All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,873
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 289–312 of 26,873 skills
- Ctf Crypto AttacksCryptographic attack decision tree for CTF crypto. Load for any crypto challenge to identify the primitive (RSA, AES, ECC, DH, hash, PRNG) and select the matching attack. Covers RSA (small e, Wiener, common modulus, Coppersmith, Fermat), AES oracles (ECB, CBC padding, CTR/GCM nonce reuse), ECDSA nonce reuse, LCG/MT state recovery, and hash length extension.Votes: 0GitHub stars: 2
- Ctf Ai SecurityAI and LLM security CTF recipes. Load for any AI hacking category challenge, prompt injection, jailbreak, MCP tool poisoning, agent tool abuse, provided model files, or AI powered filter bypass.Votes: 0GitHub stars: 2
- Sh RouterEntry point / dispatcher for the security-harness. Use when the user asks for any application-security work - 'security review', 'audit this codebase', 'pentest', 'find vulnerabilities', 'check for SQLi/XSS/IDOR/SSRF', 'generate a security report/SARIF'. Interprets the request and routes it to the full sh-security-review pipeline, a single stage, or a single vulnerability-class knowledge base.Votes: 0GitHub stars: 14
- Sh Kb CryptoKnowledge base for finding cryptographic failures - weak hashing/encryption, insecure randomness, hardcoded/static keys and IVs, ECB mode, missing integrity, and predictable tokens. Use when hunting crypto misuse. CWE-327/328/330/326/916, OWASP A02:2021-Cryptographic Failures.Votes: 0GitHub stars: 14
- Sh Kb AuthKnowledge base for finding authentication and session-management failures - weak login, broken JWT/session handling, password/reset flaws, MFA bypass, credential storage issues. Use when hunting authentication (not authorization - see sh-kb-access-control). CWE-287/384/613/620/640, OWASP A07:2021-Identification and Authentication Failures.Votes: 0GitHub stars: 14
- Sh Kb Access ControlKnowledge base for finding broken access control - IDOR/BOLA, missing function-level authorization, privilege escalation, and multi-tenant isolation failures. Use when hunting authorization issues or reviewing whether users can access resources/actions they shouldn't. CWE-284/285/639/862/863, OWASP A01:2021-Broken Access Control.Votes: 0GitHub stars: 14
- 1passwordSecure 1Password CLI (op) access patterns. Use when any task requires reading secrets, tokens, API keys, passwords, or credentials from 1Password. Also use when another skill or workflow needs to retrieve a secret from a vault. Provides secure read patterns and strict rules to prevent secret leakage into conversation context, terminal output, or environment variables visible to Claude. NEVER bypass these patterns by running op commands directly without following the security rules below.Votes: 0GitHub stars: 2
- Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns. Also lazy-loads the security.md / security-controls-org-wide.md / secrets-management.md content migrated from rules/common/ on 2026-06-02.Votes: 0GitHub stars: 12
- Quota StrategyStretch a Claude subscription's usage limits across long unattended runs (milestone loops, overnight orchestration) by reading live usage for each pool — the 5-hour window, the general weekly limit, any separate per-model weekly limit, and Codex's limit — and routing work to a cheaper model, Codex, or the main model by threshold. Use when the user mentions quota, usage limits, "stretch my quota", running overnight, or choosing which model or agent should implement a unit of work.Votes: 0GitHub stars: 2
- Feat StatusUse when the user asks for the state of pwdev-feat plans — 'status do feat', 'quais planos estão pendentes', 'show feature status' — listing pending, complete, with-caveats, failed and resumable plans plus codebase-context health. Read-only. Do NOT use to execute (feat-exec) or query the audit trail (feat-audit).Votes: 0GitHub stars: 3
- Communication StyleThis skill should be used when the user asks about "output formatting", "concise responses", "Matt Pocock planning style", "scannable output", "action steps format", or needs guidance on communication and output formatting rules for Ralph agents.Votes: 0GitHub stars: 2
- Commit PolicyYou are responsible for ensuring that all changes committed to the repository adhere to the strict `commit-guardrails-workflow`.Votes: 0GitHub stars: 2
- Commit Helper 4Generate clear conventional commit messages from git diffs. Use when writing commit messages, reviewing staged changes, or after completing TDD cycles.Votes: 0GitHub stars: 2
- Commit 62Analyzes unstaged changes, stages them, groups logically, commits with conventional commits format, and pushes.Votes: 0GitHub stars: 2
- Commit 57Create a well-structured git commit with descriptive message and push to GitHub. Automatically detects nested repos and commits to the correct repository.Votes: 0GitHub stars: 2
- Commit 34Create atomic conventional git commit following the Commitizen (cz) style and v1.0.0 specificationVotes: 0GitHub stars: 2
- Command Injection Anti PatternSecurity anti-pattern for OS Command Injection vulnerabilities (CWE-78). Use when generating or reviewing code that executes shell commands, runs system processes, or handles user input in command-line operations. Detects shell string concatenation and recommends argument arrays.Votes: 0GitHub stars: 2
- Codex Review 5This skill should be used when the user asks to "review code with codex", "run codex review", "codex review", "check code for issues", "review and fix issues", or wants to review code changes. Provides guidance for using OpenAI Codex CLI review command with automatic issue evaluation and resolution in max 3 iterations.Votes: 0GitHub stars: 2
- Codex 5Use when operating Codex CLI itself (config, profiles, sandbox, approvals, and safe usage patterns).Votes: 0GitHub stars: 2
- Codebase AuditPerforms comprehensive codebase audit checking architecture, tech debt, security, test coverage, documentation, dependencies, and maintainability. Use when auditing a project, assessing codebase health, or asked to audit/analyze the entire codebase.Votes: 0GitHub stars: 2
- Codebase AccessRead files from the currently running project codebase.Votes: 0GitHub stars: 2
- Code Reviewer Security ReviewerSafety Review: Reviews vulnerabilities, authentication, input validation, and OWASP risks.Votes: 0GitHub stars: 2
- Code Review ChecklistCode review guidelines covering code quality, security, and best practices.Votes: 0GitHub stars: 2
- Code Review Checklist 2Code review guidelines covering code quality, security, and best practices.Votes: 0GitHub stars: 2