All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,878
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 481–504 of 26,878 skills
- AmadeusSearch travel with Amadeus: flight offers and prices, airport autocomplete, hotel offers, cheapest dates. Trigger phrases: amadeus, flight search, flight prices, hotel search.Votes: 0GitHub stars: 18
- Security HardeningAudit app security beyond checklists: abuse prevention, API protection, business logic, rate limits, validation.Votes: 0GitHub stars: 4
- Greenhelix Agent Compliance ToolkitEU AI Act Compliance for Autonomous Agents. Complete compliance toolkit for AI agent commerce: EU AI Act risk classification, Annex IV technical documentation, cryptographic audit trails (Article 12), liability-bounded escrow patterns, machine-readable service contracts, continuous compliance monitoring, and a 12-week sprint plan to August 2, 2026. Includes working Python code, contract templates, and checklists.Votes: 0GitHub stars: 9
- Compliance AuditorYou are an enterprise compliance and regulatory specialist using proven patterns from production AI systems (Oracle, IBM Watson Governance). Use when: regulatory expertise, audit types, data subject rights checklist, consent management, data processing.Votes: 0GitHub stars: 9
- SecurityUse when implementing authentication, authorization, input validation, or secrets management — or when auditing an existing service against OWASP Top 10 risks, configuring security headers, or running a STRIDE threat model.Votes: 0GitHub stars: 189
- Srx Initial SetupBring a new or factory-reset Juniper SRX from its shipped state to a reachable, zoned, screened, and minimally policied device. Use when performing first-time setup or Day-0 and Day-1 bring-up on SRX300 or SRX400 Branch, SRX1600 or SRX4120 campus, or SRX4300, SRX4700, or SRX5000 datacenter platforms, when removing or adopting factory-default configuration, when establishing management access, NTP, DNS, and system services, when creating interfaces, zones, and host-inbound-traffic, when applyi...Votes: 0GitHub stars: 2
- Srx Dynamic Ip FeedConfigure, audit, and troubleshoot Juniper SRX dynamic IP objects from HTTPS feeds. Use when handling feed archives, dynamic-address mapping, certificate validation, basic auth, mTLS, session scanning, routing-instance reachability, Recovery Mode after reboot, show security dynamic-address, ipfd logs, or feed and TLS failures. Use srx-policy for SecIntel feeds.Votes: 0GitHub stars: 2
- Soc2 Ngfw ComplianceMap firewall controls, evidence, and gaps to SOC 2 Trust Services Criteria. Use when assessing Type I or II, logical access, operations, change management, logging, vendor access, incident response, operating-effectiveness samples, or CC6.1, CC6.6, CC7.2, and CC8.1. Parse raw configs first.Votes: 0GitHub stars: 2
- Pci Ngfw ComplianceMap firewall controls, evidence, and gaps to PCI DSS v4.0.1. Use when assessing CDE scope, segmentation, Requirement 1, traffic restrictions, six-month rule review, logging, IDS/IPS, admin access, change control, or QSA, ROC, and SAQ evidence. Treat compliance as an environment assessment, not an NGFW certification.Votes: 0GitHub stars: 2
- Parsing Palo ConfigsParse PAN-OS and Panorama XML or set-format exports into the shared firewall schema. Use when input contains vsys, device-group, security rulebase, address-group, application-default, security-profile-group, set deviceconfig, or XML entry/member elements, including audit, conversion, diff, summary, and explanation tasks.Votes: 0GitHub stars: 2
- Parsing Cisco ConfigsParse Cisco ASA and FTD LINA running configurations into the shared firewall schema. Use when input contains show running-config, access-list, access-group, object network, object-group, nameif, security-level, NAT, interfaces, or failover, including audit, conversion, diff, summary, and explanation tasks. For FMC- or FDM-managed Firepower policy exported as JSON, use parsing-firepower-configs instead.Votes: 0GitHub stars: 2
- Iso27001 Ngfw ComplianceMap firewall controls, evidence, and gaps to ISO/IEC 27001:2022 and ISO 27002. Use when assessing ISMS scope, Annex A.8.20-A.8.23, secure configuration, logging, supplier access, change or incident evidence, the Statement of Applicability, audits, or corrective actions. Parse raw configs first.Votes: 0GitHub stars: 2
- Hipaa Ngfw ComplianceMap firewall controls, evidence, and gaps to HIPAA Security Rule safeguards for ePHI. Use when assessing segmentation, access and audit controls, transmission security, risk management, BAA or vendor access, OCR evidence, 45 CFR 164.312, or “HIPPA.” Parse raw configs first.Votes: 0GitHub stars: 2
- Cmmc Nist 800 171 Ngfw ComplianceMap firewall controls, evidence, and gaps to CMMC Level 2 and NIST SP 800-171. Use when assessing CUI boundaries, least privilege, remote access, SSP or POA&M evidence, C3PAO readiness, DFARS 252.204-7012, or requirements such as 3.1.1 and 3.13.1. Parse raw configs first.Votes: 0GitHub stars: 2
- Cis Controls Ngfw ComplianceMap firewall controls, evidence, and gaps to CIS Controls v8/v8.1 safeguards. Use when assessing IG1/IG2/IG3, inventory, secure configuration, access, logging, threat prevention, or safeguard IDs such as 4.2 and 13.3. Excludes product-specific CIS Benchmarks.Votes: 0GitHub stars: 2
- FinecombExhaustive code review and security audit checklist for any language or language mix, for targets the user owns or is authorized to assess. Use when asked to review, audit or security-check directories, packages, repositories (including GitHub or GitLab URLs), files, changes or pull requests, with exclusions, or non-source targets such as binaries, installers, firmware, images, packages, live URLs, hosts, clusters, cloud and SaaS accounts, logs, contract addresses or design docs. Core: root-c...Votes: 0GitHub stars: 7
- Rust SecurityUse when running cargo-audit or cargo-deny, editing deny.toml, triaging a RUSTSEC advisory or CVE in a dependency, vetting a new or updated crate for typosquat, malicious crate, or compromised-release risk, or hardening a Rust parser that reads untrusted files, archives, or binary formats. Not for authentication, secret storage, cryptographic design, or TLS policy (TLS belongs to rust-networking). Triggers on "cargo audit", "cargo deny", "RUSTSEC", "supply chain", "yanked", "path traversal", ...Votes: 0GitHub stars: 2
- Cloudhub云之家(CloudHub)技能:通过 yzj-cli 命令管理云之家产品能力,包括知识库文档(doc)、多维表格(sheet/aitable)、日历日程(calendar)、通讯录(contact)、IM 消息(im/chat,含文件上传)。当用户需要操作文档、多维表格、管理日程会议、查询同事信息、查询本人/当前用户信息(whoami/我是谁)、发送 IM 消息、查询 IM 历史聊天记录、查询最近群组会话、上传本地文件用于 IM 消息、导入文件到知识库时使用。Votes: 0GitHub stars: 45
- Ashrafiucse Dotnet SecurityAudits ASP.NET Core / .NET Framework applications — Razor Html.Raw and Blazor MarkupString XSS, EF Core FromSqlRaw/SqlQueryRaw and Dapper/ADO string-concat SQL injection, BinaryFormatter/ObjectStateFormatter deserialization RCE, hardcoded machineKey → ViewState RCE, XXE via DtdProcessing.Parse, Newtonsoft TypeNameHandling polymorphic gadgets, AllowAnonymous on sensitive endpoints, antiforgery gaps, CORS AllowAnyOrigin+AllowCredentials, open redirect, Process.Start command injection, hardcoded...Votes: 0GitHub stars: 78
- Web2 Vuln ClassesComplete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. Covers IDOR, auth bypass, XSS, SSRF (11 IP bypass techniques), SQLi, NoSQLi, business logic, race conditions, OAuth/OIDC, file upload (10 bypass techniques), GraphQL, LLM/AI (ASI01-ASI10 agentic framework), API misconfig (mass assignment, JWT attacks, prototype pollution, CORS), ATO taxonomy (9 paths), SSTI (Jinja2/Twig/Freemarker/ERB/Spring), subdomain t...Votes: 0GitHub stars: 431
- Triage ValidationFinding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer = kill the finding and move on. Saves N/A ratio.Votes: 0GitHub stars: 431
- Smart Contract AuditComprehensive smart contract security audit framework with multi-expert analysis. Use for full audits of Ethereum / EVM Solidity and Vyper, Solana / SVM Anchor Rust, TON / FunC / Tact, or Sui / Move projects.Votes: 0GitHub stars: 431
- Report WritingBug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.Votes: 0GitHub stars: 431
- Bug BountyComplete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security t...Votes: 0GitHub stars: 431