All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,873
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 265–288 of 26,873 skills
- Secrets Credentials ManagementUse when handling passwords, API keys, tokens, or third-party credentials in a WordPress plugin or theme. Hashes passwords with wp_hash_password / wp_check_password, generates tokens with wp_generate_password, keeps secrets out of code and the database in plaintext, and uses Application Passwords for API auth. Prevents credential leakage and insecure storage.Votes: 0GitHub stars: 43
- Authentication Session SecurityUse when code logs users in or out, sets or clears auth cookies, manages session tokens, throttles failed logins, or builds a custom login form in WordPress. Enforces wp_signon() and core session primitives over hand-rolled credential checks, adds brute-force throttling via the wp_authenticate_user filter keyed on username + IP, destroys sessions after password or role changes, makes login error messages uniform to stop user enumeration, and validates redirect_to with wp_safe_redirect() to cl...Votes: 0GitHub stars: 43
- Tax Expert Firm Ai Compliance财税中介机构AI合规专家团:由事务所供给侧总监协调中介机构智能合规咨询、合同涉税评审、法税同审与法务审查等专题专家,助力财税事务所提升合规服务能力。Votes: 0GitHub stars: 45
- Page ViewsUse when updating Cloudflare Web Analytics page-view data, src/_data/pageViews.json, or scripts/update-page-views.mjs.Votes: 0GitHub stars: 20
- Workspace Cleanup SafePerform safe, non-destructive workspace cleanup planning and execution. Use when users ask to tidy disk usage, remove stale artifacts, or clean project directories without risking data loss.Votes: 0GitHub stars: 2
- Setup ValidatorValidate OpenClaw installation safety by checking for common security misconfigurations and setup issues. Use this skill during initial setup, periodic heartbeats, or whenever security validation is required. Checks include: excessive permissions, unsafe plugins, missing sandboxing, outdated dependencies, and more. Provides actionable warnings with fixes and clear documentation for resolving issues.Votes: 0GitHub stars: 2
- Operon GuardPre-flight trust verification for AI agents. Verify behavior, detect injection vulnerabilities, check for PII leaks, and measure reliability before granting Write/Execute permissions.Votes: 0GitHub stars: 2
- Mesh Policy EnforcerEnforce trust, routing, and tool-usage policy in multi-device OpenClaw setups. Use when users need per-device guardrails, sensitive-task pinning, emergency isolation, or policy-driven task placement.Votes: 0GitHub stars: 2
- HimalayaCLI to manage emails via IMAP/SMTP. Use `himalaya` to list, read, write, reply, forward, search, and organize emails from the terminal. Supports multiple accounts and message composition with MML (MIME Meta Language).Votes: 0GitHub stars: 2
- Ai Observability AuditCreate auditable AI operation summaries with run metadata, decision traces, and anomaly signals. Use when users ask for AI observability, periodic audit reports, incident reconstruction, or compliance-style activity tracking.Votes: 0GitHub stars: 2
- Security TriageTriage GitHub security advisories for OpenClaw with high-confidence close/keep decisions, exact tag and commit verification, trust-model checks, optional hardening notes, and a final reply ready to post and copy to clipboard.Votes: 0GitHub stars: 2
- Openclaw Ghsa MaintainerMaintainer workflow for OpenClaw GitHub Security Advisories (GHSA). Use when Codex needs to inspect, patch, validate, or publish a repo advisory, verify private-fork state, prepare advisory Markdown or JSON payloads safely, handle GHSA API-specific publish constraints, or confirm advisory publish success.Votes: 0GitHub stars: 2
- Pstack InterrogateConduct rigorous multi-perspective diff interrogation and code review. Categorize all findings strictly into 'act on', 'consider', 'noted', and 'dismissed' with explicit technical rationale. Use before opening or merging PRs.Votes: 0GitHub stars: 38
- Trace Temporal Gradient InversionTRACE methodology — temporal gradient-inversion attack on embodied RL that autoregressively reconstructs private observation-action trajectories from per-step policy gradients, exploiting cross-time gradient correlation and closed-form action recovery. Use when: (1) auditing privacy leakage of distributed/federated RL gradient streams, (2) designing sequence-aware privacy defenses, (3) threat-modeling gradient sharing in embodied agents. Keywords: gradient inversion, embodied RL, privacy atta...Votes: 0GitHub stars: 3
- SecureUse this skill when the user needs to secure their SaaS app, implement authentication, protect user data, secure APIs, or check for vulnerabilities. Also use when the user says 'is my app secure,' 'security check,' 'I'm worried about hackers,' 'how do I protect user data,' or 'security before launch.' Covers OWASP Top 10, auth best practices, data protection, and security checklists for apps built with AI tools.Votes: 0GitHub stars: 251
- Go LiveUse this skill when the user is about to launch, thinks they're ready to go live, wants a pre-launch checklist, or asks 'am I ready to launch?' This is the quality gate between building/testing and deploying/launching — a single go/no-go decision that checks whether the product is actually ready for real users and real money.Votes: 0GitHub stars: 251
- ComplianceUse this skill when the user is building software for a regulated industry and needs to understand compliance requirements. Also use when the user mentions 'HIPAA,' 'FERPA,' 'SOC 2,' 'PCI,' 'GDPR,' 'compliance,' 'regulated industry,' 'healthcare app,' 'fintech,' 'edtech,' or asks 'do I need to worry about [regulation]?' Covers what regulations mean for your tech stack — not legal theory, but concrete technical requirements.Votes: 0GitHub stars: 251
- PaymentsUse this skill when the user needs to set up Stripe, implement subscriptions, handle billing, configure payment plans, manage failed payments, deal with refunds, set up tax collection, or troubleshoot payment issues. Covers Stripe configuration, subscription lifecycle, dunning, tax compliance, and billing operations for bootstrapped SaaS.Votes: 0GitHub stars: 251
- IntegrationsUse this skill when the user needs to connect third-party services, set up APIs, add OAuth, configure webhooks, or integrate tools like Slack, Zapier, email providers, or payment processors. Covers API integration patterns, auth flows, webhook handling, and building integrations that non-technical founders can maintain.Votes: 0GitHub stars: 251
- Ctf Web VulnsWeb vulnerability attack catalog for CTF. Load when analyzing any web/HTTP challenge to systematically check SQLi, SSTI, SSRF, XXE, IDOR, JWT flaws, prototype pollution, deserialization, path traversal, command injection, open redirect, auth bypass, and race conditions. Provides the fastest confirming test and exploitation path per class.Votes: 0GitHub stars: 2
- Ctf Rev ToolkitReverse engineering toolkit and workflow for CTF rev. Load for any rev challenge to pick the right approach by target type (native ELF/PE, .NET, JVM, Python pyc, WASM, packed/obfuscated), find the flag-gating check, and recover the required input, including angr symbolic execution for constraint-heavy binaries.Votes: 0GitHub stars: 2
- Ctf Pwn PlaybookBinary exploitation playbook for CTF pwn. Load for any pwn challenge to map mitigations to attack techniques: stack overflow, ret2win, ret2libc, ret2csu, ROP, format string, GOT overwrite, one_gadget, and heap techniques (tcache, fastbin, house of force/orange). Includes a pwntools exploit template.Votes: 0GitHub stars: 2
- Ctf Forensics RecipesForensics tool-chain recipes for CTF. Load for any forensics challenge to pick the right recipe by artifact, pcap dissection, memory dumps, disk image carving, Windows artifacts, mobile, timeline analysis, browser, git, containers, steganography, documents.Votes: 0GitHub stars: 2
- Ctf Flag DisciplineFlag handling and anti-guessing discipline for CTF. Load whenever a candidate flag is produced or a challenge nears solving. Enforces the flag format, forbids guessing or brute-forcing flag text, and defines what counts as a proven solve versus an assumption.Votes: 0GitHub stars: 2