All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,868
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 73–96 of 26,868 skills
- Ai ConsoleDrive PWN::Plugins::REPL::AIConsole from pwn_eval.Votes: 0GitHub stars: 86
- Model CatalogDrive PWN::AI::ModelCatalog from pwn_eval.Votes: 0GitHub stars: 86
- Security Audit[Code Quality] Use when a workflow step or the user asks for a security review or audit: OWASP Top 10, secrets, supply-chain, infrastructure, CI/CD, AI-agent risks.Votes: 0GitHub stars: 3
- Security Audit[Code Quality] Use when a workflow step or the user asks for a security review or audit: OWASP Top 10, secrets, supply-chain, infrastructure, CI/CD, AI-agent risks.Votes: 0GitHub stars: 3
- JevgrepOperate Jevgrep (`jg`) as optional remote-agent discovery over explicitly scoped skills, wiki pages, or graph source documents. Use only when the user explicitly requests Jevgrep and separately approves transmitting source content and queries to the configured provider with potential cost. Preserve native catalog, exact/LSP/zvec retrieval and Graphify query/path/explain as defaults; Jevgrep does not query or rebuild durable graphs.Votes: 0GitHub stars: 46
- Jev Tool GuardUse `jev_guard_tool_call` immediately before a consequential tool invocation. Do not use it to bypass an approval already required by the user, platform, or policy.Votes: 0GitHub stars: 17
- Jev Task RouterUse `jev_route_task` before committing to an execution path when the task has meaningful ambiguity or risk.Votes: 0GitHub stars: 17
- Customs Trade Compliance通関書類、関税分類、関税最適化、制限当事者スクリーニング、複数の法域にわたる規制コンプライアンスのための成文化された専門知識。15年以上の経験を持つ貿易コンプライアンス専門家に情報。HS分類ロジック、インコターム適用、FTA利用、ペナルティ軽減を含みます。通関許可、関税分類、貿易コンプライアンス、輸入/輸出ドキュメント、または関税最適化を処理するときに使用します。Votes: 0GitHub stars: 17
- Read The Damn DocsUse when implementing, integrating, upgrading, debugging, or answering anything involving third-party APIs, libraries, frameworks, CLIs, cloud services, model/provider SDKs, fast-moving product behavior, user requests for latest/current/official behavior, unfamiliar repo docs/specs, errors that may indicate API drift, or high-stakes auth, security, billing, data, migration, deployment, compliance, or privacy behavior. Forces Codex to web-search for current official docs and read primary docs ...Votes: 0GitHub stars: 17
- Plow AheadUse when the user explicitly wants autonomous progress without routine clarification stops: "plow ahead", "do not stop", "use your best judgment", "keep going until done", "finish while I am away", "do not ask questions unless truly blocked", or similar. Convert ordinary ambiguity into stated assumptions, proceed through implementation and validation, stop only for true blockers, and end with a clear recap of decisions, changes, verification, and residual risk.Votes: 0GitHub stars: 17
- Top Web VulnerabilitiesThis skill should be used when the user asks to \"identify web application vulnerabilities\", \"explain common security flaws\", \"understand vulnerability categories\", \"learn about inject...Votes: 0GitHub stars: 8
- Security Scanning Security HardeningCoordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.Votes: 0GitHub stars: 8
- Security AuditorExpert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation. Handles DevSecOps integration, compliance (GDPR/HIPAA/SOC2), and incident response. Use PROACTIVELY for security audits, DevSecOps, or compliance implementation.Votes: 0GitHub stars: 8
- Mobile Security CoderExpert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns. Use PROACTIVELY for mobile security implementations or mobile security code reviews.Votes: 0GitHub stars: 8
- Backend Security CoderExpert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.Votes: 0GitHub stars: 8
- Api Security Best PracticesImplement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilitiesVotes: 0GitHub stars: 8
- Extracting Credentials From Memory DumpExtract cached credentials, password hashes, Kerberos tickets, and authenticationVotes: 0GitHub stars: 4
- PrCreate a feature branch, commit changes, push, and open a PR to main.Votes: 0GitHub stars: 2
- Audit SecurityScan the codebase for security vulnerabilities. Check OWASP top 10, input validation, auth, crypto, and known BACKLOG security items.Votes: 0GitHub stars: 2
- Secure Coding PracticesAudit code against a 14-domain secure coding checklist derived from OWASP's living sources — the Developer Guide, Cheat Sheet Series, and Proactive Controls — with the original OWASP Secure Coding Practices Quick Reference Guide noted only as the archived historical origin. Covers 14 critical domains including input validation, output encoding, authentication, session management, access control, cryptographic practices, error handling & logging, data protection, communication security, system...Votes: 0GitHub stars: 2
- Owasp Security AuditPerform OWASP-aligned security audits of source code, API handlers, mobile apps, Kubernetes manifests, LLM/agent code, and deployment configuration. Covers the OWASP Top 10 (2025), ASVS 5.0.0 (V1-V17 chapter numbering), MASVS, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the OWASP LLM Top 10 (2026) plus Agentic Applications Top 10 (2026). Use this skill whenever the user asks for a security review, vulnerability audit, threat assessment, compliance check, or hardening guidance — ...Votes: 0GitHub stars: 2
- Verify Libre SecopsInstall the LibreSecOps-Claude-Code plugin pack the way a user does, into a clean Claude Code config and a clean Grok Build home, prove every plugin validates, installs and loads its components, and keep the transcripts. Use when proving a LibreSecOps-Claude-Code PR's Done-when, checking that a plugin change still installs in both CLIs, or reproducing an install bug.Votes: 0GitHub stars: 4
- Review Security IssueGiven a GitHub issue, review the issue for security implications. You'll make a determination if the claim in the issue is legitimate and should be addressed or will be a "won't fix." Trigger keywords - security issue, review security ticket, review security issue.Votes: 0GitHub stars: 3
- Reverse Eng Thick ClientSecurity-test a desktop thick client end to end: map its trust boundaries, then work the local attack surface (config files, credential storage, IPC, update channel) and the network surface (proxying, certificate pinning, hidden APIs). Load for a C/S desktop app in scope — Electron, Qt, .NET WinForms/WPF, or native — an installer to audit, local config/credential storage to assess, named pipes or loopback IPC, an auto-update channel, or a client that hides admin-only API calls.Votes: 0GitHub stars: 20