← all publishers

securityskills

@securityskills source repo

21 published skills

  1. Attack Surface Recon · securityskills
    Map an organization's external attack surface — domains, subdomains, exposed services, leaked credentials, and brand abuse. Use at the start of assessments or for continuous monitoring.
    0
    installs
  2. Soc2 Readiness · securityskills
    Prepare an organization for a SOC 2 Type I or II audit — trust services criteria mapping, evidence collection, control implementation, and remediation planning. Use when starting a SOC 2 journey or preparing for an audit window.
    0
    installs
  3. Malware Triage · securityskills
    Safely triage unknown malware samples — static indicators, sandbox execution, behavior extraction, and reporting. Use when analyzing suspicious files during investigations.
    0
    installs
  4. Gdpr Data Mapping · securityskills
    Build a GDPR-compliant data inventory — record of processing activities, lawful basis mapping, data subject rights readiness, and breach response procedures. Use for GDPR audits and privacy programs.
    0
    installs
  5. Pci Dss Scoping · securityskills
    Scope a PCI DSS environment correctly — cardholder data flows, segmentation validation, and requirements mapping for compliance. Use when preparing for PCI DSS v4.0 assessments.
    0
    installs
  6. JWT Security Review · securityskills
    Audit JSON Web Token implementations for algorithm confusion, weak secrets, missing validation, and token lifecycle flaws. Use when a codebase or API uses JWTs for auth.
    0
    installs
  7. Ssrf Hunting · securityskills
    Find and exploit Server-Side Request Forgery across URL-fetching features, including cloud metadata bypasses and blind SSRF techniques. Use during web assessments and bug bounty hunting.
    0
    installs
  8. Bug Bounty Recon Pipeline · securityskills
    Build an automated, continuously-running reconnaissance pipeline for bug bounty programs — subdomain enumeration, service fingerprinting, and change detection. Use when starting or scaling bug bounty recon.
    0
    installs
  9. Bug Bounty Report Writing · securityskills
    Write bug bounty reports that get triaged quickly and rated accurately — clear impact statements, minimal reproduction steps, and professional tone. Use before submitting any vulnerability report.
    0
    installs
  10. Incident Response Forensics · securityskills
    Perform digital forensics during incident response — evidence preservation, volatile data collection, artifact analysis, and timeline construction. Use when investigating a suspected compromise.
    0
    installs
  11. Secure Code Review · securityskills
    Perform a security-focused code review — map trust boundaries, audit input paths and auth flows, and use vulnerability-class-driven checklists instead of line-by-line skimming. Use on any PR or codebase with security implications.
    0
    installs
  12. Owasp Top10 Analysis · securityskills
    Systematically review a web application against the OWASP Top 10 vulnerability classes with concrete test cases per category. Use for web app assessments and security gate reviews.
    0
    installs
  13. AWS Security Review · securityskills
    Audit AWS environments for IAM privilege escalation, exposed resources, logging gaps, and misconfigurations across accounts. Use for cloud security assessments and hardening reviews.
    0
    installs
  14. Stride Threat Modeling · securityskills
    Run a STRIDE-based threat modeling workshop — diagram the system, enumerate threats per element, rank them, and drive mitigations into the backlog. Use during design reviews and new feature planning.
    0
    installs
  15. Network Segmentation Review · securityskills
    Review network segmentation designs and verify enforcement — VLANs, firewalls, cloud security groups, and zero-trust boundaries. Use when assessing internal network architecture.
    0
    installs
  16. AI Change Evidence · securityskills
    Turn changes authored by AI coding agents into evidence an auditor accepts — provenance, authorization, and mapping to change-management controls. Use when agents contribute to code that falls under SOC 2, ISO 27001, PCI DSS or similar.
    0
    installs
  17. Agentic Sdlc Controls · securityskills
    Review a development pipeline where AI coding agents write, commit and deploy — permission boundaries, approval gates on irreversible actions, credential scope, and what must never be delegated. Use when agents have write access to a repository or an environment.
    0
    installs
  18. Pentest Engagement Methodology · securityskills
    Execute an authorized penetration test end-to-end, from scoping and rules of engagement through reconnaissance, exploitation, post-exploitation, and reporting. Use when planning or running an offensive security engagement.
    0
    installs
  19. Container Image Hardening · securityskills
    Harden Dockerfiles and container images — multi-stage builds, non-root users, minimal base images, and vulnerability gates. Use when building production containers or reviewing Dockerfiles.
    0
    installs
  20. Active Directory Attack Paths · securityskills
    Enumerate and exploit common Active Directory misconfigurations such as Kerberoasting, AS-REP roasting, delegation abuse, and ACL attacks. Use during authorized internal network assessments.
    0
    installs
  21. Kubernetes Security Audit · securityskills
    Audit Kubernetes clusters for RBAC excesses, pod security gaps, network policy holes, and supply-chain risks. Use when reviewing cluster configuration or hardening deployments.
    0
    installs