping, or security architecture review.
- ▌ Audit Checklists · leo4135Security audit checklists for JavaScript/TypeScript web applications covering authentication, API, frontend, infrastructure, and data protection. Use during security audits, code reviews, or when the user asks for a security checklist.
- ▌ Dependency Audit · leo4135Audits npm/yarn/pnpm dependencies for known vulnerabilities, outdated packages, license risks, and suspicious packages. Use when the user asks for dependency audit, npm audit, CVE check, or supply chain review of packages.