All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,873
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 241–264 of 26,873 skills
- Netlify DeployDeploy web projects to Netlify using the Netlify CLI (`npx netlify`). Use when the user asks to deploy, host, publish, or link a site/repo on Netlify, including preview and production deploys.Votes: 0GitHub stars: 27,803
- Writing GuidelinesReview docs/prose for Writing Guidelines compliance. Use when asked to "review my docs", "check writing style", "audit prose", "review docs voice and tone", or "check this page against the writing handbook".Votes: 0GitHub stars: 31,706
- Zeroize AuditDetects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data.Votes: 0GitHub stars: 7,287
- Vulnerability Triage BrocardsThis skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty submission", "decide if a finding is valid", "review a security finding", "dismiss a vulnerability", "should we fix this CVE", "prioritize a vulnerability report", or needs to determine whether an incoming vulnerability report warrants investigation. Applies 7 brocards (rules of thumb) to systematically accept, dismiss, or request more information on vulnerability reports, o...Votes: 0GitHub stars: 7,287
- TemplatesUse this template for domain-specific security testing (cryptographic testing, web security methodologies, etc.).Votes: 0GitHub stars: 7,287
- Constant Time TestingMeasures timing side channels in cryptographic implementations by running them, using dudect for statistical analysis and Timecop over Valgrind for dynamic tracing. Covers the formal, symbolic, dynamic, and statistical tool categories and how to read a result. Use when testing whether a running implementation is constant-time, measuring timing variance on a compiled binary, or investigating a suspected timing attack. Not for statically inspecting compiler output — the constant-time-analysis p...Votes: 0GitHub stars: 7,287
- Supply Chain Risk AuditorAudits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or review a dependency tree before an engagement.Votes: 0GitHub stars: 7,287
- Sharp EdgesIdentifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, configuration schemas, cryptographic library ergonomics, or evaluating whether code follows 'secure by default' and 'pit of success' principles. Triggers: footgun, misuse-resistant, secure defaults, API usability, dangerous configuration.Votes: 0GitHub stars: 7,287
- Modern CppGuides C++ code toward modern idioms (C++20/23/26). Use when writing new C++ code, modernizing legacy patterns, or working on security-critical C++. Replaces raw pointers with smart pointers, SFINAE with concepts, printf with std::print, error codes with std::expected.Votes: 0GitHub stars: 7,287
- Let Fate DecideDraws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over asking clarifying questions when the user's tone is casual or playful rather than precision-seeking.Votes: 0GitHub stars: 7,287
- Firebase Apk ScannerScans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzing APK files for Firebase vulnerabilities, performing mobile app security audits, or testing Firebase endpoint security. For authorized security research only.Votes: 0GitHub stars: 7,287
- Token Integration AnalyzerToken integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/ERC721 conformity, checks for 20+ weird token patterns, assesses contract composition and owner privileges, performs on-chain scarcity analysis, and evaluates how protocols handle non-standard tokens. Use when integrating or accepting arbitrary ERC20/ERC721 tokens, auditing a token implementation for standards conformity, or assessing risk from weird toke...Votes: 0GitHub stars: 7,287
- Substrate Vulnerability ScannerScans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.Votes: 0GitHub stars: 7,287
- Secure Workflow GuideGuides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for fuzzing/verification, and reviews manual security areas. Use when securing a smart contract end to end rather than hunting one bug, checking a project on every check-in or before deployment, triaging a Slither report, or asking where to start on smart contract...Votes: 0GitHub stars: 7,287
- Code Maturity AssessorSystematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls, complexity, decentralization, documentation, MEV risks, low-level code, and testing, then produces a scorecard with evidence-based ratings and a priority-ordered roadmap. Use when assessing or scoring the maturity of a smart contract or blockchain codebase, producing a maturity scorecard or evaluation, or judging how mature, well-tested, ...Votes: 0GitHub stars: 7,287
- Audit Context BuildingUnderstand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use when starting an audit, threat model, or architecture review on unfamiliar code, and before any vulnerability-hunting pass.Votes: 0GitHub stars: 7,287
- Agentic Actions AuditorAudits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct expression injection, dangerous sandbox configurations, and wildcard user allowlists. Use when reviewing workflow files that invoke AI coding agents, auditing CI/CD pipeline securit...Votes: 0GitHub stars: 7,287
- Skill ScannerScan agent skills for security issues. Use when asked to "scan a skill",Votes: 0GitHub stars: 1,037
- Gha Security ReviewGitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.Votes: 0GitHub stars: 1,037
- Find BugsFind bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.Votes: 0GitHub stars: 1,037
- Review Security ChangeReview a change for security defects such as secret exposure, injection, authentication/authorization failures, unsafe deserialization, and dependency risk. Use for an independent security perspective on a defined change set.Votes: 0GitHub stars: 67
- Wp Hardening Best PracticesUse when configuring or hardening a WordPress site, editing wp-config.php, writing .htaccess or nginx rules, setting file permissions, or advising on deployment security. Covers security keys, DISALLOW_FILE_EDIT, FORCE_SSL_ADMIN, disabling debug output, blocking PHP execution in uploads, protecting sensitive files, and least-privilege file permissions. Apply proactively when setting up or reviewing a site's configuration.Votes: 0GitHub stars: 43
- Security Auditing Code ReviewUse when auditing or code-reviewing an existing WordPress plugin or theme for security issues, triaging a vulnerability report, or hardening inherited code. Provides a systematic methodology — locate trust boundaries, inventory sensitive sinks, trace their controls and data flows, then triage confirmed issues and report with fixes. Apply proactively before shipping or when reviewing third-party code.Votes: 0GitHub stars: 43
- Secure Plugin DevelopmentUse when starting a new WordPress plugin or theme, scaffolding a plugin file, wiring hooks, or adding any feature that handles requests, options, or output. Establishes the secure-by-default baseline — ABSPATH guard, the capability + nonce + sanitize + escape flow, prepared queries, and safe defaults — and routes to the focused security skills for each concern. Apply proactively at the start of any WordPress build.Votes: 0GitHub stars: 43